[{"data":1,"prerenderedAt":481},["ShallowReactive",2],{"guide-pdpa-dpo-requirement-meta-advertisers-malaysia":3},{"id":4,"title":5,"answer":6,"authorId":7,"body":8,"category":378,"ctaVariant":379,"dataset":378,"description":380,"examples":381,"extension":382,"faqs":383,"heroImage":408,"intro":409,"meta":410,"navigation":411,"path":412,"publishedAt":413,"seo":414,"sources":415,"stats":446,"stem":479,"updatedAt":413,"__hash__":480},"blog\u002Fblog\u002Fpdpa-dpo-requirement-meta-advertisers-malaysia.md","Do Malaysian Advertisers Need a DPO?","Section 12A of Malaysia's Personal Data Protection Act 2010, in force since 1 June 2025, requires a data controller to appoint one or more data protection officers and to notify the Commissioner. The Act sets no size threshold; Circular of the Personal Data Protection Commissioner No. 1\u002F2025 does, making appointment mandatory where processing involves personal data of more than 20,000 data subjects, or sensitive personal data including financial information of more than 10,000 data subjects, or activities requiring regular and systematic monitoring. The Commissioner's DPO Guideline states that tracking and profiling data subjects online or offline for the purposes of behavioural advertising counts as regular and systematic monitoring, so the third limb can catch a business running retargeting regardless of how short its customer list is. An appointment must be registered with the Commissioner within 21 days.","likit-sae-lee",{"type":9,"value":10,"toc":361},"minimark",[11,16,20,23,26,30,33,36,39,42,45,49,52,108,111,115,118,168,171,174,177,181,184,190,193,196,205,209,212,224,230,236,247,251,254,265,268,271,274,278,281,284,288,291,294,297,300,303,306,310,313,316,319,322,326,329,332,335,339,342,345,348,351,355,358],[12,13,15],"h2",{"id":14},"the-short-version","The short version",[17,18,19],"p",{},"Malaysia has had a statutory data protection officer duty since 1 June 2025. Section 12A of the Personal Data Protection Act 2010, inserted by section 6 of the Personal Data Protection (Amendment) Act 2024, requires a data controller to appoint one or more data protection officers who are accountable to it for compliance with the Act, and separately requires a data processor to appoint one or more officers accountable to it. The section imposes no size test at all.",[17,21,22],{},"The size tests sit one level down, in Circular of the Personal Data Protection Commissioner No. 1\u002F2025, and there are three of them joined by \"or\". Appointment is mandatory where the processing involves personal data of more than 20,000 data subjects, or sensitive personal data including financial information of more than 10,000 data subjects, or activities requiring regular and systematic monitoring.",[17,24,25],{},"That third limb is the one advertisers keep missing. The Commissioner's DPO Guideline says, in terms, that \"Any form of activity where data subjects are tracked and profiled online or offline for purposes of behavioural advertising will be considered as activities which require regular and systematic monitoring.\" If you fire a pixel, build audiences out of the events it records, and serve ads back to the people in them, that sentence describes what you do. The duty can therefore bite on the nature of the activity, not only on the volume of records, and a business with a customer list far short of 20,000 can still be caught.",[12,27,29],{"id":28},"what-section-12a-actually-says","What section 12A actually says",[17,31,32],{},"Take the statute first, because the circular hangs off it and reads oddly on its own.",[17,34,35],{},"Section 12A came into operation on 1 June 2025, the third of the three commencement tranches set by gazette notification P.U. (B) 522. Its four subsections do four separate things. Subsection (1) obliges a data controller to appoint one or more data protection officers, accountable to the data controller for compliance with the Act. Subsection (2) puts the same obligation on a data processor processing personal data on a controller's behalf, with the officer accountable to the processor. Subsection (3) requires the data controller to notify the Commissioner of the appointment in the manner and form the Commissioner determines. Subsection (4) provides that the appointment \"shall not discharge the data controller or data processor from all duties and functions under this Act.\"",[17,37,38],{},"Two features of that drafting are worth carrying around. The first is that nothing in section 12A is conditional on volume, sector or turnover. Read alone, it is an unqualified duty on every data controller. The second is the asymmetry between subsections (2) and (3): processors must appoint, but the express notification duty is drafted as falling on the controller. That asymmetry is in the Act as passed and you can safely observe it, though a firm that processes for clients and also holds personal data on its own account is likely to be a controller for that second set of data, and so inside subsection (3) for it.",[17,40,41],{},"A third feature is what section 12A leaves out. Its four subsections create a duty, a notification requirement and a non-discharge rule, and none of them is a penalty provision. Contrast section 12B, inserted by the same section of the amending Act, which does carry an express offence for failing to notify the Commissioner of a breach. We could not confirm a penalty attached specifically to a failure