Part 4: Personal Data Protection (Amendment) Act 2024 - Update on Malaysia´s Data Protection Guidelines

PrintMailRate-it
​​​​​​​​Following the implementation of the Personal Data Protection (Amendment) Act 2024 (“PDPA 2024”), the Personal Data Protection Commissioner (“Commissioner”) has published several public consultation papers for the development of supplementary guidelines to provide greater clarity and certainty on compliance with the new provisions introduced in the PDPA 2024. Our previous articles highlighting the key amendments introduced in the PDPA 2024 can be accessed h​e​re (Part 1), here​​​ ​(Part 2) and here​​​ (Part 3).
      ​

Published Guidelines

On 25 February 2025, the Commissioner issued the following guidelines: 
      

The Implementation of Data Breach Notification Guideline, which sets out: 

  1. The scope and threshold of notification to the Commissioner and affected data subjects; 
  2. Timeframe for notification; 
  3. The manner and form of notifications;
  4. Management of breached personal data; and
  5. The obligations of data controllers, including record-keeping obligations. 
       

The Appointment of Data Protection Officer (“DPO”) Guideline, which sets out: 

  1. The threshold for mandatory appointment of DPO; 
  2. Expertise, qualifications and residency requirement of DPO;  
  3. Key responsibilities of a DPO; 
  4. Notification of appointment of DPO; and
  5. Obligations of data controller and data processor.
       
On 29 April 2025, the Commissioner issued the Cross-Border Data Transfer Guideline, which sets out: 
  1. New conditions for cross-border transfer under PDPA 2024; 
  2. The adoption of Binding Corporate Rules; 
  3. Applicability of Standard Contractual Clauses; 
  4. Certification mechanism; and
  5. Record-keeping obligations.
​       

Guidelines Pending Issuance by the Commissioner

The Commissioner closed the public consultation papers on 18 October 2024 for the Revised Personal Data Protection Standard 2015 (“PDP Standard”) 2024 and the development of the following guidelines: 
     

The Right to Data Portability Guideline, which discusses the following: 

  1. Compliance requirement with data portability requests; 
  2. Types of personal data that are subject to portability; 
  3. Timeline for responding to data portability requests;
  4. Limitation period for historical data portability; 
  5. Imposition of fees; and
  6. Transmission methods for personal data. 
               

Cross-Border Data Transfer Guideline, which discusses the following: 

  1. New conditions for cross-border transfer under PDPA 2024; 
  2. The adoption of Binding Corporate Rules; 
  3. Applicability of Standard Contractual Clauses; 
  4. Certification mechanism; and
  5. Record-keeping obligations.
      

Ongoing Public Consultation Papers

On 20 March 2025, the Commissioner issued public consultation papers (closing on 19 May 2025) for the development of the following guidelines: 
    
  • Data Protection Impact Assessments – a proactive process to help organizations assess the risks and impacts related to the processing of personal data to ensure compliance with legal requirements.
  • Data Protection by Design and by Default - provides guidance to organizations on integrating data protection at every stage of system and process design.
  • Automated Decision-Making & Profiling - Provides guidance on the regulation of data processing involving automated decision-making and profiling to ensure the protection of individual rights.
     
With the PDPA 2024 and guidelines taking effect from 1 June 2025, organizations are strongly encouraged to review their current data handling practices and begin aligning them with the published guidelines and proposed guidelines to ensure timely compliance.

From The Newsletter

Contact

Contact Person Picture

Geetha Salva

+603 2276 5580

Send inquiry

How We Can Help

Skip Ribbon Commands
Skip to main content
Deutschland Weltweit Search Menu