Customer Consent in Your CRM: PDPA Requirements | Disoft
CRM · Aug 24, 2026

Customer Consent in Your CRM: What Malaysia's PDPA Actually Requires

Before a name goes into your pipeline, the PDPA already has rules for how it got there: consent up front, an eight-point disclosure notice, and a withdrawal process that has no fixed deadline in the Act itself, whatever most guides claim.

Where consent starts

Section 6(1)(a) of the Personal Data Protection Act 2010, the General Principle, is the starting point for every contact in your CRM: a data user shall not process personal data about a data subject unless the data subject has given consent. Sensitive personal data, such as health or biometric information, sits under the stricter test in section 40.

Section 6(2) carves out six situations where processing is allowed without asking again: performing a contract with the data subject, taking steps toward one at their request, complying with a legal obligation, protecting the data subject's vital interests, the administration of justice, or exercising a function conferred by law. Outside those six, consent is not optional.

What your sign-up form has to disclose

Section 7, the Notice and Choice Principle, is the part most CRM opt-in forms skip past. A written notice must cover eight points: that the data is being processed, and a description of it; the purposes of collection and further processing; the source of the data, if known; the right to access and correct it, and how to raise a query; the classes of third parties it may be disclosed to; the choices and means offered to limit processing; whether supplying it is obligatory or voluntary; and, where obligatory, the consequences of not supplying it.

Section 7(2) sets the timing: as soon as practicable, when the data subject is first asked for their data or when it is first collected, or, in any other case, before it is used for a new purpose or disclosed to a third party. Section 7(3) requires the notice, and the means to exercise choice, to be given in both the national language and English, which is why the bilingual toggle on this site is not just a UX choice.

When someone withdraws consent: what the Act says, and the deadline people get wrong

This is the part worth getting right, because the number that circulates is borrowed from a different provision.

Section 38: a data subject may by notice in writing withdraw consent to the processing of their personal data. The data user shall, upon receiving that notice, cease the processing of the personal data. The Act states no fixed number of days.

Search around and you will find guides stating a flat 21 days to act on a withdrawal request. That figure is real, but it belongs to sections 31 and 35, which govern data access requests and data correction requests: a data user has 21 days to comply with those, with a further 14-day extension in limited cases. Withdrawal of consent under section 38 is a separate provision with no such window: the statutory instruction is simply to cease processing upon receiving the notice.

Practically, that makes withdrawal the stricter of the two. There is no 21-day cushion to lean on. If your CRM cannot suppress a contact from further processing the moment a withdrawal notice comes in, "we'll get to it" is not a position the Act gives you.

What it costs to get wrong

  • Continuing to process after a valid withdrawal: section 38(4) makes this an offence, with a fine of up to RM100,000 or imprisonment of up to one year, or both.
  • Processing without consent, or without a proper notice: a contravention of the General Principle or Notice and Choice Principle under section 5(2) carries a fine of up to RM1,000,000 or imprisonment of up to three years, or both.

What this means for how you run the CRM

  • Record when and how each contact's consent was given (the sign-up channel and the date), not just that a box was ticked somewhere.
  • Put the eight section 7(1) disclosures somewhere a customer actually reads, in Bahasa Malaysia and English, not buried in a footer link nobody opens.
  • Give marketing use its own, separate choice. Do not make WhatsApp broadcast or EDM opt-in a condition of being served as a customer.
  • Build a written withdrawal process that suppresses the contact from further processing immediately on receipt, not on your next campaign cycle.

Disoft's CRM pulls enquiries from Meta Ads, forms and WhatsApp straight into the pipeline, with the source recorded at the point of capture. If you want a straight answer on how your current sign-up flow and opt-out handling actually stack up against sections 6, 7 and 38, see All-in-One CRM or book a free audit and we will walk through it with you.

See also PDPA and Your CRM: What Changed in 2025 for the mandatory DPO, breach notification, and the penalties that followed the 2024 amendment.

This article is general information about Malaysian law, not legal advice, and it does not create a professional relationship. Statutory references are to the Personal Data Protection Act 2010, read as at 24 August 2026. Guidance issued by the Commissioner may impose further requirements and may change. Confirm your own position with a qualified adviser or with the Department of Personal Data Protection before acting.

Does your CRM know when someone said yes?

Book a free growth audit, no cost, no pressure. We will look at your opt-in notice, marketing consent and withdrawal handling.