Skip to content

Evidence request lists

Malaysia PDPA 2010

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cross-Border Transfer and Processor - Malaysia PDPA

MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing
Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing

Govern cross-border transfers + data processor relationships + direct marketing under Sections 4 + 129 + 43 as amended 2024. Original Section 129 whitelist approach (transferring only to Minister-gazetted whitelisted jurisdictions) ABOLISHED by 2024 Amendment + replaced with adequacy assessment + Standard Contractual Clauses (Malaysia SCC published by PDPC 2024) + Binding Corporate Rules + explicit consent + necessary for contract + vital interests + legal claims. Data processor obligations - 2024 Amendment introduced direct obligations on data processors (previously only data users) including security + breach notification + processor agreement + sub-processor authorisation + records of processing + cooperation with PDPC. Aligns with EU GDPR Article 28 processor regime. Direct marketing opt-out (Section 43) - unconditional free opt-out from electronic + telephone + postal marketing. Do

Artefacts an auditor will ask for
  • Cross-border transfer register (post 2024 Amendment whitelist abolition)
  • Malaysia SCC executed with non-Malaysian recipients
  • BCR documentation or adequacy assessment evidence
  • Processor agreements with security + breach notification + sub-processor authorisation clauses (post 2024 Amendment direct processor obligations)
  • Direct marketing opt-out infrastructure + Do Not Call Registry coordination + MCMC compliance
  • Cookie consent management + behavioural advertising controls
Where this commonly fails
  • Reliance on abolished whitelist post 2024 Amendment
  • Processor agreements lack 2024 Amendment direct-obligations clauses
  • Marketing opt-out conditional or fee-charging (Section 43 breach)
  • No cookie consent on Malaysia-targeted properties

Data Subject Rights - Malaysia PDPA

MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43
Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43

Provide and operate channels for data subjects to exercise statutory rights under Sections 30-43. Right of access (Section 30) within 21 days extendable + prescribed fee not exceeding RM10. Right of correction (Section 34) free of charge for inaccurate incomplete misleading data. Right to withdraw consent (Section 38) in writing with implications notified. Right to prevent processing causing damage or distress (Section 42). Right to prevent direct marketing (Section 43) free of charge unconditional opt out. NEW under 2024 Amendment - Right to data portability (Section 43A new) covering structured commonly-used machine-readable transfer to another controller where technically feasible. Limited automated decision-making rights. Public registers exception (Section 31). Refusal grounds (Section 32) including disproportionate effort + legal privilege + national security. Complaint to PDPC (Se

Artefacts an auditor will ask for
  • Subject rights request register with 21-day SLA evidence
  • Access fee schedule (max RM10) and waiver records
  • Correction request workflow and outcomes log
  • Withdraw consent workflow with implications notification
  • Data portability technical capability (structured + machine readable)
  • PDPC complaint mechanism documentation
Where this commonly fails
  • No 21-day SLA tracking under Section 30
  • Excessive access fees beyond RM10 cap
  • Portability right (post-2024 Amendment) not yet operationalised
  • Marketing opt-out not unconditional

Enforcement Sanctions and Remedies - Malaysia PDPA

MY-PDPA-Enforcement-PDPC-Investigation-RM1M-Fine-3-Year-Prison-Class-Action-Section-104-2024-Amendment
Malaysia PDPA Enforcement + PDPC Investigation + RM1M Fine + 3 Year Prison + Class Action + 2024 Amendment

Manage PDPC enforcement engagement + sanctions + civil remedies. PDPC powers (Sections 101-105) include investigation + summons + search and seizure + enforcement notices + variation orders + cease and desist + remedial orders. PDPC complaint mechanism (Section 104) free of charge + Appeal Tribunal (Sections 93-100). Criminal penalties significantly increased by 2024 Amendment - Section 5 unlawful processing RM1M (up from RM300K) + 3 year prison (up from 2 years) + Section 16 non-registration RM500K + 3 year prison + Section 43 marketing breach RM200K + 2 year prison + Section 130 transferring data without authority RM300K + 2 year prison. Compound offences available. Class action under Section 78A (2024 new) for representative complaints. Civil claim for damages + injunction available under Section 130. PDPC public censure + notice publication. Annual Report to Parliament. Director Gene

