Inaccurate data creates operational and financial damage long before it becomes a legal issue, and the Data Integrity Principle under section 11 of the Personal Data Protection Act 2010 tends to be the principle a business is least prepared to answer on.
To help, this guide covers:
- what section 11 requires
- why data accuracy is a commercial issue as much as a compliance one,
- how it connects to a data subject’s right to request correction, and
- what a workable process looks like
Note: For an overview of how this principle sits alongside the other six, see our guide to the 7 principles of Malaysia’s PDPA.
Data Integrity Principle requirement
Section 11 requires a data controller to take reasonable steps to ensure that personal data is accurate, complete, not misleading, and kept up to date, having regard to the purpose for which the data was collected and is to be further processed.
Each of those four words carries a distinct meaning:
| Requirement | What it means |
| Accurate | The data correctly reflects the facts. A misspelled name or a wrong bank account detail fails this. |
| Complete | The record is not missing information that makes it functionally unusable or misleading for its purpose. |
| Not misleading | The data does not create a false impression, even where each individual field is technically correct. |
| Up to date | Reflects the current position, not a historical one, where currency matters for the purpose. |
A business is not expected to maintain perfect, continuously refreshed records of everyone it has ever dealt with, but it is expected to keep data accurate enough for what it is actually being used for.
Why inaccurate data is primarily a business problem
This principle is easier to take seriously once framed in terms of what actually goes wrong. Common examples:
- Wrong delivery or correspondence address. A package goes to a former address, or a formal notice, such as a contractual termination notice or a demand letter, is served on an address the recipient left years ago. In a dispute, the adequacy of service can become a live issue.
- Outdated payroll or bank details. Salary paid into a closed account, or statutory contributions filed against an outdated identification number, creating a reconciliation problem with the relevant authority.
- Stale marketing lists. Continuing to email contacts who unsubscribed, changed roles, or left the company. Beyond the wasted spend, continuing to contact someone who withdrew consent is a separate compliance issue under the General Principle.
- Incorrect HR records. An outdated emergency contact discovered during an actual emergency. An unrecorded change in employment terms. A disciplinary file that does not reflect the final outcome.
- Duplicate records. The same individual existing three times across different systems, with different details in each. Which one is correct becomes unanswerable, and any decision made on the wrong record is made on a false basis.
If a business makes a decision that affects an individual, refuses a service, terminates an engagement, reports something to a third party, based on data that was inaccurate and that the business took no reasonable steps to keep accurate, that is a section 11 problem in addition to whatever commercial damage follows.
Accuracy at collection vs over time
It helps to separate the obligation into two stages as the practical response to each is different.
Accuracy at the point of collection
Most inaccurate data enters a system when it is first captured, and most of it is preventable:
- validation on input fields so that an identification number or postcode in the wrong format is caught immediately rather than stored
- avoiding free-text fields where a structured dropdown would do, since free text is where inconsistency and duplication originate
- collecting data directly from the data subject where possible rather than transcribing it from a third party, and
- confirming key details back to the individual at the point of collection, which is both an accuracy measure and a transparency one
Accuracy over time
This is harder because a record that was perfectly accurate when captured degrades as people change addresses, phone numbers, names, employers, and their minds about marketing preferences.
Reasonable steps here usually mean building in periodic touchpoints:
- periodic confirmation at natural moments asking to confirm or update details
- acting on signals such as bounced emails, returned letters, or failed payment
- propagating corrections to reach the rest of the system
- regular deduplication as part of data housekeeping
This connects directly to the Retention Principle. The simplest way to reduce the volume of inaccurate data a business holds is to stop holding data it no longer needs. See our guide to data retention periods under the PDPA.
Data subject correction requests
Section 11 sits alongside a data subject’s right to request that inaccurate, incomplete, misleading, or out of date personal data about them be corrected.
In practice, a business needs a process that can actually handle this and a workable correction process covers:
- Verification. Confirming the requester is who they say they are, before changing anything.
- Assessment. Whether the correction is factually supported. A business is not obliged to accept every assertion at face value.
- Action. Updating the record, and ensuring the correction flows to every system and, where relevant, to third parties the data was previously disclosed to.
- Response. Informing the individual of the outcome within a reasonable timeframe, including where the request is declined and why.
- Record keeping. Logging the request and what was done, which is what evidences that the business is taking reasonable steps.
Employee data
HR records are among the longest-held and least-reviewed personal data in most organisations. Building a periodic confirmation step into an annual process, such as appraisal or benefits enrolment, is usually the most practical fix.
See our guide to employee data privacy in Malaysia for the wider set of obligations across the employment lifecycle.
Customer and marketing data
The compliance issue here is compounded because a stale list frequently contains people who have withdrawn consent, and continuing to contact them engages the General Principle as well as section 11.
See our guide to PDPA consent in Malaysia for how withdrawal should be handled.
A practical checklist
- Identify which data actually needs to be current. Apply the “having regard to the purpose” qualifier honestly rather than treating all records as equally critical.
- Fix the collection point first. Validation and structured fields prevent more inaccuracy than any downstream cleanup effort.
- Build in periodic confirmation at natural business touchpoints rather than as a standalone exercise nobody has time for.
- Act on bounce-backs and failed contacts rather than letting them accumulate.
- Make sure corrections propagate across every system holding that individual’s data.
- Have a documented correction request process with a named owner, typically the Data Protection Officer.
- Delete what you no longer need, since the cheapest way to keep data accurate is to hold less of it.
These measures typically sit within a broader PDPA compliance framework, with day to day ownership resting with the Data Protection Officer where one has been appointed.
PDPA compliance in 90 days
We advise Malaysian businesses on the Data Integrity Principle as part of a wider PDPA compliance review, including drafting correction request procedures, reviewing how personal data flows between systems, and advising on what “reasonable steps” looks like for the specific categories of data a business holds and the purposes it holds them for. If you want your data handling practices reviewed against the PDPA, book a consultation with us.




