Meta Pixel Consent Under Malaysia's PDPA

Whether a Malaysian business running the Meta Pixel or Conversions API needs PDPA notice and consent, what the section 7 notice must say, and why legitimate interests is not available under Act 709.

Updated July 2026 · Likit Sae Lee, CTO

Meta Pixel Consent Under Malaysia's PDPA
Quick answer

A Malaysian business running the Meta Pixel or the Conversions API is processing personal data under the Personal Data Protection Act 2010 (Act 709), and section 6 makes the data subject's consent the default position. The alternatives to consent in section 6(2) are a closed list of six grounds, and legitimate interests is not among them, so the ground most GDPR-trained marketers reach for does not exist in Malaysian law. Section 7(1) then requires a written notice covering eight specified matters, in the national language and English, including the class of third parties to whom the data is or may be disclosed. The Commissioner has issued no instrument dealing with cookies, pixels, SDKs or server-side conversion APIs specifically, so this is the general law applied to a particular technology.

You installed the pixel years ago, your Conversions API feed went live when match quality started slipping, and nobody in the business has ever looked at what Malaysian law says about either. Then a customer asks what you do with their data, or a client's legal team sends a questionnaire, and the honest answer is that nobody knows. This guide walks through what Act 709 actually requires of an advertiser running Meta's tracking tools, what the Commissioner has published, and the one assumption imported from Europe that gets Malaysian advertisers into trouble.

The short version

If your Malaysian website loads the Meta Pixel, or your server posts events to the Conversions API, you are almost certainly processing personal data and Act 709 applies to what you do next. Section 6(1)(a) makes the data subject's consent the starting point. The alternatives in section 6(2) are a closed list of six grounds, and legitimate interests is not one of them. Section 7(1) then requires a written notice covering eight specified matters, in the national language and English, and paragraph (e) of that list obliges you to state the class of third parties to whom you disclose or may disclose the data.

One caveat belongs at the top rather than buried in a footnote. The Personal Data Protection Commissioner has issued no instrument that addresses cookies, tracking pixels, SDKs or server-side conversion APIs as such. There is no Malaysian cookie regulation and no pixel-specific circular. What follows is the general law of Act 709 applied to a specific technology, plus a small number of worked examples inside guidelines issued under section 48(g) that happen to describe exactly what an advertising pixel does. Anyone who tells you Malaysia has a pixel rule is describing something that does not exist.

The mistake GDPR teaches you to make

A lot of the privacy wording sitting on Malaysian websites was adapted from a European template, and the European template is built on a basis Malaysia does not have.

Under the GDPR, legitimate interests carries a great deal of ad-tech compliance. It is the reason a European privacy policy can talk about balancing tests and about the controller's commercial interest in measuring advertising. Marketers who learned privacy in that world arrive at Act 709 assuming the same structure exists here, find the consent requirement, assume there must be a flexible fallback underneath it, and stop reading.

There is no fallback. Section 6(2) sets out its alternatives to consent as a finite list and the list closes. The six grounds are performance of a contract to which the data subject is a party, taking steps at the data subject's request with a view to entering a contract, compliance with a legal obligation to which the data controller is subject other than one imposed by contract, protection of the data subject's vital interests, administration of justice, and the exercise of functions conferred on a person by or under law. That is the whole set. The Personal Data Protection (Amendment) Act 2024 rewrote a good deal of Act 709, including the penalties, the cross-border regime and the accountability provisions, but it did not touch section 6.

So the familiar line that the business processes analytics and advertising data on the basis of its legitimate interests describes a legal basis that Malaysian law does not offer. It is not a weak argument. It is not an argument at all.

The six grounds, and why a pixel struggles to reach any of them

Every one of the six grounds is gated on necessity. Section 6(2) does not permit processing that happens to be connected to a contract; it permits processing that is necessary for the performance of one. That word is where most attempts to route around consent fall over.

