What Is Personal Data Protection Act 2010 (Act 709), as amended in 2024?
Malaysia's Personal Data Protection Act 2010 (Act 709) regulates the processing of personal data in connection with commercial transactions and protects data subjects from misuse. The Personal Data Protection Department's current English materials describe seven principles and publish rights guidance covering notice, access, correction, withdrawal, objection to harmful processing, direct marketing, and automated decision-making. The Personal Data Protection (Amendment) Act 2024 changed the statutory terminology from data user to data controller in most places and introduced additional obligations and rights. The official commencement notice places its provisions into operation in stages on 1 January, 1 April, and 1 June 2025. The JPDP's current Act index also lists 2025 data-breach and data-protection-officer materials and a 2026 circular on registration of data controllers. This page is a source-backed orientation, not legal advice. Malaysia's framework is tied to commercial transactions and contains exclusions, sector rules, conditions, and implementation materials. It does not establish one universal data-broker deletion route, required field set, or guaranteed removal outcome.
At a glance
- Full name
- Personal Data Protection Act 2010 (Act 709), as amended in 2024
- Short code
- Malaysia PDPA
- Jurisdiction
- Malaysia
- Enacted
- 2010
- Last major update
- Personal Data Protection (Amendment) Act 2024; official commencement notices put its provisions into operation in stages on 1 January, 1 April, and 1 June 2025
- Regulator
- Personal Data Protection Commissioner / Personal Data Protection Department (JPDP)
- Private right of action
- Limited
- Statutory citation
- Personal Data Protection Act 2010 (Act 709)
Scope, who Malaysia PDPA covers
Protected data
Data subject rights
Right to be told the purpose of processing and relevant information about the organization, source, reasons, and intended disclosures
Right to access personal data where the statutory access conditions apply
Right to request correction of personal data that is inaccurate, incomplete, misleading, or not up to date
Right to withdraw permission to process personal data in the circumstances described by the framework
Right to prevent processing likely to cause damage or distress in the circumstances described by the Act
Right to prevent processing for direct-marketing purposes and refuse direct-marketing calls or mail
Right to the protections described by the official JPDP guidance for automated decision-making
Right to complain to the Personal Data Protection Commissioner or JPDP when personal data is misused
Notable features
Malaysia’s framework is commercial-transaction based rather than a claim that every public or private activity is covered. Its seven principles are supplemented by the 2024 amendment, staged 2025 commencement, data-protection-officer and breach-notification instruments, cross-border guidance, sector codes, and the Commissioner’s current registration and complaint systems.
Enforcement & penalties
Regulator: Personal Data Protection Commissioner / Personal Data Protection Department (JPDP)
Penalties: The Act contains offense-specific penalties and the amended framework adds breach-notification obligations. The official JPDP 2025 breach-notification guideline states that a data controller who fails to comply with section 12B(1) may, on conviction, face a fine not exceeding RM250,000, imprisonment not exceeding two years, or both. That figure is specific to the cited breach-notification provision and is not a prediction of every PDPA penalty or enforcement outcome.
Private right of action: The PDPA provides data-subject rights and regulator complaint and enforcement routes. This explainer does not assert a broad standalone damages action under the Act; private remedies, contractual claims, and any other civil routes require case-specific Malaysian legal advice.
Relevance to data brokers
A data broker, directory, or marketing service may fall within the Act when it processes personal data in connection with commercial transactions, but applicability depends on its role, purpose, establishment, equipment, sector, source, and any exclusion. Official JPDP guidance supports access, correction, withdrawal, and direct-marketing objections; it does not prove that every people-search or public-record listing must be deleted. Verify the broker’s current privacy notice and route, preserve delivery evidence, and use the JPDP complaint channel when appropriate.
Exercise your rights
Review removal workflows for 1009 US/global profiles for $9
OfflistMe helps draft opt-out requests using the details you choose. Review the provider route and legal basis, then send from your own inbox. The tool is not legal advice and does not guarantee a broker's response.
Request Removal NowFAQ
What is Malaysia’s main personal-data privacy law?+
The Personal Data Protection Act 2010, Act 709, is Malaysia’s principal personal-data statute for processing connected with commercial transactions. The framework was amended in 2024, with the official commencement notice putting amendment provisions into operation in stages during 2025.
Who can the Malaysia PDPA apply to?+
It applies to people or organizations that process or control processing of personal data in connection with commercial transactions in Malaysia. It can also cover a non-Malaysian person using equipment in Malaysia for processing, other than equipment used only for transit. Exclusions and sector-specific rules still matter.
What rights does Malaysia’s PDPA give data subjects?+
Current JPDP public guidance describes rights to be told the processing purpose, access personal data, request correction, withdraw permission in applicable circumstances, prevent harmful or distressing processing, object to direct marketing, and receive protections around automated decision-making. The exact right and exceptions depend on the Act and applicable sector rules.
How do I correct personal data held by a Malaysian organization?+
Use the organization’s current personal-data or privacy-notice contact and identify the inaccurate, incomplete, misleading, or outdated information. The reviewed Act text includes a 21-day period for responding to a data-correction request, together with an explanation and limited extension mechanism when the request cannot be completed within that period.
Can I ask a Malaysian data broker to delete my information?+
You can ask the organization to correct or delete inaccurate or unfair information and can invoke applicable withdrawal, retention, or direct-marketing rights. The public JPDP guidance and Act do not establish one universal people-search deletion form or guarantee that every public-record listing must be removed. Check the broker’s current route and preserve proof of the request.
Can I object to direct marketing in Malaysia?+
Yes. JPDP’s current public rights guidance describes a right to prevent processing for direct marketing and to refuse direct-marketing calls or mail. Use the organization’s current opt-out or privacy contact, state that the request concerns direct marketing, and keep a record of delivery.
How do I report misuse of personal data in Malaysia?+
The JPDP public page provides a “Report a Complaint” route for suspected misuse and lists the Department’s current contact details, including aduan@pdp.gov.my. Check the official page immediately before submitting because forms, portals, and contact instructions can change.
What changed under Malaysia’s 2024 PDPA amendment?+
The official amendment and commencement materials changed most statutory references from data user to data controller and introduced additional requirements and rights. The official commencement notice sets different dates in January, April, and June 2025; the JPDP Act index also lists current DPO, breach-notification, registration, and guidance materials that should be checked with the consolidated framework.
Official sources & citations
Other international privacy regimes
Malaysia PDPA sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
