Your Data Was Leaked: When a Malaysian Company Must Tell You Under the PDPA

About this guide: The current legal framework is explained here in general. Small factual differences, documents and timing can change the answer in a real case.
Since 1 June 2025, a Malaysian data controller covered by the Personal Data Protection Act 2010 must assess a personal-data breach and notify the Commissioner when it causes or is likely to cause significant harm. The official guideline requires notification as soon as practicable within 72 hours. If significant harm to affected individuals is likely, the controller must also tell them without unnecessary delay and no later than seven days after notifying the Commissioner. Sensitive data, financial or identity-fraud risk, unlawful misuse and physical or property harm can trigger the threshold even below 1,000 people. Preserve the notice, secure affected accounts and complain to the organisation or Commissioner where needed.
Why this matters
Malaysia’s mandatory data-breach notification regime has now been operating for more than a year. Section 12B of the amended Personal Data Protection Act 2010, the Commissioner’s Circular No. 2 of 2025 and the detailed breach guideline took effect on 1 June 2025. In a 30 July 2026 review, Shearn Delamore noted that this was the first anniversary of the new obligation and said it had not identified publicly reported prosecutions or clear public investigative trends under section 12B. That observation is not an official enforcement clearance and does not reduce the duty.
The official rule is risk-based, not headline-based. The Commissioner’s guideline says not every personal-data breach must be reported. A covered data controller must notify the Commissioner when the breach causes or is likely to cause ‘significant harm’. The test includes risks of physical injury, financial loss, adverse credit effects, property damage, unlawful misuse, sensitive personal data, combinations that could enable identity fraud, or a significant scale of more than 1,000 affected data subjects.
Personal notice has a related but not identical trigger. If the breach causes or is likely to cause significant harm to an individual, the controller must tell that affected person even if the incident does not exceed 1,000 people. The 1,000-person scale criterion is not used by itself to decide individual notice. A leak of one person’s medical or financial data may therefore matter more than a much larger exposure of information that remains unusable because effective safeguards protected it.
What the law says
The timing is specific. For a notifiable breach, the controller must notify the Personal Data Protection Commissioner as soon as practicable within 72 hours. The guideline explains when that clock begins through examples: when a reported unencrypted device loss reaches the controller, when an accidental disclosure is realised, or when an investigation confirms that a system was actually compromised. If the initial filing is late, reasons and supporting evidence are required. Missing details may be supplied in stages as soon as practicable and within the permitted follow-up period; delay should not become an excuse to wait for a perfect forensic report.
Affected people must be notified without unnecessary delay and no later than seven days after the controller notifies the Commissioner when significant harm to them is likely. The communication should be direct and understandable and state what happened, likely consequences, mitigation taken or proposed, steps the person can take, and a data-protection officer or other contact. Public communication may be used where individual notice is impracticable or disproportionate, but the official guideline expects the breach message to be clear and separate from routine newsletters or promotions.
Do not turn the thresholds into shortcuts. More than 1,000 affected people makes a breach significant in scale for Commissioner notification, but fewer than 1,000 can still be notifiable because of sensitive data, financial loss, unlawful use, identity fraud or another listed harm. Conversely, ‘the hacker reached our server’ does not establish that every file was readable. The guideline gives an example where strong safeguards made data unintelligible; the Commissioner was still notified in that scenario, but individual notice was not required on the stated facts.
The PDPA’s scope also matters. The Commissioner’s FAQ says the Act protects personal data processed for commercial transactions and exempts the Federal and State Governments. It identifies rights including access, correction, withdrawal of consent in relevant circumstances, prevention of damaging or distressing processing and prevention of direct marketing. It also says the Act does not specifically create a right to damages. A regulatory complaint may therefore address compliance without automatically producing compensation, and a government-agency incident may require a different official complaint route.
How does this impact me?
If you receive a breach notice, first verify it independently. Do not follow a login link in an unexpected email or message. Open the organisation’s official app or type its known website, then confirm the notice through the published contact. Genuine breach news is often copied by phishers. Save the original notice with full headers or screenshots and note when you received it, what data it says was affected and which account or service it concerns.
Match the response to the exposed data. Change the affected password and every reused password, enable multi-factor authentication, end unknown sessions and replace compromised recovery details. For bank, card or e-wallet data, contact the institution through its official channel, review transactions and activate available alerts or restrictions. For MyKad, passport, medical, biometric or address data, be alert to targeted impersonation; a password change cannot retrieve an immutable identifier, so monitoring and strong verification become more important.
Ask the organisation focused questions in writing: what categories of your data were involved, when the breach was detected, whether the data was readable, what systems and third parties were involved, what it has contained, what misuse is reasonably possible and which contact handles correction, access or complaints. The organisation may not be able to disclose security details that create further risk, but a vague ‘we value your privacy’ message is not a substitute for the items the official guideline expects in an individual notice.
If the organisation does not respond adequately or you believe commercial personal data was processed contrary to the PDPA, the Commissioner’s FAQ says you may complain to the Personal Data Protection Commissioner. Use the official complaint portal rather than the DBN form intended for controllers, attach the notice and correspondence, and describe the data, harm and remedy sought factually. For actual unauthorised transactions, identity misuse or threats, report promptly to the relevant bank, platform or enforcement body as well; a PDPA complaint is not an emergency fraud freeze.
Key lessons
The first lesson is that notification is a safety intervention, not merely an admission of fault. A timely, intelligible warning lets a person change credentials, watch an account or resist targeted impersonation. Controllers should not delay a useful notice merely to produce polished public relations, and readers should not treat a notice itself as proof that every exposed record has already been abused.