Section 6(2) groundCan it carry an advertising pixel?
Performance of a contract with the data subjectThe purchase contract is performed by taking payment and shipping the goods. A conversion event sent to an advertising platform is not necessary for that.
Steps at the data subject's request before a contractCovers a quote, an enquiry, a booking hold. A visitor who has requested nothing has requested no tracking either.
A non-contractual legal obligationThere is no Malaysian legal obligation to measure ad performance.
Vital interests of the data subjectLife-and-death territory. Not applicable.
Administration of justiceNot applicable.
Functions conferred by or under lawAimed at statutory functions, not commercial marketing.

Section 6(3) then adds cumulative conditions that apply whichever ground you rely on, and they are easy to miss because they sit below the headline. The purpose must be lawful and directly related to an activity of the data controller. The processing must be necessary for or directly related to that purpose. The personal data must be adequate but not excessive in relation to it. So even a controller who genuinely lands on one of the six grounds still has to show the data collected is proportionate. A pixel configured to fire on every page with every available parameter is a harder case under that test than one that fires on the handful of events you actually optimise against.

The practical conclusion is not dramatic. For most advertisers, most of the time, consent is the available route, and the work is making the consent good rather than hunting for a way around it.

What the regulator has actually published on tracking

The Commissioner has published nothing on pixels by name. What the Commissioner has published, on 30 April 2026, is a set of three guidelines under section 48(g) that describe behaviour indistinguishable from what a pixel does.

The Automated Decision-Making and Profiling Guideline defines profiling as any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a data subject, in particular to analyse or predict aspects concerning that data subject's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. Its worked Example (ii) is an e-commerce company that monitors a data subject's online behaviour, browsing activity and purchase frequency by category, builds a profile of predicted interests and preferences, and uses it to determine what to market to that person and whether they qualify for certain discount rates. If you build website custom audiences and feed them back into targeting, you are inside that description.

The Data Protection Impact Assessment Guideline goes further. Its Example 2, titled online click-path analytics, is an e-commerce platform that tracks browsing history, clicks, time spent on pages and purchase activity to predict buying intent, personalise prices and deliver targeted advertisements, and its stated conclusion is that the data controller is required to carry out a DPIA because the processing involves systematic and continuous monitoring of behaviour for commercial and profiling purposes.

The Data Protection by Design Guideline supplies the closest thing Malaysia has to a cookie standard, and it does so inside a worked example rather than a rule. The Commissioner's model of a compliant design has a business ensuring that by default only the strictly necessary cookies used by the online platform are active, with additional cookies activated only when the customer consents to their use, and marketing opt-in checkboxes that are by default unchecked.

Hold two things in mind about all three. They are guidance issued under section 48(g), not statutory provisions, so cite them as the regulator's expectations rather than as sections of the Act. And they are examples, which means they show the direction of travel clearly without settling every case. That is still a great deal more than Malaysian advertisers had before 30 April 2026.

The eight things your notice has to say

Section 7(1) is the operative provision and it is specific. A data controller must, by written notice, inform the data subject of eight matters. Here is each one with the pixel-shaped version of what it means.

Section 7(1) requirementWhat it means for a site running Meta tracking
(a) That the data is being processed, with a description of itName the actual data: pages viewed, events such as add-to-cart and purchase, device and browser identifiers, IP address, and any matching parameters you pass.
(b) The purposes of collection and further processingAdvertising measurement, audience building and retargeting are distinct purposes. Say so instead of writing improving your experience.
(c) The source of the dataCollected from the visitor's own interaction with your site or app, and from your order records where server events are sent.
(d) The right to request access and correction, and how to contact youA named contact route that a real person monitors, not a form that goes nowhere.
(e) The class of third parties to whom you disclose or may disclose the dataAdvertising and analytics platforms are a recipient class. A notice silent on this is incomplete on the face of the section.
(f) The choices and means you offer for limiting processingThe consent control itself, plus how to withdraw later.
(g) Whether supply is obligatory or voluntaryFor advertising tracking, voluntary. Say it plainly.
(h) The consequences of failing to supply the dataNothing happens to the customer's ability to buy. Confirming that is what makes the choice real.

