Data Protection in Malaysia

Security in Malaysia

Under the PDPA, data users / data controllers have an obligation to take ‘practical’ steps to protect personal data, and in doing so, must develop and implement a security policy. The Commissioner may also, from time to time, set out security standards with which the data user must comply, and the data user is required to ensure that its data processors comply with these security standards. However, please note that the Amending Act has amended this by imposing the direct obligation on data processors to comply with the Security Principle under the PDPA.

In addition, the Standards provide separate security standards for personal data processed electronically and for personal data processed non-electronically (among others) and require data users to have regard to the Standards in taking practical steps to protect the personal data from any loss, misuse, modification, unauthorized or accidental access or disclosure, alteration or destruction. However, please note that the Standards are currently under review.

Continue reading

  • no results

Previous topic
Back to top