The short version
Is your website still PDPA-compliant after the 2024 amendment? Only if it has been updated. The Personal Data Protection (Amendment) Act 2024 came into force in phases across 2025 and now applies in full. It renamed "data users" as "data controllers", made appointing a Data Protection Officer mandatory for qualifying organisations, introduced a duty to report a data breach to the Commissioner within 72 hours, added a right to data portability, and raised the maximum penalty for a principle breach to RM 1,000,000. A privacy notice written to the old 2010 baseline no longer reflects the law your site operates under. Upcial designs PDPA-compliant websites for insurance brokers and financial services firms in Malaysia, and every build carries a privacy notice written to the amended Act: what we build, and for whom.
| What the amended Act requires | What that looks like on your website | Where it lives |
|---|---|---|
| The term for you is data controller | The privacy notice uses it throughout, so a reader can see the notice was written after the reform. | Privacy notice |
| A Data Protection Officer, where the Commissioner’s thresholds are met | A named person with a way to reach them, answerable for the firm’s data. | Privacy notice, contact page |
| A breach reported to the Commissioner within 72 hours | The notice states the duty and who carries it, which assumes the firm can detect and trace a breach. | Privacy notice |
| A right to data portability | The notice acknowledges the right and says plainly how someone exercises it. | Privacy notice |
| Biometric data treated as sensitive personal data, from 1 April 2025 | A higher consent bar wherever the site captures a fingerprint or a face. | Any form that collects it |
| Cross-border transfer judged on adequate protection | The notice names where the forms, the analytics and the hosting send data. | Privacy notice, analytics disclosure |
| Consent that is a genuine, active choice | An unticked box the visitor chooses to tick, and a plain line at the point of collection. | Every form |
| The identity of the data controller | The legal entity that collects the data, with its SSM registration number beside it. | Privacy notice, footer |
Eight rows, and a privacy notice most Malaysian sites have left untouched since 2013. Score your own site on the eighteen-point checklist, or tell us what your firm collects and we will build the homepage first, before anything is signed.
What changed in the law
The Personal Data Protection (Amendment) Act 2024 (Act A1727) is the first substantial reform of Malaysia's data protection law since the original PDPA came into force in 2013. It was brought in across 2025 in three phases, on 1 January, 1 April and 1 July, and by 2026 it applies in full. This is not a proposal or a consultation draft. It is the law your website already operates under.
The reform is overseen by the Personal Data Protection Commissioner, whose department has since issued the detailed guidelines that put the new duties into practice, including the Guideline on Data Breach Notification, the Guideline on the Appointment of a Data Protection Officer, and the Cross-Border Personal Data Transfer Guideline (Guideline No. 3/2025, issued 29 April 2025).
Most of the change is invisible from the front of a website, which is exactly the problem. A site can look perfectly professional and still carry a privacy notice that describes obligations the law has moved past, names no one accountable for data, and makes promises about data handling that no longer match what the Act requires.
What the amendment now requires
The substantive changes the 2024 amendment introduced. Each one has a direct consequence for how a compliant website presents itself and handles the data it collects.
What your website must now do about it
The translation from statute to site. These are the concrete, checkable things a Malaysian website that collects any personal data should now get right.
What getting it wrong now costs
The 2024 amendment did not only add duties. It sharpened the consequences of ignoring them.
Reading your own site against the amendment
Three quick questions to put to your current website, before a visitor, a client, or the Commissioner does.
If any of these give you pause, the gap is worth closing deliberately. The amendment is fully in force, and "our website was built before the change" is not a defence the Act recognises.
No agency is certified PDPA-compliant. Here is what to check instead.
