Scope — what PDPA regulates for a marketing agency
PDPA governs the processing of personal data in commercial transactions. For a marketing operation that means every stage where the business touches a person's identifiable information: the lead form on the landing page, the CRM record that the sales team works, the WhatsApp thread that follows up, the retargeting audience uploaded to Meta or Google, and the retention window over which any of that data is kept. Each of these has a PDPA analysis. The Act does not distinguish "digital" from "offline" data — the same seven principles (General, Notice-and-Choice, Disclosure, Security, Retention, Data Integrity, Access) apply.
Source: Personal Data Protection Act 2010 (Act 709), sections 6–12 (Personal Data Protection Principles). Referenced against the JPDP portal at pdp.gov.my. Verified 2026-08-23.
Consent for lead forms and marketing follow-up
The Notice-and-Choice Principle (section 7 of Act 709) requires that at the point of collection the data subject is told, in the national language and in English, what data is collected, the purposes of collection, the classes of third parties to whom it may be disclosed, and the choices and means the data subject has to limit that processing. In practice this drives the shape of a lead form: a checkbox is not enough — the notice text must be present and legible, the purpose must be stated, and the choice must be revocable. Consent obtained for one purpose (say, sales follow-up on a specific enquiry) does not extend to another purpose (say, promotional emails about unrelated services) without a separate consent for the second purpose.
DNC Registry (Do Not Call)
The Do Not Call Registry at dncr.spr.gov.my is a national opt-out list operated by the Malaysian Communications and Multimedia Commission (SPR) for telemarketing follow-up (voice calls and short messages). A business making telemarketing contact must screen the number against the registry before contact. This is a parallel obligation to PDPA consent — a person can have consented to being processed for a purpose and still be on the DNC Registry, and the DNC registration overrides for the specific channels it covers. Registered numbers must not be contacted for solicitation regardless of prior consent. See the free PDPA/DNC lead-follow-up checker for a quick pre-contact check.
The Personal Data Protection (Amendment) Act 2024
The Personal Data Protection (Amendment) Act 2024 (Act A1727) commenced in stages: stage 1 on 1 January 2025, and the DPO and breach-notification provisions on 1 June 2025. The Data Breach Notification (DBN) Guideline and the DPO Guideline were both issued on 25 February 2025, alongside Circular No. 1/2025 (DBN) and Circular No. 2/2025 (Appointment of DPO) published on pdp.gov.my. The Amendment restructures core terminology and adds specific, enforceable obligations:
- Data controller replaces data user. The Amendment renames the primary regulated entity. Data processors are now directly liable (previously only the data user carried liability). Every service contract with a marketing vendor should be revisited on this point.
- Mandatory Data Protection Officer (DPO) appointment. A DPO must be appointed where the controller processes personal data of 20,000 or more data subjects, or sensitive personal data of 10,000 or more data subjects, or engages in regular and systematic monitoring of data subjects. The DPO must be resident in Malaysia for at least 180 days per year and fluent in Bahasa Malaysia and English. Source: Circular No. 2/2025 and the DPO Guideline (25 February 2025).
- Mandatory breach notification — section 12B. The Commissioner must be notified as soon as practicable and no later than 72 hours from the controller becoming aware of the breach. If the 72-hour window is missed, a written justification must accompany the late submission. Affected data subjects must be notified within 7 days of the Commissioner where significant harm is likely. Source: Circular No. 1/2025 and the DBN Guideline (25 February 2025).
- Penalties raised sharply. Breach of a data-protection principle now carries a fine of up to RM1,000,000 and imprisonment up to 3 years (raised from RM300,000 / 2 years). Failure to notify under section 12B(1) carries up to RM250,000 and 2 years.
- Data-portability right. Data subjects may request a copy of their personal data in a structured, commonly used, machine-readable format, subject to technical feasibility. Implementation shape follows JPDP guidance.
- Cross-border transfers restructured. The whitelist mechanism (previously requiring gazetted "safe" jurisdictions) is abolished in favour of a substantially-similar / adequate-protection test, with controllers expected to run Transfer Impact Assessments (TIAs) on outward transfers.
Sources: Personal Data Protection (Amendment) Act 2024 (Act A1727); Circular No. 1/2025 (Data Breach Notification); Circular No. 2/2025 (Appointment of DPO); DBN Guideline and DPO Guideline (25 February 2025); JPDP portal pdp.gov.my. Verified 2026-08-23. Honest gap: sector-specific subsidiary orders under Act A1727 continue to be issued and should be checked against pdp.gov.my before finalising controls for regulated industries.
Retention — how long is "as long as necessary"?
Section 10 of Act 709 (Retention Principle) requires that personal data not be kept longer than is necessary for the fulfilment of the purpose for which it was processed. For a marketing operation this is a policy decision, not a statutory number: define the purpose, define the retention window that supports it, document it, and delete on schedule. Common defaults used by practitioners — 24 months for enquiry-only leads, 6 years for records tied to invoiced work — are defensible only if the business can point to a written policy and evidence of deletion runs. The Retention Principle is what the DPO, once appointed, is expected to enforce.
PDPA privacy policy generator (embedded)
The free PDPA policy generator below produces a business-specific privacy notice covering the seven PDPA principles, the DNC Registry position and the 2024 Amendment obligations, tailored to lead-form and CRM data.
Prefer the standalone tool? Open the PDPA privacy policy generator in a full page.
Akta Perlindungan Data Peribadi — panduan ringkas (BM)
Ringkasan Bahasa Malaysia bagi rakan perniagaan yang mencari akta perlindungan data peribadi, pdpa compliance malaysia atau pdpa consent requirements. Akta Perlindungan Data Peribadi 2010 (Akta 709) dikuatkuasakan oleh Jabatan Perlindungan Data Peribadi (JPDP) di bawah KKD. Setiap perniagaan yang memproses data peribadi bagi transaksi komersial mesti mendapatkan persetujuan yang khusus, dimaklumkan dan boleh dibuktikan sebelum data itu digunakan untuk pemasaran. Akta Pindaan 2024 memperkenalkan kewajipan pelantikan Pegawai Perlindungan Data (DPO), notifikasi pelanggaran data dan hak mudah alih data — kuatkuasa provisi berperingkat, sila rujuk pdp.gov.my untuk tarikh kuatkuasa terkini. Daftar DNC di dncr.spr.gov.my adalah kewajipan berasingan bagi susulan telemarketing. Halaman ini bukan nasihat undang-undang.
Related shakalakaa resources
See the PDPA and lead data guide and the Singapore counterpart DNC/PDPA on Singapore lead follow-up. For the tax dimension of running an agency operation, see the e-invoice Malaysia hub and SST on digital marketing in Malaysia.