What the PDPA Actually Requires of a Business Website
The PDPA does not mandate a cookie banner; it requires a bilingual privacy notice, and 2024's amendments raised the stakes considerably.
The most common PDPA claim on Malaysian business websites is wrong
Search "PDPA website compliance" and you will find no shortage of Malaysian agencies and plugin vendors telling business owners that the Personal Data Protection Act 2010 requires a cookie consent banner, styled after the EU's GDPR pop-ups. It's a tidy, sellable claim. It is also not correct, and it's worth correcting plainly because getting it wrong costs businesses money on the wrong thing while leaving the actual legal requirement — a proper privacy notice — undone.
The PDPA does not contain a cookie-specific provision, and it does not mandate a GDPR-style consent banner. Malaysia has no dedicated ePrivacy law and, as international law firm Linklaters notes in its Malaysia data protection guide, "there are no specific ePrivacy laws" and "there are no express regulations applicable to the use of cookies" (Linklaters, Data Protected — Malaysia). That's a meaningfully different legal position from the EU, where a separate ePrivacy framework specifically governs cookies and tracking technologies. A banner can be reasonable practice if you're targeting EU visitors or want to be cautious about consent generally — but it is not what Malaysian law actually asks of you, and no business should be told otherwise as a compliance requirement.
So what does the PDPA actually require of a business website? Below is what the law requires, separated clearly from what is simply sensible practice, plus what changed when the Personal Data Protection (Amendment) Act 2024 came into force.
What the law requires: a proper privacy notice
The PDPA's Notice and Choice Principle, set out in Section 7 of the Act, is the core obligation for any business collecting personal data through a website — names, emails, phone numbers, form submissions, anything that identifies a person. It requires a written notice, given at or before the point personal data is collected, that discloses what is being collected, the purpose of collection, and the choices available to the data subject regarding their data. Malaysian legal commentary is consistent that this notice must be provided in both Bahasa Malaysia and English (Multilaw, Data Protection Guide — Malaysia).
In practice, this means a privacy notice or privacy policy page that:
- Exists in both languages, not English only.
- Names what personal data is collected (forms, WhatsApp enquiries, newsletter sign-ups, and so on).
- States why it's collected and how it will be used.
- Is genuinely accessible — linked from the footer or wherever a reasonable visitor would look, not buried.
This is the single most useful correction for most Malaysian business sites: the missing legal requirement usually isn't a cookie banner, it's a proper bilingual notice that actually describes what the business does with the data it collects.
What changed under the 2024 Amendment Act
The Personal Data Protection (Amendment) Act 2024 (Act A1727) received Royal Assent on 9 October 2024 and was gazetted on 17 October 2024. It came into force in three phases — 1 January 2025, 1 April 2025, and 1 June 2025 — rather than all at once (Legal500, Countdown to Compliance; PDP Department, Commencement Date Determination). As of 2026, the full Amendment Act is in force. Four changes matter most for an ordinary business website:
1. Mandatory Data Protection Officer appointment, from 1 June 2025. Organisations must appoint a DPO if they meet any one of these thresholds: processing personal data of 20,000 or more individuals, processing sensitive personal data of 10,000 or more individuals, or carrying out regular and systematic monitoring of personal data. The DPO must be registered with the Commissioner within 21 days of appointment (Lexology / Christopher & Lee Ong, Malaysia: New PDP Requirements Effective 1 June 2025). Most small Malaysian business websites — a shopfront, an SME collecting enquiry-form leads — will sit well under these thresholds and are not required to appoint a DPO. This is a genuine obligation, but it is a scale-triggered one, not a universal one.
2. Mandatory data breach notification, from 1 June 2025. Where a personal data breach is likely to cause significant harm to affected individuals, or affects a significant number of individuals (guidance sets this at 1,000 or more), the organisation must notify the Personal Data Protection Commissioner as soon as practicable and no later than 72 hours after becoming aware of the breach, and must notify the affected individuals without unnecessary delay and no later than seven days after the Commissioner has been notified (Christopher & Lee Ong, Guidelines on DPO Appointment and Data Breach Notification). Before this amendment, breach notification to the Commissioner was not a general statutory requirement in Malaysia.
3. Data processors are now directly regulated. Previously, the PDPA's obligations fell on the "data user" (broadly, the business that decides why and how data is processed) — a data processor acting on that business's behalf sat outside the Act's direct reach. The amendment brings data processors directly within the Security Principle in Section 9, meaning a processor handling data on your behalf now carries its own legal obligation to keep it secure, not just a contractual one owed to you.
4. Penalties for breaching the Data Protection Principles increased substantially. The maximum fine rose from RM300,000 to RM1,000,000, and the maximum prison term rose from two years to three years (Mayer Brown, Key Amendments to Malaysia's PDPA). This is a real deterrent shift, and it applies to the same underlying principles — including Section 7's Notice and Choice Principle — that a badly written or missing privacy notice would breach.
Required vs. good practice, side by side
To be explicit, since this is where most of the confusion sits:
Legally required for most business websites: a bilingual (Bahasa Malaysia and English) written privacy notice under Section 7, given at the point of data collection, disclosing what is collected and why.
Legally required only above the stated thresholds: DPO appointment and registration; the formal 72-hour/7-day breach notification process.
Good practice, not a PDPA requirement: a cookie consent banner, granular cookie preference controls, or GDPR-style consent-management platforms — reasonable if you have EU visitors, want to be cautious, or your platform's own tooling (analytics, ad pixels) recommends it, but not something the PDPA itself compels for a Malaysia-facing site.
A word on scope
The PDPA generally applies to the processing of personal data in commercial transactions in Malaysia, and it has its own definitions of "personal data," "data user," and "sensitive personal data" (now including biometric data under the amended Act) that don't map one-to-one onto GDPR terminology. If your business handles data in a way that's genuinely unusual — cross-border transfers, health data, data on minors, high-volume processing — the general summary above may not cover your situation, and that's exactly the point at which generic guidance (this article included) stops being enough.
This article is general information, not legal advice. It reflects our reading of the sources linked above as of August 2026. For anything beyond a standard small business website, get advice from a qualified Malaysian data protection lawyer, not a web agency's blog post.
Where JagaWeb fits
We're not a law firm and we don't draft your privacy notice for you claiming legal authority to do so. What we can do is check whether your website's privacy notice actually exists, is in both required languages, and is genuinely accessible — alongside the rest of your site's technical and security hygiene. JagaWeb's Essential System Review (RM1,500, currently RM999 until 16 September 2026) includes this check as part of a broader look at your site. It's an option worth considering, not a compliance guarantee — no one can promise you that. Reach us at sales@jagaweb.my or WhatsApp jagaweb.my.
Ready to verify who owns your website?
Replace uncertainty with a decision-ready ownership and access report. The fixed Ownership & Access Review is RM1,500 before SST and includes a 30-day action plan.