HomeBlogData Protection
Data Protection

Malaysia's PDPA after the 2024 amendments: 72 hours, a DPO, and processors in scope

Sep 2026 · 7 min read

A steel stopwatch beside a stack of translucent identity cards on a dark navy surface

Malaysia's Personal Data Protection Act 2010 was written before smartphones were universal and before breach notification was a global norm. The Personal Data Protection (Amendment) Act 2024 closed that gap in three phases across 2025, and the Commissioner's guidelines on breach notification and on the Data Protection Officer role turned the new duties into procedures. For most organisations the question now is whether those procedures exist and have been rehearsed.

Breach notification: two clocks

A data controller must notify the Personal Data Protection Commissioner of a personal data breach as soon as practicable and within 72 hours of becoming aware of it, where the breach causes or is likely to cause significant harm. Where it does, affected data subjects must be notified without undue delay, and in any event within seven days of the notification to the Commissioner.

The Commissioner's Data Breach Notification Guideline sets out what a notification contains and how the harm threshold is judged. The operational lesson from the first year is the same one Europe learned in 2018: the 72-hour clock is unforgiving of organisations that discover breaches slowly, so detection and escalation are as much a privacy control as the notification template itself.

The Data Protection Officer

Controllers and processors meeting the thresholds in the DPO Guideline must appoint a Data Protection Officer, register the appointment with the Commissioner and publish the DPO's contact details. The DPO is accountable for the organisation's compliance programme, is the point of contact for the Commissioner and for data subjects, and must be resourced and independent enough to do the job.

In practice the DPO becomes the owner of the privacy control set: the record of processing, the lawful-basis decisions, the retention schedule, the cross-border transfer assessments and the breach register. A DPO without a system to hold that evidence is a title, not a control.

Processors, portability and penalties

The amendments bind data processors directly to the security principle — previously only controllers carried the obligation — so a cloud provider, payroll bureau or managed service handling personal data now answers for its own safeguards. Data subjects gained a right of data portability. The cross-border transfer regime moved from a whitelist to an adequacy-and-safeguards model. Penalties for breaching the principles rose to a maximum of RM1 million and three years' imprisonment.

Processor obligations are where third-party risk and privacy meet: the supplier register now needs to record which suppliers are processors, what data they hold, and what evidence they have given of their own security measures.

How it compares across the region

For a group operating across Malaysia and the Gulf, the architecture is familiar. Saudi Arabia's PDPL and Bahrain's PDPL also require 72-hour breach notification to the regulator; Qatar's PDPPL and the UAE's federal law expect notification without undue delay; DPO requirements vary from mandatory for qualifying controllers to recommended. The concepts — lawful basis, subject rights, transfer controls, accountability — travel, and so does the evidence.

GRCLens carries the PDPA obligations as an assessable control set beside the GCC privacy laws, mapped where they overlap, so a regional privacy programme records a breach procedure or a transfer assessment once and reports it to each Commissioner in that regulator's terms.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles