For Malaysian businesses · A website resource, not legal advice

The PDPA changed in 2025.
What your website must now do.

Malaysia's Personal Data Protection Act was significantly amended in 2024 and phased fully into force across 2025. There are new duties, new penalties, and new terminology, which means a privacy notice written to the old 2010 baseline is now out of date by law. Here is what the amendment changed, what it asks of any Malaysian website that collects personal data, and how to tell whether yours still measures up.

Fully in force since 2025 Cites the regulator's guidelines For any site that collects data

The short version

Is your website still PDPA-compliant after the 2024 amendment? Only if it has been updated. The Personal Data Protection (Amendment) Act 2024 came into force in phases across 2025 and now applies in full. It renamed "data users" as "data controllers", made appointing a Data Protection Officer mandatory for qualifying organisations, introduced a duty to report a data breach to the Commissioner within 72 hours, added a right to data portability, and raised the maximum penalty for a principle breach to RM 1,000,000. A privacy notice written to the old 2010 baseline no longer reflects the law your site operates under.

A

What changed in the law

The Personal Data Protection (Amendment) Act 2024 (Act A1727) is the first substantial reform of Malaysia's data protection law since the original PDPA came into force in 2013. It was brought in across 2025 in three phases, on 1 January, 1 April and 1 July, and by 2026 it applies in full. This is not a proposal or a consultation draft. It is the law your website already operates under.

The reform is overseen by the Personal Data Protection Commissioner, whose department has since issued the detailed guidelines that put the new duties into practice, including the Guideline on Data Breach Notification, the Guideline on the Appointment of a Data Protection Officer, and the Cross-Border Personal Data Transfer Guideline (Guideline No. 3/2025, issued 29 April 2025).

Most of the change is invisible from the front of a website, which is exactly the problem. A site can look perfectly professional and still carry a privacy notice that describes obligations the law has moved past, names no one accountable for data, and makes promises about data handling that no longer match what the Act requires.

B

What the amendment now requires

The substantive changes the 2024 amendment introduced. Each one has a direct consequence for how a compliant website presents itself and handles the data it collects.

01
"Data controller", not "data user"
The Act replaced "data user" with "data controller" throughout. It is a small wording change with a real signal: a privacy notice still using the old term was written before the reform and has likely not been reviewed since.
02
A mandatory Data Protection Officer
Appointing a DPO is now mandatory for data controllers and processors that meet the Commissioner's thresholds. Where one is required, the site needs to make that person contactable.
03
Breach notification within 72 hours
A personal data breach must be reported to the Commissioner within 72 hours of becoming aware of it, and affected individuals notified soon after. That assumes you can detect and trace a breach in the first place.
04
A right to data portability
Individuals can now ask for their personal data to be moved to another controller. Your privacy notice should acknowledge the right and explain, plainly, how someone would exercise it.
05
Biometric data is now sensitive data
From 1 April 2025, biometric data such as fingerprints and facial recognition is classed as sensitive personal data, which carries a higher bar for consent and handling. Relevant the moment a site touches it.
06
Cross-border transfer on an adequacy test
Sending personal data outside Malaysia now turns on whether the destination offers adequate protection. Where your forms, analytics and hosting send data is now a compliance question as much as a technical one.
C

What your website must now do about it

The translation from statute to site. These are the concrete, checkable things a Malaysian website that collects any personal data should now get right.

07
A privacy notice that reflects the amendment
Not the 2010 baseline. It should carry the DPO contact where required, the breach-notification duty, the data-portability right, retention, and any cross-border transfer, written to be read, not to be survived.
08
Name your Data Protection Officer
Where a DPO is required, "who is accountable for our data, and how do I reach them" should have an answer on the site, not be a question a visitor has to raise a ticket to ask.
09
A notice on every form, at the point of collection
A plain-language line next to the submit button explaining what is collected and why, right where the decision to share is being made, rather than a link buried in the footer.
10
Consent that is opt-in, never pre-ticked
A pre-ticked consent box is a compliance failure, not a convenience. The notice-and-choice principle requires a genuine, active choice from the person, not an assumed one.
11
Honest disclosure of analytics and cookies
If the site runs Google Analytics or any tracking, say so, and be aware that much of it sends data abroad, which is now a cross-border question. Silence here reads as either unaware or evasive.
12
Identify the real data controller
The actual legal entity collecting the data, ideally with its SSM registration, not a vague "we". A visitor, and a regulator, should be able to see exactly who is accountable.