Artefacts an auditor will ask for
  • PDPC enforcement notice tracking and remediation evidence
  • Penalty exposure assessment (RM1M fine + 3 year prison post 2024 Amendment)
  • Class action preparedness (Section 78A post 2024 Amendment)
  • Appeal Tribunal documentation
  • Compound offer evaluation records
  • PDPC public censure response plan
  • Annual Report to Parliament awareness
  • Foreign DPA coordination (Singapore PDPC + Hong Kong PCPD + South Korea PIPC + EDPB observer + ASEAN + APEC CBPR)
Where this commonly fails
  • Penalty exposure not refreshed for 2024 Amendment 3x increase
  • No class action preparedness (Section 78A post 2024)
  • Director General correspondence not escalated to board
  • Compound offences not evaluated as remediation

Governance DPO Registration DPIA - Malaysia PDPA

MY-PDPA-DPO-Designation-Class-Data-User-Registration-DPIA-Code-Practice-Section-43A-2024-Amendment
Malaysia PDPA Governance + DPO Section 43A + Class of Data User Registration + DPIA + Code of Practice

Operate Malaysia PDPA governance structure including mandatory DPO designation + class of data user registration + DPIA + Codes of Practice. NEW under 2024 Amendment - mandatory Data Protection Officer designation (Section 43A new) for large-scale processing + sensitive data processing + regular systematic monitoring at scale (aligned with EU GDPR Article 37). DPO independent + reports to highest management + contact published + registered with PDPC within 7 days. Class of Data User registration (Section 16) originally 13 sectors (banking + insurance + healthcare + telecommunications + tourism + transportation + utilities + education + direct marketing + services + real estate + legal + pawnbroking). 2024 Amendment expanded mandatory registration. Annual renewal + RM200-RM10000 fees. NEW Data Protection Impact Assessment (DPIA) requirement for high-risk processing including profiling + l

Artefacts an auditor will ask for
  • DPO designation letter + reporting line to highest management + PDPC registration (within 7 days)
  • Class of Data User registration certificate (annual renewal + RM200-RM10000 fees)
  • DPIA register for high-risk processing + profiling + sensitive at scale
  • Registered Code of Practice adherence (banking + insurance + healthcare + utilities + comms)
  • DPO independence and contact publication evidence
Where this commonly fails
  • No DPO designated despite large-scale or sensitive processing (post 2024 Amendment Section 43A breach)
  • Expired Class of Data User registration
  • No DPIA conducted for systematic monitoring or profiling
  • DPO not registered with PDPC within 7 days

Scope and Authority - Malaysia PDPA

MY-PDPA-Scope-Act-709-Parliament-2010-Effective-15-November-2013-PDPC-JPDP-2024-Amendment-Act-A1709
Malaysia PDPA Scope + Act 709 + Parliament 2010 + Effective 15 November 2013 + PDPC + JPDP + 2024 Amendment

Establish the legal foundation of Malaysia Personal Data Protection Act 2010 (Act 709) enacted by Parliament Dewan Rakyat 2 June 2010 + Royal Assent 2 June 2010 + Gazette publication + effective 15 November 2013 administered by Personal Data Protection Commissioner (Pesuruhjaya Perlindungan Data Peribadi) under Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi JPDP) under Ministry of Digital. PDP (Amendment) Act 2024 (Act A1709) modernisation effective in phases through 2024-2025. Federal Constitution Article 5 personal liberty + Article 10 fundamental liberties anchors. Applies to all commercial transactions processing personal data in Malaysia + extraterritorial application to controllers established in Malaysia processing data overseas. Exclusions for Federal and State Government processing (subject to PSC Public Sector Cybersecurity Service). Sectoral coordin

Artefacts an auditor will ask for
  • PDPA 2010 Act 709 applicability assessment
  • 2024 Amendment Act compliance gap analysis
  • PDPC and JPDP correspondence records
  • Sectoral coordination memoranda (BNM + SC + MCMC + CSM)
  • Federal Constitution Article 5 and 10 anchor documentation
  • Cross-border establishment determination
Where this commonly fails
  • No 2024 Amendment Act gap analysis
  • Confusion between data user and data processor obligations
  • Missing sectoral coordination documentation
  • Extraterritorial scope not assessed for overseas processing

