The short version
Is your website still PDPA-compliant after the 2024 amendment? Only if it has been updated. The Personal Data Protection (Amendment) Act 2024 came into force in phases across 2025 and now applies in full. It renamed "data users" as "data controllers", made appointing a Data Protection Officer mandatory for qualifying organisations, introduced a duty to report a data breach to the Commissioner within 72 hours, added a right to data portability, and raised the maximum penalty for a principle breach to RM 1,000,000. A privacy notice written to the old 2010 baseline no longer reflects the law your site operates under.
What changed in the law
The Personal Data Protection (Amendment) Act 2024 (Act A1727) is the first substantial reform of Malaysia's data protection law since the original PDPA came into force in 2013. It was brought in across 2025 in three phases, on 1 January, 1 April and 1 July, and by 2026 it applies in full. This is not a proposal or a consultation draft. It is the law your website already operates under.
The reform is overseen by the Personal Data Protection Commissioner, whose department has since issued the detailed guidelines that put the new duties into practice, including the Guideline on Data Breach Notification, the Guideline on the Appointment of a Data Protection Officer, and the Cross-Border Personal Data Transfer Guideline (Guideline No. 3/2025, issued 29 April 2025).
Most of the change is invisible from the front of a website, which is exactly the problem. A site can look perfectly professional and still carry a privacy notice that describes obligations the law has moved past, names no one accountable for data, and makes promises about data handling that no longer match what the Act requires.
What the amendment now requires
The substantive changes the 2024 amendment introduced. Each one has a direct consequence for how a compliant website presents itself and handles the data it collects.
What your website must now do about it
The translation from statute to site. These are the concrete, checkable things a Malaysian website that collects any personal data should now get right.
What getting it wrong now costs
The 2024 amendment did not only add duties. It sharpened the consequences of ignoring them.
Reading your own site against the amendment
Three quick questions to put to your current website, before a visitor, a client, or the Commissioner does.
If any of these give you pause, the gap is worth closing deliberately. The amendment is fully in force, and "our website was built before the change" is not a defence the Act recognises.
Questions businesses are asking
Is my website still PDPA-compliant after the 2024 amendment?
Only if it has been updated. The Personal Data Protection (Amendment) Act 2024 phased fully into force across 2025. A privacy notice written to the original 2010 baseline no longer reflects the current law, because it will not carry the Data Protection Officer contact, the breach-notification duty, the data-portability right, or the updated data-controller terminology the amendment introduced.
What must a privacy policy include under the amended PDPA?
At minimum, the identity of the data controller, the purposes of collection, a point of contact for the Data Protection Officer where one is required, the data-retention approach, any cross-border transfer of the data, and how individuals can exercise their rights, including the new right to data portability. It should describe genuine opt-in consent rather than pre-ticked boxes.
Do I need to appoint a Data Protection Officer in Malaysia?
The 2024 amendment makes appointing a Data Protection Officer mandatory for data controllers and processors that meet the thresholds set by the Commissioner, under the Guideline on the Appointment of a Data Protection Officer. Where one is required, the DPO should be identifiable and contactable, which usually means naming a contact point on the website.
How quickly must a data breach be reported under the PDPA?
A data controller must notify the Personal Data Protection Commissioner of a personal data breach within 72 hours of becoming aware of it. Affected individuals must be notified without unnecessary delay, and within seven days of notifying the Commissioner where the breach is likely to cause them significant harm.
What is the maximum penalty under the amended PDPA?
The 2024 amendment raised the maximum penalty for breaching a personal data protection principle to a fine of up to RM 1,000,000, imprisonment of up to three years, or both. Failure to meet the breach-notification duty is a separate offence with its own penalty.
A note on what this is
This is a website-practice resource, not legal advice. We build and maintain websites that handle personal data properly; we do not act as your data-protection counsel. The authority here is the Act and the Commissioner's guidelines, published by the Personal Data Protection Department (JPDP) at pdp.gov.my. Read them directly, and where a specific obligation turns on your organisation's size, sector or data, take proper advice. Everything above is our reading of what the amendment means for a website, offered so you know what to look for. For a broader view of what a regulated firm's site should get right, see our 18-point credibility checklist. And if you are an approved insurance or takaful broker, there is a second reason to read your own site closely: Bank Negara's broker conduct rules now count a website as a place where audited accounts may be published, and a signed set of accounts is a document with names in it — see what paragraph 16.1 actually requires.