to appoint a data protection officer, so do not repeat a figure you have seen quoted for it without checking the current text yourself.",[17,43,44],{},"The practical upshot is that when someone says \"the PDPA sets a 20,000 threshold\", they are wrong about where the number comes from. The Act does not set it. The Commissioner's circular does. That distinction survives contact with a regulator's question in a way that a vague recollection of the number does not.",[12,46,48],{"id":47},"three-kinds-of-document-three-kinds-of-weight","Three kinds of document, three kinds of weight",[17,50,51],{},"Almost everything useful in this area sits below the Act, so it pays to keep the tiers straight before you quote anything into a policy.",[53,54,55,71],"table",{},[56,57,58],"thead",{},[59,60,61,65,68],"tr",{},[62,63,64],"th",{},"Document",[62,66,67],{},"What it is",[62,69,70],{},"How to treat it",[72,73,74,86,97],"tbody",{},[59,75,76,80,83],{},[77,78,79],"td",{},"Personal Data Protection Act 2010, as amended by Act A1727",[77,81,82],{},"Primary legislation. Sections 12A and 12B live here",[77,84,85],{},"The binding duty. Offences and penalties attach at this level",[59,87,88,91,94],{},[77,89,90],{},"Circulars of the Personal Data Protection Commissioner (No. 1\u002F2025 on DPO appointment, No. 2\u002F2025 on breach notification, No. 1\u002F2026 on registration)",[77,92,93],{},"The regulator's own instruments, addressed to data controllers and processors",[77,95,96],{},"Where much of the operational detail sits: the appointment thresholds, the 21 days, the 72 hours",[59,98,99,102,105],{},[77,100,101],{},"Commissioner's guidelines (DPO appointment, Data Breach Notification, and the three issued 30 April 2026)",[77,103,104],{},"Published guidance, several of them bilingual. The April 2026 set was issued under section 48(g) of the Act",[77,106,107],{},"The regulator's published reading, and the safest English text to quote. Guidance, not a statutory provision",[17,109,110],{},"The distinction is not academic. The one million ringgit ceiling attaches to contravening the Personal Data Protection Principles in the Act, not to missing a paragraph in a guideline. But a regulator asking why you did not appoint an officer will be reading its own circular, so treating the guidance as optional because it is not the statute is the wrong lesson to draw from the hierarchy. The workable posture is to follow the guidance and to describe it accurately in your own documents: circular, guideline, or Act, named as such.",[12,112,114],{"id":113},"the-three-triggers-side-by-side","The three triggers, side by side",[17,116,117],{},"Circular No. 1\u002F2025 sets the circumstances in which appointment is mandatory at paragraph 4(1), and the DPO Guideline restates them in official English at paragraph 4.2. Here is the structure.",[53,119,120,133],{},[56,121,122],{},[59,123,124,127,130],{},[62,125,126],{},"Limb",[62,128,129],{},"The trigger",[62,131,132],{},"The comparator",[72,134,135,146,157],{},[59,136,137,140,143],{},[77,138,139],{},"(a)",[77,141,142],{},"Processing involving personal data of more than 20,000 data subjects",[77,144,145],{},"\"melebihi\" in the Malay original, rendered \"exceeding\" in the official English. 20,000 exactly is below the line",[59,147,148,151,154],{},[77,149,150],{},"(b)",[77,152,153],{},"Processing involving sensitive personal data, including financial information, of more than 10,000 data subjects",[77,155,156],{},"Same comparator. 10,000 exactly is below the line",[59,158,159,162,165],{},[77,160,161],{},"(c)",[77,163,164],{},"Activities requiring regular and systematic monitoring",[77,166,167],{},"No number attaches to this limb at all",[17,169,170],{},"Two things follow from the table that a lot of summaries get wrong.",[17,172,173],{},"The comparator is \"more than\", not \"at least\". An organisation whose processing involves exactly 20,000 data subjects sits below the quantitative threshold on the instruments' own wording. That is a useful piece of precision if you are near the line, but do not build a compliance strategy on staying at 19,999. The count is of data subjects whose personal data your processing involves, and once you add leads, enquiry forms, abandoned carts, newsletter subscribers and everyone captured in a website audience, the working figure is usually much larger than the number of paying customers in your order table.",[17,175,176],{},"And the three limbs are alternatives. They are joined by \"atau\" in the Malay and \"or\" in the English. Each stands on its own, so limb (c) does not require you to clear either number first. The onward step, that behavioural advertising can trigger the duty for an organisation nowhere near 20,000 records, follows from that disjunctive drafting rather than from an express sentence anywhere in the instruments. Present it that way if you are writing it up internally: it is the natural reading of the text, not a published ruling.",[12,178,180],{"id":179},"why-behavioural-advertising-is-its-own-trigger","Why behavioural advertising is its own trigger",[17,182,183],{},"Paragraph 4.3 of the DPO Guideline gives worked examples of activities that require regular and systematic monitoring, and the first one is the sentence this whole page turns on:",[185,186,187],"blockquote",{},[17,188,189],{},"\"Any form of activity where data subjects are tracked and profiled online or offline for purposes of behavioural advertising will be considered as activities which require regular and systematic monitoring.