What actually changed
The Personal Data Protection (Amendment) Act 2024, Act A1727, is the largest change to Malaysian data protection law since the original Act in 2010. It came into force in stages: 1 January 2025, 1 April 2025, and 1 June 2025, with the accountability provisions covered below taking effect on the last of those dates.
The first thing to notice is a word. Throughout the Act, "data user" was replaced with "data controller". That is not cosmetic. It signals the shift the rest of the amendment makes: from holding data to being accountable for it.
If you run a CRM, this is about you
A CRM holding customer names, phone numbers, emails, addresses or purchase history is a personal data database. The business deciding how that data gets used is the data controller. The software vendor or agency processing it on your behalf is a data processor.
The amendment inserted section 5(1A), requiring a data processor acting on a controller's behalf to comply with the Security Principle in section 9, and amended section 9 so that it binds both the controller and the processor. Before this, that duty sat with the controller alone. Your vendor now carries security obligations of its own, which is worth raising in your next contract review.
You must appoint a data protection officer
Section 12A, in the new Division 1A on accountability, is direct. A data controller shall appoint one or more data protection officers accountable to the controller for compliance with the Act. Where a processor handles data on the controller's behalf, the processor must appoint one or more as well. The controller must then notify the Commissioner of the appointment.
One line in that section is easy to skim past and matters a great deal: the appointment of a DPO does not discharge the controller or processor from any other duty under the Act. Naming someone does not move the liability. It adds a point of contact.
Breach notification: what the Act says, and what most articles say
This is where accuracy matters, because the number in circulation is not the one in the statute.
Section 12B(1): where a data controller has reason to believe that a personal data breach has occurred, the controller shall, as soon as practicable, notify the Commissioner in the manner and form determined by the Commissioner.
Most coverage states a flat 72 hours. That figure comes from the Commissioner's guidance, not from the wording of the Act, which sets no fixed number of hours. In practice you should plan to meet the guidance, but the operative statutory test is as soon as practicable, and it starts from when you have reason to believe a breach occurred, not from when it is confirmed.
Under section 12B(2), where the breach causes or is likely to cause significant harm to the data subject, the affected individuals must be notified too, without unnecessary delay.
The Act also defines what counts. A personal data breach is "any breach of personal data, loss of personal data, misuse of personal data or unauthorized access of personal data". Misuse and unauthorised access are in that list, so an employee pulling the customer list on their way out of the company is a breach, not merely a staffing problem.
What it costs to get wrong
- Contravening the data protection principles: the maximum was raised from a fine of RM300,000 or two years imprisonment to a fine of up to RM1,000,000 or imprisonment of up to three years, or both.
- Failing to notify the Commissioner of a breach: a fine of up to RM250,000 or imprisonment of up to two years, or both.
Three quieter changes worth knowing
- Data portability. A requestor may now make a data portability request, alongside the existing access and correction requests. Your CRM should be able to export one customer's record on request, not only the whole database.
- Biometric data is now sensitive personal data. The Act defines it as personal data resulting from technical processing relating to physical, physiological or behavioural characteristics. Fingerprint or face attendance systems fall inside the stricter category.
- Data subject excludes a deceased individual. A small clarification with practical effect on long-lived customer databases.
What this means for how you run the CRM
- Know who your DPO is, and that the Commissioner has been notified of the appointment.
- Have a written breach procedure that starts from reason to believe, not from confirmation, and names who decides and who notifies.
- Know which vendors process data on your behalf, and that their contracts reflect the section 9 obligation they now carry directly.
- Restrict export rights. Most breaches in a CRM are not intrusions, they are exports by people who already had access.
- Delete what you no longer need. The Retention Principle requires reasonable steps to destroy or permanently delete personal data once it is no longer required for the purpose it was collected for.
Disoft builds and runs CRM systems for Malaysian businesses. If you want a straight answer on how your current setup handles access rights, exports and retention, see All-in-One CRM or book a free audit and we will walk through it with you.
See also Customer Consent in Your CRM for what section 6 and section 7 require before a contact goes into your pipeline, and why the 21-day deadline people quote for withdrawing consent does not actually apply.
