A Business Guide To The Data Integrity Principle Under PDPA 2010

A Business Guide To The Data Integrity Principle Under PDPA 2010

Table of Contents

“ A data controller must take reasonable steps to ensure that personal data is accurate, complete, not misleading, and kept up to date, having regard to the purpose for which it was collected and is to be further processed. ”

Inaccurate data creates operational and financial damage long before it becomes a legal issue, and the Data Integrity Principle under section 11 of the Personal Data Protection Act 2010 tends to be the principle a business is least prepared to answer on.  

To help, this guide covers: 

  • what section 11 requires 
  • why data accuracy is a commercial issue as much as a compliance one,  
  • how it connects to a data subject’s right to request correction, and  
  • what a workable process looks like 

Note: For an overview of how this principle sits alongside the other six, see our guide to the 7 principles of Malaysia’s PDPA. 

Data Integrity Principle requirement 

Section 11 requires a data controller to take reasonable steps to ensure that personal data is accurate, complete, not misleading, and kept up to date, having regard to the purpose for which the data was collected and is to be further processed. 

Each of those four words carries a distinct meaning: 

Requirement What it means 
Accurate The data correctly reflects the facts. A misspelled name or a wrong bank account detail fails this. 
Complete The record is not missing information that makes it functionally unusable or misleading for its purpose.  
Not misleading The data does not create a false impression, even where each individual field is technically correct.  
Up to date Reflects the current position, not a historical one, where currency matters for the purpose.  

A business is not expected to maintain perfect, continuously refreshed records of everyone it has ever dealt with, but it is expected to keep data accurate enough for what it is actually being used for.  

Why inaccurate data is primarily a business problem 

This principle is easier to take seriously once framed in terms of what actually goes wrong. Common examples: 

  1. Wrong delivery or correspondence address. A package goes to a former address, or a formal notice, such as a contractual termination notice or a demand letter, is served on an address the recipient left years ago. In a dispute, the adequacy of service can become a live issue. 
  2. Outdated payroll or bank details. Salary paid into a closed account, or statutory contributions filed against an outdated identification number, creating a reconciliation problem with the relevant authority. 
  3. Stale marketing lists. Continuing to email contacts who unsubscribed, changed roles, or left the company. Beyond the wasted spend, continuing to contact someone who withdrew consent is a separate compliance issue under the General Principle. 
  4. Incorrect HR records. An outdated emergency contact discovered during an actual emergency. An unrecorded change in employment terms. A disciplinary file that does not reflect the final outcome. 
  5. Duplicate records. The same individual existing three times across different systems, with different details in each. Which one is correct becomes unanswerable, and any decision made on the wrong record is made on a false basis. 

If a business makes a decision that affects an individual, refuses a service, terminates an engagement, reports something to a third party, based on data that was inaccurate and that the business took no reasonable steps to keep accurate, that is a section 11 problem in addition to whatever commercial damage follows. 

Accuracy at collection vs over time 

It helps to separate the obligation into two stages as the practical response to each is different. 

Accuracy at the point of collection 

Most inaccurate data enters a system when it is first captured, and most of it is preventable: 

  • validation on input fields so that an identification number or postcode in the wrong format is caught immediately rather than stored 
  • avoiding free-text fields where a structured dropdown would do, since free text is where inconsistency and duplication originate 
  • collecting data directly from the data subject where possible rather than transcribing it from a third party, and 
  • confirming key details back to the individual at the point of collection, which is both an accuracy measure and a transparency one 

Accuracy over time 

This is harder because a record that was perfectly accurate when captured degrades as people change addresses, phone numbers, names, employers, and their minds about marketing preferences.  

Reasonable steps here usually mean building in periodic touchpoints: 

  • periodic confirmation at natural moments asking to confirm or update details 
  • acting on signals such as bounced emails, returned letters, or failed payment 
  • propagating corrections to reach the rest of the system 
  • regular deduplication as part of data housekeeping 

This connects directly to the Retention Principle. The simplest way to reduce the volume of inaccurate data a business holds is to stop holding data it no longer needs. See our guide to data retention periods under the PDPA. 

Data subject correction requests 

Section 11 sits alongside a data subject’s right to request that inaccurate, incomplete, misleading, or out of date personal data about them be corrected.  

