How ELP Delivers PDPA Compliance In 90-120 Days
Our tried and tested four-step approach to deliver full PDPA compliance to organisations of all sizes and industries in Malaysia.
How ELP Delivers PDPA Compliance In 90-120 Days Read More »
Our tried and tested four-step approach to deliver full PDPA compliance to organisations of all sizes and industries in Malaysia.
How ELP Delivers PDPA Compliance In 90-120 Days Read More »
A 5-item checklist to choose the right outsourced DPO and ensure full PDPA compliance.
How To Appoint The Right External DPO For Your Business Read More »
Why a well-drafted JVA is the best line of defence for your collaboration, incorporated or otherwise.
A Full Guide To Joint Venture Agreements In Malaysia Read More »
Government requirements for Data Protection Officers (DPO) in Malaysia including core competencies and training suggestions.
The Business Guide To DPO Qualification Requirements In Malaysia Read More »
Depending on the business, you may not need to appoint a DPO at all, or be required to appoint several
Do YOU Need To Appoint A DPO In Malaysia? Read More »
Essentials of Nominee Shareholders’ Agreements in Malaysia, including when you need one and how they protect BOs in trust-based setups.
A Full Guide To Nominee Shareholders’ Agreements In Malaysia Read More »
The essentials of Malaysia’s beneficial ownership (BO) declaration requirements under the Companies Act 2016 and LLP Act 2012.
A Guide To Beneficial Ownership Declaration In Malaysia (Updated For 2025) Read More »
Why an Anti-Bribery & Corruption Policy helps shield your business from corporate liability under Section 17A of the MACC Act.
Though Malaysia’s Whistleblower Protection Act 2010 (with amendments in 2025) provides whistleblowers with certain safeguards, these protections only apply when disclosures are made to enforcement agencies and does not extend to internal company disclosures. As a result, fraud, harassment, bribery, or abuse of power can run rampant in organisations as employees, driven by fear and a lack of confidence in the system, refuse to report offences. A well-designed Whistleblower Policy changes that, empowering everyone from team members to contractors and suppliers to report wrongdoing safely and confidentially. Protections under the Whistleblower Protection Act 2010 When a whistleblower makes a disclosure of improper conduct to an enforcement agency, they may receive protection under the Whistleblower Protection Act 2010, which include: For more details, you can refer to an FAQ by the Legal Affairs Division of the Prime Minister’s Department. Drafting effective whistleblower policies An effective policy will specify the following parts: How it protects your business A well-implemented whistleblower policy protects your business in more ways than one: From policy to culture of integrity A whistleblower policy is only useful if people know it exists, understand it, and feel confident using it. That means companies must go beyond just drafting a document, they also need to embed the policy into everyday awareness, and here’s how you can put it into practice: Convenience To ensure the policy is easily accessible to all stakeholders, it can be: circulated internally via email included in the employee handbook code of conduct on company website (especially for external vendors or partners) Repeated Don’t rely on a one-time announcement. Keep the policy visible and fresh in employees’ minds through regular internal communications such as: email reminders team briefings onboarding kits Train Employees Hold regular briefings or refreshers and make sure employees know: what types of concerns should be reported how the reporting process works what protections they will receive Ready to strengthen your governance? There’s a reason a whistleblowing is on our shortlist of most important SME governance policies: it helps build workplaces where people feel safe speaking up, and where integrity is more than just a value. If you would like guidance on drafting or enhancing your Whistleblower Policy, our team is here to support you. Let’s work together to build a workplace where people feel safe speaking up, and where integrity is more than just a value, it’s part of how you operate.
The Business Guide To Whistleblower Policies In Malaysia Read More »
Good governance starts with the right policies, and so below are six core corporate governance policies that form a strong foundation for legally compliant and morally ethical operations. While not mandatory in every case, they are strongly encouraged as best practices and should be tailored to suit your company’s size, industry, and operational needs. Policy #1: Conflict of Interest Conflicts of interest often arise when personal and business interests overlap. For example: A Conflict of Interest Policy ensures that decisions are made in the company’s best interest by clearly setting expectations for employees, managers, and directors to disclose potential conflicts. What it typically covers: Policy #2: Code of Conduct A Code of Conduct defines what constitutes acceptable and expected behaviour in the workplace. It also provides guidance on issues like workplace harassment, discrimination, use of company resources, and respectful treatment of colleagues and customers. What it typically covers: Policy #3: Anti-Bribery & Corruption Section 17A of the MACC Act specifically holds companies liable if anyone associated with them engages in bribery, even if the company’s directors or management were unaware of it. An Anti-Bribery & Corruption Policy provides a framework for employees and associated parties to identify and avoid unethical conduct. Beyond internal controls, a well-documented and implemented policy may be one of the key elements of your company’s legal defence under Section 17A. What it typically covers: Policy #4: Personal Data Protection Mishandling or failing to safeguard personal data from customers, employees, or other stakeholders can lead to regulatory penalties, lawsuits, loss of customer trust, and reputational damage. A Personal Data Protection Policy sets out clear rules and procedures for collecting, storing, using, and disclosing personal data and helps your company demonstrate accountability and compliance with privacy laws such as the Malaysia’s Personal Data Protection Act (PDPA). What it typically covers: Policy #5: Confidentiality Employees, directors, and contractors often have access to sensitive company information that, without clear rules, could be inadvertently or intentionally disclosed, potentially harming your company’s competitive position or breaching contracts. A Confidentiality Policy clearly defines what information is considered confidential, who is responsible for safeguarding it, and how it must be handled in daily operations. It may also outline the consequences of breaches and reminds employees of their ongoing obligation to maintain confidentiality even after leaving the company. What it typically covers: Policy #6: Whistleblowing A Whistleblower Policy provides a safe, confidential, and protected channel to report suspected wrongdoing such as fraud, bribery, harassment, or other unethical or illegal activities without fear of retaliation. Encouraging early reporting allows the company to address issues before they escalate and demonstrates its commitment to integrity and accountability. What it typically covers: Strengthen your business with good governance Good governance starts with clear, well-implemented policies and these six core policies form the foundation of a strong governance framework and fostering an ethical, accountable culture across your organisation. If you would like guidance on drafting or reviewing these policies for your organisation, we are here to help.
6 Essential Corporate Governance Policies For Malaysian SMEs Read More »