Back to guides

PDPA breach notification: what a Malaysian SME must do in 72 hours

Last reviewed: 3 October 2026

The short version: since 1 June 2025, a business that controls personal data must tell the Personal Data Protection Commissioner within 72 hours of a breach that causes, or is likely to cause, significant harm, or that affects more than 1,000 people. If significant harm is likely, affected individuals must be told within 7 days after that.

When does the rule apply?

It applies to a personal data breach: unauthorised access, loss, misuse or disclosure of personal data you hold, such as customer lists, staff records or payment details. A stolen laptop, a phished email account or a mis-sent spreadsheet can all qualify. The Commissioner's guidelines explain what counts as significant harm and when the 72 hours starts, so read them before an incident, not during one.

What to do, in order

  1. Contain it. Change passwords, cut off access, isolate affected devices, and stop further loss.
  2. Write everything down. Record what happened, when you found out, what data is involved and how many people. You will need this for the report.
  3. Decide if you must report. Is significant harm likely, or are more than 1,000 people affected? If yes, you must notify the Commissioner.
  4. Notify within 72 hours. Use the Commissioner's notification channel and keep proof you sent it.
  5. Tell affected people within 7 days after notifying the Commissioner, where significant harm is likely. Say what happened, what data is involved, and what they should do to protect themselves.
  6. Fix the cause and keep records of your decisions, including why you decided not to report if you did not.

What is at stake

Breaching the data protection principles carries fines of up to RM1,000,000 and/or up to three years in prison. A slow, disorganised response also makes the harm to customers and the damage to your reputation worse.

Get ready now

Name one person responsible for personal data and write a one-page breach plan: who decides, who to call, what to record. Whether you need a formal data protection officer depends on thresholds in the Commissioner's guideline, such as personal data of more than 20,000 people or sensitive data (including financial data) of more than 10,000 people.

Take the SME Cyber Readiness Check to see how ready you are.

General information, not legal advice. Reviewed 3 October 2026 against published legal summaries. Check the primary sources from the Department of Personal Data Protection and the National Cyber Security Agency (NACSA), and take advice from a qualified adviser, before relying on this.

Guides   About   Privacy Policy   Contact   Terms of use