PDPA and Your Website: What Compliance Needs
Home  /  Blog

PDPA and Your Website: What Compliance Needs

The Short Answer: PDPA website compliance is mostly four small jobs: a real privacy notice, consent that is actually asked for, a retention rule, and a named person who answers data requests. None of it is expensive. What changed in 2025 is the price of ignoring it — the ceiling for breaching a data protection principle is now RM1,000,000 and three years.

Most PDPA advice written for Malaysian business owners reads like a summary of the Act. Seven principles, some section numbers, a warning at the end. It is accurate and almost useless, because it never touches the thing the owner actually controls: the website already collecting names and phone numbers every day.

That gap matters more now. The Personal Data Protection (Amendment) Act 2024 raised the penalties and extended duties to the vendors who process data on your behalf. It also added a 72-hour clock that starts the moment you realise something has leaked. None of this is theoretical for a ten-person business in Puchong with a contact form and a Meta pixel.

So this guide treats PDPA website compliance from the site inwards. What on your website counts as personal data, where it quietly gets collected, what the law now costs when it goes wrong, and which gaps to close first. It sits beside the website design and development work we do at IZILI Digital Marketing, because compliance is a build decision long before it is a legal one.

Before the detail, here is a plain overview of what the Act asks of a Malaysian business.

Malaysia’s Personal Data Protection Act (PDPA): What Your Business Should Know

Source video: Malaysia’s Personal Data Protection Act (PDPA): What Your Business Should Know on YouTube

PART 1 · DIAGNOSE

What Counts as Personal Data on Your Website?

IN BRIEFAnything that identifies a living person, directly or when combined with something else you hold. On a typical Malaysian business site that means names, phone numbers, emails, delivery addresses and enquiry messages. Sort these out during the website build, not afterwards.

Owners usually assume the PDPA is about databases. It is about identifiability. A phone number sitting in a WordPress form entry is personal data in exactly the same way a customer record in an accounting system is.

Two categories are worth separating, because the law treats them differently.

  • Ordinary personal data. Name, mobile number, email, company, address, the free-text message someone typed into your enquiry form. Most business websites collect only this.
  • Sensitive personal data. Health information, religious beliefs, political opinions, and the commission or alleged commission of an offence. Clinics, insurance agents and recruiters collect this without always realising it, and it carries a stricter consent standard.

A third bucket causes most of the arguments: identifiers you never asked for. Advertising pixels, session recordings and chat widgets all generate data tied to an individual device, and the honest reading is that these need the same care as a form field. The seven personal data protection principles published by the Commissioner apply to the whole collection, not to the parts you remember collecting.

Bottom Line: If a visitor’s action leaves something behind that could be traced to them, the PDPA is in scope. Start from that assumption and work backwards.

BENCHMARK BRIEFING 1 OF 4

Is a Website Data Leak a Real Risk in Malaysia?

IN BRIEFYes, and it is the fastest-growing category the national response centre handles. Reported data breach and intrusion incidents both rose sharply into 2025 while overall volumes barely moved, which tells you where attention is being paid.

The figures below come from the national incident response centre and compare the last quarter of 2024 with the first quarter of 2025.

Malaysian Cyber Incidents Reported to Cyber999, Q4 2024 vs Q1 2025
Incidents reported to the Cyber999 Incident Response Centre by category in the fourth quarter of 2024 and the first quarter of 2025, with percentage change.
Incident category Q4 2024 Q1 2025 Change
Intrusion 75 132 +76%
Data breach 151 195 +29%
Intrusion attempt 97 101 +3%
Fraud 1,108 1,126 +2%
All incidents reported 1,550 1,657 +7%

Source: aggregated by IZILI Digital Marketing from CyberSecurity Malaysia, MyCERT Cyber Incident Quarterly Summary Report Q1 2025. Licence.

Read the shape rather than the totals. Fraud dominates the volume but grew by two percent. Intrusion — someone getting into a system that was not theirs — grew by seventy-six. Data breach reports grew by twenty-nine. Those two categories are where a small business website ends up, and they are moving in the wrong direction while everything else sits flat.

Bottom Line: The risk is not evenly spread. Unauthorised access and leaked records are the growth categories, and both usually begin at a login or a form.

