Mandatory DPO appointment and breach notification requirements under Malaysia’s amended Personal Data Protection Act 2010 come into force today, as part of the phased implementation of the 2024 amendments.
Key points
- A DPO must be appointed.
- Breaches must be notified to the Commissioner within 72 hours.
- Individuals must be notified within 7 days if significant harm is likely.
- Data processors are now directly subject to the Security Principle.
UK organisations with Malaysian operations should appoint a DPO where required and update breach procedures to meet the new notification deadlines.
Source: Guidelines on the appointment of a DPO (Malaysia Personal Data Protection Department)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.