What Is Personal Data Protection Act 2010 (Act 709), as amended in 2024?
Malaysia's Personal Data Protection Act 2010 (Act 709) regulates the processing of personal data in connection with commercial transactions and protects data subjects from misuse. The Personal Data Protection Department's current English materials describe seven principles and publish rights guidance covering notice, access, correction, withdrawal, objection to harmful processing, direct marketing, and automated decision-making. The Personal Data Protection (Amendment) Act 2024 changed the statutory terminology from data user to data controller in most places and introduced additional obligations and rights. The official commencement notice places its provisions into operation in stages: sections 7, 11, 13, and 14 on 1 January 2025; sections 2, 3, 4, 5, 8, 10, and 12 on 1 April 2025; and sections 6 and 9 on 1 June 2025. Current JPDP guidance identifies 13 registrable-controller classes under the 2013 and 2016 orders—communications, banking and financial institutions, insurance, health, tourism and hospitality, transportation, education, direct selling and direct marketing, services, real estate, utilities, pawnbrokers, and moneylenders—and does not identify a separate data-broker class. Circular No. 1/2026 has an official eight-page PDF, but its provisions were not readable or verified in the reviewed primary source, so its controller classes, deadlines, fees, exemptions, and operative effect remain unresolved. This page is a source-backed orientation, not legal advice. Malaysia's framework is tied to commercial transactions and contains exclusions, sector rules, conditions, and implementation materials. It does not establish one universal data-broker deletion route, required field set, or guaranteed removal outcome.
At a glance
- Full name
- Personal Data Protection Act 2010 (Act 709), as amended in 2024
- Short code
- Malaysia PDPA
- Jurisdiction
- Malaysia
- Enacted
- 2010
- Last major update
- Personal Data Protection (Amendment) Act 2024; official commencement notices put its provisions into operation in stages on 1 January, 1 April, and 1 June 2025
- Regulator
- Personal Data Protection Commissioner / Personal Data Protection Department (JPDP)
- Private right of action
- Limited
- Statutory citation
- Personal Data Protection Act 2010 (Act 709)
Scope, who Malaysia PDPA covers
Protected data
Data subject rights
Right to be told the purpose of processing and relevant information about the organization, source, reasons, and intended disclosures
Right to access personal data where the statutory access conditions apply
Right to request correction of personal data that is inaccurate, incomplete, misleading, or not up to date
Right to withdraw permission to process personal data in the circumstances described by the framework
Right to prevent processing likely to cause damage or distress in the circumstances described by the Act
Right to prevent processing for direct-marketing purposes and refuse direct-marketing calls or mail
Right to the protections described by the official JPDP guidance for automated decision-making
Right to submit an individual complaint to the Commissioner through JPDP’s official complaint form and investigation route
Right to complain to the Personal Data Protection Commissioner or JPDP when personal data is misused
Notable features
Malaysia’s framework is commercial-transaction based rather than a claim that every public or private activity is covered. Its seven principles are supplemented by the 2024 amendment, staged 2025 commencement, data-protection-officer and breach-notification instruments, cross-border guidance, sector codes, and the Commissioner’s current registration and complaint systems.
Enforcement & penalties
Regulator: Personal Data Protection Commissioner / Personal Data Protection Department (JPDP)
Penalties: The Act contains offense-specific penalties and the amended framework adds breach-notification obligations. The official JPDP 2025 breach-notification guideline states that a data controller who fails to comply with section 12B(1) may, on conviction, face a fine not exceeding RM250,000, imprisonment not exceeding two years, or both. That figure is specific to the cited breach-notification provision and is not a prediction of every PDPA penalty or enforcement outcome.
Private right of action: The PDPA provides data-subject rights and regulator complaint and enforcement routes. This explainer does not assert a broad standalone damages action under the Act; private remedies, contractual claims, and any other civil routes require case-specific Malaysian legal advice.