Paragraph (e) matters more than its length suggests, because section 8 attaches to it. Absent the data subject's consent, and subject to the exemptions in section 39, personal data may not be disclosed to any party other than a third party of the class of third parties specified in paragraph 7(1)(e). Note the two qualifiers. Section 8 opens with the words subject to section 39, and its own chapeau preserves disclosure where the data subject consents, so an omitted recipient class is not an absolute bar for all time. But a notice that never mentions advertising platforms cannot be the thing that authorises sending data to one. Write the class in.

When the notice has to be in front of the user

Section 7(2) fixes the timing, and it does so as soon as practicable at three moments: when the data subject is first asked to supply his personal data, when the data controller first collects it, and in any other case before the controller uses the data for a purpose other than that for which it was collected, or discloses the data to a third party.

For a website, the second and third limbs are the ones that bite. Collection happens the instant the tag fires, and disclosure happens the instant the event reaches the platform. A notice that a visitor could find by scrolling to the footer and opening a policy page is not in front of them at either moment. That is the structural argument for surfacing the choice on entry rather than treating the privacy page as sufficient. Nothing in the Act prescribes a banner; the timing requirement simply makes some form of upfront disclosure the obvious way to satisfy it.

The third limb also catches a change you might not think of as a legal event. If you collected order data to fulfil purchases and later start uploading it as a customer list for audience matching, that is use for a new purpose and disclosure to a third party. The notice has to have got there first.

Bahasa Melayu and English

Section 7(3) reads: a notice under subsection (1) shall be in the national and English languages, and the individual shall be provided with a clear and readily accessible means to exercise his choice, where necessary, in the national and English languages.

Two duties, differently qualified. The notice must be bilingual, full stop. The means of exercising choice must be bilingual where necessary, and the drafter put that qualifier in on purpose. Do not flatten the two into one absolute rule, and do not use the qualifier as an excuse to skip the translation of the notice itself. If you are localising anyway, localising the consent interface as well removes an argument for the price of one translation job.

Consent under Act 709 is not just a state of mind. Regulation 3 of the Personal Data Protection Regulations 2013 puts three concrete demands on it, and these are the strongest primary hooks an advertiser has for designing a defensible banner.

Regulation 3(1): a data user shall obtain consent from a data subject in relation to the processing of personal data in any form that such consent can be recorded and maintained properly by the data user. Consent you cannot produce later is consent you cannot prove.

Regulation 3(2): if the form in which consent is to be given also concerns another matter, the requirement to obtain consent shall be presented distinguishable in its appearance from such other matter. Consent bundled into a terms-and-conditions checkbox at checkout fails this. The tracking consent has to look separate from whatever else it sits beside.

Regulation 3(5): the burden of proof for such consent shall lie on the data user. You prove you had it. Nobody has to prove you did not.

Regulation 3(3) adds that where the data subject is under eighteen, consent must be obtained from the parent, guardian or person with parental responsibility. If your audience skews young, that is a real design constraint and not a theoretical one.

The Regulations still use the older phrase data user rather than data controller, because the 2024 amending Act substituted the term throughout Act 709 without touching the 2013 Regulations. Read data user as your business and the obligations are unchanged.

In operational terms, those three subregulations translate into a consent log. Timestamp, the version of the notice shown, what the person chose per purpose, and the mechanism used. If a complaint lands eight months later, that log is your entire defence, and no analytics dashboard produces it for you.

The banner itself: defaults and dark patterns

The Data Protection by Design Guideline is where design meets law. Its compliant-design example has non-essential cookies inactive by default and marketing opt-in boxes unchecked by default, which is the regulator describing the shape of a good interface rather than prescribing one.

Paragraph 6.3 is firmer in tone: the data controller shall refrain from the use of deceptive design patterns in interfaces as these designs may mislead or pressure the data subject into making unintended or into making otherwise potentially harmful choices, especially those that benefit the data controller instead of protecting the data subject's best interests. Paragraph 6.4(a) names overloading as one such pattern and illustrates it with a website that asks the data subject to click through four different pop-up boxes just to confirm the cookie settings.

Put those next to a typical Malaysian ecommerce banner and the gap is usually obvious. A prominent Accept All with the decline option buried two clicks deep in a preferences modal is exactly the asymmetry paragraph 6.3 is aimed at. So is a banner that reappears on every page load until the visitor gives up and accepts. You do not need a European consent management platform to fix this; you need a reject control that is as reachable as the accept control, defaults that are off, and a record of which one the person chose.

