🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
MY · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 12 sources retrieved model claude-sonnet-5 ·

Malaysia

MY schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 64 claims · 12 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
64Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute in force with a fully commenced modernising amendment; core institutional architecture (Commissioner + PDP) is stable and actively issuing implementing guidance.

Primary frameworkPersonal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — GreenComprehensive statute in force with a fully commenced modernising amendment; core institutional architecture (Commissioner + PDP) is stable and actively issuing implementing guidance.

Sub-modules (5)

Regulator And AuthorityGreen

The Commissioner, assisted by PDP, administers and enforces the PDPA.

Claims: CLM-MY-00000001

Act And InstrumentsGreen

PDPA 2010 in force since 15 November 2013; Amendment Act 2024 gazetted 17 October 2024 with staged commencement through 1 June 2025.

Claims: CLM-MY-00000002, CLM-MY-00000003

Material ScopeGreen

PDPA covers processing of personal data in commercial transactions by an establishment in Malaysia or using equipment in Malaysia.

Claims: CLM-MY-00000004

Territorial ScopeAmber

Extraterritorial reach is anchored to use of equipment in Malaysia rather than a pure establishment test; transit-only data is excluded.

Claims: CLM-MY-00000005

Regulator Registration And FilingGreen

PDP mandates registration of 13 designated classes of data controllers/users, and separately requires DPO-appointment notification within 21 days via a dedicated registration manual.

Claims: CLM-MY-00000006, CLM-MY-00000007

Category narrative94 words

Malaysia's data-protection regime is anchored in the Personal Data Protection Act 2010 (Act 709, 'PDPA'), administered by the Personal Data Protection Commissioner supported by the Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, 'PDP'). The regime was materially modernised by the Personal Data Protection (Amendment) Act 2024, gazetted 17 October 2024 following Royal Assent, and commenced in three stages across 1 January, 1 April and 1 June 2025, bringing DPO appointment, mandatory breach notification, portability, processor accountability and revised cross-border rules into force. As of this run all staged provisions are in force.

Sources and claims (7)
  1. ConfirmedDataGuidanceThe PDPA confers powers to the Personal Data Protection Commissioner, who is assisted by the Department of Personal Data Protection (PDP) to administer and enforce the provisions of the PDPA.
  2. ConfirmedDataGuidanceThe Personal Data Protection (Amendment) Act 2024 was published in the Gazette on 17 October 2024 after receiving Royal Assent on 9 October 2024, following passage by the Senate (31 July 2024) and House of Representatives (16 July 2024).
  3. ConfirmedDataGuidanceThe Amendment Act's provisions were implemented in stages, with sections coming into effect on 1 January, 1 April, and 1 June 2025, covering biometric data, controller/processor terminology, cross-border transfer rules, DPO appointment, breach notification and portability respectively.
  4. ConfirmedDataGuidanceThe PDPA regulates the processing of personal data in commercial transactions either by an establishment in Malaysia or with equipment in Malaysia, unless the personal data only transits through Malaysia.
  5. ProbableDataGuidanceExtraterritorial application of the PDPA turns on use of equipment located in Malaysia (an equipment-based test), rather than a GDPR-style establishment/targeting test; data merely transiting Malaysia is expressly excluded.
  6. ConfirmedDataGuidancePDP mandates registration for 13 designated classes/groups of data controllers under the PDPA, with penalties for non-compliance with the registration requirement.
  7. ConfirmedDataGuidanceControllers and processors must notify the Commissioner of DPO appointments; PDP's DPO registration manual requires such notification within 21 days of appointment.

#

Core consent/sensitive-data architecture is well evidenced and in force, but consent-threshold specifics (freely-given/withdrawal standard) and pseudonymisation/anonymisation treatment were not confirmed via primary-source retrieval in this run.

Primary frameworkPersonal Data Protection Act 2010, ss.6 and 40, as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — AmberCore consent/sensitive-data architecture is well evidenced and in force, but consent-threshold specifics (freely-given/withdrawal standard) and pseudonymisation/anonymisation treatment were not confirmed via primary-source retrieval in this run.

Sub-modules (4)

Lawful BasesAmber

Consent is the primary lawful basis; limited statutory exceptions exist for contract performance/formation and legal-obligation compliance. Malaysia lacks a standalone legitimate-interest basis.

