Founder & Lead Engineer, RAITHub
Malaysia's amended PDPA now puts direct duties on data processors. Since 1 April 2025 a processor must meet the Security Principle itself, with penalties of up to RM1,000,000 or 3 years' imprisonment; since 1 June 2025 processors above set thresholds must appoint a data protection officer. Controllers must also notify the Commissioner of breaches within 72 hours and require processors to help.
This guide is for founders, CTOs and operations leads in Malaysia who use, or are about to hire, an outside development team. RAITHub is a software studio in Dhaka, so we have an interest in the answer; we would be the offshore processor in this picture, and we have no office in Malaysia. Everything below comes from the amending Act, the commencement order and the Commissioner's circulars, all linked. The circulars are published in Malay; the summaries of them here are our own translation. This is general information, not legal advice. Confirm every point with your adviser and the Personal Data Protection Commissioner (JPDP) before you sign.
What changed in the amended Malaysian PDPA?
The Personal Data Protection (Amendment) Act, Act A1727, received Royal Assent on 9 October 2024 and was gazetted on 17 October 2024 (Act A1727). It came into force in three stages under the commencement order (P.U. (B) 522). The changes that matter most to a processor are:
| Change | Act A1727 section | In force | What it means for a processor |
|---|---|---|---|
| "Data user" becomes "data controller" | s2 | 1 April 2025 | Contracts and policies should use the new term. |
| Biometric data added as sensitive personal data; "personal data breach" defined | s3 | 1 April 2025 | Face or fingerprint features in your product now carry sensitive-data rules. |
| A processor must meet the Security Principle (new s5(1A)); penalty raised from RM300,000 or 2 years to RM1,000,000 or 3 years | s4 | 1 April 2025 | The processor is directly exposed, not only through the contract. |
| The Security Principle (s9) now binds controller and processor | s5 | 1 April 2025 | Both must take practical steps to protect the data. |
| Cross-border transfer rules (s129) rewritten | s12 | 1 April 2025 | The controller needs a documented basis for sending data abroad. |
| Data protection officer (new s12A) and breach notification (new s12B) | s6 | 1 June 2025 | Processors above thresholds need a DPO; controllers need processors' help to notify on time. |
| Data portability (new s43A) | s9 | 1 June 2025 | The controller may need the vendor to export a person's data in a usable format. |
The remaining sections of the amending Act took effect on 1 January 2025. The Act also removes deceased persons from the definition of a data subject (s3).
Does the Malaysian PDPA apply to a vendor in Bangladesh?
The Malaysian business is bound either way. Whether the Act reaches the offshore vendor directly is less clear. The principal Act applies to processing in respect of commercial transactions (section 2(1)) by a person established in Malaysia, or one who uses equipment in Malaysia for processing other than for transit (section 2(2)), and it does not apply to data processed outside Malaysia unless it is intended to be processed further in Malaysia (section 3(2)) (Personal Data Protection Act 2010, Act 709).
How those tests apply to a team in Dhaka working on a Malaysian-hosted system is a question for your adviser. In practice it matters less than it seems: the controller will pass the processor duties down by contract, and a serious vendor should accept them whether or not the Act reaches it directly.
How do cross-border transfers work after the amendment?
The old model, where the Minister could specify permitted places, has gone; the amending Act deletes that subsection. Section 129 now says a data controller may transfer personal data to a place outside Malaysia that has a law substantially similar to the Act, or that ensures an adequate level of protection at least equivalent to the Act (Act A1727, s12).
The exceptions remain, including consent, performance of a contract with the data subject or with a third party at their request, legal proceedings, and a transfer where the controller has taken all reasonable precautions and exercised all due diligence to ensure the data will not be processed in a way that would breach the Act. The public-interest exception has been removed.
The Commissioner has issued guidelines on cross-border transfer of personal data. We have not summarised them here; read them with your adviser before choosing a basis.
What must happen when there is a data breach?
