#
Comprehensive statute in force with a fully commenced modernising amendment; core institutional architecture (Commissioner + PDP) is stable and actively issuing implementing guidance.
Sub-modules (5)
Regulator And AuthorityGreen
The Commissioner, assisted by PDP, administers and enforces the PDPA.
Claims: CLM-MY-00000001
Act And InstrumentsGreen
PDPA 2010 in force since 15 November 2013; Amendment Act 2024 gazetted 17 October 2024 with staged commencement through 1 June 2025.
Claims: CLM-MY-00000002, CLM-MY-00000003
Material ScopeGreen
PDPA covers processing of personal data in commercial transactions by an establishment in Malaysia or using equipment in Malaysia.
Claims: CLM-MY-00000004
Territorial ScopeAmber
Extraterritorial reach is anchored to use of equipment in Malaysia rather than a pure establishment test; transit-only data is excluded.
Claims: CLM-MY-00000005
Regulator Registration And FilingGreen
PDP mandates registration of 13 designated classes of data controllers/users, and separately requires DPO-appointment notification within 21 days via a dedicated registration manual.
Claims: CLM-MY-00000006, CLM-MY-00000007
Sources and claims (7)
- ConfirmedDataGuidance — The PDPA confers powers to the Personal Data Protection Commissioner, who is assisted by the Department of Personal Data Protection (PDP) to administer and enforce the provisions of the PDPA.
- ConfirmedDataGuidance — The Personal Data Protection (Amendment) Act 2024 was published in the Gazette on 17 October 2024 after receiving Royal Assent on 9 October 2024, following passage by the Senate (31 July 2024) and House of Representatives (16 July 2024).
- ConfirmedDataGuidance — The Amendment Act's provisions were implemented in stages, with sections coming into effect on 1 January, 1 April, and 1 June 2025, covering biometric data, controller/processor terminology, cross-border transfer rules, DPO appointment, breach notification and portability respectively.
- ConfirmedDataGuidance — The PDPA regulates the processing of personal data in commercial transactions either by an establishment in Malaysia or with equipment in Malaysia, unless the personal data only transits through Malaysia.
- ProbableDataGuidance — Extraterritorial application of the PDPA turns on use of equipment located in Malaysia (an equipment-based test), rather than a GDPR-style establishment/targeting test; data merely transiting Malaysia is expressly excluded.
- ConfirmedDataGuidance — PDP mandates registration for 13 designated classes/groups of data controllers under the PDPA, with penalties for non-compliance with the registration requirement.
- ConfirmedDataGuidance — Controllers and processors must notify the Commissioner of DPO appointments; PDP's DPO registration manual requires such notification within 21 days of appointment.