Claims: CLM-MY-00000008, CLM-MY-00000009, CLM-MY-00000010

Special CategoriesGreen

Biometric data is newly classified as sensitive personal data under the Amendment Act; deceased-persons' data is expressly placed outside the Act's scope.

Claims: CLM-MY-00000011, CLM-MY-00000012

Pseudonymisation And AnonymisationRed

No PDPA provision defining pseudonymisation or an anonymisation safe-harbour was located in the reviewed primary text or amendment commentary.

Claims: CLM-MY-00000014

Category narrative83 words

The PDPA operates on a consent-centric lawfulness model rather than a GDPR-style multi-basis Article 6 structure: general personal data requires data-subject consent (with limited contract/legal-obligation exceptions), and sensitive personal data requires compliance with the dedicated section 40 regime. Malaysia is noted among APAC jurisdictions as presently lacking a stand-alone 'legitimate interest' basis. The 2024 Amendment Act's headline change to this module is the addition of biometric data as a new sensitive-personal-data category, alongside express exclusion of deceased persons' data from the Act's application.

Sources and claims (7)
  1. ConfirmedDataGuidance (hosted copy of official Act text)Under section 6(1) of the PDPA, a data user must not process personal data unless the data subject has given consent, or, for sensitive personal data, unless processing accords with section 40.
  2. ConfirmedDataGuidance (hosted copy of official Act text)Notwithstanding the general consent requirement, section 6(2) permits processing necessary for performance of, or steps toward, a contract with the data subject, or for compliance with a legal obligation.
  3. ProbablePDPC SingaporeMalaysia is identified, alongside China, India and Vietnam, as one of the reviewed Asia-Pacific jurisdictions that presently lacks a distinct legitimate-interest lawful basis for processing personal data.
  4. ConfirmedIAPPThe Amendment Act recognises biometric data as sensitive personal data, defined as personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person.
  5. ConfirmedIAPPData of deceased persons is excluded from the Amendment Act and placed expressly outside the PDPA's application.
  6. UncertainDataGuidance (hosted copy of official Act text)No confirmed primary-source detail was retrieved in this research pass specifying the PDPA's precise consent-validity thresholds (e.g., freely-given, specific, withdrawal mechanics) as amended.
  7. UncertainDataGuidance (hosted copy of official Act text)No express PDPA provision defining pseudonymisation or providing an anonymisation safe-harbour was identified in the reviewed Act text or Amendment Act commentary.

#

Access, correction and (newly) portability rights are well evidenced and in force; restriction/objection rights and precise response deadlines remain unconfirmed gaps.

Primary frameworkPersonal Data Protection Act 2010, Division 4 (ss.30-37), as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — AmberAccess, correction and (newly) portability rights are well evidenced and in force; restriction/objection rights and precise response deadlines remain unconfirmed gaps.

Sub-modules (5)

Access RightGreen

Access Principle (s.12) and Division 4 right of access to personal data are confirmed in force.

Claims: CLM-MY-00000015

Rectification And ErasureAmber

A right to correct personal data exists (ss.34-37); no GDPR-style general 'right to erasure' beyond the controller's retention-destruction duty was confirmed.

Claims: CLM-MY-00000016

Restriction And ObjectionRed

No explicit restriction-of-processing or objection/profiling opt-out right was confirmed via retrieved Malaysia-specific sources in this run.

Claims: CLM-MY-00000018

Data PortabilityGreen

The Amendment Act introduces a portability right, qualified by technical feasibility and format compatibility, effective from the final commencement stage.

Claims: CLM-MY-00000017

Deadlines And Response WindowsRed

No confirmed Malaysia-specific statutory day-count for responding to access/correction requests was retrieved in this run.

Claims: CLM-MY-00000019

Category narrative80 words

The PDPA's Division 4 (ss.30-37) establishes a right of access and a right to correct personal data, underpinned by the Access Principle (s.12). The 2024 Amendment Act adds a new right to data portability, subject to technical feasibility and format compatibility. However, unlike the GDPR, no explicit standalone right to restriction of processing or to object (including profiling opt-out) was confirmed, and the specific statutory response-window (day count) for access/correction requests was not confirmed via primary-source retrieval in this run.

