Almost every question a Malaysian business has about data protection traces back to one of seven principles set out in the Personal Data Protection Act 2010 (PDPA), including:
- a privacy policy
- a marketing consent form
- a CCTV system, or
- a data breach
These seven PDPA principles are the actual law and all other guidelines, codes of practice, and practical compliance advice, exist to help businesses apply them.
Below, we explain each principle in layman terms, with links to detailed guides where relevant.
1. The General Principle (Section 6)
The starting point for everything else, in practice this is the principle behind every consent form, checkbox, and sign-up flow a Malaysian business uses.
Getting consent wrong tends to undermine everything built on top of it. See ELP’s full guide to PDPA consent in Malaysia for the different forms consent can take, and the mistakes that most commonly invalidate it.
2. The Notice and Choice Principle (Section 7)
This is the principle behind every privacy policy and privacy notice. The notice must be:
- given in both Bahasa Malaysia and English, and
- specific enough that the data subject genuinely understands what they are agreeing to
A common failure point is a privacy policy that describes data practices that do not match reality, which is itself a compliance issue. See ELP’s guide on writing a PDPA-compliant privacy policy for a full walkthrough using a worked e-commerce example.
3. The Disclosure Principle (Section 8)
This principle is what stops a business from, for example, collecting a customer’s phone number for delivery purposes and then adding that number to a marketing list without separate consent.
This principle comes up in other common situations too:
- sharing employee data between related companies in the same corporate group
- disclosing CCTV footage to a third party such as lawyers, or
- engaging a vendor who will process personal data on your behalf
Each of these is a disclosure that needs a proper legal basis, not an assumption that it is fine because the recipient is trustworthy. ELP’s guides on employee data privacy and CCTV installations in Malaysia both touch on disclosure scenarios specific to those contexts.
4. The Security Principle (Section 9)
This is the principle most closely tied to data breaches: weak security is frequently the direct cause of a breach, which means a business can face two separate exposures at once, the breach itself, and a separate finding that its underlying security was inadequate in the first place.
See ELP’s guide to data breaches in Malaysia for how this principle connects to breach risk in practice, including a closer look at ransomware.
5. The Retention Principle (Section 10)
Unlike some other compliance requirements, the PDPA does not give a fixed retention period. Instead, it asks each business to make a reasoned judgment for each category of data it holds, informed by:
- the original purpose
- legal risk exposure, and
- relevant statutory minimum retention periods (such as tax record-keeping requirements)
This is also the principle behind the Personal Data Protection Commissioner’s recent Data Protection by Design Guideline which encourages businesses to build retention limits into their systems automatically rather than relying on manual review.
See ELP’s guide to data retention periods under the PDPA for a detailed breakdown.
6. The Data Integrity Principle (Section 11)
This principle underpins a data subject’s right to request that inaccurate data about them be corrected, which businesses should have a working process for handling.
It is easy to overlook because it does not generate the same anxiety as a breach or a missing consent form, but outdated data creates real operational risk.
7. The Access Principle (Section 12)
This principle gets more complicated when the data in question also contains other people’s personal data, which is a common issue with CCTV footage, group emails, and shared records. Casually handing over an entire recording or document in response to an access request can itself create a fresh disclosure problem.
How the seven principles fit together
In practice, the PDPA principles overlap and cannot be effectively addressed in isolation:
- Consent (General Principle) is usually obtained through a notice (Notice and Choice Principle).
- What a business is allowed to disclose (Disclosure Principle) depends on what was stated in that same notice.
- How long data can be kept (Retention Principle) depends on the purpose disclosed at the point of collection.
- Whether data is accurate (Data Integrity Principle) and accessible (Access Principle) both depend on the business actually knowing what data it holds and why, which in turn depends on having decent security (Security Principle) so that data does not go missing or get corrupted in the first place.
Businesses that treat these as one connected system or appoint a qualified Data Protection Officer to own the framework on an ongoing basis tend to find PDPA compliance considerably more manageable.
Enjoy PDPA compliance in 90 days
We help businesses in Malaysia build compliance around all seven principles as a connected framework, including drafting privacy notices and consent forms, reviewing security and retention practices, and appointing or outsourcing a Data Protection Officer to own the framework on an ongoing basis. If you’d like your business’s data protection practices reviewed, book a consultation with us.




