Malaysia

MY · MYS · Asia-Pacific · Last verified 4 Sep 2026

10 regulators · 6 instruments · 1 upcoming deadline

Malaysia — hero image

Act 2010

Personal Data Protection Act 2010

Issued by Personal Data Protection Commissioner

Effective: 15 Nov 2013

Plain-English summary

Personal Data Protection Act 2010 (PDPA) is one of the major pieces of legislation covering personal data processing within commercial operations in Malaysia since the law was enacted on November 15, 2013. By September 2026, the Act functions on a highly modernized platform due to the successful implementation of the Personal Data Protection (Amendment) Act 2024 in mid-2025. The modified framework is strictly enforced by the Personal Data Protection Commissioner (PDPC), with strict compliance pillars being mandatory, such as the compulsory appointment of the Data Protection Officer (DPO), a 72-hour data breach notification period, and increased financial sanctions amounting to up to RM 1 million. PDPA interfaces with financial systems such as BNM RMiT to ensure the personal data processed in the digital environment complies with general privacy laws and banking security measures.

Who it applies to

Banking · Insurance · Telecom & Tech

Topics

Data Protection & Privacy

Official source

Latest news

No related news yet. We publish updates as regulators act.

Browse all newsSubscribe for updates