While almost every PDPA obligation for Malaysian businesses traces back to consent, in practice it is one of the most frequently misunderstood.
A checkbox on a form or a customer handing over their phone number may be enough, but it is often not, and this guide hopes to provide clarity on the matter by explaining:
- what makes consent valid under the PDPA
- the different forms consent can take
- when consent is not required at all, and
- the mistakes that most commonly undermine it
Let’s begin.
Consent is the foundation of the PDPA
The General Principle (Section 6) is the first of seven PDPA principles which states:
A data controller must not process personal data about a data subject unless the data subject has given consent, or unless one of the limited exceptions applies. Where the data involved is sensitive personal data such as health information, religious beliefs, or biometric data, the bar is higher: explicit consent is required, not merely ordinary consent.
Because consent sits at the very base of the compliance pyramid, getting it wrong has a way of undermining everything built on top of it.
A privacy policy, marketing campaign, or data-sharing arrangement can be technically well-documented and still fail if the underlying consent was not validly obtained in the first place.
What actually makes consent valid
In general, for consent to be considered “freely given” and “informed,” the data subject should understand what they are agreeing to and have a genuine choice as to whether to provide consent, rather than consent being assumed or implied.
The PDPA’s Personal Data Protection Regulations 2013 and General Code of Practice of Personal Data Protection set out two structural requirements that apply:
1. It must be capable of being recorded and maintained
Whatever form the consent takes, the business must be able to show, later, that consent was given. Consent that leaves no trace is difficult to rely on if it is ever challenged.
2. It must be distinguishable from other matters
Where consent is requested as part of a form or document, it must be structured so that consent to one specific matter is separate and identifiable from consent to anything else on that same form. This is the basis for the rule against bundling consent, discussed further below.
Different forms of consent
Based on type of data gathered, what it will be used for, and circumstances under which it is collected, businesses may consider one or several of the methods below to obtain consent.
1. Written or express consent
The clearest and safest form. A signature, a ticked checkbox (not pre-ticked), or a clicked “I agree” button, each of which leaves a clear, retrievable record. This is the standard form used for consent forms, application forms, and website sign-ups.
2. Verbal consent
Verbal consent is recognised, but it comes with a practical catch: it must still be capable of being recorded and maintained. In practice, this means verbal consent should be captured through some durable means such as a recorded call (with appropriate notice the call is being recorded).
Alternatively, it could be promptly followed up with a written confirmation, such as a confirmatory email summarising what was agreed to.
3. Consent by conduct
Consent can also be inferred from a data subject’s conduct, where the data subject voluntarily discloses their personal data in circumstances that make clear they are not objecting to its intended use.
For example, a customer who voluntarily fills in and hands over a physical form containing their details, without any indication of objection, may be treated as having consented by conduct to the processing described alongside that form.
This form of consent carries more risk than the first two because it depends heavily on context. It works best where the purpose of collection is obvious and narrow and becomes less viable the broader the scope of the consent becomes.
Explicit consent for sensitive personal data
Where the personal data involved is classified as sensitive personal data (health information, religious beliefs, political opinions, criminal records, and, following the 2024 amendments, biometric data), the PDPA requires explicit consent.
This generally means the data subject must take a clear, deliberate, affirmative action specifically directed at that category of data, not consent bundled in with general terms and conditions.
A business collecting a customer’s medical information for an insurance application, for example, should obtain a separate, specific consent for that purpose, distinct from the general consent given when the customer first signed up as a client.
When consent may not be required
The PDPA recognises certain circumstances where processing can proceed without consent, including where the processing is:
- necessary for the performance of a contract to which the data subject is a party,
- necessary to comply with a legal obligation to which the data controller is subject,
- necessary to protect the vital interests of the data subject, and
- necessary for the exercise of any function conferred by law.
These exceptions are narrower than they might sound and should not be treated as a general workaround for obtaining consent. For example, “necessary for the contract” covers what is genuinely required to deliver the product or service the customer signed up for, not everything a business would find useful to do with the data.
Withdrawing consent
A data subject has the right to withdraw consent at any time, by written notice to the data controller. Once consent is withdrawn, the business must stop the processing that relied on that consent, unless another legal basis (such as a legal obligation) independently justifies continuing.
Businesses should have a clear, working process for handling withdrawal requests, not just a policy that describes one in theory. Withdrawal of consent to marketing, for example, should be honoured promptly and not require the customer to jump through unnecessary hoops.
Consent involving minors
Where the data subject is under 18, consent must be obtained from a parent or guardian, not the minor directly. Businesses that collect data from users who may include minors, such as education platforms or family-oriented services, should build this into their consent flow rather than treating all users as adults by default, pursuant to the Data Protection by Design (DPbD) Guideline.
For more on compliance in this sector, see our guide to PDPA for education providers in Malaysia.
Common mistakes businesses make
Most mistakes with consent come back to relying on assumptions or convenient practices that do not provide customers with a clear, informed, and genuine choice.
Bundling consent
Requiring a customer to agree to marketing communications as a condition of completing a purchase or signing up for a service.
Pre-ticked boxes
A checkbox that is already ticked by default, requiring the customer to actively un-tick it to opt out, does not reflect a genuine affirmative choice and is a weak basis for consent.
Assuming silence means consent
Sending a notice and treating the absence of an objection as consent, particularly for anything beyond the most obvious, narrow purpose, is risky and should not be relied upon as the sole basis for processing.
Vague consent language
Asking a customer to consent to “data processing for business purposes” without specifying what that actually means does not give the data subject a real basis to understand, or meaningfully agree to, what they are consenting to.
No record of verbal consent
Relying on a verbal “yes” given over the phone with nothing written down, recorded, or confirmed afterwards leaves no way to demonstrate that consent was ever given if challenged.
Building a proper consent process
Consent mechanisms typically sit alongside a business’s privacy policy and broader PDPA compliance framework, and commonly include:
- Matching the form of consent to the sensitivity of the purpose. A simple checkbox may be fine for basic order processing; sensitive data or high-stakes uses warrant a more deliberate, explicit process.
- Keeping consent requests specific and separate. Do not bundle marketing consent with the core transaction, and do not bundle consent for sensitive data with general terms and conditions.
- Recording & retaining evidence of consent. Whether that is a timestamped checkbox log, a signed form, or a confirmatory email following a verbal conversation.
- Building a working withdrawal mechanism. Not just a policy that says withdrawal is possible, but an actual process that stops the processing when a customer asks.
- Reviewing consent language periodically. As the business adopts new tools or new uses for data, check whether existing consent actually covers the new use, or whether fresh consent is needed.
In an employment context, the question of whether consent is truly voluntary raises its own specific issues, covered in ELP’s guide to employee data privacy.
Let ELP support your PDPA compliance
We help Malaysian businesses design and document consent mechanisms that actually hold up, whether that is a website consent flow, a sensitive-data consent form, or a review of an existing process that may be relying on assumed or implied consent more heavily than it should. If you want your consent processes reviewed for PDPA compliance, book a consultation with us.




