AskLegal.my

Can You Ask a Malaysian Business to Show and Correct Your Personal Data?

8 min read · Published · Verified

A hand in a white sleeve holding a smartphone with a blank white screen against a soft pink and blue gradient background

Yes, if Malaysia's Personal Data Protection Act 2010 applies. The Personal Data Protection Commissioner's current FAQ identifies rights to be told whether an organisation processes your data, to access your personal data and to correct it. The Act focuses on personal data processed for commercial transactions and does not apply to the Federal or State Governments. Ask the responsible business, now called the data controller, in writing and describe the account, data and correction precisely. Access is not the same as a right to every internal document, deletion on demand or compensation.

Six-part request template

Send a focused personal-data access or correction request

  1. Identify yourself safely: give enough verified account information for the business to find the right record without emailing unnecessary identity documents.
  2. Name the controller: address the company that decides why and how the data is processed, not only its app vendor or call-centre contractor.
  3. Define the data: state the account, transaction, camera location, date range or personal-data category you want accessed or checked.
  4. State the remedy: say whether you want confirmation of processing, access to your data, or correction of a specific inaccurate field.
  5. Attach correction proof: provide the reliable document that shows the present entry is inaccurate, while masking unrelated private information where sensible.
  6. Keep the trail: save the privacy notice, request, delivery proof, identity-check messages, response and any complaint reference.

Why this matters

The problem usually appears in an ordinary account rather than a dramatic leak. A delivery address is wrong, a loyalty profile contains an unfamiliar telephone number, a finance application records the wrong employment detail, or a shop's CCTV may show an incident involving you. Customer service may answer the immediate problem without explaining what personal data the organisation holds or whether its record has actually been corrected.

A useful request is narrower than “send me everything you have”. It identifies the person, account or event, describes the personal data sought and says whether the reader wants access or correction. This helps the organisation find the record, protect another person's information and distinguish a data-rights request from a billing dispute, refund request or demand for legal disclosure.

The official FAQ says the PDPA protects personal information processed for commercial transactions. Personal data is information that can identify a living individual. Its examples include names and addresses, identification and passport numbers, health information, email addresses, pictures, CCTV images and information in personal files. The context matters: not every record in Malaysia falls within this Act.

The same FAQ lists three connected rights: to be informed whether an organisation is processing your data, to access personal data and to correct personal data. Access lets you ask about your own data. Correction targets an inaccurate record. Neither right should be casually described as a universal right to erase truthful records, rewrite an opinion, obtain another person's data or inspect every internal business document.

The responsible organisation is called the data controller. Act A1727 replaced the older expressions “data user” and “data users” throughout most of the principal Act with “data controller” and “data controllers”. In practical terms, direct the request to the business that controls the processing. A contractor operating software or a call centre may only process the data for that business and may not be the right decision-maker.

Scope can change the answer. The Commissioner's FAQ says the Federal and State Governments are exempt from the PDPA. A request about a government registry, licence or public-agency file may therefore need the agency's own correction, review or access process. Do not cite the commercial-data regime as if it automatically binds every public authority.

Access also has to coexist with identity and third-party protection. A controller may need to verify that the requester is the data subject and consider whether a record contains information about other people. A CCTV request, for example, should identify the camera area, date and short time range. Asking for a focused copy or explanation is more workable than demanding a whole day's raw footage that may show many unrelated people.

If a person believes personal data has been processed contrary to the Act, the official FAQ says a complaint may be made to the Personal Data Protection Commissioner. The SPDP portal provides an online complaint form and issues a reference after submission. The FAQ also says the Act does not specifically provide a right to claim damages, so a regulatory complaint should not be presented as a guaranteed compensation claim.

How does this impact me?

Example — wrong customer profile: Siti logs into a retailer's account and sees an old address and an unfamiliar phone number. She writes to the retailer, identifies the account, lists the two fields and attaches suitable proof for the correct address. She asks for confirmation that the profile has been corrected. She does not send a full unmasked identity document unless the verified channel reasonably requires it.

Example — CCTV after a shop accident: Daniel believes a store camera recorded him slipping near an entrance. He immediately asks the store to preserve the relevant footage and separately makes a focused access request identifying himself, the location and a short time range. The PDPA question concerns his personal data; evidence preservation and any injury claim are separate issues with their own urgency and proof.

Example — automated rejection: A customer suspects an application was rejected because a personal detail is wrong. An access request may help identify personal data used, while a correction request can target an inaccurate field. It does not automatically reveal confidential software, another person's information or every reason behind a commercial decision, and it does not guarantee that correcting one fact changes the outcome.

Example — government record: Priya finds an error in a State Government record. Because the official FAQ says Federal and State Governments are exempt from the PDPA, she should use that agency's correction or review procedure rather than assume an SPDP complaint creates the same access right. The applicable legislation and route depend on the record.

