Skip to content
jagaweb.Book the Review
Security & Compliance

What Malaysian Law Requires After a Personal Data Breach

7 min readBy JagaWeb

PDPA breach notification timelines, thresholds and penalties since 1 June 2025, verified against pdp.gov.my and legal sources.

A database export goes to the wrong place. Now what?

Say a staff member emails a customer spreadsheet to the wrong address, or a misconfigured storage bucket leaves order records briefly public, or a laptop with cached customer data walks out the door. Until recently, what a Malaysian business had to do next was, legally speaking, vague — the Personal Data Protection Act 2010 (PDPA) said businesses must take reasonable steps to protect personal data, but it said nothing specific about telling anyone when that protection failed. That changed with the Personal Data Protection (Amendment) Act 2024 (Act A1727). This article sets out, as precisely as the current published sources allow, what the law now requires — and where the genuinely fuzzy edges still are.

Before anything else: this article explains what the law and the Commissioner's published guideline say. It is not legal advice, and it cannot tell you whether your specific incident meets the notification threshold or what your specific obligations are. If you are dealing with an actual suspected breach, get a Malaysian data protection lawyer involved — the timelines below are short, and the assessment of "significant harm" is a judgment call with real financial and criminal exposure attached to getting it wrong.

Yes — notification is now mandatory, not optional

The Amendment Act commenced in three stages: 1 January 2025, 1 April 2025, and 1 June 2025. Mandatory data breach notification, introduced as a new Section 12B of the PDPA, is part of the final tranche and has been in force since 1 June 2025 (Personal Data Protection Department, Act A1727). The Commissioner also published a Guideline on Data Breach Notification and an accompanying circular (Circular No. 1/2025) setting out the operational detail the Act itself leaves to guidance (PDP Department, "Guidelines and Circulars on Data Breach Notification (DBN)"). Before 1 June 2025, there was no general statutory duty in Malaysia to report a data breach to anyone. There now is, and it has real deadlines attached.

Step one: work out whether this breach even needs notifying

Not every incident triggers the obligation. The duty to notify turns on whether the breach causes, or is likely to cause, "significant harm" to affected individuals. According to the Commissioner's guideline, as summarised consistently by multiple Malaysian law firms, a breach meets that bar where the compromised data:

  • could result in physical harm, financial loss, damage to a person's credit record, or loss of or damage to property;
  • could be misused for an illegal purpose;
  • consists of sensitive personal data; or
  • combined with other available information, could enable identity fraud.

Separately, a breach affecting more than 1,000 individuals is treated as significant on scale alone — but for a specific reason worth getting right: that scale threshold requires notifying the Commissioner, even if none of the four harm criteria above are otherwise met. It does not, on its own, automatically require notifying the affected individuals themselves — that separate notification still depends on the breach actually meeting one of the harm criteria (Donovan & Ho, "Guideline on Data Breach Notification 2025"; HHQ, "Personal Data Breach Notification in Malaysia"). This is a genuinely easy distinction to get wrong under time pressure, which is exactly the kind of judgment call worth a lawyer's second opinion rather than a website vendor's.

Step two: notify the Commissioner — the clock is short

Where notification is required, the data controller must notify the Personal Data Protection Commissioner as soon as practicable, and in any case no later than 72 hours after becoming aware that the breach occurred (Donovan & Ho, op. cit.; DLA Piper Privacy Matters, "Malaysia: Guidelines Issued on Data Breach Notification"). Notification is made through the Department's data breach reporting channel, referenced on the Department's own site as its "Report DBN" facility (PDP Department, "Report DBN"), by email, or by hard copy submission to the Commissioner. If 72 hours passes before you notify, the guideline requires a written explanation for the delay, supported by evidence of the incident timeline — this is not a soft deadline that quietly extends itself.

Note what starts the clock, because published summaries do not agree. Law-firm commentary on the Commissioner's guideline generally describes the 72 hours as running from the occurrence of the breach, while a reading based on awareness would start it at discovery. The difference matters enormously for a breach found weeks after it happened. Treat occurrence as the safer assumption, act as soon as you become aware regardless, and take advice on your specific facts — do not rely on a later start date without confirming it.

Step three: notify affected individuals — a second, separate clock

If the breach meets the significant-harm threshold in a way that requires individual notification (see Step One above), affected individuals must be told without unnecessary delay, and no later than seven days after the Commissioner was notified — a second deadline that runs from the first, not from the original incident (Donovan & Ho, op. cit.). The form and manner of that notification is determined by the Commissioner's guidance rather than left entirely to the business's discretion, so this is another area where checking the current guideline document itself — or getting professional advice — matters more than relying on a general description like this one.

What it costs to get this wrong

The Amendment Act created two separate offences that a business can be exposed to here, and it's worth keeping them distinct because they are frequently conflated:

  1. Failing to comply with the breach notification duty itself (the Section 12B obligation covered above) carries, on conviction, a fine of up to RM250,000, imprisonment of up to two years, or both (Donovan & Ho, op. cit.).
  2. Separately, the Amendment Act more than tripled the general penalty for breaching any of the Act's core Personal Data Protection Principles — the underlying security and handling obligations that a breach often reveals were not being met in the first place — from a maximum of RM300,000 and two years' imprisonment, to a maximum of RM1,000,000 and three years' imprisonment (Sidley Austin, "Important Changes to Malaysia's Data Protection Laws"). A single incident can, in principle, expose a business to scrutiny under both provisions at once — the failure to notify, and the underlying data-handling failure that caused the breach.

What this article deliberately does not cover

A few things are genuinely unsettled or beyond what a general article can responsibly state, and are left out rather than guessed at: how the Commissioner exercises discretion in practice, what evidence satisfies a "reasonable" late-notification explanation, how obligations split between a data controller and a data processor when a breach originates with a third-party vendor, and whether any private right of civil action exists for affected individuals beyond the statutory offences above. None of these were verifiable to the standard this article holds itself to, so none are stated as fact here. If any of them apply to your situation, that is precisely the conversation to have with a lawyer, not a website.

Where JagaWeb fits, and where it doesn't

To be direct about scope: JagaWeb is a website-care and development company, not a law firm, and nothing above is a substitute for legal advice on an actual incident. What we can do is the technical side that often sits upstream of a breach — reviewing whether your website's data handling, access controls, backups, and third-party integrations create unnecessary exposure in the first place. That's part of what the Essential System Review (RM1,500, currently RM999 until 16 September 2026) looks at across eight control points for a single site of up to 25 pages, with a decision-ready report and a 30-day action plan. It is not a legal compliance certification and does not replace a data protection lawyer's advice on notification obligations — it's a technical starting point. Details at jagaweb.my, or contact sales@jagaweb.my /, or on WhatsApp through jagaweb.my.

PROTECT YOUR ASSETS

Ready to verify who owns your website?

Replace uncertainty with a decision-ready ownership and access report. The fixed Ownership & Access Review is RM1,500 before SST and includes a 30-day action plan.

WhatsApp