Last reviewed: 3 October 2026
The short version: since 1 June 2025, a business that controls personal data must tell the Personal Data Protection Commissioner within 72 hours of a breach that causes, or is likely to cause, significant harm, or that affects more than 1,000 people. If significant harm is likely, affected individuals must be told within 7 days after that.
It applies to a personal data breach: unauthorised access, loss, misuse or disclosure of personal data you hold, such as customer lists, staff records or payment details. A stolen laptop, a phished email account or a mis-sent spreadsheet can all qualify. The Commissioner's guidelines explain what counts as significant harm and when the 72 hours starts, so read them before an incident, not during one.
Breaching the data protection principles carries fines of up to RM1,000,000 and/or up to three years in prison. A slow, disorganised response also makes the harm to customers and the damage to your reputation worse.
Name one person responsible for personal data and write a one-page breach plan: who decides, who to call, what to record. Whether you need a formal data protection officer depends on thresholds in the Commissioner's guideline, such as personal data of more than 20,000 people or sensitive data (including financial data) of more than 10,000 people.
Take the SME Cyber Readiness Check to see how ready you are.
General information, not legal advice. Reviewed 3 October 2026 against published legal summaries. Check the primary sources from the Department of Personal Data Protection and the National Cyber Security Agency (NACSA), and take advice from a qualified adviser, before relying on this.