{"id":864,"date":"2021-11-18T11:09:00","date_gmt":"2021-11-18T11:09:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=864"},"modified":"2026-03-12T08:19:54","modified_gmt":"2026-03-12T08:19:54","slug":"malaysia-pdpa","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/us\/malaysia-pdpa\/","title":{"rendered":"Data Protection Act Malaysia (PDPA)"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-quick-summary\">Quick summary<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malaysia-s-pdpa-in-brief\">Malaysia\u2019s PDPA, in brief<\/h3>\n\n\n\n<p>Malaysia\u2019s <strong>Personal Data Protection Act (PDPA)<\/strong>&nbsp;was passed in 2010, took effect in 2013 and was last updated in 2016.<\/p>\n\n\n\n<p>Malaysia\u2019s PDPA revolves around <strong>end-user consent<\/strong>, requiring your website to first obtain express and explicit consent from its visitors before activating any cookies and trackers that process personal data, much like other major data privacy laws around the world such as the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>, <a href=\"\/en\/lgpd\/\">Brazil\u2019s LGPD<\/a>&nbsp;and <a href=\"\/en\/popia\/\">South Africa\u2019s POPIA<\/a>.<\/p>\n\n\n\n<p>The Malaysian PDPA governs the <strong>commercial use<\/strong>&nbsp;of personal data, and does not apply to the public sector, federal or state governments.<\/p>\n\n\n\n<p>Most websites in the world use cookies and trackers that process personal data, such as IP addresses, unique IDs, search and browser history. Under Malaysia\u2019s PDPA, you need to ask for and get the explicit consent from your website\u2019s visitors before activating any of these cookies.<\/p>\n\n\n\n<p><strong>Did you know that a website on average has 21 cookies in use?<\/strong><br><a href=\"\/\">Scan your website for free to detect and control them all<\/a><\/p>\n\n\n\n<p>In short, <strong>Malaysia\u2019s PDPA<\/strong>&nbsp;requires that you <strong>obtain end-user consent<\/strong>, requires you to <strong>inform Malaysian users<\/strong>&nbsp;about your website\u2019s data processing, empowers Malaysian residents with the <strong>rights to access and correct<\/strong>&nbsp;their data, regulates all personal data processing through its <strong>7 PDPA Principles<\/strong>. It is enforced by the <strong>Department of Personal Data Protection (PDP)<\/strong>&nbsp;and applies to any website, company or organization in Malaysia that processes personal data from Malaysian residents.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4058\/kishor-oh23idj6azm-unsplash.jpg?width=369&amp;&amp;mode=max\" alt=\"Person behind a steamed up window wearing a face mask - Cookiebot\" width=\"770px\" height=\"513px\"\/><figcaption class=\"wp-element-caption\">Malaysia\u2019s PDPA requires that you obtain consent from your website\u2019s visitors in order to use cookies and trackers.<\/figcaption><\/figure>\n\n\n\n<p><strong>Malaysia\u2019s PDPA quick breakdown<\/strong>&nbsp;\u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Malaysia\u2019s PDPA<\/strong>&nbsp;took effect in November 2013 and was amended in 2016.<\/li>\n\n\n\n<li><strong>Malaysia\u2019s PDPA<\/strong>&nbsp;regulates the processing of personal data for commercial use in the country. It does not apply to the public sector or government, federal or state.<\/li>\n\n\n\n<li><strong>Malaysia\u2019s PDPA<\/strong>&nbsp;applies to websites, companies or organizations in Malaysia who process personal data from Malaysian residents. It does not have extraterritorial scope.<\/li>\n\n\n\n<li><strong>Malaysia\u2019s PDPA<\/strong>&nbsp;requires you to obtain explicit\/express end-user consent prior to any personal data processing and to inform users about the data processing; its purpose and who it is shared with. Implied consent like continued scrolling is not valid under the PDPA.<\/li>\n\n\n\n<li><strong>Malaysia\u2019s PDPA<\/strong>&nbsp;operates on its 7 Data Protection Principles (PDPA Principles), which spell out its consent requirements, notification and information requirements, as well as requirements for security and retention of the personal data collected.<\/li>\n\n\n\n<li><strong>Malaysia\u2019s PDPA<\/strong>&nbsp;empowers Malaysian residents with the right of access to their personal data, the right to correct their personal data, the right to withdraw consent at any time, and the right to stop the processing of their data for direct marketing purposes or if deemed that the processing is likely to cause damage or harm.<\/li>\n\n\n\n<li><strong>Malaysia\u2019s PDPA<\/strong>&nbsp;defines personal data in relation to commercial transactions as information that is able to identify an individual, either directly or indirectly. This includes cookies and trackers on your website that process data such as IP addresses, unique IDs, search and browser history.