Malaysia: Personal Data Protection Department adopted the circular on Data Protection Officer appointment (Circular No. 1/2025)

Description

Personal Data Protection Department adopted the circular on Data Protection Officer appointment (Circular No. 1/2025)

On 21 May 2025, the Department of Personal Data Protection (PDP) issued a circular on appointing Data Protection Officers (DPOs). The circular implements the amended Personal Data Protection Act by requiring organisations that process large volumes of personal data to appoint qualified DPOs. The DPO appointments are required if an organisation processes personal data of over 20’000 individuals, handles sensitive data (such as financial information) for more than 10'000 individuals, or conducts systematic monitoring. The DPO must be a Malaysian resident, physically present in the country for at least 180 days a year, and fluent in both Malay and English. DPOs are responsible for overseeing compliance, conducting impact assessments, and managing data breaches. They must have relevant legal and technical knowledge, understand business operations, uphold ethical standards, and promote a data protection culture.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection authority governance
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2024-08-23
in consultation

On 23 August 2024, the Malaysian Department of Personal Data Protection opened a public consultatio…

2024-09-06
processing consultation

On 6 September 2024, the Malaysian Department of Personal Data Protection closed its public consult…

2025-05-21
adopted

On 21 May 2025, the Department of Personal Data Protection (PDP) issued a circular on appointing Da…

2025-06-01
in force

On 1 June 2025, the Personal Data Protection Department's circular on Data Protection Officer appoi…