
Malaysia’s Privacy Reform Puts DPOs and Breach Notices on the Clock
Malaysia’s 2024 privacy amendments introduced mandatory breach notification, Data Protection Officers for qualifying processing and direct security duties for processors through a three-stage commencement schedule.
Malaysia’s Personal Data Protection (Amendment) Act 2024, Act A1727, received Royal Assent on 9 October 2024 and was published on 17 October. Its provisions did not all begin at once. The commencement order selected 1 January, 1 April and 1 June 2025 for different sections.
The final date was the operational headline. On 1 June 2025, the provisions on Data Protection Officers, personal-data-breach notification and data portability came into operation. By then, April’s changes had already modernised terminology, included biometric data within sensitive personal data, made processors directly responsible for the Security Principle and changed the cross-border-transfer framework.
The result is not simply a revised privacy notice. It is an incident, governance and supplier-management programme.
DPO duties depend on the processing, not the job title
The amended Act provides for controllers and processors to appoint one or more DPOs. The Personal Data Protection Commissioner’s implementation criteria require an appointment when processing involves any of the following:
- personal data relating to more than 20,000 data subjects;
- sensitive personal data, including financial information, relating to more than 10,000 data subjects; or
- regular and systematic monitoring of personal data, such as online behaviour tracking.
That third route matters. A business can fall below both numerical thresholds and still qualify because of how it observes people. The Commissioner’s guidance gives examples including behavioural advertising, algorithmic monitoring of searches and purchases, telecommunications networks, connected devices, wearables and some CCTV activity.
The assessment should therefore cover purposes, technology and monitoring frequency—not just the number of customer rows in a database. It should include employee, applicant, website, mobile-app, loyalty, CCTV and connected-device processing where relevant.
The DPO can be an employee, an outsourced individual or, with sufficient support, serve more than one organisation. The function nevertheless needs suitable expertise, resources, access and independence. Other duties must not create a conflict of interest. The organisation remains accountable; appointing a DPO does not transfer the controller’s or processor’s legal responsibility to that person.
Where the criteria are met, the controller must notify the Commissioner of the DPO appointment. The Commissioner’s FAQ specifies notification through the Personal Data Protection System within 21 days of appointment. Contact information must remain current and accessible.
The breach clock is 72 hours under the official guideline
New section 12B requires a controller that has reason to believe a personal data breach occurred to notify the Commissioner as soon as practicable, in the prescribed manner and form. The Commissioner’s Data Breach Notification Guideline operationalises that duty: a reportable breach must be notified as soon as practicable and no later than 72 hours from its occurrence, applying the knowledge examples and assessment process set out in the guideline.
If a breach causes or is likely to cause significant harm, the controller must also notify affected data subjects without unnecessary delay. The two communications have different audiences and purposes. The regulator needs structured facts and continuing cooperation; the individual needs understandable information about the incident, likely consequences and practical protective steps.
Failure to notify the Commissioner under section 12B is an offence carrying, on conviction, a fine of up to RM250,000, imprisonment for up to two years, or both.
An incident plan should therefore answer four questions before the next alert arrives:
- When does the organisation treat a suspected event as a personal data breach?
- Who decides whether the notification criteria are met?
- Who can submit an initial notification when facts remain incomplete?
- How will the organisation identify and communicate with affected people safely?
A 72-hour requirement is not a 72-hour investigation target. Triage, legal assessment, executive escalation and drafting all consume part of the window.
Processors now have their own security exposure
The April 2025 changes made processors directly subject to the Security Principle when processing for a controller. The related maximum penalty was increased to RM1 million, imprisonment for up to three years, or both.
This changes the contracting conversation. Controllers still need contractual safeguards and oversight, but a processor cannot treat data security solely as its customer’s statutory problem. Each party should know which systems contain Malaysian personal data, which security measures apply, and how a suspected breach moves from a subprocessor to the processor and then to the controller fast enough for the controller’s notification decision.
Contracts should require prompt incident escalation, preservation of evidence, continuing updates, cooperation with notifications and approval rules for subprocessors. A processor’s generic promise to report “without undue delay” may be too vague for an operating procedure built around a 72-hour external deadline.
Build one data-governance map
The amendment also added biometric data to sensitive personal data and introduced a data-portability right subject to technical feasibility and format compatibility. Those changes reinforce the need for a maintained map of data, systems, owners, recipients, processors, retention periods and transfer routes.
One well-governed map can support the DPO threshold assessment, breach scoping, processor oversight, portability requests and cross-border-transfer review. Separate spreadsheets assembled for each obligation will drift and create conflicting answers.
Malaysia’s privacy reform is best understood as an accountability upgrade. The DPO is a governance function, breach notification is a timed response process, and processor security is a direct legal obligation. Organisations that connect those three elements will be better prepared than those that treat the amendment as a one-time policy rewrite.
Official sources
- Personal Data Protection Commissioner: Amendment Act 2024 (Act A1727)
- Federal Government Gazette: appointment of commencement dates
- Personal Data Protection Commissioner: official DPO and PDPA FAQ
- Personal Data Protection Commissioner: Data Breach Notification Guideline
- Personal Data Protection Commissioner: DPO appointment guideline
Continue the series
- Also in Malaysia: Malaysia’s Cyber Security Act Starts a Six-Hour NCII Incident Clock
- Malaysia Cyber & Data Law Series index
This article provides general information and is not legal advice.



