The Personal Data Protection (Amendment) Act 2024 (the “Amendment Act”) has officially been gazetted on the 17th October 2024, after progressing through the Houses of the Parliament since July 2024.
Key Amendments
The Amendment Act seeks to amend the existing Personal Data Protection Act 2010 (“PDPA”), which introduces significant amendments to the PDPA for the first time since the Amendment Act is the first significant amendment to the PDPA since it came into force in 2013. The key amendments to the PDPA include, among others:
· Substitution of “Data User” term for “Data Controller” – The term “data users” which was commonly used in the Malaysian context of personal data protection, to mean someone who has control over processing of personal data is now replaced with “data controllers”, reflecting a shift towards an approach aligned with terminology used internationally in other jurisdictions including the European General Data Protection Regulation (“EU GDPR”) and the Singaporean Personal Data Protection Act 2012 (“SG PDPA”).
· Mandatory Appointment of Data Protection Officers (“DPO”) – Data Controllers are required to appoint DPO(s) responsible for ensuring compliance with data protection regulations and update the Commissioner of this appointment. Similarly, Data Processors who processes personal data on behalf of Data Controllers, must also appoint a DPO, who will be accountable to the Data Processor.
· Mandatory Personal Data Breach Notification – Data Controllers must notify the Commissioner as soon as practicable if there is reason to believe a data breach has occurred. Separately, Data Controllers are also obligated to inform the data breach to the affected individuals significantly harmed by the breach.
· Direct Obligation of Data Processor to Comply – Data Processors are directly obligated to comply with the Security Principle i.e. ensuring practical steps are taken to protect the personal data from loss, misuse, modification, unauthorized or accidental access or disclosure, alteration or destruction.
Effect of Gazette on Compliance by Companies
While the Amendment Act has been gazetted, the Amendment Act appears to only come into operation on a date to be appointed by the Minister as notified in the Gazette where the Minister may appoint different dates for different parts of the amendments to come into force. To date, there has been no notification on the date the Amendment Act comes into effect, i.e., the date companies must comply with the amendments. We are closely monitoring developments and will continue to update this space.
PDP (Amendment) Act 2024: https://lnkd.in/gpRspxkt