What getting it wrong now costs

The 2024 amendment did not only add duties. It sharpened the consequences of ignoring them.

RM 1,000,000
Maximum fine for breaching a personal data protection principle, up from the previous ceiling.
72 hours
To notify the Commissioner of a data breach once you become aware of it. Affected individuals follow soon after.
3 years
Maximum imprisonment for offences under the Act, alongside the fine, or in place of it.

Reading your own site against the amendment

Three quick questions to put to your current website, before a visitor, a client, or the Commissioner does.

Does the privacy notice still say "data user"? If so, it predates the reform and almost certainly has not been reviewed against it.
Can a visitor find who is accountable for their data? A named contact, a DPO where required, not a generic info@ address that answers to no one.
Do you know where your forms send data? Every form, analytics script and embed that pushes data outside Malaysia is now a cross-border question you should be able to answer.

If any of these give you pause, the gap is worth closing deliberately. The amendment is fully in force, and "our website was built before the change" is not a defence the Act recognises.

Q

Questions businesses are asking

Is my website still PDPA-compliant after the 2024 amendment?

Only if it has been updated. The Personal Data Protection (Amendment) Act 2024 phased fully into force across 2025. A privacy notice written to the original 2010 baseline no longer reflects the current law, because it will not carry the Data Protection Officer contact, the breach-notification duty, the data-portability right, or the updated data-controller terminology the amendment introduced.

What must a privacy policy include under the amended PDPA?

At minimum, the identity of the data controller, the purposes of collection, a point of contact for the Data Protection Officer where one is required, the data-retention approach, any cross-border transfer of the data, and how individuals can exercise their rights, including the new right to data portability. It should describe genuine opt-in consent rather than pre-ticked boxes.

Do I need to appoint a Data Protection Officer in Malaysia?

The 2024 amendment makes appointing a Data Protection Officer mandatory for data controllers and processors that meet the thresholds set by the Commissioner, under the Guideline on the Appointment of a Data Protection Officer. Where one is required, the DPO should be identifiable and contactable, which usually means naming a contact point on the website.

How quickly must a data breach be reported under the PDPA?

A data controller must notify the Personal Data Protection Commissioner of a personal data breach within 72 hours of becoming aware of it. Affected individuals must be notified without unnecessary delay, and within seven days of notifying the Commissioner where the breach is likely to cause them significant harm.

What is the maximum penalty under the amended PDPA?

The 2024 amendment raised the maximum penalty for breaching a personal data protection principle to a fine of up to RM 1,000,000, imprisonment of up to three years, or both. Failure to meet the breach-notification duty is a separate offence with its own penalty.

A note on what this is

This is a website-practice resource, not legal advice. We build and maintain websites that handle personal data properly; we do not act as your data-protection counsel. The authority here is the Act and the Commissioner's guidelines, published by the Personal Data Protection Department (JPDP) at pdp.gov.my. Read them directly, and where a specific obligation turns on your organisation's size, sector or data, take proper advice. Everything above is our reading of what the amendment means for a website, offered so you know what to look for. For a broader view of what a regulated firm's site should get right, see our 18-point credibility checklist. And if you are an approved insurance or takaful broker, there is a second reason to read your own site closely: Bank Negara's broker conduct rules now count a website as a place where audited accounts may be published, and a signed set of accounts is a document with names in it — see what paragraph 16.1 actually requires.

No pitch, no package

Send me your site. I'll tell you where it stands against the amended PDPA.

No sales call attached. Send me your website and I'll give you an honest read on where its privacy handling sits against the 2024 amendment, the notice still written for the old law, the forms with no notice of their own, the analytics quietly sending data abroad. You will come away knowing exactly what needs fixing, whether you fix it with us or not.

Get in touch →