Security Retention Breach Notification - Malaysia PDPA

MY-PDPA-Security-Principle-Retention-Data-Integrity-Breach-Notification-72-Hour-Section-12B-2024-Amendment
Malaysia PDPA Security + Retention + Data Integrity + Breach Notification 72 Hour + Section 12B + 2024 Amendment

Implement Security Principle 4 + Retention Principle 5 + Data Integrity Principle 6 + 2024 Amendment breach notification regime. Security measures appropriate to harm risk and sensitivity including encryption at rest and in transit + access controls + activity logging + secure development + secure disposal + physical security + supplier security + business continuity + workforce training. PDPC Standards 2015 + amended 2024 prescribe minimum technical organisational measures. Retention only for stated purposes + standard destruction or anonymisation protocols + retention schedule documented. Data integrity through accuracy validation + correction processes + audit trails. NEW under 2024 Amendment (Section 12B new) - Personal Data Breach Notification within 72 hours to PDPC for any breach likely to result in significant harm + concurrent affected data subject notification without undue del

Artefacts an auditor will ask for
  • PDPC Standards 2015 (amended 2024) technical and organisational measures evidence
  • Retention schedule + destruction or anonymisation records
  • Data integrity validation and correction logs
  • Breach Notification 72-hour procedure (Section 12B post 2024 Amendment) + breach register + breach response plan + CSM CERT-IN coordination evidence
  • Post-incident review reports
Where this commonly fails
  • No 72-hour notification capability (post 2024 Amendment Section 12B breach)
  • Retention beyond stated purposes (Principle 5 breach)
  • No breach response plan or tabletop exercise records
  • Encryption at rest and in transit not enforced

Sensitive Data and Children - Malaysia PDPA

MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent
Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent

Process sensitive personal data and children data only under Section 40 explicit consent or narrow exceptions. Sensitive categories include physical or mental health condition + political opinion + religious or other beliefs + commission or alleged commission of any offence + sexual orientation (added 2024 Amendment) + biometric data (added 2024 Amendment) + financial data (PDPC guidance). Processing prohibited unless explicit consent + necessary for legal claim + vital interests + manifestly made public by data subject + employment law obligation + medical purposes by health professional + insurance underwriting. Children below 18 require parental or guardian explicit consent (post 2024 Amendment alignment with EU GDPR Article 8). Marketing to children restricted. Special protections for biometric authentication + facial recognition processing under CSM Guidelines. Public Consultation 3

Artefacts an auditor will ask for
  • Sensitive data inventory (health + religious + political + sexual + biometric + financial)
  • Explicit consent records for sensitive processing
  • Parental consent records for under-18 processing (post 2024 Amendment)
  • Biometric authentication DPIA + CSM Guidelines compliance
  • Marketing-to-children restriction enforcement evidence
Where this commonly fails
  • Biometric and financial sensitivity added 2024 not yet inventoried
  • Children below 18 parental consent not obtained
  • Implied consent for sensitive processing (breach Section 40)
  • No medical or insurance lawful basis documentation

Seven Personal Data Protection Principles - Malaysia PDPA

MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access
Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access

Implement the seven foundational Personal Data Protection Principles mandatory for all data users. Principle 1 General Principle (lawful processing with consent or specified statutory ground + relevant + not excessive). Principle 2 Notice and Choice (written privacy notice in Bahasa Malaysia and English specifying purposes + recipients + rights + complaint mechanism). Principle 3 Disclosure (no disclosure beyond stated purposes without consent). Principle 4 Security (technical and organisational measures appropriate to harm risk + sensitivity). Principle 5 Retention (retention only for necessary period + destruction or anonymisation thereafter). Principle 6 Data Integrity (accurate + complete + not misleading + up to date). Principle 7 Access (data subjects entitled to access and correction). 2024 Amendment introduced explicit data portability right + clarified consent must be express in

Artefacts an auditor will ask for
  • Bilingual privacy notices (Bahasa Malaysia + English)
  • Consent management records (express informed unambiguous)
  • Lawful basis register per processing purpose
  • Disclosure register and purpose limitation evidence
  • Data minimisation justification per Principle 1
Where this commonly fails
  • English-only privacy notices (Principle 2 breach)
  • Implied consent assumed where express required
  • No purpose limitation enforcement (Principle 3 breach)
  • Notices not pre-collection delivered
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Malaysia PDPA 2010 framework page.