PART 2 · DIAGNOSE

Four Places Your Website Collects Data Quietly

IN BRIEFForms, tracking tags, chat widgets and checkout. Owners remember the first, forget the other three, and it is usually the forgotten three that send data overseas or into an account nobody controls any more. Map all four before writing any policy.

Do this as a physical walk through your own site, clicking what a customer clicks. Every point where something is typed, tracked or transmitted goes on the list.

  • Enquiry and booking forms. The obvious one. Note where submissions land — an inbox, a plugin database, a Google Sheet — because each location is a separate copy you are responsible for.
  • Analytics and advertising tags. Meta pixels, Google tags and remarketing scripts generate identifiers before anyone types anything. They also usually transmit to servers outside Malaysia, which brings the Commissioner’s cross-border transfer guidelines into play. Our analytics and CRO reviews normally start here.
  • WhatsApp buttons and live chat. The conversation itself is personal data, held on someone’s phone. If that phone belongs to a staff member who leaves, the data leaves too — the same weakness that leaves a business Facebook Page stranded on a former employee’s account.
  • Checkout and payment. Addresses, order history and, increasingly, a third-party lender. Adding instalment options is a data decision as much as a conversion one, which is worth reading alongside how BNPL works on a Malaysian online store.
Bottom Line: You cannot write an honest privacy notice until this map exists. Most notices are wrong because the map was skipped.

Not sure what your own site is collecting?

A collection map takes an afternoon and usually turns up two tags nobody remembers installing. See how a Blueprint diagnosis runs

BENCHMARK BRIEFING 2 OF 4

When Did Each PDPA Obligation Actually Start?

IN BRIEFIn stages, not all at once. The bulk of the amendments took effect in January 2025, and the two obligations that bite hardest for smaller businesses — breach notification and appointing a data protection officer — followed in June 2025.

The sequence below is why so many owners believe nothing has changed. It arrived quietly, in pieces, over eighteen months.

Rollout of Malaysia’s Amended PDPA Obligations, 2024 to 2026
Timeline of the Personal Data Protection (Amendment) Act 2024 and related guidance, showing what took effect at each stage and what it means for a website owner.
Stage What landed What it means for a website owner
Late 2024 Amendment Act A1727 published “Data user” becomes “data controller” across the Act
January 2025 Main amendments in force Higher penalties; your processors carry duties of their own
June 2025 Breach notification and DPO duties in force A 72-hour reporting clock, and a threshold test to run
2025 to 2026 Guidelines and circulars issued Practical detail arrives as guidance, not as new law

Source: aggregated by IZILI Digital Marketing from the Personal Data Protection Commissioner’s published Amendment Act and commencement records, 2024 to 2026. Licence.

The practical consequence sits in the last row. Most of what you need to do is now defined in guidance documents rather than in the Act itself, including the guidelines on data breach notification and on appointing a data protection officer. Reading the Act alone will leave you short.

Bottom Line: Nothing is pending. Every obligation discussed here is already live, which removes “we are waiting to see” as a position.

PART 3 · DESIGN

What PDPA Website Compliance Actually Needs

IN BRIEFFive things, and only one of them is a document. A bilingual privacy notice, consent that is genuinely requested, a retention rule, a named contact for requests, and access control on wherever submissions land. Build them into the site itself.

Take them in order, because each one is cheap on its own and awkward to retrofit later.

  • A privacy notice in Malay and English. The Notice and Choice Principle expects both languages. A single English page copied from an overseas template does not meet it, and the copy-paste is usually visible.
  • Consent that is asked, not assumed. An unticked box with plain wording beside the submit button. Pre-ticked boxes and buried “by continuing you agree” lines are the two most common failures we see.
  • A retention rule you can state out loud. Decide how long enquiry data is kept, write it down, and delete on schedule. Indefinite storage is the default nobody chose.
  • A named contact for data requests. A real email address that a real person reads, because visitors have the right to ask what you hold and to correct it.
  • Access control on the destination. Whoever can open the form inbox holds the data. Remove ex-staff, use individual logins, and check who your web provider has added over the years.

DECISION BOX · WHO OWNS PDPA WORK ON YOUR SITE

Option Cost Speed Depth of cover
You, in-house Your own hours Slow — weeks Basics only
Web provider, in contract Bundled or low Fast — days Technical layer
Legal or privacy adviser Highest Moderate Full, documented

Verdict: Put the technical fixes in your web provider’s scope, since they hold the access anyway. Bring in an adviser only if you handle sensitive data or cross a DPO threshold — below that, paid legal review of a five-page site is usually money spent on reassurance.

