Jan 16
DATA PROTECTION OFFICER (DPO) Under Personal Data Protection Act (PDPA)

Effective Date: 1 June 2025
BACKGROUND
Malaysia’s data protection rules have become stricter. Under the Personal Data Protection (Amendment) Act 2024, certain organisations are now required by law to appoint a Data Protection Officer (DPO). This change reflects the growing risks around personal data misuse, cyber incidents, and privacy complaints. Businesses that collect, use, or store personal data must now take clearer responsibility for how that data is managed and protected.

WHAT IS A DATA PROTECTION OFFICER (DPO)?
A Data Protection Officer (DPO) is the person responsible for overseeing how an organisation handles personal data. In simple terms, the DPO:
• Ensures the organisation follows the PDPA
• Monitors how personal data is collected, used, stored, and shared
• Advises management on data protection risks
• Acts as the main contact point for:
– Regulators
– Customers, employees, and other data subjects
The DPO helps the organisation move from “reacting to problems” to preventing data protection issues.
• Ensures the organisation follows the PDPA
• Monitors how personal data is collected, used, stored, and shared
• Advises management on data protection risks
• Acts as the main contact point for:
– Regulators
– Customers, employees, and other data subjects
The DPO helps the organisation move from “reacting to problems” to preventing data protection issues.

WHAT IS A DATA PROTECTION OFFICER (DPO)?
A Data Protection Officer (DPO) is the person responsible for overseeing how an organisation handles personal data. In simple terms, the DPO:
• Ensures the organisation follows the PDPA
• Monitors how personal data is collected, used, stored, and shared
• Advises management on data protection risks
• Acts as the main contact point for:
– Regulators
– Customers, employees, and other data subjects
The DPO helps the organisation move from “reacting to problems” to preventing data protection issues.
• Ensures the organisation follows the PDPA
• Monitors how personal data is collected, used, stored, and shared
• Advises management on data protection risks
• Acts as the main contact point for:
– Regulators
– Customers, employees, and other data subjects
The DPO helps the organisation move from “reacting to problems” to preventing data protection issues.

WHICH ORGANISATIONS MUST APPOINT A DPO?
An organisation must appoint a DPO if it processes personal data involving:
• More than 20,000 data subjects (general personal data), or
• More than 10,000 data subjects involving sensitive personal data
Sensitive personal data includes:
• Financial information
• Health or medical records
• Biometric data
• Disciplinary or misconduct records
A DPO is also required if the organisation carries out regular and systematic monitoring, including:
• CCTV surveillance
• Tracking systems
• Profiling or behavioural monitoring activitiesThis applies to both private companies and organisations, regardless of size, if the thresholds are met.
• More than 20,000 data subjects (general personal data), or
• More than 10,000 data subjects involving sensitive personal data
Sensitive personal data includes:
• Financial information
• Health or medical records
• Biometric data
• Disciplinary or misconduct records
A DPO is also required if the organisation carries out regular and systematic monitoring, including:
• CCTV surveillance
• Tracking systems
• Profiling or behavioural monitoring activitiesThis applies to both private companies and organisations, regardless of size, if the thresholds are met.

WHO CAN BE APPOINTED AS A DPO?
A DPO can be:
• An internal employee, or
• An outsourced service provider
However, the DPO must:
• Have good knowledge of PDPA requirements
• Understand the organisation’s business operations
• Be familiar with data handling and IT/security practices
• Be a Malaysian resident, or be present in Malaysia for more than 180 days per year
• Be able to communicate effectively in Bahasa Malaysia and English
• An internal employee, or
• An outsourced service provider
However, the DPO must:
• Have good knowledge of PDPA requirements
• Understand the organisation’s business operations
• Be familiar with data handling and IT/security practices
• Be a Malaysian resident, or be present in Malaysia for more than 180 days per year
• Be able to communicate effectively in Bahasa Malaysia and English

WHAT MUST ORGANISATIONS DO?
If your organisation meets the criteria, you must:
• Formally appoint a DPO
• Formally appoint a DPO
• Register the DPO via the Sistem Perlindungan Data Peribadi (SPDP)
– Registration must be completed within 21 days of appointment
• Publish the DPO’s business contact details in:
– Company website
– Privacy notices
– PDPA or data protection statements
These details must be easily accessible to the public.
– Registration must be completed within 21 days of appointment
• Publish the DPO’s business contact details in:
– Company website
– Privacy notices
– PDPA or data protection statements
These details must be easily accessible to the public.

WHY THIS MATTERS
Failure to comply with PDPA obligations can result in serious consequences, including:
• Fines of up to RM250,000
• Imprisonment of up to 2 years
• Imprisonment of up to 2 years
• Or both
Beyond penalties, non-compliance can also damage trust, reputation, and customer confidence.
KEY TAKEAWAY
If your organisation handles large volumes of personal or sensitive data, DPO appointment is no longer optional. Early preparation helps reduce legal risk, strengthens governance, and demonstrates responsible data management.
Beyond penalties, non-compliance can also damage trust, reputation, and customer confidence.
KEY TAKEAWAY
If your organisation handles large volumes of personal or sensitive data, DPO appointment is no longer optional. Early preparation helps reduce legal risk, strengthens governance, and demonstrates responsible data management.
Source: Pesuruhjaya Perlindungan Data Peribadi (PDP Commissioner)
Performance
Portal
About
Legal & Policy
Copyright © 2026 3ntity Sdn Bhd & Training Kaw Kaw
