Data Protection Atlas

Malaysia

Tier 3 Comprehensive law Asia-Pacific

Principal framework: PDPA 2010 (amended 2024) (2010). Regulator: PDP Commissioner (JPDP). The 2024 Amendment Act commenced in phases through 2025: breach notification and DPOs became mandatory, ‘data users’ became ‘controllers’, and the cross-border whitelist was repealed.

At a glance

Principal law
PDPA 2010 (amended 2024)
Regulator
PDP Commissioner (JPDP)
Breach notification
Notify the Commissioner as soon as practicable — within 72 hours where significant harm — and affected subjects (mandatory since June 2025)
Maximum penalty
Raised fines (to RM1m) and imprisonment for various offences after the 2024 amendments
DPO required
DPO appointment mandatory above thresholds from June 2025
Digital consent age
Under 18 — parental consent
Extraterritorial reach
Processing in Malaysia; the 2024 amendments extend duties to processors

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
MY

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.

Never independently verified — seeded from the prototype.