Under the new s12B, the controller notifies the Commissioner as soon as practicable, and affected people without unnecessary delay where the breach causes or is likely to cause significant harm. The Commissioner's breach notification circular (Pekeliling DBN, effective 1 June 2025, our translation) sets the detail:
| Step | Who | What the circular says |
|---|---|---|
| Tell the controller and help | Processor | The controller must oblige the processor, by contract or other reasonable means, to notify it of a breach and give all reasonable assistance |
| Notify the Commissioner | Controller | As soon as practicable once it has reason to believe a breach occurred, and within 72 hours of the breach (paragraph 4(1) and 4(4)); a late notice must give reasons and supporting evidence, and further information can follow in stages within 30 days |
| Decide whether harm is significant | Controller | Includes possible physical harm or financial loss, possible unlawful misuse, sensitive data, risk of identity fraud, or significant scale, meaning more than 1,000 affected people |
| Notify affected people | Controller | Where harm is significant, within 7 days of notifying the Commissioner |
| Keep records | Controller | At least 2 years |
Failing to notify the Commissioner can bring a fine of up to RM250,000 or imprisonment of up to 2 years. For a processor, the practical job is to make the first row fast. A small incident log helps both sides see the clock:
-- One row per suspected personal data breach, written by the vendor.
CREATE TABLE incident_log (
id bigserial PRIMARY KEY,
detected_at timestamptz NOT NULL,
controller_notified_at timestamptz,
affected_count integer,
data_classes text[] NOT NULL DEFAULT '{}',
summary text NOT NULL
);
-- Open incidents the controller has not been told about, oldest first.
SELECT id, detected_at, now() - detected_at AS age
FROM incident_log
WHERE controller_notified_at IS NULL
ORDER BY detected_at;
The log only works if the application records who touched which records; designing a SaaS audit log covers that side.
Does an offshore processor need its own data protection officer?
Only above the thresholds. The Commissioner's DPO circular (Pekeliling DPO, effective 1 June 2025, our translation) requires controllers and processors to appoint one where processing involves:
- personal data of more than 20,000 data subjects;
- sensitive personal data, including financial information, of more than 10,000 data subjects; or
- regular and systematic monitoring of personal data.
The DPO must be resident in Malaysia for at least 180 days a year or be easily reachable, and must be proficient in Bahasa Melayu and English. The role can be outsourced, and one person can serve several organisations. The controller registers its DPO with the Commissioner within 21 days, uses a dedicated business email for the role, and publishes the contact details.
Whether a development vendor crosses those thresholds depends on how much live data it actually processes. A team that builds on synthetic data and has no standing access to production is in a different position from one that runs your production database. Confirm where your vendor stands with your adviser.
What should a processor contract under the amended PDPA contain?
The Act puts the Security Principle on the processor directly; the rest reaches it through your contract. The table maps each clause to its source.
| Clause | Where it comes from | What to ask the vendor for |
|---|---|---|
| Security measures | s5(1A) and s9, as amended | Written security measures, covering the factors in s9(1), including where the data is stored and how it is transferred securely. |
| Breach notice and assistance | s12B; DBN circular | Notice to you fast enough for your 72-hour window, a named contact, and all reasonable assistance, including logs. |
| Transfer basis and locations | s129, as amended | A list of the countries where data is stored or accessed, and the facts you need to document your basis for the transfer. |
| DPO position | s12A; DPO circular | Either the vendor's DPO details, or a written statement of why it is below the thresholds, reviewed each year. |
| Instructions and scope | Processor definition, s4 of Act 709 | Processing only on your behalf and on your instructions, for the listed purposes. |
| Sub-processors | Contract term | A list, your approval before any new one, and the same terms flowed down. |
| Portability support | s43A | Help exporting a person's data in a usable format when you receive a request. |
| Deletion or return | Contract term | Deletion or return of your data at the end of the contract, with written confirmation. |
Bundle it with the IP assignment and NDA; the offshore IP assignment checklist covers those. If you also sell into Europe, outsourcing under GDPR shows the equivalent clauses there.
Can the data stay in Malaysia while the team builds from Dhaka?
