A 7-Item PDPA Compliance Checklist For Businesses

A 7-Item PDPA Compliance Checklist For Businesses

Table of Contents

Under Malaysia’s Personal Data Protection Act 2010 (PDPA), organisations that process personal data are considered data controllers and are legally responsible for how that data is collected, used, stored and disclosed. 

The checklist below highlights key steps Malaysian businesses should consider when reviewing their personal data protection compliance framework. 

1. Privacy notices at all collection points

Under the PDPA, individuals must be informed about how their personal data will be collected and used. Data controllers should ensure that clear privacy notices are provided at the point where personal data is collected. 

2. You know what personal data you hold 

PDPA compliance begins with understanding what personal data your business collects and processes. Many organisations gather personal data through everyday operations, such as customer registrations, marketing activities, employee records, or supplier databases, without maintaining a clear overview of where that data is stored or how it is used. 

3. Appropriate security measures in place 

Under the PDPA, data controllers must take practical steps to protect personal data from loss, misuse, unauthorised access, disclosure or alteration. This obligation is reflected in the Security Principle, which requires organisations to implement reasonable security measures when handling personal data. 

4. Employee access is properly controlled 

Data controllers should ensure that access to personal data is restricted to authorised personnel who require the information for business purposes. Without proper access controls, this information could be viewed or copied by employees who do not need it for their roles. 

5. Third-party providers are managed properly 

Many businesses rely on external service providers that process personal data as part of their services. This may include payroll vendors, cloud storage providers, IT service providers, marketing platforms, or outsourced customer support services. 

6. You have a personal data retention policy 

Under the PDPA, personal data should not be kept longer than necessary for the purpose for which it was collected. In practice, many businesses continue to store personal data long after it is no longer required. 

7. Ready for access and correction requests 

Under the PDPA, individuals have the right to request access to their personal data and to request correction of personal data that is inaccurate, incomplete, or outdated. This obligation is reflected in the Access Principle. 

PDPA-readiness diagnosis 

The more items on this list readers can check off, the closer they are to PDPA compliance, and those who find three or more items unchecked are advised to treat them as a high priority considering the heavy penalties for PDPA non-compliance. 

Businesses who want to handle PDPA compliance internally may want to see: 

That’s it from us, and we wish you a smooth PDPA compliance journey. 

PDPA compliance in 90 days with ELP 

If your business requires assistance in reviewing data protection practices, preparing privacy notices, or developing PDPA compliance frameworks, our team at ELP can help ensure your organisation’s data handling practices align with the requirements of the PDPA

shen-ming-casual

Wong Shen Ming

Shen Ming is a corporate and commercial lawyer who is deeply committed to supporting her clients in achieving their business goals. Specialising in commercial and employment law, she demonstrates her expertise by crafting and reviewing various types of commercial agreements.

View her full profile here.

Let us know how we can support your business

Drop us a message and let us better understand your needs. Get your first consultation within 24-hours.
Share this article:
Post might interest you:
ABOUT THE AUTHOR

Wong Shen Ming

signed-contract-header

How To Amend a Signed Contract in Malaysia?

Contracts serve as the cornerstone of business transactions and establish the rights and responsibilities of all parties involved. Once contracts are signed, they become legally binding documents on the parties

Want more content like this?

Drop us your email and be the first to know when we have more informative contents on the latest legal updates, just like this one.

A boutique corporate & commercial law firm in Kuala Lumpur.

FREE Legal Updates

Sign up for our newsletter to get the latest updates, happenings and goodies!
We don't spam, promise.
Global Chamber of Business Leaders logo - Light

 © Copyright 2025, Edwin Lee & Partners (Reg No.: 000020008633)

Edwin Lee & Partners is a Malaysian law firm registered with the Malaysian Bar and is regulated under the Legal Profession Act 1976. 
Click here to see our certificate of registration

Responsibilities of Executor:

  • Apply for and extract the grant of probate.
  • Make arrangements for the funeral of the deceased.
  • Collect and make an accurate inventory of the deceased’s assets.
  • Settling the debts and obligations of the deceased.
  • Distributing the assets.

Note for Digital Executor:
If you wish to leave your digital assets to certain people in your Will, there are important steps that need to be taken to ensure that your wishes can be carried out:

  • Keep a note of specific instructions on how to access your username and password of your digital asset.
  • You are advised to store these private and confidential information in a USB stick, password management tool or write them down.
  • Please inform your executor or a trusted person of the whereabouts of the tools so that they will have access to your digital asset.