<\/li>\n\n\n\n<li><strong>Malaysia\u2019s PDPA<\/strong>&nbsp;defines processing broadly to include collecting, using, sharing, selling, storing etc. of personal data. This means that cookies on your website collecting personal data and sharing it with third parties falls under the definition of processing under Malaysia\u2019s PDPA.<\/li>\n\n\n\n<li><strong>Malaysia\u2019s PDPA<\/strong>&nbsp;prohibits transfers of personal data outside of Malaysia, with the exception of countries that have been whitelisted by the Malaysian government, or if specific consent is obtained from the end-user to do so.<\/li>\n\n\n\n<li><strong>Malaysia\u2019s PDPA<\/strong>&nbsp;is enforced by the Department of Personal Data Protection (PDP) and its appointed Commissioner.<\/li>\n\n\n\n<li>Non-compliance with <strong>Malaysia\u2019s PDPA<\/strong>&nbsp;can result in fines up to MYR 500,000 and\/or up to three years imprisonment.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4059\/zamirul-roslan-gg0z4rsfky4-unsplash.jpg?width=365&amp;&amp;mode=max\" alt=\"Three people sitting on the ground chatting outside - Cookiebot\" width=\"770px\" height=\"513px\"\/><figcaption class=\"wp-element-caption\">Under Malaysia\u2019s PDPA, Malaysian residents are empowered with enforceable rights over their personal data.<\/figcaption><\/figure>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot consent management platform (CMP) for free<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see all cookies and trackers in use<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-malaysia-pdpa-compliance-with-cookiebot-cmp\">Malaysia PDPA compliance with Cookiebot CMP<\/h2>\n\n\n\n<p>Cookiebot CMP\u00a0is a world-leading solution for controlling all cookies and trackers on your website to ensure compliance with major data privacy laws around the world, including\u00a0<strong>Malaysia\u2019s PDPA<\/strong>,\u00a0<a href=\"\/\">EU\u2019s GDPR<\/a>,<a href=\"\/en\/uk-gdpr\/\">\u00a0UK\u2019s GDPR<\/a>,\u00a0<a href=\"\/en\/ccpa\/\">California\u2019s CCPA<\/a>,\u00a0<a href=\"\/en\/lgpd\/\">Brazil\u2019s LGPD<\/a>,\u00a0<a href=\"\/en\/popia\/\">South Africa\u2019s POPIA<\/a>\u00a0and many others.<\/p>\n\n\n\n<p>Since Malaysia\u2019s PDPA requires you to\u00a0<strong>ask for and obtain the express and explicit consent from Malaysian users before using cookies and trackers on your website<\/strong>,\u00a0Cookiebot CMP\u00a0is the optimal solution to make your domain fully compliant without any need for complex technical implementation on your end.<\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;is a plug-and-play compliance solution that has automated the entire PDPA compliance process \u2013 from automatically detecting all your website\u2019s cookies and controlling them, to collecting the PDPA compliant consents from end-users and securely storing them, as well as renewing them regularly.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"\/media\/4333\/consent_en.png?width=500&amp;\" alt=\"Cookieboot Pop Up Banner - Cookiebot\" width=\"770px\" height=\"449px\"\/><figcaption class=\"wp-element-caption\">Consent banner by Cookiebot CMP for PDPA compliance in Malaysia.<\/figcaption><\/figure>\n\n\n\n<p>By giving you detailed information on each cookie on your website, including the <strong>purpose<\/strong>, <strong>duration<\/strong>, <strong>technical specifications<\/strong>&nbsp;and <strong>provider<\/strong>, <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;enables your website to meet the notification and information requirements necessary for PDPA compliance in Malaysia.<\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;comes with <strong>highly customizable consent banners<\/strong>&nbsp;to match your website\u2019s layout and can be shaped to fit compliance requirements under most other major data privacy laws in the world.<\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for PDPA compliance in Malaysia<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website for free to see what cookies and trackers are in use<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Get started with Cookiebot CMP and Google Consent Mode<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-malaysia-s-pdpa-in-detail\">Malaysia\u2019s PDPA, in detail<\/h2>\n\n\n\n<p>Let\u2019s break down <strong>Malaysia\u2019s PDPA in detail<\/strong>&nbsp;and have a look at its <strong>7 PDPA Principles<\/strong>, which spell out the specifics of its compliance requirements, as well as making a comparison between Malaysia\u2019s PDPA and the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>.