The clinic is the data controller. The AI vendor is a processor. That distinction is the entire post. Everything below follows from it.
What the PDPA (Amendment) Act 2024 changed
Three material changes matter for AI marketing tools:
- Mandatory breach notification. Where a breach is likely to cause significant harm, the clinic must notify the Personal Data Protection Commissioner and affected data subjects. Previously voluntary; now statutory.
- Data Protection Officer requirement for organisations processing personal data at scale — a category most clinics with active digital enquiry funnels sit within.
- Explicit data processor obligations. The Act now recognises processors as a distinct category with their own duties, but the controller — the clinic — retains primary responsibility.
What "passing patient data to an AI tool" actually looks like
Three common patterns, each with the same PDPA analysis:
- Pattern A — WhatsApp chatbot with an LLM backend. Patient types a symptom; the message hits the vendor\'s API; the LLM returns a suggested reply. The message content, phone number and any metadata sit on the vendor\'s infrastructure.
- Pattern B — CRM with AI enrichment. Patient enquiry lands in the CRM; an enrichment API classifies intent, urgency or lead score. The enquiry text is transmitted to the enrichment vendor.
- Pattern C — Ad-copy generator fed with real reviews or testimonials. Patient reviews (personal data if identifiable) go into the vendor\'s tool as prompt input.
In all three, the AI vendor is a data processor. That does not remove the clinic\'s obligations — it defines them.
What a Malaysian clinic must document
Five artefacts. If a Commissioner audit lands, these are what defensibility looks like:
- Consent statement in the enquiry form / chatbot intro that names AI processing as a purpose. "Your message may be processed by an AI system to help us respond" — plain language, positive opt-in where the processing is not obviously necessary for the service requested.
- Data processor agreement (DPA) with the AI vendor specifying what data is transmitted, what the vendor may do with it, whether it is used for model training, retention period, and breach-notification obligations back to the clinic.
- Data flow map. One page. Which fields go where, to which vendor, on which trigger. Cannot be verbal.
- Retention and deletion policy for chatbot transcripts and AI-processed enrichment records — separate from your general CRM retention because the classification is different.
- Breach response runbook. Who is notified, in what order, on what timeline, if the AI vendor discloses a breach to you. The clock on the PDPA notification runs from when you know, not from when the vendor tells you.
Model-training as the specific risk
The single question most Malaysian clinics have not asked their AI marketing vendor: is our data used to train your model? If the answer is yes, or the answer is "we don\'t know", the clinic has an unmanaged data flow. Under the PDPA, purpose limitation means personal data collected for one purpose (responding to a patient enquiry) cannot be used for a materially different purpose (training a general-purpose model) without a fresh legal basis.
The practical fix is contractual: require an enterprise-tier agreement or written opt-out from training. Consumer-tier accounts on public LLM providers frequently default to training-on-inputs; that default is a PDPA problem for a clinic that has not disclosed it.
KKM/MDC content rules are unchanged
The AI tool does not change what a clinic is allowed to say. That is still governed by KKM/MDC advertising rules. See the KKM Ad Checker for pre-publish review, and our post on AI-generated ad copy under KKM/MDC.
What to do this month
- List every AI tool that touches a patient interaction. Rows, not paragraphs.
- For each row, answer: is our data used for model training? If yes, fix or replace.
- Draft the consent line for the chatbot intro. One sentence, plain language.
- Ask each vendor for a DPA. If they cannot supply one, that is a vendor answer.
References
- Personal Data Protection (Amendment) Act 2024 — pdp.gov.my
- Personal Data Protection Commissioner\'s guidance on breach notification, 2025
- KKM Guidelines on Aesthetic Medical Practice (Malaysian Medical Council) — applicable to AI-generated content by reference