Description

Personal Data Protection Commissioner adopted circular on personal data breach notification (Circular No. 2/2025)

On 21 May 2025, the Malaysian Personal Data Protection Commissioner adopted the circular on personal data breach notification (Circular No. 2/2025). Under the circular, data controllers must notify the Commissioner as soon as practicable upon suspecting a breach and submit detailed information within 72 hours of the incident. If the breach is likely to cause significant harm, affected individuals must also be informed within seven days of the Commissioner being notified, using clear and accessible communication. The circular outlines circumstances that constitute significant harm, including physical injury, financial loss, damage to credit records, the risk of illegal misuse or identity fraud, involvement of sensitive personal data, or breaches affecting more than 1’000 individuals. Notifications must include the circumstances of the breach, the types and volume of data affected, a timeline of events, the potential consequences, the measures taken in response, and contact details for further inquiries. Data controllers are required to keep detailed breach records for a minimum of two years and may be subject to investigation to verify compliance. Non-compliance may result in fines of up to RM 250’000, imprisonment for up to two years, or both.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2024-08-23
in consultation

On 23 August 2024, the Malaysian Department of Personal Data Protection opened a public consultatio…

2024-09-06
processing consultation

On 6 September 2024, the Malaysian Department of Personal Data Protection closed its public consult…

2025-05-21
adopted

On 21 May 2025, the Malaysian Personal Data Protection Commissioner adopted the circular on persona…

2025-06-01
in force

On 1 June 2025, the Personal Data Protection Commissioner’s circular on personal data breach notifi…