What the PDPA amendments mean for a small company's laptops, email and files: 72-hour breach notification, when you need a DPO, and a practical IT checklist.
What Changed in the PDPA
The Personal Data Protection Act 2010 (PDPA) was amended in 2024. Two of the changes that matter most to a small or medium company took effect on 1 June 2025:
- Mandatory data breach notification. If personal data you hold is breached, you must tell the Personal Data Protection Commissioner.
- Data Protection Officer (DPO). Organisations above certain thresholds must appoint a DPO.
This guide covers the IT side of meeting those obligations. It is not legal advice — for how the law applies to your company, speak to a lawyer.
Breach Notification: The Timelines
Under the Commissioner's guidelines:
| Who you notify | When |
|---|---|
| The Personal Data Protection Commissioner | As soon as practicable, within 72 hours |
| Affected individuals (where the breach is likely to cause significant harm) | Without unnecessary delay, within 7 days of notifying the Commissioner |
"Significant harm" covers breaches that risk physical harm, financial loss, damage to credit records or loss of property; misuse of data for illegal purposes; compromise of sensitive personal data; data that together could enable identity fraud; and breaches affecting more than 1,000 people.
You must also keep a register of data breaches for at least two years. Failing to notify can lead to a fine of up to RM250,000, imprisonment of up to two years, or both.
The IT point: 72 hours is very little time if you cannot answer basic questions — which laptop was lost, what was on it, whether it was encrypted, who had access to the mailbox. Those answers come from records you keep before anything goes wrong.
Do You Need a DPO?
The guidelines require a DPO when you process:
- personal data of more than 20,000 people, or
- sensitive personal data, including financial information, of more than 10,000 people, or
- personal data in activities that involve regular and systematic monitoring.
The DPO must be proficient in Malay and English and be resident in Malaysia or easily contactable, and the Commissioner must be told of the appointment within 21 days. A company's customer database, HR records and CCTV can add up quickly — count them before assuming you are below the threshold.
The IT Checklist
Most personal data in a small company sits on laptops, in email and in shared folders. This checklist covers those.
1. Know where the data is
- Keep an IT asset register: every laptop and phone, who has it, and what data it holds
- List the systems holding customer and staff data: email, accounting, HR, CRM, shared drives
- Note who has access to each one
2. Protect the devices
- Turn on full-disk encryption — BitLocker on Windows, FileVault on Mac. An encrypted lost laptop is a very different incident from an unencrypted one
- Require a password or PIN on every laptop and phone
- Keep operating systems and browsers up to date
- Run endpoint protection on every device
3. Protect the accounts
- Turn on multi-factor authentication for email and cloud systems
- Give each person their own account — no shared logins
- Remove access on a leaver's last day
4. Back up, and test the backup
- Keep at least one backup that ransomware on the office network cannot reach
- Test a restore regularly — a backup you have never restored is a hope, not a plan
5. Dispose of devices properly
- Wipe or destroy storage before a laptop is sold, donated or recycled
- Record which device was wiped, how and when
6. Be ready to respond
- Write down who decides whether an incident is a notifiable breach, and who contacts the Commissioner
- Keep the breach register — even for incidents you decide not to notify
- Train staff to report a lost device or a suspicious email immediately
Where TechFix Helps
We handle the IT side: the asset register, device encryption, account security, backups and secure disposal. See our PDPA compliance IT page, or start with a cybersecurity assessment for SMEs.
