Malaysia
Tier 3 Comprehensive law Asia-PacificPrincipal framework: PDPA 2010 (amended 2024) (2010). Regulator: PDP Commissioner (JPDP). The 2024 Amendment Act commenced in phases through 2025: breach notification and DPOs became mandatory, ‘data users’ became ‘controllers’, and the cross-border whitelist was repealed.
At a glance
- Principal law
- PDPA 2010 (amended 2024)
- Regulator
- PDP Commissioner (JPDP)
- Breach notification
- Notify the Commissioner as soon as practicable — within 72 hours where significant harm — and affected subjects (mandatory since June 2025)
- Maximum penalty
- Raised fines (to RM1m) and imprisonment for various offences after the 2024 amendments
- DPO required
- DPO appointment mandatory above thresholds from June 2025
- Digital consent age
- Under 18 — parental consent
- Extraterritorial reach
- Processing in Malaysia; the 2024 amendments extend duties to processors
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- MY
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- No
- EEA member
- No
Instruments
No instrument profiled yet.
Sources
No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.
Never independently verified — seeded from the prototype.