PDPA compliance, Cyber Security Act 2024 and NCII obligations, and ISO/IEC 27001 certification support for organisations operating in Malaysia.
Malaysia’s compliance landscape shifted materially between 2024 and 2025, and many organisations are still catching up with obligations that are already in force.
The amendment introduced substantial new duties. Qualifying data controllers and processors must appoint a Data Protection Officer. A mandatory data breach notification regime now requires the Commissioner to be notified within 72 hours of becoming aware of a breach, with affected individuals notified where the breach is likely to cause significant harm. Both obligations came into force on 1 June 2025, supported by guidelines issued by the Commissioner.
Penalties rose sharply at the same time — to fines of up to RM 1 million and imprisonment of up to three years, from the previous RM 300,000 and two years. Data processors also now carry direct obligations rather than sitting behind their controllers.
The Cyber Security Act establishes the National Cyber Security Agency’s expanded role and creates obligations for entities designated as National Critical Information Infrastructure. Designated NCII entities must implement their sector’s code of practice, conduct a cyber security risk assessment at least annually, undergo a cyber security audit at least once every two years, and report cyber security incidents to NACSA and their sector lead.
Non-compliance carries penalties of up to RM 500,000, imprisonment of up to ten years, or both. The Act also introduced a licensing regime for certain cyber security service providers, which is worth checking if you procure security services locally.
The two regimes intersect. An NCII entity handling personal data faces annual risk assessment and biennial audit under the Cyber Security Act, plus DPO appointment, breach notification within 72 hours, and cross-border transfer controls under the PDPA. Run separately, that is two programmes collecting overlapping evidence.
The 72-hour clock deserves particular attention. Most organisations discover during their first real incident that the constraint is not detection but decision-making — establishing quickly enough whether a breach is notifiable, and who has authority to decide. That is a process problem to solve before an incident, not during one.
Where you want a platform rather than spreadsheets, GRCLens runs ISO/IEC 27001, SOC 2, PCI DSS and other frameworks on a shared control model, and can be deployed on-premises or in a Malaysia-hosted environment where residency is required.
No — the requirement applies to qualifying data controllers and processors, with the Commissioner’s guidelines setting out the thresholds. Assess whether you qualify rather than assuming either way, because the appointment carries defined responsibilities once made.
The Commissioner must be notified within 72 hours of becoming aware of the breach. Where the breach is likely to cause significant harm, affected individuals must also be notified without unnecessary delay.
NCII designation is made under the Cyber Security Act across defined sectors. If you operate in a sector such as banking, energy, healthcare, transport, water or government services and provide services the country depends on, it is worth assessing your position formally rather than waiting to be told.
Substantially. Both regimes expect risk assessment, access control, incident response and third-party management, all of which map onto ISO/IEC 27001 Annex A. Regime-specific duties — DPO appointment, statutory notification timelines, NCII audit cycles — still need addressing explicitly.
Whether the driver is the PDPA amendments, NCII designation or a customer asking for ISO 27001, we can set out what applies and what it will realistically take. Get in touch.

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informe with the latest cybersecurity news, expert tips.
Copyright © 2026 All Rights Reserved.