A Business Guide To The Security Principle Under PDPA 2010

A Business Guide To The Security Principle Under PDPA 2010

Table of Contents

“ A data controller must take practical steps to protect personal data from loss, misuse, unauthorised access, or destruction, having regard to the nature of the data, where it is stored, and the reliability of personnel with access to it. ”

Of the seven PDPA data protection principles, the Security Principle under section 9 is the one most likely to surface after something has gone wrong.  

When a breach occurs, the regulator does not only ask what happened but also what the business had in place beforehand, and one that suffered a breach despite reasonable safeguards is in a very different position from one that had none. 

To help businesses in Malaysia avoid finding themselves in the second situation, our guide covers: 

  • what section 9 actually requires 
  • how to translate it into practical safeguards, and 
  • what changed for vendors under the 2024 amendments 

Note: For an overview of how this principle sits alongside the other six, see our guide to the 7 principles of Malaysia’s Personal Data Protection Act 2010. 

Security Principle requirements

Section 9 requires a data controller to take practical steps to protect personal data from loss, misuse, modification, unauthorised or accidental access or disclosure, alteration, or destruction. 

The phrase “practical steps” is deliberately not a fixed checklist as practicality depends on the business, and so instead of specific measures, the Act lists five factors a business must have regard to when deciding what is adequate: 

Statutory factor What it means in practice 
Nature of the data and the harm that would result Sensitive personal data, such as health records or biometric data, warrants stronger protection than a mailing list. Ask what the realistic consequence would be for the individual if this data leaked. 
Where the data is stored On-premise server, cloud platform, a laptop that leaves the office, or a filing cabinet. Each location carries different risks and needs different controls. 
Security measures built into the storage equipment Whether the system itself supports encryption, access logging, and role-based permissions, or whether these have to be layered on. 
Reliability, integrity, and competence of personnel with access Who can see the data, whether they have been screened, and whether they have been trained on how to handle it. 
Measures for secure transfer How data moves: email attachments, file-sharing links, USB drives, or API integrations. Data in transit is frequently the weakest point. 

The practical implication is proportionality – a business is not expected to implement enterprise-grade security regardless of context. It is expected to make a reasoned judgment about risk and act on it.  

What is not defensible is having given the question no thought at all. 

Translating the principle into real safeguards 

Section 9 does not use these categories, but they are a useful way to organise a security review, because businesses tend to focus heavily on one and neglect the other two. 

1. Technical safeguards 

The measures most people think of first: 

  • Access controls. Role-based permissions so that staff can only see the data their role actually requires. The most common failure here is not a hacker, it is an internal system where everyone can see everything by default. 
  • Encryption. For data at rest (stored) and in transit (being sent). Particularly important for laptops and mobile devices that leave the premises. 
  • Authentication. Strong password requirements and multi-factor authentication for systems holding personal data. 
  • Patching and updates. Known, unpatched software vulnerabilities are a recurring cause of breaches, and one that is difficult to characterise as an unforeseeable event. 
  • Audit logs. A record of who accessed what and when. This matters for detecting misuse, and it also matters after an incident, when the business needs to establish the scope of what was affected. 
  • Backups. Held securely and tested. An untested backup is an assumption, not a safeguard. 

2. Physical safeguards 

Often overlooked entirely by businesses that have digitised most of their operations but still hold paper records or unsecured hardware: 

  • Restricted physical access to server rooms, filing cabinets, and areas where personal data is handled. 
  • Clear desk and screen practices, particularly in open-plan offices or reception areas where visitors can see screens and documents. 
  • Secure disposal. Shredding paper records and properly wiping or destroying hard drives and devices before disposal or resale. 
  • Device controls. Policies on removable media, and on personal devices used for work. 

3. Organisational safeguards 

This category relates closely to the statutory requirement on the “reliability, integrity, and competence of personnel” and focuses on ensuring that these requirements are properly implemented in practice, including: 

  • Written policies setting out how personal data is to be handled, who is responsible, and what to do when something goes wrong. 
  • Staff training. Most breaches begin with an ordinary employee action, not a sophisticated attack. Training on recognising phishing, handling data requests, and escalating suspected incidents is a security measure in its own right. 
  • Access provisioning and, critically, de-provisioning. Removing access promptly when someone changes role or leaves. 
  • Vendor due diligence, covered separately below. 
  • A named owner. Someone must be responsible for reviewing this periodically, typically the Data Protection Officer. 

2024 updates to third-party roles

Most businesses store personal data under their control with various third parties that the PDPA treats as data processors acting on the data controller’s behalf. 

The original position was that the data controller remained responsible for the security of data handled by its processors, but the Personal Data Protection (Amendment) Act 2024 changed this by imposing direct security obligations on data processors themselves.  

Processors are now directly accountable for complying with the Security Principle, rather than the obligation resting solely with the controller. 

