Regional Round-up
Issue 3 of 2024

Your Snapshot of Key Legal Developments in Asia

Issue 3 of 2024 (Jul / Aug / Sep)

Cover Story

MALAYSIA

Amendments to Personal Data Protection Act 2010

On 31 July 2024, the Malaysian Parliament passed the Personal Data Protection (Amendment) Bill 2024 (“Amendment Bill“), which will introduce key amendments to the Personal Data Protection Act 2010 (“PDPA“) including:

  1. changing the term “data users” to “data controllers”;
  2. recognising the increased importance of biometric data by amending the definition of “sensitive personal data” to include biometric data such as fingerprint scans;
  3. increasing the maximum penalty for breaches of any personal data protection principles to RM1 million or imprisonment of up to three years, or both;
  4. directly regulating all “data processors” under section 9 of the PDPA and requiring them to comply with the same security requirements that “data controllers” are subject to;
  5. requiring all “data controllers” and “data processors” to appoint a Data Protection Officer (“DPO“), with a guideline on DPOs expected to be issued soon;
  6. requiring data breaches that meet a certain threshold to be reported to the Personal Data Protection Commissioner and to affected data subjects, with a Guideline on Data Breach Notifications to be issued soon;
  7. introducing a new right to data portability, which will be supplemented by the upcoming Guideline on Data Portability; and
  8. removing the country whitelist for cross-border data transfers, and further clarifying the transfer mechanisms through the upcoming issuance of the Guideline on Cross-Border Data Transfers.

On 17 October 2024, the Amendment Bill has received royal assent and was published in the Federal Gazette as the  Personal Data Protection (Amendment) Act 2024 (“Amendment Act“). However, the Amendment Act has not yet come into force. It will take effect on a later date to be appointed by Digital Minister Gobind Singh. There is a possibility that different provisions of the Amendment Act may come into force on different dates.

Please note that whilst the information in this Update is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as a substitute for specific professional advice.

Rajah & Tann Asia is a network of legal practices based in Asia.

Member firms are independently constituted and regulated in accordance with relevant local legal requirements. Services provided by a member firm are governed by the terms of engagement between the member firm and the client.

This website is solely intended to provide general information and does not provide any advice or create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on this website.

© 2024 Rajah & Tann Asia. All Rights Reserved. All trademarks are property of their respective owners.