PDPA Amendments 2025: Do You Need a Data Protection Officer (DPO)?

- 18 February 2026
- Technology
Key Takeaways
- Mandatory DPO Appointment: Effective June 1, 2025, businesses meeting specific data volume thresholds must appoint a Data Protection Officer.
- 72-Hour Breach Rule: You must notify the PDP Commissioner within 72 hours of discovering a breach that causes “significant harm.”
- RM1 Million Fines: Maximum penalties for non-compliance have more than tripled from RM300,000 to RM1 million.
- Biometric Data Update: Facial recognition and fingerprint data are now officially classified as “Sensitive Personal Data.”
- Data Processor Liability: Vendors (like your payroll or cloud provider) are now directly liable for security, not just the business owner.
Does Your Malaysian SME Need a Data Protection Officer Under the 2025 PDPA Amendments?
Yes, if your business processes personal data for over 20,000 individuals, handles sensitive data (like health records) for over 10,000 people, or performs “systematic monitoring” of user behavior. While many micro-SMEs might be exempt from the mandatory appointment, the increased fines mean having a designated compliance lead is no longer optional—it’s survival.
If you think “I’m just a small business, hackers won’t bother with me,” you’re missing the point. The danger isn’t just hackers anymore—it’s the law. With the Personal Data Protection (Amendment) Act 2024 now in force, a simple mistake like cc’ing the wrong email list could cost you RM1 million.
This guide breaks down the new “72-hour rule,” the specific thresholds for hiring a DPO, and why your old privacy policy is likely illegal.
🚨 The 72-Hour Rule: Mandatory Breach Notification
Previously, if you lost customer data, you could (quietly) fix it and move on. That era is over.
Under the new amendments, you are legally required to notify the Personal Data Protection Commissioner (PDP) within 72 hours of becoming aware of a data breach.
When is Notification Mandatory?
You must report a breach if it is likely to cause “Significant Harm” to the individuals involved. “Significant Harm” includes:
- Identity Theft Risk: Leaking MyKad numbers, credit card info, or passwords.
- Financial Loss: Direct theft or fraud potential.
- Sensitive Data: Leaking health records, religious beliefs, or biometric data (fingerprints/FaceID).
- Scale: If the breach affects more than 1,000 people.
Warning: If the breach causes significant harm, you must also notify the affected customers “without unnecessary delay.” Hiding it is now a crime.
💰 RM1 Million Fines: The New Cost of Mistakes
The government isn’t playing games with digital trust anymore. The penalties for failing to protect user data have skyrocketed.
Violation | Old Penalty (PDPA 2010) | New Penalty (PDPA Amendment 2024) |
Breach of Data Principles | Max RM300,000 | Max RM1,000,000 |
Jail Term | Max 2 Years | Max 3 Years |
Data Processor Liability | None (Data User liable) | Direct Liability for IT Vendors |
What this means for you: If you outsource your IT to a cheap vendor who leaves your server unlocked, both you and the vendor can be fined RM1 million.
Find Verified Partners: Need compliant vendors? Listing.my as a Business Directory connects you with verified Malaysian experts, from IT to legal, ready to secure your business. Find your partner today.
✅ Checklist: Do You Need to Hire a DPO?
Starting June 1, 2025, the appointment of a Data Protection Officer (DPO) becomes mandatory for specific categories of businesses. The DPO does not have to be a new full-time hire; it can be an existing employee or an outsourced agency, but they must be registered with the PDP Department.
The “Must-Hire” Thresholds
You MUST appoint a DPO if you meet ANY of these criteria:
- Mass Data Processing: You process personal data of more than 20,000 data subjects (customers/staff) per year.
- Sensitive Data Processing: You process “sensitive” personal data (medical records, biometrics, political views) of more than 10,000 data subjects.
- Systematic Monitoring: Your core activity involves tracking user behavior online (e.g., e-commerce profiling, behavioral advertising, GPS tracking).
Who Else Should Appoint One?
Even if you don’t hit the 20,000 number, if you are in a high-risk sector (like finance, healthcare, or education), appointing a DPO is the best defense against the new liability rules.
🛡️ What Actually Changes for Your IT Team?
Compliance isn’t just paperwork; it requires technical changes to your IT infrastructure.
1. Biometrics are Now “Sensitive”
Do you use a fingerprint scanner or FaceID for staff attendance? That is now classified as “Sensitive Personal Data.” You need explicit, written consent from every employee to collect this, and it must be stored with higher encryption standards than regular data.
2. The “Data Processor” Shift
If you use a cloud HR system or a third-party marketing agency, you must review your contracts. The new law holds Data Processors directly accountable.
- Action Item: Ask your vendors: “Are you compliant with the PDPA 2024 Amendment? Send me your updated data handling policy.”
3. Data Disposal is Critical
You can’t just throw old hard drives in the bin. The law requires you to ensure data is permanently deleted once it’s no longer needed.