Conversions API and server-side tags

Moving events server-side changes the transport, not the analysis. If anything it raises the stakes, because a server feed usually carries more identifying detail than a browser tag: hashed email and phone, order value, external identifiers you already hold in your commerce platform. That is the entire point of running it, and it is also why the processing is harder to characterise as anonymous.

Sections 6, 7 and 8 attach to the processing and the disclosure, not to the route the packet takes. A server-to-server call to an advertising platform is still a disclosure to a class of third parties under paragraph 7(1)(e), and the consent question is the same one the browser tag raises. The practical consequence is that your consent signal has to reach the server side too. A site where the banner suppresses the browser pixel while the backend keeps posting purchase events regardless has a compliance gap that no privacy policy wording closes. If you are still deciding how to split the two, the mechanics are set out in pixel versus Conversions API, and the deployment detail in the Conversions API setup guide and the wider server-side tracking walkthrough. Read all of those as engineering, then come back and make sure the consent state actually travels with the event.

Deduplication deserves a sentence of its own in your notice. If the same purchase is reported twice, once from the browser and once from your server, and reconciled by event ID, then describing your processing as one activity rather than two is both accurate and simpler for a reader to follow.

The knock-on duties most advertisers miss

Behavioural tracking pulls three other duties into view. Keep track of where each one comes from, because only the last has a section of the Act behind it: the first two live in guidance the Commissioner issued under section 48(g), which sets the regulator's expectations rather than creating an offence.

The first is the impact assessment. Under the DPIA Guideline's two-tier approach, you check the quantitative thresholds first: processing expected to involve more than 20,000 data subjects, or processing of sensitive personal data including financial information data expected to involve more than 10,000. Note the wording is more than, so an organisation sitting at exactly 20,000 is below the line on the instrument's own terms. Where neither threshold is met, the data protection officer exercises best judgment against qualitative factors, one of which is tracking of the data subject's location or behaviour. Given the Guideline's own click-path example concludes a DPIA is required, an advertiser running site-wide tracking should assume the question is live rather than assume it away. A completed DPIA is valid for two years.

The second is profiling. The ADMP Guideline says that automated decision-making and profiling is one of the qualitative factors triggering a DPIA regardless of the nature or extent of its intended use, and that the data protection officer shall ensure a DPIA is carried out for any planned processing including such elements. That sentence has to be read with paragraph 7.1, which says the Guideline may not apply to all such activities and that officers are required to exercise best judgment on whether the threshold is met, the threshold being outcomes that produce legal effects or significantly affect the data subject. Where profiling feeds differential pricing or discount eligibility, the Guideline treats that as inside the threshold. Where it only decides which creative a person sees, the position is genuinely unsettled and your officer has to make the call. Anyone who tells you the answer is obvious in either direction is guessing.

The third is the officer, and this one is statutory. Section 12A of Act 709, inserted by the 2024 amending Act and in force since 1 June 2025, requires a data controller to appoint one or more data protection officers accountable to it for compliance with the Act, and separately requires a data processor to do the same. The Act itself sets no size threshold. The thresholds come from Circular of the Personal Data Protection Commissioner No. 1/2025, which makes appointment mandatory above certain volumes of data subjects or where the activity requires regular and systematic monitoring, the three limbs being alternatives rather than a stack. The circular is published in Malay only, so any English rendering of it, including this one, is a translation.

That last limb is the one advertisers should read twice. The Commissioner's Data Protection Officer Guideline, Version 1.0 of 25 February 2025, which carries the official English text, states that any form of activity where data subjects are tracked and profiled online or offline for purposes of behavioural advertising will be considered as activities which require regular and systematic monitoring. Reading that against the circular's disjunctive structure suggests a business running behavioural advertising is caught irrespective of headcount or record volume, though that step is an inference from how the limbs are joined rather than a sentence anyone has written down.

