Home / Area of Practice / Data Privacy
Malaysia’s data protection landscape has changed significantly since the enactment of the Personal Data Protection Act 2010, most notably through the Personal Data Protection (Amendment) Act 2024, which introduced mandatory Data Protection Officer appointments, data breach notification obligations, a revised cross-border data transfer regime and enhanced data subject rights. Businesses that collect, process or manage personal data are now operating under a materially more demanding compliance framework, with real regulatory and reputational consequences for non-compliance.
We advise businesses on navigating these obligations in a practical and commercially sensible manner, helping clients build compliance frameworks that are proportionate to their risk profile and operational realities, while remaining responsive to the evolving expectations of the Department of Personal Data Protection (JPDP) and the wider regulatory environment.
Our advice is informed by an understanding of our clients’ data flows, systems and operational processes, allowing us to identify compliance obligations at an early stage and to develop practical, risk-proportionate solutions that support business objectives without losing sight of regulatory requirements.
Advising organisations on compliance with the Personal Data Protection Act 2010 and the Personal Data Protection (Amendment) Act 2024, including data protection policies, notices and internal governance frameworks.
Advising on the appointment, registration and governance role of Data Protection Officers, including internal reporting lines and oversight structures.
Advising data controllers and processors on breach identification, assessment and notification obligations to the Commissioner and affected data subjects within the prescribed timeframes, and assisting with regulatory engagement following a breach.
Advising on the requirements for transferring personal data outside Malaysia under the adequacy-based framework, including the preparation of Transfer Impact Assessments.
Advising on compliance with data subject rights requests, including access, correction, withdrawal of consent and the right to data portability.
Drafting and reviewing data processing agreements, data sharing agreements and other contractual arrangements governing the collection, use and disclosure of personal data.
Assisting clients in engagement with the Department of Personal Data Protection (JPDP), including responding to inquiries, audits and enforcement action.
Advising on disputes and potential disputes arising from data breaches, unauthorised disclosure of personal data and non-compliance with data protection obligations.
Whether advising a business on building a data protection compliance framework from the ground up, responding to a data breach, or navigating cross-border data transfer requirements, our objective is to provide advice that is legally rigorous, commercially practical and responsive to Malaysia’s evolving data protection landscape.