\"",[17,191,192],{},"Read the components. Tracked and profiled. Online or offline. For purposes of behavioural advertising. There is no volume qualifier, no carve-out for small businesses, and no distinction between doing the tracking yourself and doing it through a platform's tools. A standard Meta setup, where a pixel or a server-side integration records page views, add-to-carts and purchases, those events build audiences, and those audiences receive different creative from cold traffic, matches every component.",[17,194,195],{},"Two adjacent items in the same paragraph help calibrate the edges. A retail website whose algorithms monitor customers' searches and purchases in order to make recommendations is also treated as regular and systematic monitoring, which is a useful reminder that the concept is not limited to advertising: on-site personalisation counts too. And there is a carve-out for loyalty-programme management where the purpose is strictly account management rather than monitoring purchase behaviour. That carve-out is narrower than it looks. A points card used only to track balances and issue rewards sits inside it. The same card used to segment members by spending pattern and target them with different offers does not.",[17,197,198,199,204],{},"So the question to ask is not \"how many records do we hold\" but \"what are we doing with them\". If your ",[200,201,203],"a",{"href":202},"\u002Fblog\u002Ffacebook-retargeting","retargeting"," setup exists precisely to treat people differently based on their observed behaviour, the honest answer to limb (c) is yes.",[12,206,208],{"id":207},"working-the-question-in-practice","Working the question in practice",[17,210,211],{},"The decision runs cleanest as a sequence rather than a single test. Here is a worked version for a Malaysian e-commerce brand of the kind that runs Meta ads all year.",[17,213,214,218,219,223],{},[215,216,217],"strong",{},"Step one, count the data subjects, not the customers."," Add the order table, the newsletter list, the lead forms, the WhatsApp enquiry log, and the website visitors whose events feed your ",[200,220,222],{"href":221},"\u002Fblog\u002Ffacebook-custom-audiences","custom audiences",". A store with 6,000 orders may well have several times that number of identified or identifiable people in scope once retention and remarketing windows are counted. If the total exceeds 20,000, limb (a) settles it and you can stop.",[17,225,226,229],{},[215,227,228],{},"Step two, check for sensitive personal data."," The 10,000 threshold in limb (b) applies to sensitive personal data including financial information. Since 1 April 2025, biometric data has been part of the statutory list of sensitive personal data, defined as personal data resulting from technical processing relating to a person's physical, physiological or behavioural characteristics. Most advertisers will not be holding sensitive data at scale, but health, religious or financial angles change that assessment quickly.",[17,231,232,235],{},[215,233,234],{},"Step three, describe your advertising honestly."," Write one paragraph in plain language describing what you actually do: what events you collect, how long you keep them, what audiences you build, and whether people who behave differently see different ads or different prices. If that paragraph reads like tracking and profiling for the purposes of behavioural advertising, limb (c) applies whatever steps one and two produced.",[17,237,238,241,242,246],{},[215,239,240],{},"Step four, if none of the limbs is met, record why."," The value of the exercise is not the conclusion, it is the evidence that you reached the conclusion deliberately. Date it, name the person who signed it off, and revisit it when your setup changes. Migrating to ",[200,243,245],{"href":244},"\u002Fblog\u002Fserver-side-tracking-facebook-ads","server-side event forwarding"," or adding on-site personalisation is exactly the kind of change that moves the answer.",[12,248,250],{"id":249},"who-you-are-allowed-to-appoint","Who you are allowed to appoint",[17,252,253],{},"The eligibility criteria are in the DPO Guideline at paragraphs 6.10.1 to 6.10.3, and their logical shape is easy to misread from the Malay circular alone. The Guideline's numbered structure resolves it: the officer must be resident in Malaysia, meaning physically present here for at least 180 days in one calendar year, or easily contactable via any means, and must be proficient in the Bahasa Melayu and English languages.",[17,255,256,257,260,261,264],{},"So it reads as (resident ",[215,258,259],{},"or"," contactable) ",[215,262,263],{},"and"," bilingual. The language requirement is not an alternative. A regional privacy counsel in Singapore who is reachable in practice can satisfy the first condition, but only if that person works in both Bahasa Melayu and English.",[17,266,267],{},"On sourcing the person, the circular is permissive. Paragraph 4(3) allows one individual to serve as data protection officer for more than one data controller or processor, on a part-time or full-time basis, taking into account the organisation's function, structure and size. Paragraph 4(6) allows the role to be filled from existing employees or outsourced under a signed contract of services with an individual or an organisation. The Guideline adds at paragraph 6.9 that a shared