<\/p>\n\n\n\n<p>The Personal Data Protection Act (PDPA) forms Malaysia\u2019s data privacy regime and is accompanied by both the <a href=\"https:\/\/www.pdp.gov.my\/jpdpv2\/assets\/2019\/09\/Peraturan-peraturan_Perlindungan_Data_Peribadi.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Personal Data Protection Regulations (PDPR) 2013<\/a>&nbsp;that detail the practical aspects of PDPA compliance, and the <a href=\"https:\/\/www.pdp.gov.my\/jpdpv2\/assets\/2019\/09\/Communications-Sector-PDPA-COP.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Codes of Practice 201<\/a>7 that set best-practice standards for PDPA compliance in each sector of Malaysia.<\/p>\n\n\n\n<p>Under Malaysia\u2019s PDPA, you are <strong>required to register as a data user<\/strong>&nbsp;with the <a href=\"https:\/\/www.pdp.gov.my\/\" target=\"_blank\" rel=\"noreferrer noopener\">Department of Personal Data Protection (PDP)<\/a>&nbsp;if you process personal data within sectors such as communications, banking, finance, insurance, tourism, education, and others.<\/p>\n\n\n\n<p>You are also required to, as part of the registration to Commissioner at the PDP, to appoint a representative responsible for PDPA compliance.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.kkmm.gov.my\/pdf\/Personal%20Data%20Protection%20Act%202010.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">See the full Malaysia PDPA law text (in English)<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.pdp.gov.my\/jpdpv2\/assets\/2019\/09\/Peraturan-peraturan_Perlindungan_Data_Peribadi.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">See the full Personal Data Protection Regulations (in Malay)<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.pdp.gov.my\/jpdpv2\/assets\/2019\/09\/Communications-Sector-PDPA-COP.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">See the full Codes of Practice for the Communications sector (relevant for websites) (in English)<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.pdp.gov.my\/\" target=\"_blank\" rel=\"noreferrer noopener\">Visit the Department of Personal Data Protection (PDP) for more on Malaysia\u2019s PDPA<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malaysia-s-7-pdpa-principles\">Malaysia\u2019s 7 PDPA Principles<\/h3>\n\n\n\n<p>Under Malaysia\u2019s data privacy law, compliance is governed by seven data protection principles that detail how your website is required to handle user\u2019s personal data.<\/p>\n\n\n\n<p>The seven Malaysian PDPA Principles are \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>General Principle<\/li>\n\n\n\n<li>Notice and Choice Principle<\/li>\n\n\n\n<li>Discourse Principle<\/li>\n\n\n\n<li>Security Principle<\/li>\n\n\n\n<li>Retention Principle<\/li>\n\n\n\n<li>Data Integrity Principle<\/li>\n\n\n\n<li>Access Principle<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4060\/esmonde-yong-9b08udumyy-unsplash.jpg?width=368&amp;&amp;mode=max\" alt=\"Petronas Twin Tower in Kuala Lumpur - Cookiebot\" width=\"770px\" height=\"517px\"\/><figcaption class=\"wp-element-caption\">End-users are protected under Malaysia\u2019s PDPA from unconsented data harvest by third parties.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malaysia-s-pdpa-principle-1-general-principle\">Malaysia\u2019s PDPA Principle 1 \u2013 General Principle<\/h3>\n\n\n\n<p>Under the first Malaysian PDPA Principle called the \u201cGeneral Principle\u201d, the <strong>requirement for your website to obtain the valid consent from users prior to any personal data collection<\/strong>&nbsp;is explained.<\/p>\n\n\n\n<p>This PDPA Principle states that <strong>consent must be an explicit, affirmative opt-in on part of a user<\/strong>&nbsp;for it to be valid under Malaysia\u2019s PDPA.<\/p>\n\n\n\n<p>This means that implied consent does not constitute valid consent under Malaysia\u2019s PDPA (e.g. having a cookie banner on your website saying that personal data is being collected with no real way for users to first consent to the collection or to opt out).<\/p>\n\n\n\n<p>In general, under Malaysia\u2019s PDPA, <strong>personal data is only allowed to be processed if it\u2019s<\/strong>&nbsp;\u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>directly related to a lawful purpose for your website\u2019s activity<\/li>\n\n\n\n<li>necessary for that lawful purpose<\/li>\n\n\n\n<li>and limited to what is adequate to fulfill that purpose<\/li>\n<\/ul>\n\n\n\n<p>Exceptions to the consent requirement are also detailed and include situations such as when personal data is collected in order to fulfill a contract, among others.