Sources and claims (5)
  1. ConfirmedDataGuidance (hosted copy of official Act text)Under the Access Principle (section 12) and Division 4 of the PDPA, a data subject shall be given access to his personal data held by a data user, except where compliance with the access request is refused under the Act.
  2. ConfirmedDataGuidance (hosted copy of official Act text)The PDPA provides a statutory right to correct personal data (sections 34-37), including circumstances in which a data user may refuse a correction request and must notify the data subject of such refusal.
  3. ConfirmedIAPPThe Amendment Act grants data subjects a right to data portability, allowing transfer of their data between controllers, subject to the technical feasibility and compatibility of the data format.
  4. UncertainDataGuidance (hosted copy of official Act text)No explicit standalone right to restrict processing or to object to processing/profiling (analogous to GDPR Arts 18/21) was identified in the reviewed PDPA text or Amendment Act commentary.
  5. UncertainDataGuidanceNo confirmed Malaysia-specific statutory response-window (day count) for access or correction requests under PDPA sections 31/35 was retrieved in this research pass.

#

DPO, breach-notification, security and retention duties are strongly evidenced and in force; DPIA/ROPA/joint-controller equivalents remain unconfirmed gaps versus the GDPR baseline.

Primary frameworkPersonal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — AmberDPO, breach-notification, security and retention duties are strongly evidenced and in force; DPIA/ROPA/joint-controller equivalents remain unconfirmed gaps versus the GDPR baseline.

Sub-modules (7)

Accountability And DpiaRed

A general accountability principle underlies the PDPA; no DPIA-specific obligation was confirmed for Malaysia in this run.

Claims: CLM-MY-00000026

Dpo RequirementsGreen

Mandatory DPO appointment for qualifying controllers/processors, with notification to the Commissioner within 21 days, effective from the final 2025 commencement stage.

Claims: CLM-MY-00000020, CLM-MY-00000021

Ropa RequirementsRed

No Article-30-style records-of-processing obligation was confirmed for Malaysia in the reviewed materials.

Claims: CLM-MY-00000027

Joint Controller ArrangementsRed

No explicit joint-controller regime analogous to GDPR Art 26 was confirmed for Malaysia.

Claims: CLM-MY-00000028

Security MeasuresGreen

The Amendment Act extends the security principle to data processors directly, not solely controllers.

Claims: CLM-MY-00000024

Breach NotificationGreen

Mandatory notification of the Commissioner within 72 hours of becoming aware of a breach, with sanctions for non-compliance.

Claims: CLM-MY-00000022, CLM-MY-00000023

Retention And DisposalGreen

Data users must take reasonable steps to destroy or permanently delete personal data no longer required for its processing purpose.

Claims: CLM-MY-00000025

Category narrative59 words

The Amendment Act materially expands controller/processor duties: mandatory DPO appointment, mandatory 72-hour breach notification to the Commissioner, and extension of the security principle directly to data processors (not just controllers). A pre-existing retention/disposal duty requires destruction of data no longer needed. However, GDPR-equivalent DPIA, ROPA (Article 30 records) and joint-controller-arrangement provisions were not confirmed in the reviewed Malaysia-specific materials.

Sources and claims (9)
  1. ConfirmedDataGuidanceThe Amendment Act introduces a mandatory Data Protection Officer appointment obligation for qualifying data controllers and processors.
  2. ConfirmedDataGuidanceControllers and processors must notify the Data Protection Commissioner of DPO appointments, via a registration manual requiring notification within 21 days of appointment.
  3. ConfirmedDataGuidanceData controllers must notify the Commissioner of a data breach within 72 hours after becoming aware of the breach, and must also notify affected data subjects within specified time frames.
  4. ConfirmedIAPPEnhanced enforcement powers under the Amendment Act increase fines for PDPA violations to up to MYR1 million, extend the maximum imprisonment term to three years, and empower the Commissioner to conduct proactive compliance audits.
  5. ConfirmedDataGuidanceThe amended PDPA enhances data subjects' rights to data portability and requires data processors, not just controllers, to adhere to the security principle.
  6. ConfirmedDataGuidance (hosted copy of official Act text)It is the duty of a data user to take all reasonable steps to ensure that all personal data is destroyed or permanently deleted if it is no longer required for the purpose for which it was processed.
  7. UncertainDataGuidanceNo PDPA/Amendment-Act provision imposing a formal Data Protection Impact Assessment obligation (analogous to GDPR Art 35) was confirmed in the reviewed Malaysia-specific materials.
  8. UncertainDataGuidanceNo PDPA/Amendment-Act obligation to maintain formal records of processing activities (analogous to GDPR Art 30) was confirmed in the reviewed Malaysia-specific materials.
  9. UncertainDataGuidance (hosted copy of official Act text)No PDPA provision establishing a joint-controller regime analogous to GDPR Art 26 was identified in the reviewed Act text or Amendment Act commentary.

