An executive with a coffee by an office window, looking out over the city

Malaysia's PDPA amendments, for CRM and AI teams.

What changed, when it took effect, and what to do in the CRM.

Malaysia's Personal Data Protection (Amendment) Act 2024 came into force in three stages between 1 January and 1 June 2025. Its new duties on data protection officers, breach notification, processors and portability all land in the CRM.

By Aaron Goh, CEO, Azend Group · 2 October 2026 · 4 min read

Most CRM and AI teams in Malaysia heard about the PDPA amendments as a legal update. They are also an operating update. Every new obligation in the 2024 amendment touches the systems those teams run: who holds the customer record, how fast a breach can be spotted and reported, and whether a customer's data can be exported cleanly when they ask.

It is operational guidance, not legal advice; confirm your position with Malaysian counsel.

What did the 2024 amendment change, and when?

According to a summary by law firm DFDL, the amendments came into force in three stages.

  • 1 January 2025. Notices and other documents may be served electronically.
  • 1 April 2025. “Data user” became “data controller”. Biometric data joined the definition of sensitive personal data. Data processors became directly regulated under the security principle. The maximum fine rose to RM1,000,000 from RM300,000, and the maximum prison term to three years from two. The old whitelist for cross-border transfers was removed. Data about deceased individuals fell outside the Act.
  • 1 June 2025. Controllers and processors must appoint a data protection officer. Controllers must notify the Commissioner of personal data breaches, and notify affected individuals where the breach is likely to cause significant harm. Data subjects gained a right to data portability.

The Personal Data Protection Commissioner then issued guidelines on appointing a DPO and on data breach notification, both published on pdp.gov.my.

Three stages, six months.

When each change took effect, as summarised by DFDL.

011 JAN 2025Electronic serviceof noticesSTAGE 1 021 APR 2025Data controller termProcessors under securityBiometric data sensitiveHigher penaltiesSTAGE 2 031 JUN 2025Data protection officerBreach notificationData portabilitySTAGE 3 1 JAN 202501Electronic serviceof noticesSTAGE 1 1 APR 202502Data controller termProcessors under securityBiometric data sensitiveHigher penaltiesSTAGE 2 1 JUN 202503Data protection officerBreach notificationData portabilitySTAGE 3

Who now needs a data protection officer?

As DLA Piper summarises the DPO guideline, an appointment is required where an organisation processes personal data of more than 20,000 data subjects, sensitive personal data (including financial information) of more than 10,000, or carries out regular and systematic monitoring. The DPO must be proficient in both Malay and English, be resident in Malaysia or easily contactable, and the appointment must be notified to the Commissioner within 21 days (DLA Piper).

Any enterprise with a working CRM is likely to cross the first threshold. The practical point is that the DPO needs a view of the systems, not only the policies. Give them read access to the CRM's data model, the list of connected apps and the agents in use. A DPO who cannot see where customer data flows cannot answer the Commissioner's questions.

What does breach notification mean for a CRM team?

The breach notification guideline, again as DLA Piper describes it, expects controllers to notify the Commissioner as soon as practicable and within 72 hours of becoming aware of a breach that causes or is likely to cause significant harm, and affected individuals within seven days. A breach affecting 1,000 or more people is one of the markers of significant harm. Processors must promptly notify the controller, and breach records must be kept for at least two years.

Seventy-two hours is short when the breach is in a system nobody watches. In CRM terms, the common risks are ordinary ones: an over-permissioned user exporting a contact list, an integration key left active after a vendor leaves, a shared inbox forwarded to a personal address. Three controls make the clock manageable.

  1. Know what is connected. Keep a register of every app, integration and agent with access to customer data, and its owner.
  2. Least access. Review user permissions and export rights each quarter. Remove leavers on the day they leave.
  3. A runbook. Write down who decides whether an incident is notifiable, who drafts the notice and who talks to customers. Rehearse it once.

What changes now that processors are regulated?

Since 1 April 2025, processors carry their own security obligation. For a CRM programme, the processors usually include the platform vendor, the implementation partner, messaging providers and any agency handling campaign data. Contracts should say what each one may do with the data, how fast they will report an incident to you and how they will help you meet the 72-hour window. Azend acts as a processor for clients in exactly this way, and we expect clients to ask us these questions.

How should teams prepare for data portability?

Mayer Brown notes that the new right lets a data subject ask for their personal data to be transmitted from one controller to another, “subject to technical feasibility and data format compatibility” (Mayer Brown). Teams should watch for further guidance from the Commissioner on the detail.

Portability is far easier when one customer record exists. If a customer's data is spread across a CRM, a spreadsheet, a WhatsApp phone and a legacy system, a portability request becomes a manual search. A unified record in HubSpot, with clear properties and an export path, turns it into a routine task.

What should AI teams do differently?

AI agents read and write customer data at speed, so they raise the stakes on everything above.

  • Treat biometric data with care. Voice and face data used for identification now sits in the sensitive category. Check whether any voice or identity tool you plan to use falls within it.
  • Limit what agents can read. Give each agent access to the records and properties its job needs, and nothing more.
  • Log what agents do. You cannot report a breach you cannot reconstruct.
  • Check transfers. Know where your CRM and AI providers process data. Mayer Brown reports that cross-border transfer guidelines followed on 29 April 2025.

None of this slows AI down. It is the groundwork that lets a leadership team say yes to agents with confidence. Start with the register of connected apps, integrations and agents; every control above depends on it.

Questions.

How fast must a data breach be reported in Malaysia?

Under the Commissioner's guideline, as summarised by DLA Piper, within 72 hours to the Commissioner for breaches likely to cause significant harm, and within seven days to affected individuals.

Does my company need a data protection officer under the PDPA?

The guideline requires one where you process personal data of more than 20,000 people, sensitive data of more than 10,000, or carry out regular and systematic monitoring. Confirm with counsel.

Make compliance part of the build.

A strategy call maps your CRM, integrations and agents against the amended PDPA.