Bottom Line: Compliance is a build specification, not a document you commission. Written into the scope, it costs almost nothing.

BENCHMARK BRIEFING 3 OF 4

What Does Getting PDPA Wrong Now Cost?

IN BRIEFUp to RM1,000,000 and three years for breaching a data protection principle, and up to RM250,000 with two years for the newer administrative failures. The principle ceiling more than tripled, which is the single change most owners have not registered.

The bars below scale each maximum fine against the highest one, with the old ceiling included for comparison.

Maximum PDPA Penalties by Type of Failure, Malaysia
Maximum fines and imprisonment terms for different categories of failure under Malaysia’s Personal Data Protection Act as amended in 2024, with relative scale shown as bars.
Type of failure Max fine Max jail Relative scale
Breaching a data protection principle RM 1,000,000 3 years
Same failure, before the amendment RM 300,000 2 years
Not notifying a data breach RM 250,000 2 years
Not appointing a required DPO RM 250,000 2 years

Source: aggregated by IZILI Digital Marketing from the Personal Data Protection (Amendment) Act 2024 (Act A1727) published by the Personal Data Protection Commissioner. Maximum penalties, not typical outcomes. Licence.

Ceilings are not forecasts, and a small business with a tidy record is not looking at a million-ringgit fine for a missing privacy page. What the numbers change is the calculus. When the worst case was RM300,000, ignoring the topic was a defensible commercial gamble for some owners. At RM1,000,000 with personal liability attached to directors and managers, it stops being one.

Consultant’s Note: The exposure that actually catches Malaysian SMEs is not enforcement. It is a customer complaint after an argument, or a competitor’s staff member noticing that your form has no consent line. Regulators mostly respond to complaints, so the practical protection is being unremarkable — not being audit-proof.
Bottom Line: Treat the penalty rise as a change in the odds, not a threat. It moved compliance from optional housekeeping to standard business hygiene.

PART 4 · DESIGN

Do You Need a Data Protection Officer?

IN BRIEFMost small Malaysian businesses do not. The duty is triggered by volume — broadly, personal data on 20,000 or more people, sensitive data on 10,000 or more, or large-scale systematic monitoring. Count before you assume you are clear.

The counting is where owners get caught out. Volume is measured across everything you hold, not per system, so a decade of newsletter subscribers plus a customer database plus years of form entries adds up faster than expected.

Three points decide it in practice.

  • The thresholds are cumulative. An e-commerce business trading since 2018 can pass 20,000 individuals without ever feeling large. A B2B consultancy with 400 clients will not.
  • The role can be outsourced. A DPO may be an employee or an external appointment, so it does not require a new headcount.
  • Appointment must be registered. Details go to the Commissioner within 21 days, through the official DPO registration process. Appointing quietly and telling nobody does not discharge the duty.

Separately, businesses in the prescribed classes of data controller carry their own registration obligation — worth checking against your industry rather than guessing.

Bottom Line: Do the count once and record the date you did it. That single note is the difference between a considered decision and an assumption.

Unsure whether your data volumes cross the line?

Counting properly usually takes an hour and settles the question for a year. Talk it through with our consultants

BENCHMARK BRIEFING 4 OF 4

Which Website Gaps to Fix First, and What Each Takes

IN BRIEFAlmost every PDPA website compliance gap takes under a day to close. The model below groups the usual ones by priority and shows the realistic effort and owner for each, so the whole job can be scoped before anyone quotes for it.

Effort figures assume an existing WordPress or similar site with a handful of forms.

Website Compliance Gap Ladder by Priority (Illustrative)
Illustrative grouping of common website personal data compliance gaps by priority band, with typical effort and the person best placed to fix each.
Gap Typical effort Who fixes it
BAND 1 · THIS WEEK
No privacy notice, or English only Half a day Owner, with review
Forms with no consent line 2 to 4 hours Web developer
BAND 2 · THIS MONTH
Tracking tags firing before consent 4 to 8 hours Developer plus marketing
No retention rule for submissions 1 to 2 hours to decide Owner
BAND 3 · THIS QUARTER
Overseas processors undocumented 1 day to map Owner plus provider
Stale logins on form destinations 2 hours to audit Whoever holds admin

Illustrative model by IZILI Digital Marketing, built on the obligations set out in the Personal Data Protection Act 2010 and the Commissioner’s published guidance, 2026. Modelled effort, not measured results. Licence.

