DxtraBETA
Back to blog
GuidesMalaysiaSmall Business July 2026 7 min read

The Small Business Guide to Malaysia in 2026

Malaysia's Personal Data Protection Act now carries breach notification deadlines, DPO duties and higher penalties after the 2024 amendments. Here is what a small business actually has to do, and what it can safely ignore.

Why this matters now

If you run a small business in Malaysia and you collect customer names, phone numbers, addresses or payment details, you are covered by the Personal Data Protection Act 2010. That has been true for years. What has changed is that the Act now has teeth, and the practical expectations placed on you have become more specific.

The Personal Data Protection (Amendment) Act 2024 was phased into force through 2025. It brought in mandatory breach notification, direct obligations on the companies that process data on your behalf, a right for customers to take their data with them, a requirement for some organisations to appoint a Data Protection Officer, and a significantly higher maximum penalty. None of this requires a legal department to handle. It does require you to know which pieces apply to you.

The regulator is the Personal Data Protection Department, known locally as Jabatan Perlindungan Data Peribadi or JPDP, which sits under the Ministry of Digital. It publishes guidelines, and as you will see below, several of the numbers small businesses care about most live in those guidelines rather than in the Act itself. That distinction matters, and this guide is careful about it.

Who this applies to

The PDPA applies to you if you process personal data in connection with commercial transactions in Malaysia. Personal data means information that identifies a living person, directly or indirectly. A customer email list, a delivery address book, a spreadsheet of leads, CCTV footage of shoppers, employee records in your payroll system: all personal data.

There is an important limit on scope that a lot of writing on this topic gets wrong. Malaysia's PDPA does not apply to personal data processed outside Malaysia unless that data is intended to be further processed in Malaysia. This is a real and useful difference from Europe's GDPR, which reaches businesses anywhere in the world that target European customers. The PDPA is narrower. A foreign business with no Malaysian establishment is often outside the Act entirely, even if it has Malaysian customers. If you are a Malaysian business processing data here, though, you are squarely in scope, and so is the data you send abroad for processing.

The Act is built on seven personal data protection principles: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access. Most of what follows maps onto those.

What you actually have to do

Tell people what you are collecting and why, in a language they read. This is the Notice and Choice principle, and it is the obligation small businesses most often fall short on. You need a written notice that explains what data you collect, why, who you disclose it to, and how someone can access or correct it. In Malaysia that notice needs to be available in both Bahasa Malaysia and English. A privacy policy page on your website is the usual home for it, but it also needs to reach people who sign up in person or over the phone.

Get consent, and keep a record that you got it. The General principle requires consent for processing personal data, with narrow exceptions. The part people forget is the record. If a customer or the regulator asks you to demonstrate that someone agreed to marketing emails, "we had a checkbox on the form" is a weaker answer than a timestamped log showing who consented, to what, and when. Build the record at the moment of consent, because you cannot reconstruct it later.

Do not disclose data for purposes people were not told about. The Disclosure principle is simple and strict. If you collected email addresses to fulfil orders, you cannot sell that list to a partner or hand it to an affiliate marketer without going back for consent. This catches a surprising number of small businesses who treat a customer list as an asset to be traded.

Secure the data, and make sure your suppliers do too. The Security principle requires practical protection against loss, misuse and unauthorised access. For most small businesses that means access controls so not everyone can export the customer database, encryption where it is available, and prompt removal of access when staff leave. The 2024 amendments changed something important here: data processors now owe direct security obligations, rather than responsibility resting only with you as the data user. Your booking platform, payroll provider and email tool carry their own duties now. That does not remove yours, but it does mean the contracts you sign should be explicit about who does what.

Notify a breach quickly. Mandatory breach notification is new and it is the obligation most likely to catch an unprepared business off guard. The expectation is that you notify the Commissioner as soon as practicable and no later than 72 hours, and that you notify affected individuals within 7 days where the breach causes or is likely to cause significant harm. Say the numbers out loud now, because you will not have time to look them up in the middle of an incident. One caveat you should understand: the 72-hour and 7-day deadlines sit in the Commissioner's guidelines rather than in the text of the Act. They are the regulator's stated expectations and the practical standard you will be measured against, not statutory text. Treat them as the deadline.