officer must remain easily accessible by the different entities receiving that officer's service, which is the substance test that a shared appointment has to survive.",[17,269,270],{},"Independence is where the circular has real teeth. It requires the officer to act professionally, not to be bound by instructions in carrying out the role, and to report directly to senior management. It prohibits the data controller or processor from dismissing the officer for performing the duties listed at paragraph 5(1). And it requires a dedicated official business email account for the officer, distinct and separate from that individual's personal email address and from their ordinary official business email address. That last requirement is small and frequently skipped, and it is the sort of thing an inspection notices immediately. Paragraph 6(9) also requires an interim officer to be appointed promptly to monitor that mailbox when the incumbent leaves, so the channel never goes dark.",[17,272,273],{},"Finally, the contact details are meant to be public. Paragraph 9 of the circular requires the officer's business contact information to be published on the official website or other official media, included in the personal data protection notice, and reflected in security policies and guidelines. If you have appointed someone and their address appears nowhere a data subject could find it, the appointment is not yet finished.",[12,275,277],{"id":276},"registering-the-appointment-21-days-then-14","Registering the appointment: 21 days, then 14",[17,279,280],{},"Section 12A(3) requires notification; the circular puts a clock on it. An appointed data protection officer must be registered with the Commissioner within twenty-one days of the appointment, at paragraph 8(2). Where the incumbent ceases service, the registration details must be updated within fourteen days of the appointment of the replacement officer, at paragraph 8(3). Both figures are restated in the official English of the DPO Guideline at paragraphs 7.1 and 7.4, and the Guideline identifies the filing channel at paragraph 7.2 as the Personal Data Protection System, SPDP, at daftar.pdp.gov.my.",[17,282,283],{},"The sequencing point people trip on is that the twenty-one days run from the appointment, not from the date you decided you needed one. Make the appointment a dated internal act, in writing, and start the clock from that document.",[12,285,287],{"id":286},"what-the-officer-actually-does-after-april-2026","What the officer actually does, after April 2026",[17,289,290],{},"The job description got materially heavier on 30 April 2026, when the Commissioner issued three guidelines at once: on Data Protection Impact Assessments, on Automated Decision-Making and Profiling, and on Data Protection by Design. The first two land directly on the officer's desk, and the DPIA Guideline expressly hangs its requirements off subparagraph 5(1)(d) of the DPO circular, which is where the officer's duties are listed.",[17,292,293],{},"The DPIA Guideline uses a two-tier approach. First come the Quantitative Thresholds at paragraph 7.5: processing expected to involve more than 20,000 data subjects, or processing of sensitive personal data including financial information expected to involve more than 10,000 data subjects. Note that these mirror the DPO thresholds, including the \"more than\" comparator. Where those are not met, the second tier applies, and the officer is required to exercise best judgment against a non-exhaustive list of qualitative factors. One of those factors is tracking of the data subject's location or behaviour.",[17,295,296],{},"The Guideline's own worked Example 2, under the heading \"Online click-path analytics\", is about as close to an advertiser's setup as regulator guidance gets. It describes an e-commerce platform that \"tracks the data subject's online behaviour such as browsing history, clicks, time spent on pages and purchase activity, to predict buying intent, personalise prices and deliver targeted advertisements\", and concludes that because the processing involves systematic and continuous monitoring of behaviour for commercial and profiling purposes, the controller is required to carry out a DPIA. A completed DPIA is valid for two years from its date of completion, after which a refreshed one is required.",[17,298,299],{},"The ADMP Guideline is the one to handle carefully, because it is easy to over-read. It says that automated decision-making and profiling is one of the qualitative factors that triggers a DPIA \"regardless of the nature or extent of its intended use\", and that the officer shall ensure a DPIA is carried out for any planned processing that includes ADMP elements. But paragraph 7.1 cuts that back: the Guideline \"may not apply to all ADMP activities\", and officers \"are required to exercise their best judgment when assessing whether the ADMP threshold is met\". The ADMP Threshold is met where the outcome may produce legal effects concerning the data subject, or significantly affect them. So the correct statement is not that every profiling activity mandates a DPIA; it is that profiling inside the ADMP Threshold does, and whether a given activity is inside is the officer's judgment.",[17,301,302],{},"One illustration narrows the judgment usefully. The Guideline treats decisions that result in one data subject being offered a more favourable, lower price than another as meeting