#

Transfer mechanism and TIA obligation are well evidenced and in force; the specific whitelist, adequacy-received status, and SCC/BCR/localisation architecture remain unconfirmed.

Primary frameworkPersonal Data Protection Act 2010, Part V, as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — AmberTransfer mechanism and TIA obligation are well evidenced and in force; the specific whitelist, adequacy-received status, and SCC/BCR/localisation architecture remain unconfirmed.

Sub-modules (6)

Transfer MechanismsGreen

Transfers permitted to adequate/whitelisted countries, under public-interest circumstances, or with data-subject consent.

Claims: CLM-MY-00000029

Adequacy ReceivedRed

No evidence located of Malaysia having received a formal adequacy determination from another regime (e.g., EU/UK).

Claims: CLM-MY-00000032

Adequacy GrantedAmber

No published list of countries Malaysia has designated as having 'adequate' protection was retrieved in this run, though PDP issued cross-border transfer guidelines in April 2025.

Claims: CLM-MY-00000031

Sccs And BcrsAmber

Malaysia's transfer regime relies on a whitelist-plus-consent model rather than an EU-style SCC/BCR mechanism.

Claims: CLM-MY-00000033

Transfer Impact AssessmentGreen

The Amendment Act introduces a Transfer Impact Assessment requirement for cross-border transfers.

Claims: CLM-MY-00000030

Data LocalisationRed

No general data-localisation mandate was confirmed for commercial personal data in the reviewed sources.

Claims: CLM-MY-00000034

Category narrative76 words

The PDPA permits cross-border transfers to jurisdictions with adequate data protection laws ('whitelisted' countries), under circumstances of public interest, or with data-subject consent. The 2024 Amendment Act tightens this regime by requiring data controllers to undertake Transfer Impact Assessments and a more rigorous assessment of the receiving country's protections, while leaving existing mechanisms such as consent-based transfers unchanged. No formal SCC or BCR instrument, published adequacy whitelist, or data-localisation mandate was confirmed in the reviewed sources.

Sources and claims (6)
  1. ConfirmedIAPPThe PDPA permits international transfers of personal data where the receiving country has adequate data protection laws (a 'whitelisted' jurisdiction) or under circumstances of public interest; consent-based transfer remains an available mechanism.
  2. ConfirmedDataGuidanceThe Amendment Act revises cross-border transfer mechanisms to require Transfer Impact Assessments (TIAs) by data controllers, including a more rigorous assessment of the receiving country's data protection framework.
  3. UncertainDataGuidancePDP published cross-border data transfer guidelines in April 2025 implementing the amended transfer regime, though the specific countries treated as having 'adequate' protection were not enumerated in the retrieved sources.
  4. UncertainDataGuidanceNo evidence was located in this research pass that Malaysia has received a formal adequacy determination from the EU, UK or another comprehensive-regime regulator.
  5. ProbableIAPPMalaysia's cross-border transfer regime is structured around whitelisted-country adequacy and consent-based mechanisms rather than a distinct SCC or BCR instrument comparable to the EU model.
  6. UncertainDataGuidanceNo general data-localisation mandate applicable to commercial personal data was identified in the reviewed PDPA/Amendment Act materials.

#

Financial-sector overlay mechanism is evidenced; other sectoral overlays are unconfirmed gaps in this research pass.

Primary frameworkPersonal Data Protection Act 2010, ss.23-29 (Codes of Practice)
Traffic-light rationale — AmberFinancial-sector overlay mechanism is evidenced; other sectoral overlays are unconfirmed gaps in this research pass.

Sub-modules (7)

Financial Sector OverlayAmber

PDP designates industry classes required to register and approves/registers sector Codes of Practice, including for financial-sector data users.

