A Guide To Legally Compliant Office CCTV Installations In Malaysia

Office CCTV: A Guide To Legal Compliance For Businesses In Malaysia

Table of Contents

As of August 2026, Malaysia does not appear to have one standalone law of general application dealing exclusively with CCTV. Instead, CCTV issues are generally considered under the Personal Data Protection Act 2010 (PDPA) together with related regulations, standards, and official guidance. 

For businesses in Malaysia installing CCTV in their offices, warehouses, and other premises, this means thinking about how the footage is collected, used, stored, accessed, and managed

Our article below explains what Malaysian businesses should know in practical terms. 

CCTV is a source of personal data collection

Like forms, websites, emails, HR files, or customer databases, CCTV can also be a source of personal data collection because it records identifiable persons entering or moving within premises, and is often specifically used to capture images and video footage of: 

  • employees  
  • customers  
  • visitors  
  • contractors  
  • members of the public  

Where a person can be identified directly or indirectly from the footage, the recording will amount to personal data.   

For this reason, businesses should review whether their Privacy Notice / Privacy Policy properly explains relevant matters such as that CCTV surveillance is in operation and the purpose of collection (security, safety, incident investigation, access control).  

What businesses should focus on 

Businesses should ensure people know surveillance is taking place, use CCTV for legitimate purposes, restrict access to recordings, secure stored footage, and avoid keeping data longer than necessary. 

Transparency 

People should know CCTV is in operation. Visible notices at entrances, reception areas, cashier counters, or monitored zones are good practice. A person should not be unknowingly recorded where reasonable notice is expected. 

Clear Purpose 

CCTV should be installed for genuine operational reasons such as safety, security, access control, loss prevention, or incident review. Problems often arise when systems originally installed for security later become tools for unrelated monitoring without proper justification. 

Access control 

Footage should not be casually accessible by multiple staff members. Businesses need to determine who can view recordings, who can export clips, and under what circumstances access is allowed. Internal misuse of CCTV footage is often a greater risk than the camera itself. 

Security and retention 

CCTV footage should be stored securely, whether on local devices, servers, or cloud platforms. Businesses should also avoid keeping recordings indefinitely. Many organisations use automatic overwrite cycles such as 14, 30, or 90 days depending on operational needs, storage capacity, and incident risk. 

Workplace CCTV requires extra care 

CCTV in offices or staff areas can become more sensitive than ordinary premises security as footage may later be referred to during: 

  • misconduct investigations  
  • attendance records   
  • disciplinary matters  
  • safety incidents  
  • employee complaints  

For this reason, businesses should be careful not to turn a security system into excessive staff surveillance. Using CCTV for reasonable security and safety purposes is very different from constant employee monitoring.  

Where CCTV is used for other purposes, businesses should be transparent about this in its employee privacy policy. Where appropriate, employees should also be asked to acknowledge this during onboarding and written consent should be obtained where consent is being relied upon as the basis for the monitoring.  

Smart CCTV and facial recognition 

Extra care is needed where CCTV does more than simply record images, particularly where it is used to identify people through facial recognition or other biometric technology. 

Where CCTV captures or uses biometric data, businesses should consider the additional requirements that apply to sensitive personal data, which includes: 

  • being clear about why the biometric information is needed 
  • telling people how it will be used 
  • limiting who can access it, and  
  • keeping it only for as long as necessary 

This is particularly relevant following Malaysia’s PDPA amendments, which now recognise biometric data as a category of sensitive personal data

If the CCTV system is also used to automatically identify, assess or make decisions about people, the requirements relating to Automated Decision Making and Profiling should be considered. For example, this may happen where facial recognition is used to automatically decide whether someone should be allowed into a building.  

A Data Protection Impact Assessment should also be considered where the proposed use of CCTV or biometric technology is likely to create a high risk to individuals’ personal data. 

Handling requests for CCTV footage 

Businesses should have a clear process for handling requests to view, obtain or export CCTV footage. They should first verify who is making the request, understand the reason for the request, and consider whether the footage contains personal data of other individuals. 

  1. Internal access to footage should be limited to authorised personnel, and any viewing, copying or export of footage should be properly controlled and recorded.  
  2. Where footage is provided to a third party such as the police, the business should consider whether the disclosure is permitted and ensure that only the relevant footage is disclosed. 

This is particularly important because CCTV footage may contain multiple individuals, and casually exporting or sharing an entire recording may result in unnecessary disclosure of other people’s personal data. 

Common mistakes 

Many CCTV issues arise from poor management afterward. Common examples include:  

  • no signage being displayed 
  • unlimited staff access to recordings 
  • footage shared casually 
  • retention periods never reviewed 
  • third-party vendors controlling systems without clear safeguards. 

These are practical governance issues that businesses can usually fix with proper internal policies.  

Key takeaway 

Properly handled and used for legitimate purposes, CCTV remains a useful operational tool for businesses in Malaysia, but poorly managed, it can become an avoidable legal and reputational risk. 

As a practical safeguard, businesses using CCTV should consider having a dedicated CCTV policy or procedure setting out how CCTV is operated and how footage is handled. A clear CCTV policy helps ensure that access to footage is not dealt with on an ad hoc basis and gives staff a consistent process to follow when footage is requested, viewed, exported or disclosed. 

PDPA compliance in 90 -120 days with ELP  

If your business requires assistance in reviewing data protection practices, preparing privacy notices, or developing PDPA compliance frameworks, our team at ELP can help ensure your organisation’s data handling practices align with the requirements of the PDPA.  

shen-ming-casual

Wong Shen Ming

Shen Ming is a corporate and commercial lawyer who is deeply committed to supporting her clients in achieving their business goals. Specialising in commercial and employment law, she demonstrates her expertise by crafting and reviewing various types of commercial agreements.

View her full profile here.

Let us know how we can support your business

Drop us a message and let us better understand your needs. Get your first consultation within 24-hours.
Share this article:
Post might interest you:
ABOUT THE AUTHOR

Wong Shen Ming

Want more content like this?

Drop us your email and be the first to know when we have more informative contents on the latest legal updates, just like this one.

A boutique corporate & commercial law firm in Kuala Lumpur.

FREE Legal Updates

Sign up for our newsletter to get the latest updates, happenings and goodies!
We don't spam, promise.
Global Chamber of Business Leaders logo - Light

 © Copyright 2025, Edwin Lee & Partners (Reg No.: 000020008633)

Edwin Lee & Partners is a Malaysian law firm registered with the Malaysian Bar and is regulated under the Legal Profession Act 1976. 
Click here to see our certificate of registration

Responsibilities of Executor:

  • Apply for and extract the grant of probate.
  • Make arrangements for the funeral of the deceased.
  • Collect and make an accurate inventory of the deceased’s assets.
  • Settling the debts and obligations of the deceased.
  • Distributing the assets.

Note for Digital Executor:
If you wish to leave your digital assets to certain people in your Will, there are important steps that need to be taken to ensure that your wishes can be carried out:

  • Keep a note of specific instructions on how to access your username and password of your digital asset.
  • You are advised to store these private and confidential information in a USB stick, password management tool or write them down.
  • Please inform your executor or a trusted person of the whereabouts of the tools so that they will have access to your digital asset.