Malaysia

MY · MYS · Asia-Pacific · Last verified 4 Sep 2026

10 regulators · 6 instruments · 1 upcoming deadline

Malaysia — hero image

Personal Data Protection Commissioner PDPC-MY

Official site
https://www.pdp.gov.my
Established
2011
Constituting statute
Personal Data Protection Act 2010

Who they are

The Personal Data Protection Commissioner (PDPC) is the chief regulatory body in Malaysia that manages the regulation and implementation of the Personal Data Protection Act 2010 (PDPA). Formally constituted on May 16, 2011, the PDPC leads the Department of Personal Data Protection (JPDP), which is an independent enforcement department functioning within the ambit of the Digital Ministry. As the official chief custodian of data privacy in Malaysia, the PDPC has been legally mandated to register data controllers, audit the compliance of corporations with the basic tenets of data protection in Malaysia, and impose penalties on non-compliant corporate organizations.

What they do

The Personal Data Protection Commissioner (PDPC) closely oversees, controls, and imposes regulations on how private organizations gather and process personal data in Malaysia. The Commissioner has the responsibility of managing the compulsory registration of data controllers, whereby companies have to abide by the basic data protection principles. In case of any security breach or data breach, the Commissioner will conduct investigations and audits, and will also utilize the powers given to him or her to fine or prosecute non-complying organizations financially. Presently, under the mandates of PDPC, the Commissioner also has the authority to oversee mandatory notifications of data breaches, making sure that qualified organizations appoint DPOs, and issue binding operational guidelines for data impact assessments and data transfer across borders.

Key instruments issued

All laws from PDPC-MY →

Latest news

No news tagged to this regulator yet.

Browse all news

Related regulators

Others in Malaysia supervising overlapping sectors.