Malaysia Issues Three New Data Protection Risk Management Guides

Malaysia’s Personal Data Protection Commissioner (PDPC) has issued three new guidelines aimed at strengthening how organisations identify, assess and manage risks arising from the processing of personal data. The guidance covers Data Protection Impact Assessments (DPIA), Data Protection by Design (DPbD), and Automated Decision-Making and Profiling (ADMP).

The guidelines have been introduced against the backdrop of changes made through Malaysia’s Personal Data Protection (Amendment) Act 2024 and represent a more structured approach to privacy governance under the Personal Data Protection Act 2010. Although the guidelines are not legally binding, Hogan Lovells notes that they provide an important indication of the PDPC’s supervisory expectations and how compliance could be assessed in practice.

The guidance is particularly relevant for organisations using artificial intelligence, automated analytics, profiling and large-scale personal-data processing, where privacy risks can extend beyond conventional cybersecurity concerns to questions of transparency, fairness, individual rights and accountability.

1. Data Protection Impact Assessments

The first guideline establishes a framework for conducting Data Protection Impact Assessments. A DPIA is intended to identify privacy risks associated with a proposed processing activity before those risks materialise and to determine what controls should be introduced to mitigate them.

Responsibility for ensuring that a DPIA is conducted rests with the data controller, with ultimate oversight expected from senior management. The organisation’s Data Protection Officer can support the process by developing assessment templates, identifying when a DPIA is required and advising on appropriate mitigation measures.

Quantitative DPIA Thresholds

The guideline identifies specific processing volumes that can trigger a DPIA. These include:

  • Processing sensitive personal data involving more than 10,000 individuals
  • Processing other categories of personal data involving more than 20,000 individuals

Sensitive information can include data relating to areas such as health, biometrics, religion, political views and criminal matters.

However, volume is not the only trigger. A DPIA may also be expected where processing could significantly affect an individual’s legal rights or status, involves continuous or systematic monitoring, uses new or emerging technology, or involves children and other vulnerable groups.

Five-Step DPIA Process

The PDPC framework sets out a structured five-stage approach:

  • Describe the nature, scope, context and purpose of the processing.
  • Assess whether the processing is lawful, necessary and proportionate.
  • Identify privacy risks and assess their likelihood and severity.
  • Establish controls and mitigation measures.
  • Determine the residual risk remaining after those safeguards are applied.

Following completion, findings should be escalated to senior management, identified controls should be implemented and the DPIA should be kept under review. Hogan Lovells notes that the guideline expects assessments to be reconsidered following significant changes or at least once every two years.

DPIA documentation should also be retained for a minimum of two years after the relevant processing activity ends, supporting regulatory review and demonstrating how privacy risks were considered.

2. Data Protection by Design

The second guideline deals with Data Protection by Design, which seeks to integrate privacy controls into systems, products and business processes from the beginning rather than introducing safeguards only after problems arise.

The guideline identifies four core elements of this approach.

Proactive Risk Management

Organisations should identify foreseeable privacy risks before implementation and build appropriate controls into their governance and system architecture. This can include restricting unnecessary data collection and configuring systems with privacy-friendly defaults.

End-to-End Data Protection

Protection should extend throughout the complete personal-data lifecycle, covering collection, use, storage and eventual deletion rather than concentrating exclusively on system security.

Transparency and Accountability

Organisations should clearly communicate how personal information is processed and maintain sufficient documentation to demonstrate compliance with internal policies and applicable data-protection requirements.

User-Centric Design

Systems and processes should be developed with the interests and rights of data subjects in mind, including mechanisms that provide individuals with meaningful control over how their information is handled.

The guideline also makes clear that Data Protection by Design is not purely an information-technology responsibility. It calls for leadership commitment, shared organisational responsibility and continuous review and improvement, effectively making privacy governance a wider organisational-risk issue.

3. Automated Decision-Making and Profiling

The third guideline addresses Automated Decision-Making and Profiling, a particularly important area as organisations increasingly deploy artificial intelligence, machine learning and other algorithmic systems.

ADMP covers automated processes that use personal data to evaluate individuals, make decisions about them or analyse and predict their behaviour, preferences or characteristics.

The guideline establishes an important connection between AI governance and privacy risk management: before implementing an ADMP activity, organisations must first conduct a DPIA.

This requirement seeks to ensure that privacy and individual-rights risks are assessed before an automated system begins influencing decisions.

Additional Controls for High-Impact Decisions

Stronger safeguards apply where automated decisions are likely to create legal effects or significant and lasting consequences for individuals.

For such applications, organisations are expected to ensure compliance with applicable data-protection requirements, including obtaining explicit consent where necessary, particularly when sensitive personal information is involved.

Organisations should also provide clear written notices explaining automated processing and make these disclosures readily accessible and current.

Importantly, individuals should be provided with straightforward mechanisms to withdraw consent, and organisations should clearly inform them about that right and how it can be exercised.

Important Implications for Banks and Insurers

The guidelines have particular relevance for financial institutions because banks and insurers increasingly use personal data and automated models in activities including:

  • Credit scoring and loan approvals
  • Fraud detection
  • Customer segmentation
  • Transaction monitoring
  • Insurance underwriting
  • Claims assessment
  • Pricing and risk classification
  • Customer behavioural analytics

Where such applications involve profiling or automated decision-making, the new ADMP and DPIA expectations could require organisations to evaluate privacy risks before deployment, strengthen disclosures and establish stronger governance over how automated decisions affect customers.

This is especially important where an algorithm could materially influence whether an individual receives credit, insurance coverage or another financial service. This financial-sector implication follows from the guidelines’ requirements for high-impact automated decisions rather than constituting a separate sector-specific requirement in the guidelines themselves.

Privacy Risk Becomes a Governance Issue

The three guidelines collectively signal a shift towards more preventive and risk-based data governance.

Rather than treating data protection primarily as a legal notice or information-security exercise, organisations are being encouraged to identify risks before implementation, embed safeguards throughout the processing lifecycle, document decisions and maintain senior-management accountability.

The PDPC’s official repository now lists all three guidelines alongside Malaysia’s Personal Data Protection Act, regulations, breach-notification guidance, Data Protection Officer requirements and other privacy frameworks.

For organisations using large-scale analytics, artificial intelligence or customer profiling, the practical message is particularly significant: privacy risk assessment, system design and algorithm governance increasingly need to operate as connected disciplines.

Want to deepen your expertise beyond today’s news?

Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.

Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.

#Riskmanagementnews

author avatar
RMA INDIA

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.