Personal data compliance in Malaysia is no longer something company secretaries can treat as a purely operational issue for HR or IT. Under the Personal Data Protection Act 2010 (PDPA) and its critical 2024 amendments, directors, management, and the internal teams that maintain statutory, employee, shareholder, customer, and vendor records all sit inside the compliance chain. In practice, the company secretary is often the person best placed to see where those records are collected, disclosed, retained, transferred, and governed. That makes PDPA literacy a core governance skill.
This article highlights the Malaysian PDPA points a company secretary should actively monitor, including notices, board and shareholder records, vendor oversight, registration, cross-border transfers, data breach notification protocols, and Data Protection Officer (DPO) mandates.
1. Start with the right scope: the PDPA applies to personal data processed in commercial transactions
The PDPA regulates the processing of personal data in respect of commercial transactions. Official PDP guidance makes clear that the concept of “processing” is broad. It covers collection, recording, holding, storing, organising, adapting, disclosing, and destroying personal data. If the company keeps employee files, beneficial ownership records, customer lists, board papers containing personal details, CCTV footage, payroll records, or onboarding documentation, the PDPA is strictly in play.
The Act applies to private sector organisations and individuals processing personal data. While Federal and State Governments are exempt, private companies are not. For company secretaries, PDPA touches multiple functional areas:
- Directors’ and officers’ records
- Shareholders’ and beneficial owners’ information
- Employee appointment, payroll, and resignation records
- Signatory and banking documentation
- Statutory forms and supporting documentation
- Service provider and counterparty due diligence files
- Meeting minutes, attendance lists, and board packs
2. Treat PDPA compliance as a governance issue, not just a privacy-policy issue
A common mistake is reducing PDPA compliance to the mere existence of a privacy notice on a website. From a governance perspective, the real questions are:
- What personal data the company holds and why it holds it
- Whether the legal basis and consent position are clear
- Who has access internally and which third parties receive it
- Whether retention periods are defensible
- Whether disclosures into board, investor, payroll, and vendor processes are controlled
- Whether the company can respond to data subject access or correction requests
- Whether the company has appointed and registered a Data Protection Officer (DPO)
- Whether the company is prepared to notify the Commissioner as soon as practicable of a notifiable data breach
These issues overlap directly with internal controls, board reporting, record retention, and regulatory hygiene.
3. Privacy notices are mandatory, and they need to be operational
Under Section 7 of the PDPA, a personal data protection notice is mandatory for data controllers processing personal data.
A company secretary should check whether the organisation’s notices:
- Accurately identify the entity collecting the data
- Clearly explain the categories of personal data collected and the actual purposes of processing
- Identify relevant disclosures to third parties or service providers
- Explain access and correction rights
- Cover direct marketing and cross-border transfer issues where relevant
- Are actually delivered at the point the data is collected
4. Know the seven PDPA principles
The official PDP framework requires adherence to seven core principles:
- General Principle: Processing requires a lawful basis and cannot simply happen for corporate convenience.
- Notice and Choice: The organisation must communicate relevant information to the data subject and handle consent properly.
- Disclosure: Data must not be disclosed for unpermitted purposes.
- Security: Corporate secretarial records, payroll documents, and KYC files must not sit in unsecured drives or loose messaging groups.
- Retention: Data cannot be retained indefinitely without a defensible retention logic.
- Data Integrity: Records must be accurate and updated.
- Access: The organisation must respond when an individual seeks access to or correction of their data.
5. Registration remains critical for prescribed classes
Not every organisation is required to register. However, organisations falling within the 13 prescribed classes of data controllers under the relevant Orders must apply for registration. Failure to register is a statutory offence, and the registration certificate must be displayed at the business premises.
Confirm:
- Whether the business falls into a prescribed class requiring registration
- Whether the certificate has been issued, is valid, and is displayed
- Whether renewal dates are diarised
6. Outsourcing: Data Processors now face direct liability
Modern administration work is frequently outsourced, including payroll, HR systems, cloud storage, and corporate secretarial software.
Previously, accountability rested solely on the data controller to contractually enforce security. Under the 2024 amendments, Data Processors now have a direct statutory obligation to comply with the Security Principle. A breach by a processor can result in direct fines of up to RM1 million and/or 3 years imprisonment.
Company secretaries must ensure vendor agreements reflect these elevated stakes, clearly outlining:
- Strict confidentiality and security obligations
- Immediate breach escalation requirements
- Return or deletion obligations on exit
- Audit and reporting clauses
7. Cross-border transfers require documented due diligence
Where personal data is transferred outside Malaysia (e.g., via global HR systems, cloud repositories, or regional shared service centres), the data controller must ensure the destination offers an adequate level of protection. The 2024 amendments allow transfers if the data controller exercises due diligence and takes reasonable steps to protect the personal data. The company must document how the transfer is justified and protected.
8. Sensitive personal data demands strict access control
Sensitive personal data includes information on health (including biometric data), political opinions, religious beliefs, and alleged offences. Processing generally requires express consent. Corporate records frequently contain sensitive data, such as:
- Medical documents in employment files
- Fit and proper assessments
- Declarations involving criminal history
- Internal grievance or whistleblowing records
Access control, purpose limitation, and document circulation for these files must be strictly siloed.
9. The 2024 Amendment Act is fully in force: Update terminology and protocols
The statutory term has officially shifted from “data user” to “data controller.” All internal documents, board reporting, templates, and vendor matrices should now reflect current terminology and the active regulatory environment.
10. Mandatory DPO Appointment
Under the new Section 12A of the Act, both data controllers and data processors must appoint one or more Data Protection Officers who are accountable for compliance, and must formally notify the Commissioner of this appointment.
11. Data Breach Notification (DBN) Requires Prompt Action
Malaysia legally mandates data breach notifications under Section 12B of the amended Act. When a personal data breach occurs, the data controller must:
- Notify the Personal Data Protection Commissioner as soon as practicable.
- Notify affected data subjects without unnecessary delay if the breach causes or is likely to cause any significant harm to the data subject.
Failure to comply carries statutory fines of up to RM250,000 and/or imprisonment. Organisations must have a tested incident workflow identifying who owns the escalation path and regulator communication.
12. Corporate records are part of the privacy landscape
Board and corporate secretarial records often contain highly sensitive personal data:
- Directors’ identification details, addresses, and specimen signatures
- Declarations of interest and tax documents
- Due diligence reports on officers or investors
If these materials are emailed loosely, stored indefinitely, or uploaded into unsecured tools, the governance function itself creates PDPA exposure. Review board portal access permissions, document classification rules, and the destruction practices for old board papers.
13. What company secretaries should do now
To bridge the gap between policy and practice, implement the following:
- Confirm the entity map and data flows: Identify which companies in the group control personal data.
- Assess DPO obligations: Ensure the company has appointed a Data Protection Officer and formally notified the Commissioner, as required by the Act.
- Establish a prompt DBN Protocol: Ensure an incident response workflow is documented to meet the statutory “as soon as practicable” reporting requirement.
- Review outsourcing contracts: Update processor agreements to reflect the new statutory liabilities imposed directly on vendors under the Security Principle.
- Tighten governance records: Apply strict access controls to board papers, registers, and statutory support documents.
- Brief the board: Transition PDPA from an IT sub-committee item to a primary board governance subject.
Conclusion
For Malaysian companies, PDPA compliance is no longer a website wording exercise. The expanded liabilities, mandatory breach reporting timelines, and DPO requirements fundamentally change how an organisation secures and governs data. Company secretaries sit closest to the records, workflows, and approvals where privacy failures often begin. The right approach is to ensure the company’s governance machinery is not the weak link in the compliance chain.