Where the data goes next

The pixel sends data out of Malaysia. That engages section 129, which the 2024 amendments rewrote with effect from 1 April 2025.

The old prohibition in section 129(1), which barred transfer except to places specified by the Minister in the Gazette, was deleted. That whitelist mechanism is gone, and it is worth knowing that no notification specifying destination countries was ever actually gazetted while it existed: the Attorney General's Chambers register of subsidiary legislation under Act 709 holds sixteen records and none of them is a transfer-destination Order. Malaysia has no adequacy list, and never had one.

What replaced it is section 129(2), which permits transfer where the destination has in force a law substantially similar to Act 709 or ensures an adequate level of protection at least equivalent to it, and section 129(3), which sets out seven conditions including the data subject's consent. The Commissioner's Cross Border Personal Data Transfer Guidelines, Version 1.0 of 29 April 2025, add that whatever route you take, the controller shall through its personal data protection notice or such other written notice inform the data subject about the transfer.

Two honest limits. The regulator has published no view on whether any particular jurisdiction passes the section 129(2) test, so the assessment is yours to make and its outcome is not pre-decided for you. And with subsection (1) deleted, the surviving subsections are permissive in form, so precisely what conduct now contravenes the section is not spelled out anywhere. State the position carefully in your documentation rather than asserting a conclusion the instruments do not support.

Penalties, and the ones people miss

Since 1 April 2025 the maximum penalty for contravening the seven Personal Data Protection Principles has been a fine not exceeding one million ringgit or imprisonment not exceeding three years or both, up from three hundred thousand ringgit and two years. Notice and Choice is one of those seven principles, alongside General, Disclosure, Security, Retention, Data Integrity and Access, so a defective notice sits squarely inside that exposure.

Resist the temptation to quote the million-ringgit figure as Malaysia's PDPA penalty in general. It attaches to section 5(2), and through the new subsection 5(1a) to a data processor's breach of the Security Principle. Other offences in the Act carry their own separate and lower ceilings, and conflating them is a good way to lose credibility with the lawyer reading your policy.

One more provision advertisers routinely overlook. Section 43(1) gives a data subject the right, at any time by notice in writing, to require a data controller at the end of such period as is reasonable in the circumstances to cease or not to begin processing his personal data for the purposes of direct marketing, defined in section 43(5) as the communication by whatever means of any advertising or marketing material which is directed to particular individuals. The wording is a reasonable period rather than immediately, and the enforcement path runs through the Commissioner rather than directly from the individual's letter. But if you build audiences from customer lists, you need a route by which somebody's objection actually removes them, and a process that ends at an unread inbox is not one.

A worked pass for a Malaysian online store

Take a store running the pixel on every page, the Conversions API for purchases, and a customer list upload once a month for lookalike seeding. Here is the sequence that gets it defensible.

Start by writing down every event you actually send and every parameter that rides along with it. Most teams discover something they did not know was there, usually an advanced matching field switched on years ago by whoever installed the tag. Then answer, on paper, whether those fields relate to an identifiable individual. That is the section 4 question, and it decides whether the rest of this applies at all.

Next, pick your basis and record the reasoning. If it is consent, say so and stop looking for a fallback, because section 6(2) does not have one for you. Then rebuild the notice against the eight paragraphs of section 7(1) in order, treating paragraph (e) as non-negotiable: advertising and analytics platforms are named as a recipient class, and the cross-border transfer is disclosed in the same document.

Then fix the interface. Non-essential tags off by default. A reject control with the same prominence as the accept control. No repeated pop-ups. A consent state that is written to a log and read by both the browser tag and the server feed, so a refusal actually suppresses both. Publish the notice in Bahasa Melayu and English, and localise the choice interface while you are in there.

Finally, deal with the assessments. Count your data subjects against the quantitative thresholds. Whether or not you clear them, document the qualitative judgment on behaviour tracking, because that is the record that shows the question was considered rather than ignored, and diarise the two-year DPIA refresh. If you have not appointed a data protection officer, read the behavioural-advertising sentence in the DPO Guideline and take advice before concluding you are outside the appointment duty.

