For Malaysian businesses · Read from the guideline on

The guideline your website is
supposed to be built against.

On 30 April 2026 the Personal Data Protection Commissioner published a guideline. It is about building data protection in while a system is still being designed. It reaches the data processor as well as the firm that owns the data. So it reaches whoever builds your forms. Here is what it says, paragraph by paragraph, and what each part asks of a website.

Issued 30 April 2026 Quoted, paragraph by paragraph A website resource, not legal advice

The short version

Malaysia now has a published standard for how a system should be built, and a website is a system. The Commissioner issued the Data Protection by Design Guideline on 30 April 2026. It defines the approach and sets out four elements. Then it works through all seven Personal Data Protection Principles and closes with a checklist. Paragraph 1.1 applies it to the data controller and the data processor. So a studio that builds and runs your forms sits inside it. It is a guideline rather than a regulation, so the binding duties are still the principles in section 5. What it changes is the standard you are measured against.

A

What it is, and who it reaches

The definition is the useful part, because it fixes when the work has to happen.

Paragraph 3.1 · the definition

“Data protection by design” means an approach that incorporates appropriate technical and organisational measures, which are designed to implement the PDP Principles, into the entire lifecycle of a data processing activity, from design, development and deployment to decommissioning.”
Data Protection by Design Guideline, paragraph 3.1. Read from the Commissioner’s own document, 18 September 2026.

Two words in that sentence do the work. Lifecycle means it covers the whole life of the data, through to decommissioning. Design means the measures go in at the start. Paragraph 3.2 says so plainly: the measures are incorporated “from the outset”.

And it reaches further than most firms expect. Paragraph 1.1 applies the approach to the data controller and the data processor. A studio that builds your contact form, hosts it and maintains it is usually processing personal data on your behalf. So the standard lands on the build, not only on the firm that owns the data.

The legal footing is worth stating precisely. Paragraph 2.1 says the guideline is issued by the Commissioner under subsection 48(g) of Act 709. That makes it guidance rather than a regulation. The duties themselves come from section 5, which requires a data controller to comply with the seven Personal Data Protection Principles. So the guideline creates no new offence. It tells you how the regulator expects the old ones to be met.

B

The four elements

Paragraph 4.1 names them. Each one has a plain consequence for a website.

ElementWhat the guideline saysWhat it means on a site
ProactivenessAnticipate and prevent privacy risks before they happen. Paragraph 4.2.2 asks for systems that collect, use and keep the least data necessary, and protect it by default.Fewer fields on the form. A shorter retention window. The private setting as the default.
End-to-end protectionProtection across the whole life of the data. Every phase counts: collection, processing, storage and the rest.The form, the inbox it lands in, the backup, and the day you delete it.
TransparencyBe open and honest about how the data is handled, and be “prepared to demonstrate compliance with the stated practices”.A notice that matches what the site actually does, and a record that shows it.
User-centricityThe data “ultimately belongs to the data subject”. Design around that person’s interests and give them control.Plain choices, easy withdrawal, and a real route to ask what you hold.
Data Protection by Design Guideline, paragraphs 4.1 to 4.5. Read from the Commissioner’s own document on 18 September 2026.
C

The checklist at the back, which is the part to actually use

Annex A lists measures with a yes or no beside each. These are the data-oriented ones, in the guideline’s own order and its own words.

MeasureWhat it asks
PredeterminationEstablish the purposes and the legal basis before the processing takes place.
SpecificityDefine the purposes as narrowly and specifically as possible.
Data minimisationCollect and process only what is strictly necessary for those purposes.
SeparationKeep data obtained for different purposes apart. The guideline’s own example is separate databases by default.
AbstractionAnonymise or delete as soon as identifying a person stops being necessary.
Access limitationGrant access only to authorised parties with a legitimate need.
SecurityProtect the data across its whole lifecycle, through to secure destruction.
User-centred designStrong privacy defaults, and privacy notices written for the person reading them.
Annex A, the data-oriented measures, in the guideline’s own order and its own words. Read 18 September 2026.

Annex A also carries process-oriented measures, and Part J adds best practices for governance. The full document runs to 31 pages and it is free to download. Read it yourself. Our summary is a way in, and the guideline is the authority.

D

Where a website usually fails this, in our experience

Four patterns, all common on Malaysian corporate sites, each one a measure in Annex A.

01
The form asks for more than the reply needs
A quote request that takes a full address, an IC number and a date of birth, where a name and an email would do. Data minimisation is measure 3, and a shorter form converts better anyway.
02
The mailbox keeps every enquiry forever
Enquiries pile up for years because deletion sits in nobody’s calendar. Abstraction is measure 5, and it asks for deletion once identifying the person stops being necessary.
03
The consent box is ticked when the page loads
A pre-ticked marketing box is the opposite of a privacy default. Measure 8 asks for strong privacy defaults, and paragraph 4.2.2 asks for protection by default.
04
The privacy notice describes a different website
A notice copied from a template names analytics the site no longer runs, and misses the ones it does. Transparency in paragraph 4.4 asks you to be ready to demonstrate what you actually do.
Q

Questions firms are asking

What is data protection by design under Malaysian law?

The Commissioner set it out in the Data Protection by Design Guideline, issued on 30 April 2026. The guideline defines it as an approach that builds the PDP Principles into a system’s whole life. That runs from design and development through to decommissioning. In plain terms, the protection goes in while the thing is being built.

Does the Data Protection by Design Guideline apply to my web agency?

It applies to whoever processes the data. Paragraph 1.1 applies the approach to the data controller and the data processor. A studio that builds and runs your forms is usually a processor. So it reaches the people building the site as well as the firm that owns it.

Is the Data Protection by Design Guideline law?

It is a guideline, issued by the Commissioner under subsection 48(g) of Act 709. The binding duties are still the seven Personal Data Protection Principles. Section 5 requires a data controller to comply with them. The guideline is how the regulator says to meet them. In practice it is the standard you are measured against.

What are the four elements of data protection by design?

Paragraph 4.1 lists them: proactiveness, end-to-end protection, transparency and user-centricity. Proactiveness includes designing systems that collect, use and keep the least data necessary. And it means protecting personal data by default.

What should a Malaysian website do differently because of it?

Collect fewer fields, keep them for less time, and make the privacy-friendly option the default. Annex A puts it as a checklist. Predetermine the purpose and define it narrowly. Collect the least data. Keep separate purposes in separate stores. Limit access, secure the whole lifecycle, and design around the person whose data it is.

Sources, and the date each one was read

A note on what this is

This is a website-practice resource, not legal advice. We build and maintain websites that handle personal data, and we read the instruments that govern them. The authority here is the guideline itself. Read the guideline itself. Put anything that turns on interpretation to the Commissioner or to your own counsel. Everything above is our reading of what it means for a firm’s website, current as of 18 September 2026.

Before you commission a ringgit

Send me your firm's name and I will design your homepage, free, before anything is signed.

You see a working version of your own homepage on your own screen, and you decide after that. It takes about a week and it costs nothing, because a written brief and a finished page are different things and this is how we make sure what you get is what you had in mind. Built inside the lines above: a form that asks less, keeps it for less time, and defaults to private. What that site looks like, and what it costs.

Request your concept →