Claims: CLM-MY-00000035

Health Sector OverlayRed

No Malaysia-specific health-sector data-protection overlay was confirmed in this run.

Claims: CLM-MY-00000036

Telecoms And EprivacyRed

No Malaysia-specific telecoms/ePrivacy overlay was confirmed in this run.

Claims: CLM-MY-00000037

Employment DataRed

No Malaysia-specific employment-data overlay was confirmed in this run.

Claims: CLM-MY-00000038

Credit And ScoringRed

No Malaysia-specific credit-scoring overlay was confirmed in this run.

Claims: CLM-MY-00000039

EducationRed

No Malaysia-specific education-sector overlay was confirmed in this run.

Claims: CLM-MY-00000040

InsuranceRed

No Malaysia-specific insurance-sector overlay was confirmed in this run.

Claims: CLM-MY-00000041

Category narrative51 words

The PDPA is the general commercial-transactions statute, and PDP is empowered to designate industry classes for registration and to approve sector-specific Codes of Practice (including for the financial sector). Beyond the financial-sector overlay, no health-, telecoms-, employment-, credit-scoring-, education- or insurance-specific overlay statute was confirmed via Malaysia-specific retrieval in this run.

Sources and claims (7)
  1. ProbableDataGuidancePDP can designate the industry classes and business entities required to register, and approve and register Personal Data Protection Codes of Practice for various industry sectors, including the financial sector.
  2. UncertainDataGuidanceNo confirmed Malaysia-specific health-sector data-protection overlay statute or Code of Practice was located in this research pass.
  3. UncertainDataGuidanceNo confirmed Malaysia-specific telecoms/ePrivacy overlay statute was located in this research pass.
  4. UncertainDataGuidanceNo confirmed Malaysia-specific employment-data overlay was located in this research pass.
  5. UncertainDataGuidanceNo confirmed Malaysia-specific credit-scoring overlay was located in this research pass.
  6. UncertainDataGuidanceNo confirmed Malaysia-specific education-sector overlay was located in this research pass.
  7. UncertainDataGuidanceNo confirmed Malaysia-specific insurance-sector overlay was located in this research pass.

#

No comprehensive adtech/commercial-privacy regime was confirmed for Malaysia in this research session; this is treated as an explicit evidentiary gap rather than a substantive finding of 'no regulation'.

Traffic-light rationale — RedNo comprehensive adtech/commercial-privacy regime was confirmed for Malaysia in this research session; this is treated as an explicit evidentiary gap rather than a substantive finding of 'no regulation'.

Sub-modules (6)

Cookies And TrackersRed

No Malaysia-specific cookie/tracker consent rule confirmed.

Claims: CLM-MY-00000042

Dark PatternsRed

No Malaysia-specific dark-pattern prohibition confirmed.

Claims: CLM-MY-00000043

Opt Out SignalsRed

No Malaysia-specific recognition of Global Privacy Control/DAA-style opt-out signals confirmed.

Claims: CLM-MY-00000044

Clean Rooms And DcrRed

No Malaysia-specific clean-room/data-collaboration-room rule confirmed.

Claims: CLM-MY-00000045

Cross Context AdvertisingRed

No Malaysia-specific cross-context-advertising ('sale'/'share') rule confirmed.

Claims: CLM-MY-00000046

Direct MarketingRed

A search for a PDPA direct-marketing/Do-Not-Call provision returned Singapore PDPA results (section 43/DNC Provisions), which were deliberately excluded as out-of-scope for the MY JID; no Malaysia-specific direct-marketing suppression regime was confirmed.

Claims: CLM-MY-00000047

Category narrative50 words

No Malaysia-specific cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal (GPC/DAA) recognition, clean-room rule, cross-context-advertising rule, or direct-marketing/Do-Not-Call regime was confirmed in this research pass. A targeted search for a PDPA direct-marketing provision returned only Singapore PDPA 'Do Not Call' materials, underscoring a JID-disambiguation risk that was deliberately avoided rather than mis-attributed.

