The short version
Malaysia now has a published standard for how a system should be built, and a website is a system. The Commissioner issued the Data Protection by Design Guideline on 30 April 2026. It defines the approach and sets out four elements. Then it works through all seven Personal Data Protection Principles and closes with a checklist. Paragraph 1.1 applies it to the data controller and the data processor. So a studio that builds and runs your forms sits inside it. It is a guideline rather than a regulation, so the binding duties are still the principles in section 5. What it changes is the standard you are measured against.
What it is, and who it reaches
The definition is the useful part, because it fixes when the work has to happen.
Paragraph 3.1 · the definition
“Data protection by design” means an approach that incorporates appropriate technical and organisational measures, which are designed to implement the PDP Principles, into the entire lifecycle of a data processing activity, from design, development and deployment to decommissioning.”Data Protection by Design Guideline, paragraph 3.1. Read from the Commissioner’s own document, 18 September 2026.
Two words in that sentence do the work. Lifecycle means it covers the whole life of the data, through to decommissioning. Design means the measures go in at the start. Paragraph 3.2 says so plainly: the measures are incorporated “from the outset”.
And it reaches further than most firms expect. Paragraph 1.1 applies the approach to the data controller and the data processor. A studio that builds your contact form, hosts it and maintains it is usually processing personal data on your behalf. So the standard lands on the build, not only on the firm that owns the data.
The legal footing is worth stating precisely. Paragraph 2.1 says the guideline is issued by the Commissioner under subsection 48(g) of Act 709. That makes it guidance rather than a regulation. The duties themselves come from section 5, which requires a data controller to comply with the seven Personal Data Protection Principles. So the guideline creates no new offence. It tells you how the regulator expects the old ones to be met.
The four elements
Paragraph 4.1 names them. Each one has a plain consequence for a website.
| Element | What the guideline says | What it means on a site |
|---|---|---|
| Proactiveness | Anticipate and prevent privacy risks before they happen. Paragraph 4.2.2 asks for systems that collect, use and keep the least data necessary, and protect it by default. | Fewer fields on the form. A shorter retention window. The private setting as the default. |
| End-to-end protection | Protection across the whole life of the data. Every phase counts: collection, processing, storage and the rest. | The form, the inbox it lands in, the backup, and the day you delete it. |
| Transparency | Be open and honest about how the data is handled, and be “prepared to demonstrate compliance with the stated practices”. | A notice that matches what the site actually does, and a record that shows it. |
| User-centricity | The data “ultimately belongs to the data subject”. Design around that person’s interests and give them control. | Plain choices, easy withdrawal, and a real route to ask what you hold. |
The checklist at the back, which is the part to actually use
Annex A lists measures with a yes or no beside each. These are the data-oriented ones, in the guideline’s own order and its own words.
| Measure | What it asks |
|---|---|
| Predetermination | Establish the purposes and the legal basis before the processing takes place. |
| Specificity | Define the purposes as narrowly and specifically as possible. |
| Data minimisation | Collect and process only what is strictly necessary for those purposes. |
| Separation | Keep data obtained for different purposes apart. The guideline’s own example is separate databases by default. |
| Abstraction | Anonymise or delete as soon as identifying a person stops being necessary. |
| Access limitation | Grant access only to authorised parties with a legitimate need. |
| Security | Protect the data across its whole lifecycle, through to secure destruction. |
| User-centred design | Strong privacy defaults, and privacy notices written for the person reading them. |
Annex A also carries process-oriented measures, and Part J adds best practices for governance. The full document runs to 31 pages and it is free to download. Read it yourself. Our summary is a way in, and the guideline is the authority.
Where a website usually fails this, in our experience
Four patterns, all common on Malaysian corporate sites, each one a measure in Annex A.
Questions firms are asking
What is data protection by design under Malaysian law?
The Commissioner set it out in the Data Protection by Design Guideline, issued on 30 April 2026. The guideline defines it as an approach that builds the PDP Principles into a system’s whole life. That runs from design and development through to decommissioning. In plain terms, the protection goes in while the thing is being built.
Does the Data Protection by Design Guideline apply to my web agency?
It applies to whoever processes the data. Paragraph 1.1 applies the approach to the data controller and the data processor. A studio that builds and runs your forms is usually a processor. So it reaches the people building the site as well as the firm that owns it.
Is the Data Protection by Design Guideline law?
It is a guideline, issued by the Commissioner under subsection 48(g) of Act 709. The binding duties are still the seven Personal Data Protection Principles. Section 5 requires a data controller to comply with them. The guideline is how the regulator says to meet them. In practice it is the standard you are measured against.
What are the four elements of data protection by design?
Paragraph 4.1 lists them: proactiveness, end-to-end protection, transparency and user-centricity. Proactiveness includes designing systems that collect, use and keep the least data necessary. And it means protecting personal data by default.
What should a Malaysian website do differently because of it?
Collect fewer fields, keep them for less time, and make the privacy-friendly option the default. Annex A puts it as a checklist. Predetermine the purpose and define it narrowly. Collect the least data. Keep separate purposes in separate stores. Limit access, secure the whole lifecycle, and design around the person whose data it is.
Sources, and the date each one was read
- Data Protection by Design Guideline (DpbD), Personal Data Protection Commissioner, Malaysia. Read in full from the Commissioner’s own PDF at pdp.gov.my, 31 pages, English. Paragraphs 1.1, 1.2, 2.1, 3.1, 3.2, 4.1 to 4.5 and Annex A are quoted above. Verified 18 September 2026.
- On the date. Published reports differ, some saying 30 April 2026 and some 8 May 2026. The document’s own file properties record it as created 29 April 2026 and modified 30 April 2026. The regulator also hosts it under an April 2026 path, so 30 April is used here. Verified 18 September 2026.
- Personal Data Protection Act 2010 (Act 709), sections 5 and 48(g), and the seven Personal Data Protection Principles. The guideline cites both.
- Two companion guidelines were issued alongside it, both listed on the same regulator page. They cover Data Protection Impact Assessment, and Automated Decision-Making and Profiling. This page rests on neither of them, because neither has been read in full yet.
A note on what this is
This is a website-practice resource, not legal advice. We build and maintain websites that handle personal data, and we read the instruments that govern them. The authority here is the guideline itself. Read the guideline itself. Put anything that turns on interpretation to the Commissioner or to your own counsel. Everything above is our reading of what it means for a firm’s website, current as of 18 September 2026.