However, the data controller still has its own obligations: 

  1. Due diligence before engagement. Ask what security measures the vendor actually has, where data will be stored, and who will have access. Do not assume a well-known brand name equals adequate security for your specific use case. 
  2. A written agreement. Security obligations, breach notification timelines, access restrictions, and what happens to the data on termination should all be in the contract. 
  3. Ongoing verification. “Reasonable steps to ensure compliance” is an ongoing obligation, not a one-off box ticked at onboarding. 

If a vendor suffers a breach involving your customers’ data, you are still the one who has to notify the Commissioner and, where relevant, the affected individuals. See our guide to data breaches in Malaysia for how that works. 

Double exposure risk

A business that suffers a breach caused by weak security is facing two distinct problems: 

  1. The breach notification obligation itself, which must be met within the statutory timeframe, with its own penalty for failure to notify. 
  2. A potential finding that the Security Principle was breached, separate to the incident, because adequate safeguards were not in place. 

A business with poor security that then also fails to report the resulting breach in time is exposed on both fronts. Breaching any of the seven PDPA principles carries a fine of up to RM1 million and/or imprisonment of up to 3 years. 

Conversely, a business that can demonstrate it had reasonable, documented, proportionate safeguards in place is in a materially stronger position when explaining an incident to the regulator, even if the incident still happened. 

A security review checklist 

A reasonable starting point for most Malaysian businesses: 

  1. Know what you hold. A data inventory listing what personal data the business has, where it sits, and who can access it. Security decisions cannot be made about data nobody has mapped. 
  2. Classify by sensitivity. Identify which categories are sensitive personal data, since these warrant stronger controls. 
  3. Review access rights. Check who currently has access to each system and remove anything that is no longer justified. 
  4. Check the basics are actually in place. Multi-factor authentication, encryption on portable devices, current software patching, tested backups. 
  5. List your vendors and confirm each has a written agreement addressing data security. 
  6. Train staff and refresh periodically rather than treating onboarding as sufficient. 
  7. Document the reasoning. Record why the chosen measures were judged proportionate. This is what demonstrates that the business actually turned its mind to the question. 
  8. Review on a set cycle, and whenever the business adopts a new system or materially changes how it handles data. 

These measures sit within a broader PDPA compliance framework, and where the business has appointed a Data Protection Officer, ownership of this review typically sits with them. 

PDPA compliance in 90 days 

We advise Malaysian businesses on the legal side of the Security Principle: reviewing data handling practices against section 9, drafting policies, preparing and reviewing data processing agreements with vendors, and advising on what proportionate safeguards look like for a business of a given size and risk profile. If you want your data security practices reviewed against the PDPA, book a consultation with us. 

shen-ming-casual

Wong Shen Ming

Shen Ming is a corporate and commercial lawyer who is deeply committed to supporting her clients in achieving their business goals. Specialising in commercial and employment law, she demonstrates her expertise by crafting and reviewing various types of commercial agreements.

View her full profile here.

Let us know how we can support your business

Drop us a message and let us better understand your needs. Get your first consultation within 24-hours.
Share this article:
Post might interest you:
ABOUT THE AUTHOR

Wong Shen Ming

A complete Guide To MOUs For Company Acquisitions

A Quick Guide To MOUs For Company Acquisitions

Company acquisitions sometimes start with a non-binding document to align on key intentions before due diligence and contract drafting.   This non-binding document is known as a Memorandum of Understanding

Protecting Personal Data In Malaysia

Protecting Personal Data In Malaysia

The PDP is still a step in the right direction and a good beginning, although it lacks the right to claim for compensation in the case of breaches that cause

Want more content like this?

Drop us your email and be the first to know when we have more informative contents on the latest legal updates, just like this one.

A boutique corporate & commercial law firm in Kuala Lumpur.

FREE Legal Updates

Sign up for our newsletter to get the latest updates, happenings and goodies!
We don't spam, promise.
Global Chamber of Business Leaders logo - Light

 © Copyright 2025, Edwin Lee & Partners (Reg No.: 000020008633)

Edwin Lee & Partners is a Malaysian law firm registered with the Malaysian Bar and is regulated under the Legal Profession Act 1976. 
Click here to see our certificate of registration

Responsibilities of Executor:

  • Apply for and extract the grant of probate.
  • Make arrangements for the funeral of the deceased.
  • Collect and make an accurate inventory of the deceased’s assets.
  • Settling the debts and obligations of the deceased.
  • Distributing the assets.

Note for Digital Executor:
If you wish to leave your digital assets to certain people in your Will, there are important steps that need to be taken to ensure that your wishes can be carried out:

  • Keep a note of specific instructions on how to access your username and password of your digital asset.
  • You are advised to store these private and confidential information in a USB stick, password management tool or write them down.
  • Please inform your executor or a trusted person of the whereabouts of the tools so that they will have access to your digital asset.