Sources and claims (6)
  1. UncertainDataGuidanceNo Malaysia-specific cookie/tracker consent regime was identified in the sources reviewed in this research pass.
  2. UncertainDataGuidanceNo Malaysia-specific dark-pattern prohibition was identified in the sources reviewed in this research pass.
  3. UncertainDataGuidanceNo Malaysia-specific recognition of technical opt-out signals (e.g., Global Privacy Control, DAA) was identified in the sources reviewed in this research pass.
  4. UncertainDataGuidanceNo Malaysia-specific clean-room or data-collaboration-room rule was identified in the sources reviewed in this research pass.
  5. UncertainDataGuidanceNo Malaysia-specific cross-context-advertising rule analogous to CPRA 'sale'/'share' concepts was identified in the sources reviewed in this research pass.
  6. UncertainDataGuidance (hosted copy of official Act text)A targeted search for a Malaysian PDPA direct-marketing/consent-suppression provision (analogous to a 'section 43' Do-Not-Call regime) returned only Singapore PDPA materials; no Malaysia-specific direct-marketing suppression mechanism was confirmed in this research pass.

#

Biometric-data governance is confirmed and in force; all other sub-modules in this space remain unconfirmed gaps.

Primary frameworkPersonal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 (biometric data provisions)
Traffic-light rationale — AmberBiometric-data governance is confirmed and in force; all other sub-modules in this space remain unconfirmed gaps.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction provision analogous to GDPR Art 22 confirmed.

Claims: CLM-MY-00000049

Automated Decision Making TransparencyRed

No ADM-transparency/explanation right confirmed.

Claims: CLM-MY-00000050

Ai Risk AssessmentsRed

No AI-specific risk-assessment obligation confirmed.

Claims: CLM-MY-00000051

Biometric RegimeGreen

Biometric data is now categorised as sensitive personal data under the Amendment Act, subject to stricter processing requirements.

Claims: CLM-MY-00000048

Genetic DataRed

No Malaysia-specific genetic-data-specific regime confirmed in this run.

Claims: CLM-MY-00000052

State Surveillance CarveoutsRed

No state-surveillance carveout provision confirmed in this run.

Claims: CLM-MY-00000053

Category narrative36 words

The Amendment Act's classification of biometric data as sensitive personal data is the principal confirmed finding in this module. No profiling-restriction, ADM-transparency, AI-specific risk-assessment, genetic-data-specific, or state-surveillance-carveout provision was confirmed via Malaysia-specific retrieval in this run.

Sources and claims (6)
  1. ConfirmedDataGuidanceBiometric data is now recognised as sensitive personal data under the Amendment Act, subject to stricter processing requirements than general personal data.
  2. UncertainDataGuidanceNo PDPA/Amendment-Act provision restricting automated profiling analogous to GDPR Article 22 was identified in the reviewed materials.
  3. UncertainDataGuidanceNo PDPA/Amendment-Act automated-decision-making transparency or explanation right was identified in the reviewed materials.
  4. UncertainDataGuidanceNo AI-specific risk-assessment obligation interfacing with the PDPA was identified in the reviewed materials.
  5. UncertainDataGuidance (hosted copy of official Act text)No Malaysia-specific genetic-data-specific processing regime distinct from the general sensitive-personal-data category was confirmed in this research pass.
  6. UncertainDataGuidance (hosted copy of official Act text)No PDPA provision on national-security/state-surveillance carveouts and their limits was confirmed in this research pass.

#

No comprehensive children/vulnerable-groups regime was confirmed for Malaysia in this research session; this is an explicit evidentiary gap requiring primary-source escalation, not a substantive finding of 'no protection exists'.

Traffic-light rationale — RedNo comprehensive children/vulnerable-groups regime was confirmed for Malaysia in this research session; this is an explicit evidentiary gap requiring primary-source escalation, not a substantive finding of 'no protection exists'.

Sub-modules (5)

Age VerificationRed

No Malaysia-specific age-of-consent threshold for data processing was confirmed.

Claims: CLM-MY-00000054

Minor Profiling BansRed

No Malaysia-specific minor-profiling ban was confirmed.

Claims: CLM-MY-00000056

Education SettingsRed

No Malaysia-specific education-settings data rule was confirmed.

Claims: CLM-MY-00000057

Dependent AdultsRed

No Malaysia-specific dependent-adult (elderly/incapacitated) protection was confirmed.

