Data-Breach and DPO Duties Now Bite Under Malaysia's Amended PDPA
In brief: Malaysia's data-protection regime has been tightened. Under the Personal Data Protection (Amendment) Act 2024, two previously absent duties now apply: mandatory notification of serious data breaches, and mandatory appointment of a Data Protection Officer (DPO). A controller must notify the Commissioner within 72 hours of becoming aware of a breach likely to cause significant harm, and tell affected individuals without undue delay — generally within seven days of notifying the Commissioner.
This article is general information about Malaysian data-protection law for the public.
What is the new breach-notification duty?
If a data controller becomes aware of a personal-data breach that is likely to cause significant harm, it must notify the Commissioner within 72 hours, and inform affected individuals without undue delay — generally within seven days of notifying the Commissioner. In practice, that means organisations need a tested plan to detect, assess and report a breach quickly, rather than working it out after the fact.
What is the DPO requirement?
The DPO rule requires qualifying controllers and processors to appoint an officer who operates independently, reports to senior management and is the main contact with the regulator. These changes bring Malaysia closer to standards like Europe's GDPR and raise the stakes for every organisation handling personal data — including law firms holding sensitive client information — since non-compliance is treated as a quasi-criminal matter carrying fines and possible imprisonment.
Why does it matter?
Firms must both advise clients and get their own house in order — appointing a DPO where required and having a tested plan to meet the 72-hour window. For anyone holding personal data, these duties change day-to-day compliance, not just paperwork.
What happens next?
Watch for the Commissioner's guidelines on thresholds and early enforcement, and confirm current requirements against published guidance before relying on them.
Frequently asked questions
How quickly must a data breach be reported?
A controller must notify the Commissioner within 72 hours of becoming aware of a breach likely to cause significant harm, and tell affected individuals without undue delay — generally within seven days of notifying the Commissioner.
Who must appoint a Data Protection Officer?
Qualifying data controllers and processors must appoint a DPO who works independently, reports to senior management, and is the main point of contact with the regulator.
What are the consequences of non-compliance?
Non-compliance is treated as a quasi-criminal matter, carrying fines and possible imprisonment — so organisations should confirm current requirements against the Commissioner's published guidance.
Last updated: 30 September 2026.
This article is published by Khaw Ewe Seng & Co., Advocates & Solicitors (Penang) for general information about Malaysian law. It is not legal advice, and it does not create a solicitor–client relationship. For advice on a specific matter, please consult a qualified lawyer.



Comments