<\/p>\n\n\n\n<p>For data to be regarded as <strong>personal data<\/strong>&nbsp;under Malaysia\u2019s PDPA, it must meet the following three thresholds \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>be processed in connection with a commercial purpose\/transaction<\/li>\n\n\n\n<li>be processed partly or fully by automated means<\/li>\n\n\n\n<li>be directly or indirectly identifiable of an individual in Malaysia<\/li>\n<\/ul>\n\n\n\n<p><strong>Sensitive personal data<\/strong>&nbsp;includes \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Health and medical data<\/li>\n\n\n\n<li>Political convictions<\/li>\n\n\n\n<li>Religious beliefs<\/li>\n<\/ul>\n\n\n\n<p>There are no specific requirements in regard to consent when it comes to <strong>sensitive personal data<\/strong>&nbsp;\u2013 all consents must be explicit and express opt-in on part of the end-user.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4061\/siti-rahmanah-mat-daud-klijbmgs3ke-unsplash.jpg?width=366&amp;&amp;mode=max\" alt=\"Road in Malaysia with buildings in the background - Cookiebot\" width=\"770px\" height=\"513px\"\/><figcaption class=\"wp-element-caption\">Under Malaysia\u2019s PDPA, personal data includes the stuff that most cookies on websites process: IP addresses, search history, browser history, device details and unique IDs.<\/figcaption><\/figure>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for PDPA compliance today<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see if you have cookies and trackers that process personal data<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malaysia-s-pdpa-principle-2-notice-and-choice\">Malaysia\u2019s PDPA Principle 2 \u2013 Notice and choice<\/h3>\n\n\n\n<p>The second PDPA Principle explains how <strong>you must give end-users a prior notice about- and detailed information on your website\u2019s personal data processing activities<\/strong>.<\/p>\n\n\n\n<p>You must inform your Malaysian end-users about \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>your website\u2019s intention to collect personal data<\/li>\n\n\n\n<li>what kinds of data is to be collected<\/li>\n\n\n\n<li>why your website collects personal data (for what purposes)<\/li>\n\n\n\n<li>who you share this personal data with<\/li>\n\n\n\n<li>their rights to access and correct personal data<\/li>\n\n\n\n<li>whether the data collection is mandatory or voluntary (e.g. as part of a contract)<\/li>\n\n\n\n<li>any means by which the end-users can limit the processing of their personal data<\/li>\n\n\n\n<li>your contact information<\/li>\n<\/ul>\n\n\n\n<p>This notice for your Malaysian end-users forms part of the basis for the consent requirement, since users <strong>must know what they are consenting to<\/strong>.<\/p>\n\n\n\n<p>The notice must be given <strong>before any processing takes place<\/strong>&nbsp;of personal data from end-users, and it must be given <strong>in both Malay and English<\/strong>.<\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for PDPA compliance today<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see if you process personal data in Malaysia<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malaysia-s-pdpa-principle-3-disclosure\">Malaysia\u2019s PDPA Principle 3 \u2013 Disclosure<\/h3>\n\n\n\n<p>Disclosure of personal data to any third party is <strong>prohibited by Malaysia\u2019s PDPA unless explicit consent<\/strong>&nbsp;has been obtained from the end-user.<\/p>\n\n\n\n<p>This means that whatever personal data your website collects through its cookies and trackers, e.g. via analytics services or social media plugins, can only be shared with anyone else if your website\u2019s visitors have given you their express consent to do so.<\/p>\n\n\n\n<p>In general, sharing and disclosure of personal data is restricted to the purposes stated in your notice and information to the end-user and limited to the third parties that you\u2019ve listed.<\/p>\n\n\n\n<p>Correct and accurate lists of third parties that your website shares personal data with can be requested by the <a href=\"http:\/\/www.pdp.gov.my\/\" target=\"_blank\" rel=\"noreferrer noopener\">Personal Data Protection Department of Malaysia (PDPD)<\/a>&nbsp;and subject to inspection.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"\/media\/4062\/mkjr_-ru6mp7w_uli-unsplash.jpg?width=379&amp;&amp;mode=max\" alt=\"Malaysian flag on a flag pole - Cookiebot\" width=\"770px\" height=\"442px\"\/><figcaption class=\"wp-element-caption\">While transfers of personal data abroad is not prohibited under Malaysia\u2019s PDPA, end-users must consent to all third parties, who their personal is shared with.<\/figcaption><\/figure>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for PDPA compliance today<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see what cookies and trackers are in use<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malaysia-s-pdpa-principle-4-security\">Malaysia\u2019s PDPA Principle 4 \u2013 Security<\/h3>\n\n\n\n<p>Under Malaysia\u2019s PDPA, it is mandatory for you to put in place safeguards to protect whatever personal data you collect from end-users.