Claims: CLM-MY-00000058

Category narrative47 words

No Malaysia-specific age-of-consent, parental-consent mechanism, minor-profiling ban, education-settings rule, or dependent-adult protection was confirmed via Malaysia-specific retrieval in this research pass. Searches for PDPA children/minor provisions in the Amendment Act returned no Malaysia-specific results; adjacent PDPC Singapore children's-data guidance was excluded as out-of-scope for the MY JID.

Sources and claims (5)
  1. UncertainDataGuidance (hosted copy of official Act text)No express age-of-consent threshold for personal-data processing was identified in the reviewed PDPA/Amendment Act materials.
  2. UncertainDataGuidance (hosted copy of official Act text)No express parental/guardian-consent mechanism for processing a minor's personal data was identified in the reviewed PDPA/Amendment Act materials.
  3. UncertainDataGuidance (hosted copy of official Act text)No minor-specific profiling ban was identified in the reviewed PDPA/Amendment Act materials.
  4. UncertainDataGuidance (hosted copy of official Act text)No education-settings-specific data-protection rule was identified in the reviewed PDPA/Amendment Act materials.
  5. UncertainDataGuidance (hosted copy of official Act text)No dependent-adult (elderly/mentally-incapacitated) protection provision was identified in the reviewed PDPA/Amendment Act materials.

#

Statutory powers and penalties are well evidenced and in force; enforcement-activity, funding, collective-redress, private-right-of-action and within-180-day developments remain unconfirmed gaps.

Primary frameworkPersonal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024
Traffic-light rationale — AmberStatutory powers and penalties are well evidenced and in force; enforcement-activity, funding, collective-redress, private-right-of-action and within-180-day developments remain unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Fines up to MYR1 million and imprisonment up to three years, plus proactive audit powers, confirmed under the Amendment Act.

Claims: CLM-MY-00000059

Enforcement Activity IndexRed

No confirmed record of Malaysia PDPC enforcement decisions/fines in the last 12 months was retrieved in this run.

Claims: CLM-MY-00000060

Regulator Funding And CapacityRed

No confirmed data on PDP's funding or headcount was retrieved in this run.

Claims: CLM-MY-00000061

Collective Redress And Class ActionsRed

No confirmed collective-redress or class-action mechanism under the PDPA was retrieved in this run.

Claims: CLM-MY-00000062

Private Right Of ActionRed

No confirmed private right of direct court action for data subjects under the PDPA was retrieved in this run.

Claims: CLM-MY-00000063

Recent Developments 180DRed

The most recent confirmed dated development identified (PDP cross-border transfer guidance, dated October 2025) predates the 180-day window from this run's date (2026-08-05); no confirmed developments within the last 180 days were retrieved.

Claims: CLM-MY-00000064

Category narrative81 words

The Amendment Act materially strengthens the Commissioner's enforcement toolkit: fines for violations rise to up to MYR1 million, imprisonment terms extend to up to three years, and the Commissioner gains proactive audit powers. No confirmed enforcement-activity data (fines/decisions) for the last 12 months, regulator funding/headcount signals, collective-redress mechanism, or private right of action were retrieved in this research pass; the most recent confirmed dated development (PDP cross-border transfer guidance, October 2025) falls outside the 180-day recent-developments window as of this run.

Sources and claims (6)
  1. ConfirmedIAPPThe Amendment Act increases maximum fines for PDPA violations to MYR1 million, extends the maximum imprisonment term to three years, and empowers the Commissioner to conduct proactive audits of organisations.
  2. UncertainDataGuidanceNo specific record of Malaysia PDPC enforcement decisions or imposed fines within the last 12 months was located in this research pass.
  3. UncertainDataGuidanceNo confirmed data on PDP's operating budget or headcount was located in this research pass.
  4. UncertainDataGuidance (hosted copy of official Act text)No confirmed collective-redress or class-action mechanism available to data subjects under the PDPA was located in this research pass.
  5. UncertainDataGuidance (hosted copy of official Act text)No confirmed private right of action allowing data subjects direct court recourse (independent of Commissioner enforcement) under the PDPA was located in this research pass.
  6. UncertainDataGuidanceThe most recent confirmed dated Malaysia development in this research pass is PDP's cross-border data transfer guidance dated October 2025, which precedes the 180-day window measured from this run's date (2026-08-05); no confirmed developments from February-August 2026 were retrieved.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Malaysia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 64 claim(s), 12 source(s) in the cumulative register.