Often, yes, and it shrinks most of the questions above. AWS runs an Asia Pacific (Malaysia) region, ap-southeast-5, which has to be enabled on the account before use (AWS Regions). Host production there, keep development and staging on synthetic data, and grant production access only for approved, time-limited, logged incident work. Row-level security keeps tenants apart in the database itself; the Postgres row-level security guide shows how. This is engineering guidance; whether remote access counts as a transfer in your set-up is for your adviser.
Kuala Lumpur is on UTC+8 and Dhaka on UTC+6, a fixed 2-hour gap. With both sides on a 9:00 to 18:00 day, that leaves about 7 shared working hours, 11:00 to 18:00 in Kuala Lumpur, which matters when a 72-hour clock is running.
Why RAITHub for this
- We sign your paper. RAITHub signs DPAs and SCCs and follows your controls. NDA is standard, and the client owns the IP.
- Synthetic data by default. Builds run on generated data, with seed scripts that refuse to touch a production database, so most of the team never sees live records.
- Access control we have shipped. Sundor Skin runs 146 PostgreSQL tables with row-level security, 88 permission codes and 12 staff roles, covered by 530+ tests.
- About 7 shared hours with Kuala Lumpur, plus written daily handoffs, so a breach question gets a live answer.
- A clear next step. Multi-tenant products run under SaaS development; integration work under API and backend development.
When you don't need us
- You need your vendor to supply a DPO. The circular requires Bahasa Melayu and English, and RAITHub works in English only. Use an outsourced DPO service in Malaysia.
- You need legal advice. RAITHub has no legal expertise; have a Malaysian data protection lawyer draft or review the contract.
- You need a certified vendor. RAITHub is not SOC 2 or ISO 27001 certified. See answering a security questionnaire without SOC 2 for what we can show instead.
- You need notices and interfaces in Malay. The Act requires notices in Malay and English (section 7(3) of Act 709). RAITHub can build bilingual screens from your translations, but cannot write or check the Malay.
- You want a developer placed in your team. RAITHub does not offer staff augmentation.
For a wider view of choosing a vendor, see how to choose a software company in Bangladesh and is it safe to hire a Bangladesh software agency.
Sources checked on 30 September 2026: Act A1727, P.U. (B) 522, Act 709, and the Commissioner's DBN and DPO circulars (our translation from Malay). General information only; confirm with your adviser and the Commissioner.
If none of those rule us out, book the free 15-minute technical audit. Bring a list of the personal data your product holds, and we will tell you on the call what the team would and would not need to see.
Frequently asked questions
When did the Malaysian PDPA amendments take effect?
In three stages: 1 January 2025, 1 April 2025 for processor security duties, the new penalty and the cross-border rules, and 1 June 2025 for the DPO, breach notification and data portability provisions. This is general information; confirm the current position with your adviser.
Are data processors now directly liable under the Malaysian PDPA?
For security, yes. The new section 5(1A) requires a data processor to meet the Security Principle, with penalties of up to RM1,000,000 or 3 years' imprisonment. Other duties reach the processor through its contract with the controller.
How quickly must a data breach be reported in Malaysia?
The Commissioner's circular says within 72 hours of the breach, with further information allowed in stages within 30 days. Where harm is significant, affected people must be told within 7 days of notifying the Commissioner.
Can Malaysian personal data be transferred abroad after the amendment?
Yes, to a place with a substantially similar law or adequate protection at least equivalent to the Act, or under an exception such as consent or all reasonable precautions and due diligence. The ministerial whitelist has been removed.
Does an offshore developer need a DPO in Malaysia?
Only if its processing crosses the circular's thresholds, such as more than 20,000 data subjects or sensitive data of more than 10,000. The DPO must be proficient in Bahasa Melayu and English and resident in, or easily reachable from, Malaysia.
Can RAITHub host our data in Malaysia?
RAITHub can deploy your product to your own cloud account in a Malaysian region and build on synthetic data, so production stays onshore. RAITHub signs DPAs and SCCs and follows your controls; it holds no SOC 2 or ISO 27001 certification.
Related posts
Ready to discuss your project?
Book a free 15-minute technical audit with our engineering team.