Add the bands together and the entire remediation is roughly two to three days of work spread over a quarter. That figure is worth holding on to, because the reason most sites stay non-compliant is a belief that the job is large. It rarely is. What it is, is unowned.

Bottom Line: Scope the whole ladder before quoting any of it. Piecemeal fixes cost more in coordination than the work itself.

PART 5 · DEPLOY

A 30-Day Sequence for a Site Starting From Zero

IN BRIEFMap, then notify, then control, then rehearse. Four steps across four weeks gets a typical Malaysian SME site from nothing to defensible PDPA website compliance, and the order matters more than the speed.

  1. Week 1 — map the collection. Walk the site as a customer. List every form, tag, chat widget and checkout, and note where each one sends data.
  2. Week 2 — write and publish the notice. Malay and English, describing what you actually collect from the map, why, how long you keep it, and who to contact.
  3. Week 3 — fix consent and access. Add unticked consent lines to every form, hold tracking tags until consent, and remove logins belonging to people who have left.
  4. Week 4 — rehearse the 72 hours. Write a one-page plan naming who is called, who decides, and who notifies the Commissioner. Test it once against an imaginary leaked form inbox.

Week 4 is the step people skip, and it is the one with a legal clock attached. Whether your site is bought outright or rented monthly changes who executes each step, which is a question worth settling when you compare website subscription against a one-off build. Put it in the contract, not in an email.

Bottom Line: A rehearsed breach plan is worth more than a perfect policy. The clock runs whether or not anyone knows who to call.

FAQ

Frequently Asked Questions

1. Does the PDPA apply to a small business website in Malaysia?

Yes, if the site collects personal data in the course of commercial transactions. Size is not the test — a one-person business with a contact form carries the same principles as a large company. What scales with size is the volume-based duties, such as appointing a data protection officer.

2. Do I need a privacy policy page on my website?

Yes, and it needs to be in both Malay and English. The Notice and Choice Principle requires you to tell people what you collect and why, in both languages, before or at the point of collection. A generic template copied from an overseas site usually describes data you do not hold and misses data you do.

3. Does my website need a cookie consent banner under the PDPA?

Not by name, but the underlying duty is real. The Act does not prescribe cookie banners the way European rules do, though consent is still required for processing personal data — and advertising or analytics identifiers are hard to argue out of that category. Holding non-essential tags until consent is the defensible position.

4. Do I need a Data Protection Officer for my business?

Probably not, unless you hold data at scale. The duty is broadly triggered at personal data on 20,000 or more individuals, sensitive data on 10,000 or more, or large-scale systematic monitoring. Count across every system you hold, appoint if you cross a line, and register the appointment with the Commissioner within 21 days.

5. What do I do if my website’s enquiry data leaks?

Contain it first, then start the notification clock. You have 72 hours to notify the Commissioner once you are aware of a breach that meets the notification criteria, with affected people told after that where required. Decide now who makes that call, because three days disappears quickly during an incident.

THE VERDICT

Treat It as Build Scope, Not Legal Work

PDPA website compliance fails in Malaysian SMEs for an unglamorous reason. Nobody owns it. The owner assumes the web agency handled it, the agency assumes it was a legal question, and the site runs for years collecting phone numbers under no particular rule.

The fix is to name an owner and give them the ladder. Two to three days of work, sequenced over a quarter, closes the gaps that a complaint would expose — and most of that work belongs in your web provider’s scope rather than a lawyer’s. That expectation is a fair thing to raise when you shortlist a digital marketing agency in Kuala Lumpur, or renew with the one you have.

Then review it once a year, on a date you set now. Sites accumulate forms and tags the way a desk accumulates paper, and the map you drew this month will be wrong by the next campaign.

Want to know where your website actually stands?

Book a free Blueprint consultation. We will map what your site collects, show you which gaps a complaint would expose first, and hand you a sequenced fix list you can give to any developer.

Book my free consultation

Have a campaign in mind? Let's talk.