the significant-effect limb. So behavioural profiling that feeds differential pricing or discount eligibility is comfortably inside the threshold. Behavioural ad targeting that does neither, where the only consequence is which creative someone sees, is genuinely unsettled, and the Guideline leaves it to the officer rather than answering it. Anyone telling you the answer is obvious in either direction is going beyond the published text.",[17,304,305],{},"Note also the vocabulary shift. The ADMP Guideline defines \"Profiling\" as any form of automated processing of personal data used to evaluate certain personal aspects relating to a data subject, in particular to analyse or predict aspects concerning their personal preferences, interests, reliability, behaviour, location or movements. Its worked example of profiling is an e-commerce company monitoring browsing activity and purchase frequency to build a profile of predicted interests, used to determine what to market to that person and their eligibility for discount rates. That is the regulator naming your audience-building in its own words. Once you accept the label, the DPIA and ADMP machinery follows.",[12,307,309],{"id":308},"the-breach-clock-the-officer-inherits","The breach clock the officer inherits",[17,311,312],{},"The same commencement tranche that brought in section 12A brought in section 12B, and in practice the two are one workload. Section 12B requires a data controller with reason to believe a personal data breach has occurred to notify the Commissioner as soon as practicable, and to notify affected data subjects without unnecessary delay where the breach causes or is likely to cause significant harm. Failure to notify the Commissioner is an offence carrying a fine not exceeding two hundred and fifty thousand ringgit or imprisonment not exceeding two years or both. Read that carefully: the offence in subsection (3) penalises contravention of subsection (1) only, so the criminal exposure attaches to failing to tell the regulator, not to failing to tell the individuals.",[17,314,315],{},"Circular No. 2\u002F2025, the breach circular, supplies the operational clock. The prescribed breach information must be submitted within seventy-two hours of the personal data breach. Where notification is not made within that period, the controller must state its reasons, accompanied by supporting evidence. Affected data subjects must be given the prescribed information within seven days of the notification to the Commissioner. Where simultaneous provision of the full information is impossible, it may be staged, no later than thirty days from the initial notification, and breach-notification records must be kept for at least two years.",[17,317,318],{},"Two details matter for planning. The seventy-two hours runs from the breach, not from the moment you became aware of it, which is a tighter formulation than practitioners familiar with other regimes expect. And the circular defines a breach as being of \"significant scale\" where the number of affected data subjects exceeds 1,000, as one of five risk factors bearing on whether a breach causes or is likely to cause significant harm. That 1,000 figure is not a floor for notifying individuals: notification to affected data subjects is required wherever significant harm is caused or likely, regardless of significant scale.",[17,320,321],{},"If you use vendors, push the duty down. The breach circular requires a controller to impose on its data processors, by contract or other reasonable means, an obligation to notify the controller and to provide all reasonable and necessary assistance in complying with the Act. That is a contracting job with a deadline attached, and it is one of the first things a newly appointed officer should audit. Since 1 April 2025 processors have also been directly bound by the Security Principle in their own right, with the same one million ringgit and three-year ceiling on conviction, so the conversation is easier than it used to be.",[12,323,325],{"id":324},"where-the-paperwork-is-genuinely-messy","Where the paperwork is genuinely messy",[17,327,328],{},"Two problems with the source documents will slow you down, and it is better to know about them before you go looking.",[17,330,331],{},"The first is the circular numbering. The regulator's English index on its website labels the two 2025 circulars the wrong way round, and a great deal of secondary commentary has copied the error. The PDF covers self-designate: Bilangan 1 Tahun 2025 is the appointment of data protection officers, and Bilangan 2 Tahun 2025 is data breach notification. The Commissioner's own official English texts settle it, because the DPO Guideline names Circular No. 1\u002F2025 as the appointment circular at paragraphs 1.4 and 4.1, and the 2026 DPIA Guideline does the same at paragraph 2.1. Cite by title as well as by number and the confusion cannot reach your file.",[17,333,334],{},"The second is language. Both 2025 circulars are published in Malay only. Every English rendering of their thresholds, deadlines and duties, including the ones on this page, is a translation. Where the same figure also appears in the official English of the DPO Guideline, which is bilingual, cite the Guideline instead of the circular. That is not pedantry: if the two ever diverge, the document with an official English text is the one you can quote without arguing about your own