An Overview Of The 7 PDPA 2010 Principles

An Overview Of The 7 PDPA 2010 Principles

Table of Contents

Almost every question a Malaysian business has about data protection traces back to one of seven principles set out in the Personal Data Protection Act 2010 (PDPA), including: 

  • a privacy policy 
  • a marketing consent form 
  • a CCTV system, or  
  • a data breach 

These seven PDPA principles are the actual law and all other guidelines, codes of practice, and practical compliance advice, exist to help businesses apply them. 

Below, we explain each principle in layman terms, with links to detailed guides where relevant. 

1. The General Principle (Section 6) 

“ A data controller must not process personal data unless the data subject has given consent, or unless one of a limited set of exceptions applies (such as processing necessary to perform a contract, or to comply with a legal obligation). Where the data is sensitive personal data, such as health information or biometric data, the bar is higher: explicit consent is required. ”

The starting point for everything else, in practice this is the principle behind every consent form, checkbox, and sign-up flow a Malaysian business uses.  

Getting consent wrong tends to undermine everything built on top of it. See ELP’s full guide to PDPA consent in Malaysia for the different forms consent can take, and the mistakes that most commonly invalidate it. 

2. The Notice and Choice Principle (Section 7) 

“ A data subject must be told, by written notice, what personal data is being collected, why, who it may be disclosed to, and what rights they have over it. ”

This is the principle behind every privacy policy and privacy notice. The notice must be: 

  • given in both Bahasa Malaysia and English, and  
  • specific enough that the data subject genuinely understands what they are agreeing to 

A common failure point is a privacy policy that describes data practices that do not match reality, which is itself a compliance issue. See ELP’s guide on writing a PDPA-compliant privacy policy for a full walkthrough using a worked e-commerce example. 

3. The Disclosure Principle (Section 8) 

“ Personal data collected for one purpose should not, without consent, be disclosed to a third party or used for a different purpose than the one originally stated. ”

This principle is what stops a business from, for example, collecting a customer’s phone number for delivery purposes and then adding that number to a marketing list without separate consent. 

This principle comes up in other common situations too:  

  • sharing employee data between related companies in the same corporate group 
  • disclosing CCTV footage to a third party such as lawyers, or  
  • engaging a vendor who will process personal data on your behalf 

Each of these is a disclosure that needs a proper legal basis, not an assumption that it is fine because the recipient is trustworthy. ELP’s guides on employee data privacy and CCTV installations in Malaysia both touch on disclosure scenarios specific to those contexts. 

4. The Security Principle (Section 9) 

“ A data controller must take practical steps to protect personal data from loss, misuse, unauthorised access, or destruction, having regard to the nature of the data, where it is stored, and the reliability of personnel with access to it. ”

This is the principle most closely tied to data breaches: weak security is frequently the direct cause of a breach, which means a business can face two separate exposures at once, the breach itself, and a separate finding that its underlying security was inadequate in the first place. 

See ELP’s guide to data breaches in Malaysia for how this principle connects to breach risk in practice, including a closer look at ransomware. 

5. The Retention Principle (Section 10) 

“ Personal data must not be kept longer than necessary for the purpose it was collected. ”

Unlike some other compliance requirements, the PDPA does not give a fixed retention period. Instead, it asks each business to make a reasoned judgment for each category of data it holds, informed by: 

  • the original purpose 
  • legal risk exposure, and 
  • relevant statutory minimum retention periods (such as tax record-keeping requirements) 

This is also the principle behind the Personal Data Protection Commissioner’s recent Data Protection by Design Guideline which encourages businesses to build retention limits into their systems automatically rather than relying on manual review.  

See ELP’s guide to data retention periods under the PDPA for a detailed breakdown. 

6. The Data Integrity Principle (Section 11) 

“ A data controller must take reasonable steps to ensure that personal data is accurate, complete, not misleading, and kept up to date, having regard to the purpose for which it was collected and is to be further processed. ”

This principle underpins a data subject’s right to request that inaccurate data about them be corrected, which businesses should have a working process for handling. 