Appoint a Data Protection Officer if you cross the thresholds. Appointment of a DPO is now mandatory for organisations above prescribed thresholds: broadly, processing the personal data of more than 20,000 data subjects, or more than 10,000 data subjects' sensitive personal data or financial transaction data. As with the breach deadlines, these thresholds come from the Commissioner's guidelines rather than the Act. Most businesses with fewer than fifty staff will sit below them, but an e-commerce shop with a long customer history can pass 20,000 records without noticing. Count before you assume.

Honour access, correction and portability requests. The Access principle gives people the right to see the data you hold and to have it corrected. The amendments added a right to data portability, which lets someone ask you to transmit their data to another provider. This right has been in force since 1 June 2025. What is still outstanding is the implementing guideline setting out how portability is to be operationalised in practice. So the right exists and you should be ready to respond to a request; the detailed mechanics are still being written.

What changed with the 2024 amendments

Pulling the changes together: processors now carry direct security obligations; biometric data has been added to the definition of sensitive personal data, which matters if you use fingerprint or facial recognition for staff attendance; mandatory breach notification exists; DPO appointment is required above the thresholds; the portability right is live; and the cross-border transfer rules have moved away from the old whitelist approach, so transfers are assessed rather than checked against a fixed list of approved countries.

The penalty position also changed. The Amendment Act raised the maximum penalty for a breach of the personal data protection principles to a fine of up to RM 1,000,000, imprisonment of up to three years, or both. That is a maximum, not a typical outcome, and it applies to breaches of the principles rather than to every procedural slip. But it is a meaningful shift from where the Act sat before.

Common mistakes

The most common mistake is having a privacy policy that was copied from a foreign website. GDPR-derived text will not describe your Malaysian obligations correctly, will not mention the JPDP, and will usually be missing the Bahasa Malaysia version entirely.

The second is treating consent as a one-time event. If you change what you do with data, the old consent does not stretch to cover it.

The third is discovering during a breach that nobody knows who is supposed to call the Commissioner. Seventy-two hours is not long when the first day is spent working out what happened. Write down, in advance, who investigates, who notifies and who talks to customers.

The fourth is assuming your vendors have it handled. Processors owe their own duties now, but if your email platform leaks your list, you are still the business your customers will hold responsible.

Where Dxtra fits

Dxtra generates a privacy program from a questionnaire: a privacy policy, cookie notice, consent records, processing records, a public Transparency Center and DSAR handling, covering more than 500 obligations across 140+ countries, from $10 a month. It will not replace judgement on the questions specific to your business, but it removes the drafting work that stops most small teams from starting.

If you would rather see where you stand before committing to anything, Dxtra's free scan reads your site's public pages in about two minutes with no signup and returns a risk band with findings mapped to named sources. It flags gaps for you to look at; it does not determine whether you are compliant.

Where to start

Start with an inventory. Write down every place customer data lives: your website forms, your e-commerce backend, your email tool, your accounting software, the shared drive, the WhatsApp Business account. You cannot protect or describe what you have not listed.

Then count your data subjects, so you know whether the DPO thresholds apply. Then fix the notice, in both languages, and make sure it reflects what you actually do rather than what a template assumed. Then write the breach plan on a single page and put a name against each step.

That sequence will take a small business a few days spread over a few weeks, and it will put you ahead of most of your competitors. The businesses that struggle are not the ones that did it imperfectly. They are the ones that had not started when something went wrong.

This article is general information, not legal advice. Rules change; confirm anything that matters with Malaysia's Personal Data Protection Department (pdp.gov.my) or a qualified adviser before you rely on it.

Ready to get compliant?

Start your privacy program today — from $10/month.