PDPA-Compliant Marketing in Malaysia Individual Rights

PDPA-Compliant Marketing in Malaysia: Individual Rights

Table of Contents

FYI!

This article is the second of a series of pieces on PDPA compliance for marketing processes in Malaysia. Click to read Part 1: PDPA and Marketing in Malaysia and continue with Part 3: Managing Customer Databases for PDPA Compliance.

Marketing activities place individuals in frequent and direct contact with emails, messages, calls, advertisements, and promotions, sometimes through automated systems.  

As a result, marketing is one of the areas where individuals are most likely to feel that their personal data is being misused, overused, or processed without proper control. 

Under the Personal Data Protection Act 2010 (PDPA), individuals are given specific rights to control how their personal data is used for marketing purposes, particularly the ability to opt out of direct marketing and withdraw consent. 

Right to prevent processing for direct marketing 

Under Section 43 of the PDPA, a data subject can require the business to cease processing their personal data for direct marketing purposes. Once a data subject exercises this right: 

  • the business must stop using the individual’s personal data for direct marketing within a reasonable period; and 
  • marketing communications must not resume unless fresh consent has been obtained 

Where a business fails to comply, the data subject may submit a complaint to the Personal Data Protection Commissioner, who may in turn require the business to take steps to comply with the opt-out request, failing which the business will face potential fines of up to RM200,000, imprisonment for up to two years, or both. 

Businesses should make it easy for individuals to opt out of marketing communications and ensure that opt-out requests are properly recorded and acted upon.  

Withdrawal of consent 

Section 38 of the PDPA allows data subjects to withdraw consent to the processing of their personal data at any time. Key points businesses should be aware of: 

  • withdrawal of consent does not require justification 
  • once consent is withdrawn for marketing purpose, marketing activities must stop 
  • the business may still process personal data for contractual or legal obligations, but not for marketing purposes 

For example, a customer may withdraw consent to receive promotional emails but may still receive transactional communications such as invoices, service notifications, or account-related updates.  

Businesses should take care not to include marketing content within such transactional communications after consent has been withdrawn as failure to comply is punishable by a fine of up to RM100,000, imprisonment for up to 1 year, or both. 

Let ELP be your PDPA legal advisors 

Businesses in Malaysia must recognise that under the PDPA, individuals have enforceable rights to opt out of direct marketing and withdraw consent at any time and failure to respect these rights may escalate from dissatisfaction to severe penalties. 

If your organisation requires assistance reviewing marketing consent practices, updating privacy notices, or assessing PDPA compliance risks, feel free to reach out for a consultation. 

shen-ming-casual

Wong Shen Ming

Shen Ming is a corporate and commercial lawyer who is deeply committed to supporting her clients in achieving their business goals. Specialising in commercial and employment law, she demonstrates her expertise by crafting and reviewing various types of commercial agreements.

View her full profile here.

Let us know how we can support your business

Drop us a message and let us better understand your needs. Get your first consultation within 24-hours.
Share this article:
Post might interest you:
ABOUT THE AUTHOR

Wong Shen Ming

Special Cyber Court and E-Court

Special Cyber Court and E-Court

Special Cyber Court The number of cybercrime cases in Malaysia has increased at an average of 10,000 cases reported every year. It was reported that in 2015 alone, CyberSecurity Malaysia

Legalising Ride-Sharing Services

Legalising Ride-Sharing Services

Taxi-booking services such as MyTeksi and Easy Taxi, as well as ride-sharing booking services such as Uber and GrabCar, have been touted as the game changers as they set to

Want more content like this?

Drop us your email and be the first to know when we have more informative contents on the latest legal updates, just like this one.

A boutique corporate & commercial law firm in Kuala Lumpur.

FREE Legal Updates

Sign up for our newsletter to get the latest updates, happenings and goodies!
We don't spam, promise.
Global Chamber of Business Leaders logo - Light

 © Copyright 2025, Edwin Lee & Partners (Reg No.: 000020008633)

Edwin Lee & Partners is a Malaysian law firm registered with the Malaysian Bar and is regulated under the Legal Profession Act 1976. 
Click here to see our certificate of registration

Responsibilities of Executor:

  • Apply for and extract the grant of probate.
  • Make arrangements for the funeral of the deceased.
  • Collect and make an accurate inventory of the deceased’s assets.
  • Settling the debts and obligations of the deceased.
  • Distributing the assets.

Note for Digital Executor:
If you wish to leave your digital assets to certain people in your Will, there are important steps that need to be taken to ensure that your wishes can be carried out:

  • Keep a note of specific instructions on how to access your username and password of your digital asset.
  • You are advised to store these private and confidential information in a USB stick, password management tool or write them down.
  • Please inform your executor or a trusted person of the whereabouts of the tools so that they will have access to your digital asset.