<\/p>\n\n\n\n<p>To meet this PDPA compliance requirement, your website must have <strong>a<\/strong> <strong>security policy<\/strong>&nbsp;that details, among others \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>who has access to personal data, including a registration system in place to monitor access<\/li>\n\n\n\n<li>what measures are taken to ensure that personal data is always handled confidentially<\/li>\n\n\n\n<li>what technical safeguards are in place, such as secure storage and recovery systems<\/li>\n\n\n\n<li>how personal data is transferred securely<\/li>\n<\/ul>\n\n\n\n<p>The legal responsibility of protecting Malaysian end-users\u2019 personal data includes, - but is not limited to - technical security measures (e.g. safe storage, encryption, safe transfer means), organizational security measures (e.g. appointed compliance personnel, access and authorizations) and safeguarding personal data from misuse and abuse (e.g. unconsented disclosure, data breaches and loss).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malaysia-s-pdpa-principle-5-retention\">Malaysia\u2019s PDPA Principle 5 \u2013 Retention<\/h3>\n\n\n\n<p>Once you\u2019ve collected personal data from end-users, you\u2019re <strong>only allowed to retain (or store) it<\/strong>&nbsp;for the amount of time necessary for the fulfilment of the purpose, which you stated in your notice and information.<\/p>\n\n\n\n<p>Under Malaysia\u2019s PDPA, once personal data has been used for the purpose it was collected for, your website is legally required to <strong>delete it<\/strong>.<\/p>\n\n\n\n<p>There are no standard minimum retention periods detailed in Malaysia\u2019s PDPA, but it is up to you to determine the minimum necessary duration for storing personal data collected on your website (with regard to the purpose for which it was initially collected, of course).<\/p>\n\n\n\n<p>However, there are certain additional requirements that you need to be aware of, such as \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>to maintain records of your deletion of personal data, subject to inspection by the PDPD<\/li>\n\n\n\n<li>to keep a 24-month schedule for the regular clean-up\/deletion of personal data not in use<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4063\/vismen-subramaniam-zgzprkbomyc-unsplash.jpg?width=371&amp;&amp;mode=max\" alt=\"Aerial view of a a part of Malaysia - Cookiebot\" width=\"770px\" height=\"513px\"\/><figcaption class=\"wp-element-caption\">You\u2019re not allowed to collect more data or to keep it for longer than necessary, under Malaysia\u2019s PDPA.<\/figcaption><\/figure>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for PDPA compliance today<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Get started with Cookiebot CMP and Google Consent Mode<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malaysia-s-pdpa-principle-6-data-integrity\">Malaysia\u2019s PDPA Principle 6 \u2013 Data Integrity<\/h3>\n\n\n\n<p>\u201cData integrity\u201d means the responsibility that \u2013 under Malaysia\u2019s PDPA \u2013 rests on you and your website\u2019s shoulders to always make sure that the personal data collected from end-users is <strong>complete<\/strong>, <strong>accurate<\/strong>&nbsp;and<strong>&nbsp;up to date<\/strong>.<\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for PDPA compliance today<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Learn more about website tracking and cookies<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malaysia-s-pdpa-principle-7-access\">Malaysia\u2019s PDPA Principle 7 \u2013 Access<\/h3>\n\n\n\n<p>It\u2019s the right of Malaysian end-users to <strong>request access<\/strong>&nbsp;to see what personal data you\u2019ve collected on them, e.g. through cookies and trackers on your website \u2013 and to <strong>request correction<\/strong>&nbsp;of that data, if they find it to be incomplete, inaccurate or misleading.<\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for PDPA compliance today<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see all cookies and trackers in use<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-malaysia-s-pdpa-vs-gdpr\">Malaysia\u2019s PDPA vs GDPR<\/h2>\n\n\n\n<p>Malaysia\u2019s PDPA is very similar to the <a href=\"\/\">EU\u2019s GDPR<\/a>&nbsp;in key areas, chief among them being <strong>prior consent<\/strong>&nbsp;and <strong>rights to access<\/strong>&nbsp;and <strong>correct<\/strong>&nbsp;personal data.