There is no PDPA certification for a web design agency in Malaysia, and a firm claiming one is describing something that does not exist. What you can do is ask five questions before you sign, and verify every answer yourself.
| Ask for this | What a straight answer looks like | How you check it yourself |
|---|---|---|
| A privacy notice written after the reform | It calls you a data controller, names the retention period, and says how a person asks for their data. | Open a site they built and read its privacy notice. The old term is data user. |
| The consent box on their own forms | An unticked box, worded for one purpose, that a person has to choose. | Go to the agency’s own contact form and look at it. |
| Where the data sits and who can reach it | A named host, a named region, and every third party the form touches. | Ask for it in writing with the quote, rather than after. |
| A breach route that works on day one | Who they call, who notifies the Commissioner, and the clock they work to. | Ask what happens at 4pm on a Saturday. A firm that has thought about it answers in one sentence. |
| Handover documentation you own | The accounts, the records and the notice in your name, handed over at launch. | Ask whose email the domain and hosting sit under. If it is theirs, it is theirs. |
Upcial answers all five in writing before anything is signed, and builds websites for Malaysian insurance brokers, reinsurance brokers, loss adjusters and financial services firms, where the buyer is the one carrying the obligation. See what we build, and for whom →
Questions businesses are asking
How do I choose a PDPA-compliant web design agency in Malaysia?
There is no PDPA certification for agencies, so the useful test is what you can verify yourself. Ask for a privacy notice written after the 2024 reform, which should call you a data controller; look at the consent box on the agency’s own contact form; ask in writing where the data is hosted and which third parties the form touches; ask who notifies the Commissioner after a breach; and ask whose name the domain and hosting sit in at handover. The five questions, and how to check each one →
Is my website still PDPA-compliant after the 2024 amendment?
Only if it has been updated. The Personal Data Protection (Amendment) Act 2024 phased fully into force across 2025. A privacy notice written to the original 2010 baseline no longer reflects the current law, because it will not carry the Data Protection Officer contact, the breach-notification duty, the data-portability right, or the updated data-controller terminology the amendment introduced.
What must a privacy policy include under the amended PDPA?
At minimum, the identity of the data controller, the purposes of collection, a point of contact for the Data Protection Officer where one is required, the data-retention approach, any cross-border transfer of the data, and how individuals can exercise their rights, including the new right to data portability. It should describe genuine opt-in consent rather than pre-ticked boxes.
Do I need to appoint a Data Protection Officer in Malaysia?
The 2024 amendment makes appointing a Data Protection Officer mandatory for data controllers and processors that meet the thresholds set by the Commissioner, under the Guideline on the Appointment of a Data Protection Officer. Where one is required, the DPO should be identifiable and contactable, which usually means naming a contact point on the website.
How quickly must a data breach be reported under the PDPA?
A data controller must notify the Personal Data Protection Commissioner of a personal data breach within 72 hours of becoming aware of it. Affected individuals must be notified without unnecessary delay, and within seven days of notifying the Commissioner where the breach is likely to cause them significant harm.
What is the maximum penalty under the amended PDPA?
The 2024 amendment raised the maximum penalty for breaching a personal data protection principle to a fine of up to RM 1,000,000, imprisonment of up to three years, or both. Failure to meet the breach-notification duty is a separate offence with its own penalty.
Who designs PDPA-compliant websites in Malaysia?
Upcial does, for insurance and takaful brokers, reinsurance brokers, loss adjusters and licensed financial advisers in Malaysia. Every build carries a privacy notice written to the amended Act, consent wording on every form that collects personal data, and a phase 03 compliance review your compliance officer signs before design starts. What we build, and for whom.
A note on what this is
This is a website-practice resource, not legal advice. We build and maintain websites that handle personal data properly; we do not act as your data-protection counsel. The authority here is the Act and the Commissioner's guidelines, published by the Personal Data Protection Department (JPDP) at pdp.gov.my. Read them directly, and where a specific obligation turns on your organisation's size, sector or data, take proper advice. Everything above is our reading of what the amendment means for a website, offered so you know what to look for. For a broader view of what a regulated firm's site should get right, see our 18-point credibility checklist. And if you are an approved insurance or takaful broker, there is a second reason to read your own site closely: Bank Negara's broker conduct rules now count a website as a place where audited accounts may be published, and a signed set of accounts is a document with names in it. See what paragraph 16.1 actually requires.