What Malaysia Personal Data Protection Act 2010 (Act 709) - PDPA requires
The Personal Data Protection Act 2010 (PDPA, Act 709) is Malaysia's primary legislation governing the processing of personal data in commercial transactions. The PDPA was enacted on 2 June 2010 and came into force on 15 November 2013. Administered by the Personal Data Protection Commissioner under the Ministry of Communications, the PDPA establishes seven data protection principles that all data users (persons who process personal data) must comply with: (1) General Principle - personal data may only be processed with data subject consent or as otherwise specified; (2) Notice and Choice Principle - data subjects must be notified of the purpose of processing and given the right to choose; (3) Disclosure Principle - personal data may only be disclosed for the purpose it was collected; (4) Security Principle - practical steps must be taken to protect personal data from loss, misuse, or unauthorised access; (5) Retention Principle - personal data must not be kept longer than necessary; (6) Data Integrity Principle - data must be accurate, complete, not misleading, and kept up to date; (7) Access Principle - data subjects have the right to access and correct their personal data. Scope: the PDPA applies to any person who processes personal data in Malaysia in respect of commercial transactions. Government agencies are explicitly excluded. Sensitive personal data (health, political opinions, religious beliefs, commission of criminal offences, biometrics) requires express consent for processing. International data transfers: personal data may not be transferred to any place outside Malaysia except to countries listed in the Personal Data Protection (Place of Transfer) Order 2010 or where the Commissioner grants approval. Data user class registration: specific categories of data users (telecommunications, banking, insurance, health, transport, direct selling, education, and others) must register with the Commissioner under the Personal Data Protection (Class of Data Users) Order 2013. Breach notification: the PDPA 2010 did not originally include mandatory breach notification provisions; however, this obligation was introduced by amendments enacted in 2023 (Personal Data Protection (Amendment) Act 2023), which also added mandatory appointment of a Data Protection Officer for certain data users and data portability rights. Enforcement: the Commissioner may investigate complaints and initiate prosecutions; penalties include fines up to RM 500,000 and imprisonment up to 3 years for data users, and fines up to RM 300,000 and imprisonment up to 2 years for data processors who fail to comply with instructions. Malaysia has obtained an adequacy finding from the United Kingdom (post-Brexit) for data transfers. The PDPA applies to all sectors engaged in commercial transactions with Malaysian data subjects, including foreign entities processing personal data of Malaysian residents.
Pillar: Data Protection & Privacy · Authority: Personal Data Protection Commissioner, Malaysia (Ministry of Communications) · Version: 1.0.0 · Last updated:
Primary source: https://www.pdp.gov.my/jpdpv2/
SHA-256 integrity: f24a72ce9585dbe5caacc5ac2ee4f08c50e2dd8584a53e4d7531def1862b1a1a
Primary Citations — 7 traced to source
- Personal Data Protection Act 2010 (Act 709, Malaysia) - seven data protection principles: General (lawful basis for processing), Notice and Choice (privacy notice in Bahasa Malaysia or English), Disclosure (purpose limitation), Security (technical and organisational measures), Retention (data minimisation over time), Data Integrity (accuracy), Access (data subject rights); enacted 2 June 2010, in force 15 November 2013; government agencies excluded from scope; penalties: fine up to RM 500,000 and/or imprisonment up to 3 years
- Personal Data Protection (Class of Data Users) Order 2013 (Malaysia) - mandates registration with the Commissioner for data users in specified classes: communications, banking and financial institutions, insurance, health, transportation, direct sales, services, real estate, utilities, education, and retail; registration via SPDP online portal; non-registered data users in prescribed classes commit a criminal offence
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/my-pdpa-2010.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/my-pdpa-2010.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/my-pdpa-2010
- Back to registry: Browse all 10,090 compliance nodes