Dashboard
Digital Transformation
← Back to Knowledge Hub
AI Executive Summary
Crucial privacy requirements under PDPA 2010 & 2024 Amendments: mandatory Data Protection Officer (DPO) duties, 72-hour breach notices, and customer consent.
The Strengthening of Malaysian Privacy Law
The Personal Data Protection (Amendment) Act 2024 significantly escalated compliance responsibilities for commercial organizations operating in Malaysia, increasing maximum fines to RM1 million and introducing mandatory breach notifications.
7 Core Principles Every SME Must Follow
- General Principle: Processing of personal data requires explicit, informed written or electronic consent from the data subject.
- Notice & Choice Principle: Must provide written privacy notices in both English and Bahasa Malaysia explaining the purpose of data collection.
- Disclosure Principle: Data cannot be disclosed to unauthorized third parties without prior consent.
- Security Principle: Implement technical safeguards (SSL, encrypted databases, restricted staff access) to prevent loss or unauthorized access.
- Retention Principle: Customer and employee data must not be kept longer than necessary for the fulfillment of the original business purpose.
- Data Integrity & Access: Data subjects have the statutory right to request access and corrections to their stored personal data.
Mandatory Breach Notification
Under the revised law, data controllers must report significant data breaches to the Personal Data Protection Commissioner within 72 hours of discovery.