translation.",[12,336,338],{"id":337},"what-this-page-cannot-settle-for-you","What this page cannot settle for you",[17,340,341],{},"Three open items, stated plainly rather than guessed at.",[17,343,344],{},"Registration of data controllers is a live and separate regime. Circular No. 1\u002F2026 on the registration of data controllers takes effect from 1 June 2026 and revokes only the 2024 circular it replaced, leaving both 2025 circulars in force. Which classes of data controller must register under it turns on the Class of Data Users Order made under the Act, which this guide has not analysed, so nothing here should be read as saying that a general Meta advertiser must or need not register. Check the current instruments, or take advice, before concluding either way.",[17,346,347],{},"The competency side of the role is developing. The Commissioner published a Data Protection Officer Competency Guideline dated 1 August 2025. We have confirmed that it exists at that date on the regulator's site but have not analysed its contents, so treat any summary of what it requires, including a summary that says it changes nothing about the appointment thresholds, as unverified until you read the document itself.",[17,349,350],{},"And the pace of change is the real risk. Three of the guidelines that most affect an advertiser's obligations were issued on a single day in April 2026, less than a year after the DPO duty commenced. Anything you write down about this area should carry the version and issuance date of the instrument it rests on, and a review date. The instruments cited here were current when this guide was written; check the current text before you rely on a figure in a filing.",[12,352,354],{"id":353},"a-sensible-order-of-operations","A sensible order of operations",[17,356,357],{},"If you have concluded that the duty applies, the sequence that produces the least rework is: write the one-paragraph description of what your advertising actually does with personal data; use it to decide the limb you are caught by, and record that decision with a date; appoint the officer in writing, checking the residency-or-contactability and bilingual criteria first; open the dedicated business email account; register through SPDP within twenty-one days; publish the contact details on your site and in your personal data protection notice; then hand the officer their first two tasks, which are the DPIA assessment under the 2026 Guideline and the processor breach-notification clauses in your vendor contracts.",[17,359,360],{},"None of that requires a large team. It requires a named person with real independence, a documented reason for every judgment call, and the discipline to revisit the file when the setup changes. In an area where the regulator has published this much this fast, showing your reasoning is worth more than showing a conclusion.",{"title":362,"searchDepth":363,"depth":363,"links":364},"",2,[365,366,367,368,369,370,371,372,373,374,375,376,377],{"id":14,"depth":363,"text":15},{"id":28,"depth":363,"text":29},{"id":47,"depth":363,"text":48},{"id":113,"depth":363,"text":114},{"id":179,"depth":363,"text":180},{"id":207,"depth":363,"text":208},{"id":249,"depth":363,"text":250},{"id":276,"depth":363,"text":277},{"id":286,"depth":363,"text":287},{"id":308,"depth":363,"text":309},{"id":324,"depth":363,"text":325},{"id":337,"depth":363,"text":338},{"id":353,"depth":363,"text":354},null,"local","Which Malaysian businesses must appoint a Data Protection Officer under the PDPA, why behavioural advertising is its own trigger, and what the appointment and 21-day registration involve.",[],"md",[384,387,390,393,396,399,402,405],{"question":385,"answer":386},"Does a small Malaysian business running Facebook retargeting really need a DPO?","It may, and the size of your list is not the whole answer. The Commissioner's DPO Guideline, Version 1.0 of 25 February 2025, states at paragraph 4.3 that any form of activity where data subjects are tracked and profiled online or offline for the purposes of behavioural advertising will be considered an activity requiring regular and systematic monitoring. Regular and systematic monitoring is the third of the three triggers in Circular No. 1\u002F2025, and the three are joined by the word 'or', which means each stands on its own. The onward step, that the monitoring limb bites even where the 20,000 and 10,000 figures are not reached, follows from that disjunctive drafting rather than from an express sentence, so treat it as the natural reading rather than a settled ruling. If you build custom audiences from pixel events and serve ads back to those people, you are doing the thing the paragraph describes, and the sensible course is to assume the duty applies and document your reasoning if you conclude otherwise.",{"question":388,"answer":389},"We hold exactly 20,000 customer records. Are we over the line?","No, not on that limb. The Malay original of Circular No. 1\u002F2025 uses 'melebihi' and the Commissioner's official English rendering in the DPO Guideline uses 'exceeding', so the trigger is more than 20,000 data subjects, not 20,000 or more. An organisation sitting at exactly 20,000 is below the quantitative threshold. The same applies to the 10,000 figure for sensitive personal data including financial information. Two cautions, though. First, the count is of data subjects whose personal data your processing involves, which is usually larger than the tidy number in your