The second lesson is that impact outranks raw headcount. One sensitive medical file or a package of identity and financial data can create significant harm below 1,000 people. Headcount becomes an additional Commissioner-notification trigger when it exceeds 1,000; it does not erase the content-based risks or decide individual notice by itself.
The third lesson is to separate regulatory rights from compensation. The Commissioner can receive complaints and investigate compliance, but the official FAQ says the PDPA does not specifically provide a damages claim. Anyone facing measurable financial or professional loss should preserve proof and obtain individual advice about other possible contractual, negligence, consumer, employment or criminal-law routes and their deadlines.
Bottom line
Malaysia’s breach rules now impose a real timetable, but not every cyber incident produces the same notice. A covered controller assesses significant harm, reports a notifiable breach to the Commissioner within 72 hours and, where affected people face significant harm, warns them no later than seven days after the Commissioner filing. Readers should verify the notice, secure the exposed accounts, preserve evidence and use the proper complaint or fraud channel without assuming that notification guarantees compensation.
What can I do if this happens to me?
- Verify the notice through the organisation’s independently located official website, app or phone number; do not sign in through a link in the breach message.
- Save the original notice and record when it arrived, the affected service, the data categories identified, the contact person and every follow-up response.
- Change the affected and reused passwords, enable multi-factor authentication, end unknown sessions and secure email or phone recovery methods.
- Contact banks, card issuers, e-wallets or platforms immediately for exposed credentials, unauthorised transactions or account takeover; use official fraud channels and preserve reference numbers.
- Ask the controller targeted written questions and, if the response remains inadequate, use the Personal Data Protection Commissioner’s official complaint portal with the evidence.
FAQ
Must a Malaysian company tell me about every data breach?
No. The official guideline makes individual notice depend on whether the breach causes or is likely to cause significant harm to you. Sensitive data, financial or identity-fraud risk, unlawful misuse and physical or property harm are important. The fact that fewer than 1,000 people were affected does not prevent individual notice where your own harm threshold is met.
Do the 72 hours run from the cyberattack or from discovery?
The official guideline says notification is due as soon as practicable within 72 hours and gives event-specific starting examples. The clock can begin when an unencrypted device loss is reported, an accidental disclosure is realised, or investigation confirms that a system was compromised. The exact start depends on how the breach became known; a controller should document it rather than wait for a perfect investigation.
Does a leak affecting more than 1,000 people always require personal notice?
More than 1,000 affected data subjects is ‘significant scale’ for deciding Commissioner notification. The guideline expressly says that scale criterion does not by itself apply when deciding notice to each affected person. Personal notice turns on significant harm to that person, although the nature and readability of the exposed data may make such harm likely.
Can I claim compensation under the PDPA for leaked data?
The Commissioner’s official FAQ says the PDPA does not specifically provide a right to claim damages. You may still make a regulatory complaint where covered personal data was processed contrary to the Act. Actual loss may raise other legal routes depending on the facts, relationship and proof, so preserve documents and obtain advice rather than assuming a breach notice creates an automatic payout.
Where should an individual report a suspected PDPA breach?
An individual complaint should use the Personal Data Protection Commissioner’s official complaint route shown on the Commissioner’s website. The separate DBN form is presented for data controllers reporting a breach. Also contact the relevant bank, platform or enforcement body immediately for fraud, account takeover, threats or active loss; the PDPA complaint process is not a substitute for urgent containment.
This article is general legal information, not legal advice, and reading it does not create a lawyer–client relationship.
This article provides general Malaysian personal-data information verified on 15 August 2026. It is not legal, cybersecurity, banking or identity-restoration advice and does not determine whether a particular incident is a notifiable breach, whether the PDPA covers a controller, whether safeguards made data unreadable, or whether compensation is available. Government bodies, commercial controllers, processors and sector regulators may follow different rules. Use independently verified official contacts, respond urgently to active fraud, preserve evidence and obtain individual advice for substantial loss or disputed rights.
Spot something outdated or wrong? Tell us — we’ll verify and correct it.
Key sources (4) — how this was verified
- Personal Data Protection Commissioner Malaysia, 2025-05-21, “Personal Data Protection Guideline: Data Breach Notification” — Official primary guidance on the significant-harm and more-than-1,000-person thresholds, 72-hour Commissioner timetable, seven-day individual-notice timetable, examples, required notice contents and governance process effective from 1 June 2025.: https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/02/GARIS-PANDUAN-PERLINDUNGAN-DATA-PERIBADI_-PEMBERITAHUAN-PELANGGARAN-DATA.pdf
- Shearn Delamore & Co, 2026-07-30, “Cyber Breach Update: One Year On, What Have We Learnt?” — Current independent one-year review of section 12B’s mandatory regime and the authors’ qualified observation that they had not identified publicly reported prosecutions or clear public investigative trends, without treating that as absence of the legal duty.: https://www.shearndelamore.com/whats-new/alerts/cyber-breach-update-july-2026
- Mayer Brown, 2025-07-25, “From Legislative Reform to Practical Guidance: Key Amendments to Malaysia’s PDPA and the Launch of Cross-Border Transfer Guidelines” — Independent legal context on the phased commencement, section 12B’s Commissioner and affected-person notification duties, new breach definition and wider 2024 amendment framework.: https://www.mayerbrown.com/en/insights/publications/2025/07/from-legislative-reform-to-practical-guidance-key-amendments-to-malaysias-pdpa-and-the-launch-of-cross-border-transfer-guidelines
- Personal Data Protection Commissioner Malaysia, 2026-08-15, “Frequently Asked Questions” — Official current explanation of the PDPA’s commercial-transaction scope, government exemptions, data-subject rights, complaint route and statement that the Act does not specifically provide a damages claim.: https://www.pdp.gov.my/ppdpv1/en/faq/