Of the seven PDPA data protection principles, the Security Principle under section 9 is the one most likely to surface after something has gone wrong.
When a breach occurs, the regulator does not only ask what happened but also what the business had in place beforehand, and one that suffered a breach despite reasonable safeguards is in a very different position from one that had none.
To help businesses in Malaysia avoid finding themselves in the second situation, our guide covers:
- what section 9 actually requires
- how to translate it into practical safeguards, and
- what changed for vendors under the 2024 amendments
Note: For an overview of how this principle sits alongside the other six, see our guide to the 7 principles of Malaysia’s Personal Data Protection Act 2010.
Security Principle requirements
Section 9 requires a data controller to take practical steps to protect personal data from loss, misuse, modification, unauthorised or accidental access or disclosure, alteration, or destruction.
The phrase “practical steps” is deliberately not a fixed checklist as practicality depends on the business, and so instead of specific measures, the Act lists five factors a business must have regard to when deciding what is adequate:
| Statutory factor | What it means in practice |
| Nature of the data and the harm that would result | Sensitive personal data, such as health records or biometric data, warrants stronger protection than a mailing list. Ask what the realistic consequence would be for the individual if this data leaked. |
| Where the data is stored | On-premise server, cloud platform, a laptop that leaves the office, or a filing cabinet. Each location carries different risks and needs different controls. |
| Security measures built into the storage equipment | Whether the system itself supports encryption, access logging, and role-based permissions, or whether these have to be layered on. |
| Reliability, integrity, and competence of personnel with access | Who can see the data, whether they have been screened, and whether they have been trained on how to handle it. |
| Measures for secure transfer | How data moves: email attachments, file-sharing links, USB drives, or API integrations. Data in transit is frequently the weakest point. |
The practical implication is proportionality – a business is not expected to implement enterprise-grade security regardless of context. It is expected to make a reasoned judgment about risk and act on it.
What is not defensible is having given the question no thought at all.
Translating the principle into real safeguards
Section 9 does not use these categories, but they are a useful way to organise a security review, because businesses tend to focus heavily on one and neglect the other two.
1. Technical safeguards
The measures most people think of first:
- Access controls. Role-based permissions so that staff can only see the data their role actually requires. The most common failure here is not a hacker, it is an internal system where everyone can see everything by default.
- Encryption. For data at rest (stored) and in transit (being sent). Particularly important for laptops and mobile devices that leave the premises.
- Authentication. Strong password requirements and multi-factor authentication for systems holding personal data.
- Patching and updates. Known, unpatched software vulnerabilities are a recurring cause of breaches, and one that is difficult to characterise as an unforeseeable event.
- Audit logs. A record of who accessed what and when. This matters for detecting misuse, and it also matters after an incident, when the business needs to establish the scope of what was affected.
- Backups. Held securely and tested. An untested backup is an assumption, not a safeguard.
2. Physical safeguards
Often overlooked entirely by businesses that have digitised most of their operations but still hold paper records or unsecured hardware:
- Restricted physical access to server rooms, filing cabinets, and areas where personal data is handled.
- Clear desk and screen practices, particularly in open-plan offices or reception areas where visitors can see screens and documents.
- Secure disposal. Shredding paper records and properly wiping or destroying hard drives and devices before disposal or resale.
- Device controls. Policies on removable media, and on personal devices used for work.
3. Organisational safeguards
This category relates closely to the statutory requirement on the “reliability, integrity, and competence of personnel” and focuses on ensuring that these requirements are properly implemented in practice, including:
- Written policies setting out how personal data is to be handled, who is responsible, and what to do when something goes wrong.
- Staff training. Most breaches begin with an ordinary employee action, not a sophisticated attack. Training on recognising phishing, handling data requests, and escalating suspected incidents is a security measure in its own right.
- Access provisioning and, critically, de-provisioning. Removing access promptly when someone changes role or leaves.
- Vendor due diligence, covered separately below.
- A named owner. Someone must be responsible for reviewing this periodically, typically the Data Protection Officer.
2024 updates to third-party roles
Most businesses store personal data under their control with various third parties that the PDPA treats as data processors acting on the data controller’s behalf.
The original position was that the data controller remained responsible for the security of data handled by its processors, but the Personal Data Protection (Amendment) Act 2024 changed this by imposing direct security obligations on data processors themselves.
Processors are now directly accountable for complying with the Security Principle, rather than the obligation resting solely with the controller.
However, the data controller still has its own obligations:
- Due diligence before engagement. Ask what security measures the vendor actually has, where data will be stored, and who will have access. Do not assume a well-known brand name equals adequate security for your specific use case.
- A written agreement. Security obligations, breach notification timelines, access restrictions, and what happens to the data on termination should all be in the contract.
- Ongoing verification. “Reasonable steps to ensure compliance” is an ongoing obligation, not a one-off box ticked at onboarding.
If a vendor suffers a breach involving your customers’ data, you are still the one who has to notify the Commissioner and, where relevant, the affected individuals. See our guide to data breaches in Malaysia for how that works.
Double exposure risk
A business that suffers a breach caused by weak security is facing two distinct problems:
- The breach notification obligation itself, which must be met within the statutory timeframe, with its own penalty for failure to notify.
- A potential finding that the Security Principle was breached, separate to the incident, because adequate safeguards were not in place.
A business with poor security that then also fails to report the resulting breach in time is exposed on both fronts. Breaching any of the seven PDPA principles carries a fine of up to RM1 million and/or imprisonment of up to 3 years.
Conversely, a business that can demonstrate it had reasonable, documented, proportionate safeguards in place is in a materially stronger position when explaining an incident to the regulator, even if the incident still happened.
A security review checklist
A reasonable starting point for most Malaysian businesses:
- Know what you hold. A data inventory listing what personal data the business has, where it sits, and who can access it. Security decisions cannot be made about data nobody has mapped.
- Classify by sensitivity. Identify which categories are sensitive personal data, since these warrant stronger controls.
- Review access rights. Check who currently has access to each system and remove anything that is no longer justified.
- Check the basics are actually in place. Multi-factor authentication, encryption on portable devices, current software patching, tested backups.
- List your vendors and confirm each has a written agreement addressing data security.
- Train staff and refresh periodically rather than treating onboarding as sufficient.
- Document the reasoning. Record why the chosen measures were judged proportionate. This is what demonstrates that the business actually turned its mind to the question.
- Review on a set cycle, and whenever the business adopts a new system or materially changes how it handles data.
These measures sit within a broader PDPA compliance framework, and where the business has appointed a Data Protection Officer, ownership of this review typically sits with them.
PDPA compliance in 90 days
We advise Malaysian businesses on the legal side of the Security Principle: reviewing data handling practices against section 9, drafting policies, preparing and reviewing data processing agreements with vendors, and advising on what proportionate safeguards look like for a business of a given size and risk profile. If you want your data security practices reviewed against the PDPA, book a consultation with us.