CRM once you add leads, enquiries, abandoned checkouts and pixel-derived audiences. Second, being below both numbers does not end the analysis, because the monitoring limb is independent of both.",{"question":391,"answer":392},"Does the Personal Data Protection Act itself set the 20,000 threshold?","No, and this distinction matters if you are ever asked to justify a decision. Section 12A(1) of Act 709, inserted by section 6 of the Personal Data Protection (Amendment) Act 2024 and in force since 1 June 2025, requires a data controller to appoint one or more data protection officers without qualifying that duty by size, sector or volume. The numeric thresholds live in Circular of the Personal Data Protection Commissioner No. 1\u002F2025, which is regulator guidance issued under the Act rather than a provision of the Act. So do not write in a board paper that the PDPA sets a 20,000 threshold; write that the Act imposes an unqualified appointment duty and that the Commissioner's circular identifies the circumstances in which appointment is mandatory. The penalties in the Act attach to the Personal Data Protection Principles, not to a paragraph in a circular.",{"question":394,"answer":395},"Can we appoint someone who is not based in Malaysia?","Possibly. The DPO Guideline, Version 1.0 of 25 February 2025, sets out the criteria at paragraphs 6.10.1 to 6.10.3, and the structure is important. The officer must be resident in Malaysia, meaning physically present in Malaysia for at least 180 days in one calendar year, or be easily contactable via any means, and must be proficient in the Bahasa Melayu and English languages. Residency and contactability are alternatives to one another. Language proficiency is not an alternative to anything: it attaches to both routes. A regional privacy lead sitting outside Malaysia who is genuinely reachable can satisfy the first condition, but if that person does not work in both Bahasa Melayu and English, the appointment does not meet the published criteria.",{"question":397,"answer":398},"Can our agency, law firm or an outside consultant serve as our DPO?","Yes. Circular No. 1\u002F2025 permits the role to be filled either from existing employees or by outsourcing under a signed contract of services with an individual or an organisation, at paragraph 4(6). It also permits one individual to serve as data protection officer for more than one data controller or data processor, full-time or part-time, taking into account the organisation's function, structure and size, at paragraph 4(3). The DPO Guideline adds at paragraph 6.9 that a shared officer must remain easily accessible by the different entities receiving that officer's service. Two practical consequences follow. Contract for real availability, not a name on a form, because accessibility is the published test. And remember that outsourcing does not move the legal exposure: section 12A(4) provides that the appointment shall not discharge the data controller or data processor from all duties and functions under the Act.",{"question":400,"answer":401},"How do we register the appointment, and what is the deadline?","Section 12A(3) requires the data controller to notify the Commissioner of the appointment in the manner and form the Commissioner determines. Circular No. 1\u002F2025 puts a clock on it: the appointed officer must be registered with the Commissioner within twenty-one days of the appointment, at paragraph 8(2), and where the incumbent ceases service, the registration details must be updated within fourteen days of the appointment of the replacement, at paragraph 8(3). Both deadlines are restated in the official English of the DPO Guideline at paragraphs 7.1 and 7.4. The Guideline identifies the filing channel at paragraph 7.2 as the Personal Data Protection System, SPDP, at daftar.pdp.gov.my. Note the asymmetry in the Act: section 12A(2) requires processors to appoint an officer, but the notification duty in section 12A(3) is drafted as falling on the data controller.",{"question":403,"answer":404},"Does appointing a DPO move liability off the company?","No. Section 12A(4) is explicit, and it is worth quoting in its own awkward phrasing: the appointment of a data protection officer under subsections (1) and (2) shall not discharge the data controller or data processor from all duties and functions under the Act. The company remains the accountable party. What the officer changes is internal: Circular No. 1\u002F2025 requires the officer to act professionally, not to be bound by instructions in carrying out the role, and to report directly to senior management, and it prohibits the organisation from dismissing the officer for performing the duties listed at paragraph 5(1). Read together, those provisions describe an internal check rather than a liability shield. Since 1 April 2025 the maximum penalty for contravening the Personal Data Protection Principles has been a fine not exceeding one million ringgit or imprisonment not exceeding three years or both, and that exposure sits with the organisation.",{"question":406,"answer":407},"Why do the regulator's circular numbers not match what I see online?","Because the English index on the regulator's website has the two 2025 circulars the wrong way round, and a lot of secondary commentary has copied the error. The PDF covers self-designate: Bilangan 1 Tahun 2025 is the DPO circular, on the appointment of data protection officers, and