One of the most common questions Malaysian businesses ask about the PDPA is also one of the least straightforward to answer:
How long are we actually allowed to keep personal data?
Unlike some other compliance requirements, the PDPA does not give a fixed number, and this guide explains what the PDPA’s retention principle actually says, how to work out an appropriate retention period for different types of data and what a data retention policy should cover.
What does the PDPA say about data retention?
The PDPA’s Retention Principle (Section 10) requires that personal data processed for any purpose must not be kept longer than is necessary for that purpose.
Once the original purpose has been fulfilled, and there is no continuing legitimate business need or other legal requirement to keep the data, a data controller has a duty to take all reasonable steps to ensure it is destroyed or permanently deleted.
This is worth being precise about, since “purpose” is broader than just a strict legal obligation. If a business still has a genuine, ongoing reason to hold data, such as maintaining an active customer relationship, or honouring a warranty period, that counts as the original purpose continuing. What is not permitted is holding data indefinitely on the basis that it might be useful someday, with no defined purpose or timeframe in mind.
Notice what the law does not say: it does not specify “3 years” or “5 years” as a fixed retention period. Instead, it asks businesses to make a reasoned judgment about how long each category of data is actually needed.
This is deliberately flexible, but it also means the burden is on the business to justify its own retention periods, rather than being able to point to a fixed statutory number.
How to work out the right retention period
Based on our experience advising clients on this, the right retention period for a given category of data generally depends on three overlapping considerations:
- The original purpose. How long is the data actually needed to fulfil the reason it was collected? Customer data needed to process a single transaction has a much shorter natural lifespan than data needed to manage an ongoing service relationship.
- Other statutory retention requirements. Several Malaysian laws impose their own minimum retention periods. For example, tax records generally need to be kept for 7 years, and certain employment records have their own retention requirements under the Employment Act and EPF/SOCSO regulations.
- Legal risk exposure. Contracts and related records are often kept for the duration of the limitation period for bringing a legal claim (generally 6 years for contracts under the Limitation Act 1953), so that evidence remains available if a dispute arises.
The retention period for a given category of data is usually the longer of the time needed to fulfil the original purpose, or any applicable statutory minimum.
Once both of these have passed, the data should not be kept “just in case.”
Illustrative retention periods by data category
| Data category | Typical retention consideration |
| Customer transaction records | Duration of the customer relationship plus the contractual limitation period (commonly around 6 years) |
| Marketing contact data | Until consent is withdrawn or the contact becomes inactive for an extended period; should not be kept indefinitely |
| Employee payroll and tax records | Generally 7 years, in line with the income tax record-keeping requirements |
| Job applicant data (unsuccessful candidates) | A shorter defined period after the recruitment process concludes, for example 6 to 12 months, unless the candidate consents to being kept on file for future roles |
| CCTV and access control footage | Typically a short, defined period (weeks to a few months) unless retained for an active investigation |
Note: These are illustrative examples only. The appropriate retention period for your business depends on your specific data processing activities and should be confirmed against the relevant statutory requirements.
Data Protection by Design (DPbD) for the Retention Principle
The Personal Data Protection Commissioner issued a Data Protection by Design Guideline, which sets out how data controllers should build personal data protection into their systems and processes from the outset. The Guideline gives useful guidance on what regulators expect a well-designed retention practice to look like.
Rather than working through the concepts in the abstract, here is what applying them would actually look like for Toko ABC, our hypothetical online store.
Toko ABC’s customer database has been running for three years. Names, emails, and order histories from 2023 sit alongside this year’s orders, and nobody has ever gone back to clean it up. Applying DPbD to retention would mean:
- Data minimisation. Toko ABC periodically checks whether older customer records are still needed. A customer who ordered once in 2023 and never returned no longer needs their full order history kept identifiable, it can be deleted or reduced to anonymised sales figures for reporting purposes.
- Deletion and/or anonymisation. Instead of manually deciding case-by-case, Toko ABC sets a clear internal rule: inactive accounts with no order in 24 months are anonymised automatically.