Key lessons

The first lesson is to ask for data, not a mystery. A controller can respond more accurately when the request names the account, field, transaction, camera, date range or communication. A broad demand may mix personal data with legal discovery, customer-service records, security material and information about other people.

The second lesson is to separate access, correction and deletion. Access asks what personal data is processed. Correction addresses inaccuracy. Withdrawal of consent and prevention of certain processing are separate rights identified by the official FAQ, with their own limits. None should be advertised as an automatic right to make every lawful record disappear.

The third lesson is safe verification. A genuine controller may need proof before releasing personal data, but scammers also imitate privacy teams. Start from the business's official site or app, verify the address independently, ask what minimum proof is required and avoid sending identity documents through a link supplied only in an unexpected message.

Bottom line

Malaysia's PDPA gives a covered data subject practical rights to ask whether a business processes personal data, access that data and seek correction of inaccuracies. The strongest request is written, specific and sent to the verified data controller with proportionate identity proof. Keep access, correction, deletion, evidence disclosure and compensation as separate questions. If a covered business does not address an apparent breach, preserve the correspondence and use the Commissioner's official complaint route.

Detailed steps

  • Save the business's current privacy notice and identify the legal company or organisation that appears to control the account or service.
  • Write a focused request stating who you are, the relevant account or event, the data category and whether you seek confirmation, access or correction.
  • For a correction, quote the existing entry, state the accurate replacement and attach reliable proof with unrelated details masked where appropriate.
  • Use a contact channel independently obtained from the official website or app and ask what minimum identity verification is reasonably required.
  • Keep the complete request, attachments, delivery proof, replies and dates; do not rely only on a telephone promise that the record was fixed.
  • If you believe a covered controller processed the data contrary to the Act, organise the evidence and use the official SPDP complaint form or obtain Malaysian privacy advice.

FAQ

Can I demand every document that mentions my name?

Not necessarily. The official right concerns your personal data, not automatic inspection of every complete document or another person's information. Define the data and context you need. A contract dispute, court disclosure request or regulatory investigation may use different rules and should not be collapsed into a PDPA access request.

Can I force a company to delete accurate records?

Access and correction do not amount to a universal deletion right. Correction addresses inaccurate personal data. Retention duties, a continuing transaction, legal claims and other lawful purposes may affect whether accurate information can be kept. Ask the controller to explain its basis and obtain advice on the specific processing if it remains disputed.

Can I ask a shop for CCTV footage showing me?

The Commissioner's FAQ identifies CCTV images as capable of being personal data, so an access request may be relevant. Give the precise place, date and short time range. The controller may need to verify you and protect other people shown. Preserve evidence quickly, but do not assume the PDPA guarantees release of an unedited full recording.

Does the PDPA access right apply to government records?

The Commissioner's current FAQ says the Federal and State Governments are exempt from the PDPA. A government record may have another statutory, administrative or review process. Contact the responsible agency and check the rules for that record instead of assuming the commercial-data complaint route applies.

Will an SPDP complaint get me compensation?

Do not assume so. The Commissioner's FAQ says the PDPA does not specifically provide a right to claim damages. The official portal is a route to submit a regulatory complaint for review. Any separate claim for loss or another remedy depends on its own legal basis, evidence and facts.

This article is general legal information, not legal advice, and reading it does not create a lawyer–client relationship.

This guide explains general access and correction rights under Malaysia's personal-data framework, checked on 26 September 2026. It does not decide whether the PDPA covers a particular organisation, record or processing activity, what identity proof is proportionate, whether a controller must provide a particular document or CCTV copy, or whether deletion, compensation or another remedy is available. Federal and State Governments are exempt according to the Commissioner's FAQ, and sector rules may also apply. Obtain specific Malaysian advice for sensitive records, substantial loss, litigation or an urgent evidence-preservation issue.

Spot something outdated or wrong? Tell us — we’ll verify and correct it.

Key sources (3) — how this was verified
  • Personal Data Protection Commissioner Malaysia, 2026-09-26, “Frequently Asked Questions” — Current official explanation of the PDPA's commercial-transaction scope, government exemptions, examples of personal data, access and correction rights, complaint route and absence of a specific statutory damages right.: https://www.pdp.gov.my/ppdpv1/en/faq/
  • Attorney General's Chambers of Malaysia, 2024-10-17, “Personal Data Protection (Amendment) Act 2024 (Act A1727)” — Primary amending Act supporting the current data-controller terminology, continued statutory recognition of data access and correction requests, the living-person definition of data subject and the 2024 reform context.: https://lom.agc.gov.my/ilims/upload/portal/akta/outputaktap/2430673_BI/Act%20A1727.pdf
  • Personal Data Protection Commissioner Malaysia, 2026-09-26, “SPDP Personal Data Protection Complaint Form” — Current official online complaint endpoint showing the SPDP complaint submission route, complaint review status and issuance of a complaint reference and email notification after submission.: https://daftar.pdp.gov.my/p_aduan