Extract of the article (Compoundable Offences for Violations Marks New Regime) . Is your business compliant with the Personal Data Protection Act?

Extract of the article (Compoundable Offences for Violations Marks New Regime). Is your business compliant with the Personal Data Protection Act?

Our associate Jane Tan contributed an article to Data Guidance’s “Data Protection Law & Policy” journal. She explores the effect of the new Personal Data (Compounding of Offences) Regulations 2016 which came into force on 15 March 2016.

Businesses which have yet to comply with the requirements of Malaysia’s personal data protection legislation are strongly advised to do so as the implementation of the new compouding regulations could signal the start of enforcement proceedings. Fines under the Personal Data Protection Act can go up to RM500,000 or imprisonment of up to 3 years, or both.

Whilst business organisations may welcome the enforcement of the Compounding Regulations as penalties may be reduced and prosecution may not be instituted, its coming into force indicates that the Commissioner may start enforcement against offenders. Whilst the [Personal Data Protection Act, or PDPA] has been in force in Malaysia since 2013, there has been no known prosecution instituted against a data user for a breach of the PDPA to date, but the Compounding Regulations may signal a change in times to come. This also means that business organisations should quickly comply with the Personal Data Protection Standards 2015 (‘the PDP Standards’), which came into force on 23 December 2015, given that an offence of the PDP Standards is also compoundable.

The PDP Standards set out many specific measures to be implemented by a data user in relation to security, retention and integrity of personal data and it would certainly require time and proper planning in order to comply with the PDP Standards.

You can read the full article at the Data Protection Law & Policy journal (May 2016 issue). The full article will be republished on our blog next month.

 

You've Been Served!
Personal Data Protection Act - PDPA Compliance Case Study

Latest Articles

Guideline on Data Breach Notification 2025 (“Guideline”)

by | February 3, 2026 |

Case Spotlight: Poor Performers Are Not Entitled to Termination Benefits Case Spotlight: Is a Domestic Inquiry Necessary When the Employee Admits to the Misconduct?

New Guideline on Online Healthcare Services

by | January 23, 2026 |

Case Spotlight: Is a Domestic Inquiry Necessary When the Employee Admits to the Misconduct? While All Illegal Agreements Are Void, Not All Void Agreements […]

While All Illegal Agreements Are Void, Not All Void Agreements Are Illegal

by | January 22, 2026 |

New Guideline on Online Healthcare Services Overlapping Public Holidays for Federal Territory Day and Thaipusam (1 February 2026)

Share This