In practice, a business needs a process that can actually handle this and a workable correction process covers: 

  1. Verification. Confirming the requester is who they say they are, before changing anything. 
  2. Assessment. Whether the correction is factually supported. A business is not obliged to accept every assertion at face value. 
  3. Action. Updating the record, and ensuring the correction flows to every system and, where relevant, to third parties the data was previously disclosed to. 
  4. Response. Informing the individual of the outcome within a reasonable timeframe, including where the request is declined and why. 
  5. Record keeping. Logging the request and what was done, which is what evidences that the business is taking reasonable steps. 

          Employee data 

          HR records are among the longest-held and least-reviewed personal data in most organisations. Building a periodic confirmation step into an annual process, such as appraisal or benefits enrolment, is usually the most practical fix.  

          See our guide to employee data privacy in Malaysia for the wider set of obligations across the employment lifecycle. 

          Customer and marketing data 

          The compliance issue here is compounded because a stale list frequently contains people who have withdrawn consent, and continuing to contact them engages the General Principle as well as section 11.  

          See our guide to PDPA consent in Malaysia for how withdrawal should be handled. 

          A practical checklist 

          1. Identify which data actually needs to be current. Apply the “having regard to the purpose” qualifier honestly rather than treating all records as equally critical. 
          2. Fix the collection point first. Validation and structured fields prevent more inaccuracy than any downstream cleanup effort. 
          3. Build in periodic confirmation at natural business touchpoints rather than as a standalone exercise nobody has time for. 
          4. Act on bounce-backs and failed contacts rather than letting them accumulate. 
          5. Make sure corrections propagate across every system holding that individual’s data. 
          6. Have a documented correction request process with a named owner, typically the Data Protection Officer. 
          7. Delete what you no longer need, since the cheapest way to keep data accurate is to hold less of it. 

                      These measures typically sit within a broader PDPA compliance framework, with day to day ownership resting with the Data Protection Officer where one has been appointed. 

                      PDPA compliance in 90 days 

                      We advise Malaysian businesses on the Data Integrity Principle as part of a wider PDPA compliance review, including drafting correction request procedures, reviewing how personal data flows between systems, and advising on what “reasonable steps” looks like for the specific categories of data a business holds and the purposes it holds them for. If you want your data handling practices reviewed against the PDPA, book a consultation with us. 

                      shen-ming-casual

                      Wong Shen Ming

                      Shen Ming is a corporate and commercial lawyer who is deeply committed to supporting her clients in achieving their business goals. Specialising in commercial and employment law, she demonstrates her expertise by crafting and reviewing various types of commercial agreements.

                      View her full profile here.

                      Let us know how we can support your business

                      Drop us a message and let us better understand your needs. Get your first consultation within 24-hours.
                      Share this article:
                      Post might interest you:
                      ABOUT THE AUTHOR

                      Wong Shen Ming

                      Want more content like this?

                      Drop us your email and be the first to know when we have more informative contents on the latest legal updates, just like this one.

                      A boutique corporate & commercial law firm in Kuala Lumpur.

                      FREE Legal Updates

                      Sign up for our newsletter to get the latest updates, happenings and goodies!
                      We don't spam, promise.
                      Global Chamber of Business Leaders logo - Light

                       © Copyright 2025, Edwin Lee & Partners (Reg No.: 000020008633)

                      Edwin Lee & Partners is a Malaysian law firm registered with the Malaysian Bar and is regulated under the Legal Profession Act 1976. 
                      Click here to see our certificate of registration

                      Responsibilities of Executor:

                      • Apply for and extract the grant of probate.
                      • Make arrangements for the funeral of the deceased.
                      • Collect and make an accurate inventory of the deceased’s assets.
                      • Settling the debts and obligations of the deceased.
                      • Distributing the assets.

                      Note for Digital Executor:
                      If you wish to leave your digital assets to certain people in your Will, there are important steps that need to be taken to ensure that your wishes can be carried out:

                      • Keep a note of specific instructions on how to access your username and password of your digital asset.
                      • You are advised to store these private and confidential information in a USB stick, password management tool or write them down.
                      • Please inform your executor or a trusted person of the whereabouts of the tools so that they will have access to your digital asset.