Relevance to data brokers
A data broker, directory, or marketing service may fall within the Act when it processes personal data in connection with commercial transactions, but applicability depends on its role, purpose, establishment, equipment, sector, source, and any exclusion. JPDP’s current registration guidance identifies 13 registrable-controller classes and does not identify “data broker” as a separate class; that does not establish whether a particular broker falls within a broader class or general controller obligations. No current JPDP source reviewed identifies a data-broker-specific complaint category, broker registry, dedicated broker deletion portal, or broker-specific statutory deletion route. The confirmed individual route is the official JPDP complaint form and Commissioner investigation framework, alongside controller-facing rights; Circular No. 1/2026’s actual provisions remain unresolved because the official PDF was not readable in the reviewed primary-source pass. Official JPDP guidance supports access, correction, withdrawal, and direct-marketing objections, but it does not prove that every people-search or public-record listing must be deleted.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
What is Malaysia’s main personal-data privacy law?+
The Personal Data Protection Act 2010, Act 709, is Malaysia’s principal personal-data statute for processing connected with commercial transactions. The framework was amended in 2024, with the official commencement notice putting amendment provisions into operation in stages during 2025.
Who can the Malaysia PDPA apply to?+
It applies to people or organizations that process or control processing of personal data in connection with commercial transactions in Malaysia. It can also cover a non-Malaysian person using equipment in Malaysia for processing, other than equipment used only for transit. Exclusions and sector-specific rules still matter.
What rights does Malaysia’s PDPA give data subjects?+
Current JPDP public guidance describes rights to be told the processing purpose, access personal data, request correction, withdraw permission in applicable circumstances, prevent harmful or distressing processing, object to direct marketing, and receive protections around automated decision-making. The exact right and exceptions depend on the Act and applicable sector rules.
How do I correct personal data held by a Malaysian organization?+
Use the organization’s current personal-data or privacy-notice contact and identify the inaccurate, incomplete, misleading, or outdated information. The reviewed Act text includes a 21-day period for responding to a data-correction request, together with an explanation and limited extension mechanism when the request cannot be completed within that period.
Can I ask a Malaysian data broker to delete my information?+
You can ask the organization to correct or delete inaccurate or unfair information and can invoke applicable withdrawal, retention, or direct-marketing rights. The public JPDP guidance and Act do not establish one universal people-search deletion form or guarantee that every public-record listing must be removed. Check the broker’s current route and preserve proof of the request.
Can I object to direct marketing in Malaysia?+
Yes. JPDP’s current public rights guidance describes a right to prevent processing for direct marketing and to refuse direct-marketing calls or mail. Use the organization’s current opt-out or privacy contact, state that the request concerns direct marketing, and keep a record of delivery.
How do I report misuse of personal data in Malaysia?+
An individual who believes personal data was processed contrary to the Act may complain to the Commissioner. JPDP provides an official individual complaint form that asks the complainant to identify the organization and describe the complaint, and the form states that JPDP may forward the complaint and supporting documents to that organization; the Act’s complaint provisions allow the Commissioner to investigate. Check the live form and JPDP instructions before submitting.
What changed under Malaysia’s 2024 PDPA amendment?+
The official amendment and commencement materials changed most statutory references from data user to data controller and introduced additional requirements and rights. The official commencement notice sets different dates in January, April, and June 2025; the JPDP Act index also lists current DPO, breach-notification, registration, and guidance materials that should be checked with the consolidated framework.
What is confirmed about Malaysia’s Circular No. 1/2026?+
The official JPDP pages link to an eight-page PDF, but its text was not readable in the reviewed primary-source pass. Its controller classes, deadlines, fees, exemptions, operative provisions, and precise effective-date wording therefore remain unresolved; do not treat secondary commentary about the circular as verified law.
Official sources & citations
- JPDP: Personal Data Protection Act 2010 (Act 709)
- JPDP: Personal Data Protection (Amendment) Act 2024
- JPDP: Act 2024 commencement date determination
- JPDP: Data Subject Rights
- JPDP: Public complaint route
- JPDP: SPDP complaint form
- JPDP: Personal Data Protection Guidelines on Data Breach Notification
- JPDP: Act 709 consolidated bilingual text
- JPDP: Relevant documents and registrable classes
- JPDP: Circular No. 1/2026 registration page
- JPDP: Circular No. 1/2026 official PDF
Other international privacy regimes
Malaysia PDPA sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