Bilangan 2 Tahun 2025 is the data breach notification circular. The Commissioner's own official English texts confirm that reading, since the DPO Guideline names Circular No. 1\u002F2025 as the appointment circular at paragraphs 1.4 and 4.1, and the 2026 DPIA Guideline does the same at paragraph 2.1. Both circulars are published in Malay only, so any English version of their thresholds and deadlines that you rely on is a translation. The defensive habit is to cite by title as well as by number, and where the same figure appears in the official English of the DPO Guideline, cite the Guideline.","\u002Fimages\u002Fblog\u002Fpdpa-dpo-requirement-meta-advertisers-malaysia-hero.webp","You run Meta ads, you fire a pixel, you build retargeting audiences, and someone has just asked whether Malaysian law now requires you to appoint a Data Protection Officer. The honest answer is that it may, and not because of how many customers you have. The Commissioner's own guidance treats behavioural advertising as a qualifying activity in its own right, which changes who the duty reaches. The thresholds, the eligibility criteria and the registration clock each sit in a different document, and the numbers get misquoted often enough to be worth reading off the instruments themselves.",{},true,"\u002Fblog\u002Fpdpa-dpo-requirement-meta-advertisers-malaysia","2026-07-31",{"title":5,"description":380},[416,420,423,427,430,433,437,440,443],{"label":417,"url":418,"year":419},"Personal Data Protection (Amendment) Act 2024 [Act A1727]","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2024\u002F11\u002FAct-A1727.pdf","2024",{"label":421,"url":422,"year":419},"P.U. (B) 522 - Appointment of Date of Coming into Operation, Act A1727","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2024\u002F12\u002FPENETAPAN-TARIKH-PERMULAAN-KUAT-KUASA-1.pdf",{"label":424,"url":425,"year":426},"Personal Data Protection Guideline: Appointment of Data Protection Officer, Version 1.0","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2025\u002F02\u002FGARIS-PANDUAN-PERLINDUNGAN-DATA-PERIBADI_PELANTIKAN-PEGAWAI-PERLINDUNGAN-DATA-1.pdf","2025",{"label":428,"url":429,"year":426},"Pekeliling Pesuruhjaya Perlindungan Data Peribadi Bilangan 1 Tahun 2025 (Pelantikan Pegawai Perlindungan Data)","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2025\u002F02\u002FPekeliling-DPO.pdf",{"label":431,"url":432,"year":426},"Pekeliling Pesuruhjaya Perlindungan Data Peribadi Bilangan 2 Tahun 2025 (Pemberitahuan Pelanggaran Data)","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2025\u002F02\u002FPekeliling-DBN.pdf",{"label":434,"url":435,"year":436},"Personal Data Protection Guideline: Data Protection Impact Assessment (DPIA), Version 1.0","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2026\u002F04\u002FData-Protection-Impact-Assessment-Guideline-DPIA.pdf","2026",{"label":438,"url":439,"year":436},"Personal Data Protection Guideline: Automated Decision-Making and Profiling (ADMP), Version 1.0","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2026\u002F04\u002FAutomated-Decision-Making-And-Profiling-Guideline-ADMP.pdf",{"label":441,"url":442,"year":436},"Pekeliling Pesuruhjaya Perlindungan Data Peribadi Bilangan 1 Tahun 2026 (Pendaftaran Pengawal Data)","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2026\u002F06\u002FPekeliling-Pesuruhjaya-Bil.1-2026.pdf",{"label":444,"url":445,"year":426},"Personal Data Protection Commissioner - Data Protection Officer (DPO) Competency Guideline","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fdata-protection-officer-dpo-competency-guideline\u002F",[447,451,455,459,463,467,471,475],{"label":448,"value":449,"source":450},"Date the section 12A DPO duty came into operation","1 June 2025","P.U. (B) 522, commencement notification for Act A1727, 2024",{"label":452,"value":453,"source":454},"DPO mandatory where processing involves more than this many data subjects","20,000","Circular of the Personal Data Protection Commissioner No. 1\u002F2025, para 4(1)(a), 2025",{"label":456,"value":457,"source":458},"DPO mandatory for sensitive personal data including financial information above this many data subjects","10,000","Circular of the Personal Data Protection Commissioner No. 1\u002F2025, para 4(1)(b), 2025",{"label":460,"value":461,"source":462},"Deadline to register an appointed DPO with the Commissioner","21 days from appointment","Circular No. 1\u002F2025, para 8(2); DPO Guideline v1.0, para 7.1, 2025",{"label":464,"value":465,"source":466},"Deadline to update the registration after appointing a replacement officer","14 days","Circular No. 1\u002F2025, para 8(3); DPO Guideline v1.0, para 7.4, 2025",{"label":468,"value":469,"source":470},"Physical presence in Malaysia for a DPO to count as resident","180 days in one calendar year","Personal Data Protection Guideline: Appointment of Data Protection Officer v1.0, para 6.10.1, 2025",{"label":472,"value":473,"source":474},"Maximum fine for contravening the Personal Data Protection Principles","RM1,000,000","Act A1727 s.4(b)(ii) amending s.5(2) of Act 709, in force 1 April 2025",{"label":476,"value":477,"source":478},"Validity of a completed Data Protection Impact Assessment","2 years from completion","Personal Data Protection Guideline: Data Protection Impact Assessment v1.0, para 11.2, 2026","blog\u002Fpdpa-dpo-requirement-meta-advertisers-malaysia","Q9-m7-7GSiJADCQvErDhRmysRm1Q5vEObwQ5b20SVXc",1785891721096]