
Malaysia's Personal Data Protection Act 2010 was written before smartphones were universal and before breach notification was a global norm. The Personal Data Protection (Amendment) Act 2024 closed that gap in three phases across 2025, and the Commissioner's guidelines on breach notification and on the Data Protection Officer role turned the new duties into procedures. For most organisations the question now is whether those procedures exist and have been rehearsed.
Breach notification: two clocks
A data controller must notify the Personal Data Protection Commissioner of a personal data breach as soon as practicable and within 72 hours of becoming aware of it, where the breach causes or is likely to cause significant harm. Where it does, affected data subjects must be notified without undue delay, and in any event within seven days of the notification to the Commissioner.
The Commissioner's Data Breach Notification Guideline sets out what a notification contains and how the harm threshold is judged. The operational lesson from the first year is the same one Europe learned in 2018: the 72-hour clock is unforgiving of organisations that discover breaches slowly, so detection and escalation are as much a privacy control as the notification template itself.
The Data Protection Officer
Controllers and processors meeting the thresholds in the DPO Guideline must appoint a Data Protection Officer, register the appointment with the Commissioner and publish the DPO's contact details. The DPO is accountable for the organisation's compliance programme, is the point of contact for the Commissioner and for data subjects, and must be resourced and independent enough to do the job.
In practice the DPO becomes the owner of the privacy control set: the record of processing, the lawful-basis decisions, the retention schedule, the cross-border transfer assessments and the breach register. A DPO without a system to hold that evidence is a title, not a control.
Processors, portability and penalties
The amendments bind data processors directly to the security principle — previously only controllers carried the obligation — so a cloud provider, payroll bureau or managed service handling personal data now answers for its own safeguards. Data subjects gained a right of data portability. The cross-border transfer regime moved from a whitelist to an adequacy-and-safeguards model. Penalties for breaching the principles rose to a maximum of RM1 million and three years' imprisonment.
Processor obligations are where third-party risk and privacy meet: the supplier register now needs to record which suppliers are processors, what data they hold, and what evidence they have given of their own security measures.
How it compares across the region
For a group operating across Malaysia and the Gulf, the architecture is familiar. Saudi Arabia's PDPL and Bahrain's PDPL also require 72-hour breach notification to the regulator; Qatar's PDPPL and the UAE's federal law expect notification without undue delay; DPO requirements vary from mandatory for qualifying controllers to recommended. The concepts — lawful basis, subject rights, transfer controls, accountability — travel, and so does the evidence.
GRCLens carries the PDPA obligations as an assessable control set beside the GCC privacy laws, mapped where they overlap, so a regional privacy programme records a breach procedure or a transfer assessment once and reports it to each Commissioner in that regulator's terms.
Keep reading

Data protection across the Gulf: KSA PDPL and the UAE compared
Saudi Arabia's PDPL and the UAE's federal data protection law share DNA with global privacy regimes — but the details differ. A side-by-side orientation.

Enhanced CIRMP Rules 2026: What to Do and When
The enhanced CIRMP Rules commenced on 10 June 2026. What nine high-risk asset classes must do, which frameworks now qualify, and the deadlines.

Saudi OTCC and CSCC: Which NCA Controls Apply?
OTCC-1:2022 covers critical OT and ICS. CSCC-1:2019 covers other critical systems. Scope, control counts, facility levels and the ECC link.