<\/p>\n\n\n\n<p><em><strong>Prior consent<\/strong><\/em>&nbsp;is perhaps the most famous part of the <a href=\"\/\">EU\u2019s GDPR<\/a>&nbsp;and Malaysia\u2019s equivalent regime puts it on the map as one of the consent-focused data privacy laws in the world, alongside <a href=\"\/en\/lgpd\/\">Brazil\u2019s LGPD<\/a>, <a href=\"\/en\/pipeda\/\">Canada\u2019s PIPEDA<\/a>, <a href=\"\/en\/popia\/\">South Africa\u2019s POPIA<\/a>&nbsp;and <a href=\"\/en\/singapore-pdpa\/\">Singapore\u2019s PDPA<\/a>&nbsp;\u2013 and setting it apart from opt-out focused laws like <a href=\"\/en\/ccpa\/\">California\u2019s CCPA<\/a>.<\/p>\n\n\n\n<p>But while <strong>Malaysia\u2019s PDPA<\/strong>&nbsp;and the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>&nbsp;look quite similar, the two data privacy laws are different in key areas.<\/p>\n\n\n\n<p>Big differences between the PDPA and GDPR include \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Malaysia\u2019s PDPA only applies to personal data for commercial use, while the EU\u2019s GDPR governs all personal data, regardless of purpose of use.<\/li>\n\n\n\n<li>Malaysia\u2019s PDPA does not have a \u2018right to be forgotten\u2019 as the EU\u2019s GDPR includes, i.e. Malaysian users cannot retrospectively request your website to delete personal data (except for data that exceeds the retention requirement in PDPA Principle 5).<\/li>\n\n\n\n<li>Malaysia\u2019s PDPA doesn\u2019t give end-users the right to data portability as the EU\u2019s GDPR does, empowering EU users to receive copies of their personal data in readable and easily accessible formats.<\/li>\n\n\n\n<li>Malaysia\u2019s PDPA does not have a \u2018privacy by design\u2019 clause like the EU\u2019s GDPR, which requires data controllers to think privacy into the default settings of their processing activities.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"\/media\/4064\/malay-eu001.jpeg?width=378&amp;&amp;mode=max\" alt=\"Flag of Malaysia with the European Union flag stars on it  - Cookiebot\" width=\"498px\" height=\"248px\"\/><figcaption class=\"wp-element-caption\">Core similarities, yet big differences between the PDPA and GDPR in Malaysia and EU.<\/figcaption><\/figure>\n\n\n\n<p><strong>Cookiebot CMP enables compliance with major data privacy laws<\/strong><br><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP free for 14 days<\/a>\u00a0\u2013 or forever if you have a small website<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-summary-of-malaysia-s-pdpa\">Summary of Malaysia\u2019s PDPA<\/h2>\n\n\n\n<p>Malaysia\u2019s <strong>Personal Data Protection Act (PDPA)<\/strong>&nbsp;is one of the world\u2019s consent-based data privacy laws, empowering Malaysian residents with enforceable rights to their personal data, and requiring websites and companies located inside Malaysia to play by fair rules so as not to abuse the data privacy of visitors and customers.<\/p>\n\n\n\n<p>Malaysia\u2019s PDPA is <a href=\"https:\/\/iapp.org\/news\/a\/malaysian-government-reviewing-pdpa\/\" target=\"_blank\" rel=\"noreferrer noopener\">scheduled to be updated<\/a>&nbsp;sometime in the next couple of years.<\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP for PDPA compliance<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see and control all cookies in use<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/gdpr\/\">Learn more about GDPR compliance<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/google-consent-mode\/\">Get started with Cookiebot CMP and Google Consent Mode<\/a><\/p>\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>Quick summary Malaysia\u2019s PDPA, in brief Malaysia\u2019s Personal Data Protection Act (PDPA)&nbsp;was passed in 2010, took effect in 2013 and was last updated in 2016. Malaysia\u2019s PDPA revolves around end-user consent, requiring your website to first obtain express and explicit consent from its visitors before activating any cookies and trackers that process personal data, much [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":12603,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":true,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-864","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/us\/wp-content\/uploads\/sites\/8\/2021\/11\/Malaysia_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts\/864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/comments?post=864"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts\/864\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/media\/12603"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/media?parent=864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/categories?post=864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/tags?post=864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}