Who now needs a data protection officer?
As DLA Piper summarises the DPO guideline, an appointment is required where an organisation processes personal data of more than 20,000 data subjects, sensitive personal data (including financial information) of more than 10,000, or carries out regular and systematic monitoring. The DPO must be proficient in both Malay and English, be resident in Malaysia or easily contactable, and the appointment must be notified to the Commissioner within 21 days (DLA Piper).
Any enterprise with a working CRM is likely to cross the first threshold. The practical point is that the DPO needs a view of the systems, not only the policies. Give them read access to the CRM's data model, the list of connected apps and the agents in use. A DPO who cannot see where customer data flows cannot answer the Commissioner's questions.
What does breach notification mean for a CRM team?
The breach notification guideline, again as DLA Piper describes it, expects controllers to notify the Commissioner as soon as practicable and within 72 hours of becoming aware of a breach that causes or is likely to cause significant harm, and affected individuals within seven days. A breach affecting 1,000 or more people is one of the markers of significant harm. Processors must promptly notify the controller, and breach records must be kept for at least two years.
Seventy-two hours is short when the breach is in a system nobody watches. In CRM terms, the common risks are ordinary ones: an over-permissioned user exporting a contact list, an integration key left active after a vendor leaves, a shared inbox forwarded to a personal address. Three controls make the clock manageable.
- Know what is connected. Keep a register of every app, integration and agent with access to customer data, and its owner.
- Least access. Review user permissions and export rights each quarter. Remove leavers on the day they leave.
- A runbook. Write down who decides whether an incident is notifiable, who drafts the notice and who talks to customers. Rehearse it once.
What changes now that processors are regulated?
Since 1 April 2025, processors carry their own security obligation. For a CRM programme, the processors usually include the platform vendor, the implementation partner, messaging providers and any agency handling campaign data. Contracts should say what each one may do with the data, how fast they will report an incident to you and how they will help you meet the 72-hour window. Azend acts as a processor for clients in exactly this way, and we expect clients to ask us these questions.
How should teams prepare for data portability?
Mayer Brown notes that the new right lets a data subject ask for their personal data to be transmitted from one controller to another, “subject to technical feasibility and data format compatibility” (Mayer Brown). Teams should watch for further guidance from the Commissioner on the detail.
Portability is far easier when one customer record exists. If a customer's data is spread across a CRM, a spreadsheet, a WhatsApp phone and a legacy system, a portability request becomes a manual search. A unified record in HubSpot, with clear properties and an export path, turns it into a routine task.
What should AI teams do differently?
AI agents read and write customer data at speed, so they raise the stakes on everything above.
- Treat biometric data with care. Voice and face data used for identification now sits in the sensitive category. Check whether any voice or identity tool you plan to use falls within it.
- Limit what agents can read. Give each agent access to the records and properties its job needs, and nothing more.
- Log what agents do. You cannot report a breach you cannot reconstruct.
- Check transfers. Know where your CRM and AI providers process data. Mayer Brown reports that cross-border transfer guidelines followed on 29 April 2025.
None of this slows AI down. It is the groundwork that lets a leadership team say yes to agents with confidence. Start with the register of connected apps, integrations and agents; every control above depends on it.