- Effectiveness of anonymisation/deletion. Toko ABC checks that once a record is anonymised, no one can trace it back to the original customer, and that “deleted” backup copies are actually gone, not just hidden from the main dashboard.
- Automation. Rather than relying on someone remembering to run a cleanup every year, Toko ABC’s e-commerce platform is configured to flag and delete these records on a rolling basis.
- Retention criteria. Before any of this is built, Toko ABC decides upfront: order records are kept for 6 years (to match contractual limitation periods), marketing consent is kept until the customer unsubscribes, and job applications are kept for 6 to 12 months.
- Justification. If asked by the PDPC, Toko ABC can explain exactly why each period was chosen and point to the legal or business reason behind it, rather than shrugging and saying “we’ve always just kept everything.”
- Enforcement of retention policies. Toko ABC doesn’t just write the policy and file it away, it periodically tests whether old records are actually being deleted as scheduled, not quietly piling up.
- Backups and logs. Toko ABC’s nightly backups don’t get a free pass either. If a customer’s data is deleted from the live database, it should also age out of backup storage within a defined period, not linger there indefinitely.
- Data flow. Toko ABC maps where customer data actually goes, its website, its CRM, its email marketing tool, its accounting software, so it isn’t creating five scattered copies of the same customer record with five different (or no) retention rules.
The practical difference this makes is significant: A business that relies on someone manually reviewing and flagging old records for deletion will, in practice, fall behind, and data quietly piles up past the point it’s needed.
A business that builds the retention period into the system from the start, so records are automatically flagged or deleted once their time is up, keeps compliance running in the background rather than depending on someone remembering to act on it.
Why a generic retention schedule doesn’t work for every business
It’s tempting to treat retention periods as a fixed checklist, and statutory minimums are real and should be followed, but they are not a complete answer – the right retention period for a given category of data still depends on what your specific business actually does with it, and what risks it carries if kept too long or deleted too early.
Two businesses can hold the same type of data and reasonably retain it differently.
A clinic and an e-commerce store both hold customer contact details, but a clinic may have a legitimate reason to retain patient records well beyond a typical commercial limitation period, given the nature of ongoing care and potential future medical or legal relevance, while an online store has far less justification to hold onto a one-time customer’s details once the order is fulfilled and the limitation period lapses.
In practice, this means a retention schedule should be built around what your business actually collects, why, and what happens if that data is kept too long or too short, rather than copying a generic table (including the one earlier in this guide) and assuming it fits.
The risks of over-retention
Keeping personal data longer than necessary creates several real exposures:
- a larger volume of data increases the potential harm and scope of any future data breach,
- data subjects can request access to or correction of data you hold, and older, unused data creates unnecessary administrative burden in responding,
- if a PDPC investigation occurs, an inability to justify why old data is still being held reflects poorly on the organisation’s overall compliance posture, and
- storage and security costs increase with data volume, for no corresponding business benefit.
What a data retention policy should cover
- A data inventory. A list of the categories of personal data the business holds and where they are stored.
- Defined retention periods. For each category, based on purpose and applicable statutory requirements.
- A deletion or anonymisation process. A defined method and schedule for securely destroying or anonymising data once its retention period expires, ideally automated where practical.
- Exceptions process. A way to flag and extend retention where data is subject to an ongoing legal dispute, investigation, or other legitimate reason to retain it longer.
- Ownership. Clear responsibility for who monitors and enforces the retention schedule, often the Data Protection Officer.
A data retention policy typically forms part of a broader PDPA compliance framework, and its ongoing implementation is often managed by a Data Protection Officer. It also connects closely to employee data privacy practices, since HR records are one of the largest categories of long-retained personal data in most organisations.
Let ELP support your PDPA compliance
We help Malaysian businesses build data retention policies that are properly justified against the PDPA’s retention principle, so that data is retained no longer than necessary while remaining compliant with sector-specific laws. If your business needs a data retention policy or a review of your current data holdings, book a consultation with us.