What to do this month

None of this needs a project. Open your privacy notice and search it for the words legitimate interests; if they are there, that paragraph is describing a basis Malaysian law does not provide, and it goes. Search it again for any mention of advertising platforms as a recipient class; if there is none, paragraph 7(1)(e) is unsatisfied and that is the second fix. Then check whether your consent banner's reject path is as short as its accept path, and whether the server feed respects the answer.

Two closing cautions on currency. Nothing here is legal advice, and a regulatory area that produced three new guidelines on a single day in April 2026 will produce more. Act 709 also has no consolidated reprint incorporating the 2024 amendments, so anyone reading the Act on the Attorney General's Chambers site is reading the 2010 print and needs to apply the amendments by hand. Check the current text of anything you are about to rely on, and get a Malaysian adviser to look at the version you actually publish. The technical setup, from pixel installation onwards, is the easy half of this.

By the numbers

6 grounds
Alternatives to consent in section 6(2) of Act 709 (a closed list)
Act 709, s.6(2)(a) to (f), as reproduced in the DPbD Guideline v1.0, 2026
8
Matters a section 7(1) personal data protection notice must state
Act 709, s.7(1)(a) to (h), as reproduced in the DPbD Guideline v1.0, 2026
2 (national language and English)
Languages a personal data protection notice must be in
Act 709, s.7(3), as reproduced in the DPbD Guideline v1.0, 2026
RM1,000,000
Maximum fine for contravening the Personal Data Protection Principles
Act A1727 s.4(b)(ii) amending Act 709 s.5(2), 2024
3 years
Maximum imprisonment for contravening the Personal Data Protection Principles
Act A1727 s.4(b)(ii) amending Act 709 s.5(2), 2024
1 April 2025
Date the raised principle penalties took effect
P.U. (B) 522, para (b), 2024
more than 20,000
DPIA quantitative threshold, data subjects
Personal Data Protection Guideline: DPIA, Version 1.0, para 7.5(a), 2026
2 years
Validity of a completed DPIA before a refresh is required
Personal Data Protection Guideline: DPIA, Version 1.0, para 11.2, 2026

Frequently asked questions

Does the Meta Pixel need consent under Malaysian law?

Start from section 6(1)(a) of Act 709, which says a data controller shall not process non-sensitive personal data about a data subject unless the data subject has given his consent. The alternatives sit in section 6(2), and there are only six of them: performance of a contract to which the data subject is a party, steps at the data subject's request with a view to entering a contract, compliance with a non-contractual legal obligation, protection of the data subject's vital interests, administration of justice, and the exercise of functions conferred by law. Each one applies only where the processing is necessary for that purpose. Advertising measurement and audience building do not obviously sit inside any of those six, which is why the practical answer for most advertisers is that consent is the route available. The threshold question before all of that is whether what your pixel sends back relates to an identifiable individual at all, so read the definition in section 4 of Act 709 against your actual event payload rather than assuming the answer in either direction.

Can I rely on legitimate interests the way we do under GDPR?

No. This is the single most expensive assumption a GDPR-trained marketer brings into Malaysia. The GDPR has a legitimate interests basis and a great deal of European ad-tech compliance is built on it. Act 709 has no equivalent. Section 6(2) is an exhaustive list of six grounds and legitimate interests is not one of them, and the Personal Data Protection (Amendment) Act 2024 did not amend section 6 at all. So a legitimate interests assessment, however carefully drafted, is not a lawful basis for processing in Malaysia. If your privacy documentation was adapted from a European template, this is the first thing to check and usually the first thing to fix.

Does the Conversions API change the analysis?

Not in the way people hope. Moving an event from the browser to your server changes the transport, not the legal character of the processing. You are still collecting information about a person's activity and passing it to a third party for advertising purposes, and in a server-side setup you are often sending more identifying detail rather than less, because advanced matching parameters like a hashed email or phone number are exactly what makes the API worth deploying. Sections 6, 7 and 8 of Act 709 apply to the processing and the disclosure, not to the technical route the packet takes. Treat browser tag and server event as one processing activity described in one notice, and if you deduplicate events across both, say so in plain language rather than leaving a reader to guess.

What exactly does the notice have to say about the pixel?