It is easy to overlook because it does not generate the same anxiety as a breach or a missing consent form, but outdated data creates real operational risk. 

7. The Access Principle (Section 12) 

“ A data subject has the right to access their own personal data, and to request that it be corrected if it is inaccurate. A business needs a clear process for verifying who is making a request, confirming what data is actually held, and responding within a reasonable timeframe. ”

This principle gets more complicated when the data in question also contains other people’s personal data, which is a common issue with CCTV footage, group emails, and shared records. Casually handing over an entire recording or document in response to an access request can itself create a fresh disclosure problem.  

How the seven principles fit together 

In practice, the PDPA principles overlap and cannot be effectively addressed in isolation: 

  1. Consent (General Principle) is usually obtained through a notice (Notice and Choice Principle). 
  2. What a business is allowed to disclose (Disclosure Principle) depends on what was stated in that same notice. 
  3. How long data can be kept (Retention Principle) depends on the purpose disclosed at the point of collection. 
  4. Whether data is accurate (Data Integrity Principle) and accessible (Access Principle) both depend on the business actually knowing what data it holds and why, which in turn depends on having decent security (Security Principle) so that data does not go missing or get corrupted in the first place. 

        Businesses that treat these as one connected system or appoint a qualified Data Protection Officer to own the framework on an ongoing basis tend to find PDPA compliance considerably more manageable. 

        Enjoy PDPA compliance in 90 days 

        We help businesses in Malaysia build compliance around all seven principles as a connected framework, including drafting privacy notices and consent forms, reviewing security and retention practices, and appointing or outsourcing a Data Protection Officer to own the framework on an ongoing basis. If you’d like your business’s data protection practices reviewed, book a consultation with us.

        shen-ming-casual

        Wong Shen Ming

        Shen Ming is a corporate and commercial lawyer who is deeply committed to supporting her clients in achieving their business goals. Specialising in commercial and employment law, she demonstrates her expertise by crafting and reviewing various types of commercial agreements.

        View her full profile here.

        Let us know how we can support your business

        Drop us a message and let us better understand your needs. Get your first consultation within 24-hours.
        Share this article:
        Post might interest you:
        ABOUT THE AUTHOR

        Wong Shen Ming

        WiFi Piggybacking – Is It Legal?

        WiFi Piggybacking – Is It Legal?

        It was recently reported that the Malaysian Communications and Multimedia Commision (“MCMC”) had received six complaints regarding the supply and sale of devices that can hack into WiFi connections. Three

        A complete Guide To MOUs For Company Acquisitions

        A Quick Guide To MOUs For Company Acquisitions

        Company acquisitions sometimes start with a non-binding document to align on key intentions before due diligence and contract drafting.   This non-binding document is known as a Memorandum of Understanding

        Want more content like this?

        Drop us your email and be the first to know when we have more informative contents on the latest legal updates, just like this one.

        A boutique corporate & commercial law firm in Kuala Lumpur.

        FREE Legal Updates

        Sign up for our newsletter to get the latest updates, happenings and goodies!
        We don't spam, promise.
        Global Chamber of Business Leaders logo - Light

         © Copyright 2025, Edwin Lee & Partners (Reg No.: 000020008633)

        Edwin Lee & Partners is a Malaysian law firm registered with the Malaysian Bar and is regulated under the Legal Profession Act 1976. 
        Click here to see our certificate of registration

        Responsibilities of Executor:

        • Apply for and extract the grant of probate.
        • Make arrangements for the funeral of the deceased.
        • Collect and make an accurate inventory of the deceased’s assets.
        • Settling the debts and obligations of the deceased.
        • Distributing the assets.

        Note for Digital Executor:
        If you wish to leave your digital assets to certain people in your Will, there are important steps that need to be taken to ensure that your wishes can be carried out:

        • Keep a note of specific instructions on how to access your username and password of your digital asset.
        • You are advised to store these private and confidential information in a USB stick, password management tool or write them down.
        • Please inform your executor or a trusted person of the whereabouts of the tools so that they will have access to your digital asset.