Section 7(1) sets out eight matters, and the two that most website notices get wrong are paragraph (e) and paragraph (f). Paragraph (e) requires the notice to state the class of third parties to whom the data controller discloses or may disclose the personal data, so a notice that talks vaguely about improving your experience without ever naming advertising and analytics platforms as a recipient class is incomplete on its face. Paragraph (f) requires the choices and means the data controller offers for limiting the processing, which for a pixel means telling the reader how to refuse or withdraw and giving them a working control. The remaining six cover the fact of processing and a description of the data, the purposes of collection and further processing, the source of the data, the right of access and correction plus contact details, whether supply is obligatory or voluntary, and the consequences of not supplying it.

Does my privacy notice have to be in Bahasa Melayu as well as English?

Section 7(3) of Act 709 provides that a notice under subsection (1) shall be in the national and English languages, and that the individual shall be provided with a clear and readily accessible means to exercise his choice, where necessary, in the national and English languages. Read those two limbs carefully because they are not identical. The bilingual requirement attaching to the notice itself is unqualified. The bilingual requirement attaching to the means of exercising choice carries the phrase where necessary, which is a qualifier the drafter put there deliberately. In practice, publishing both language versions of the notice and localising the consent interface as well is the low-risk position, and it costs one translation.

Do I have to run a Data Protection Impact Assessment for tracking?

The Commissioner's Data Protection Impact Assessment Guideline, Version 1.0 issued 30 April 2026, sets a two-tier approach. First come the quantitative thresholds in paragraph 7.5: processing expected to involve more than 20,000 data subjects, or processing of sensitive personal data including financial information data expected to involve more than 10,000 data subjects. Where neither is met, paragraph 7.6 asks the data protection officer to exercise best judgment on a non-exhaustive list of qualitative factors, one of which is tracking of the data subject's location or behaviour. The Guideline's own worked Example 2 is an e-commerce platform tracking browsing history, clicks, time on page and purchase activity to predict buying intent, personalise prices and deliver targeted advertisements, and it concludes that a DPIA is required. That example is close enough to a standard pixel deployment that most advertisers should assume the question is live. A completed DPIA is valid for two years from its date of completion under paragraph 11.2.

What are the penalties if we get this wrong?

Since 1 April 2025 the maximum penalty for contravening the seven Personal Data Protection Principles is a fine not exceeding one million ringgit or imprisonment for a term not exceeding three years or both, raised by the Personal Data Protection (Amendment) Act 2024 from three hundred thousand ringgit and two years. Notice and Choice is one of those seven principles, so a defective notice sits inside that exposure. Do not assume the million-ringgit ceiling applies everywhere in the Act, though: it attaches to section 5(2) and, through the new subsection 5(1a), to a data processor's breach of the Security Principle. Other offences carry their own separate ceilings. In practice the pressure often arrives long before any prosecution would: a customer complaint, or a client due-diligence questionnaire you cannot answer, which is a commercial problem before it is a legal one.

Is a pre-ticked cookie banner acceptable in Malaysia?

There is no statutory cookie rule in Malaysia, so the honest answer is that no instrument says pre-ticked is unlawful in terms. What does exist is the Commissioner's Data Protection by Design Guideline, Version 1.0 issued 30 April 2026, whose worked example of a compliant design has a business ensuring that by default only the strictly necessary cookies used by the online platform are active, with additional cookies activated only when the customer consents to their use, and opt-in checkboxes for marketing that are by default unchecked. That is the regulator describing what good looks like. Alongside it, paragraph 6.3 tells data controllers to refrain from deceptive design patterns that mislead or pressure the data subject, and paragraph 6.4(a) gives overloading as an example, illustrated by a website that asks the data subject to click through four different pop-up boxes just to confirm the cookie settings. A pre-ticked marketing box runs against the grain of all of that, and separately runs into regulation 3(5) of the 2013 Regulations, which puts the burden of proving consent on you.

Sources

Keep exploring

Turn ad research into winning ads

See what 16,000 Malaysian brands advertise, then generate on-brand creative, all in one tool.

7-day free trial · No credit card required