Yes, if your website collects personal data for business. Malaysia’s Personal Data Protection Act 2010 (PDPA) covers personal data processed in commercial transactions, and a contact form, quotation form, newsletter sign-up or online checkout all collect it. Your website needs a privacy notice in Bahasa Malaysia and English, a clear way for people to make choices, secure handling of what they submit, and a plan for data breaches.
The rules became stricter in 2025. Below is what the law says and what it means for a typical business website.
When the PDPA applies to a website
The PDPA regulates the processing of personal data in commercial transactions, and has been in force since 1 January 2013. Personal data is information that relates to a person who can be identified from it, such as a name, phone number, email address or IC number.
If a visitor can type any of these into your website and send it to your business, your website is processing personal data. That includes:
- Contact and enquiry forms
- Quotation or booking forms
- Newsletter sign-ups
- Job application forms
- Online stores that take delivery addresses
- WhatsApp or live chat widgets that collect a name and number
A website that only shows information, with no forms and no tracking of named users, collects far less. Most business websites have at least one form.
What the law requires: the privacy notice
Section 7 of the PDPA, the Notice and Choice Principle, requires a written notice telling people that their data is being processed, what data is collected and why, among other matters. Law firm Shearn Delamore’s PDPA compliance guide (read September 2026) lists the purpose of collection and the third parties the data is shared with as required contents.
Two details catch many websites out:
- Timing. The notice must be given as soon as practicable, including when a person is first asked for their data. On a website, that means the notice should be linked right at the form, not only in the footer.
- Language. Section 7(3) states: “A notice under subsection (1) shall be in the national and English languages.” A privacy notice in English only does not meet this. Large companies publish both versions; Deloitte Malaysia’s notice, for example, says it is issued in English and Bahasa Malaysia “in accordance with Section 7(3) of the PDPA”.
What changed in 2025
The Personal Data Protection (Amendment) Act 2024 came into force in phases during 2025. Three changes matter most for website owners.
| Change | What it means | Source (read September 2026) |
|---|---|---|
| Higher penalties | Maximum fine for breaching the data protection principles rose from RM300,000 to RM1,000,000, and maximum prison term from two to three years | Mayer Brown |
| Data breach notification | From 1 June 2025, section 12B requires a data controller who believes a personal data breach has happened to notify the Commissioner as soon as practicable. The Commissioner’s guideline of 25 February 2025 sets a 72-hour deadline | Shearn Delamore |
| Data Protection Officer | From June 2025, data controllers and processors must appoint a Data Protection Officer (DPO), under a Commissioner’s guideline that sets out when this applies | Mayer Brown, One Asia Lawyers |
Law firms describe the 72-hour clock differently: one says it runs from when the breach occurs, another from when the business becomes aware of it. Where the timing matters to you, read the Commissioner’s guideline itself or ask a lawyer.
Where a breach causes or is likely to cause significant harm, section 12B(2) also requires the business to tell the affected people without unnecessary delay.
Website checklist
Use this as a working list with your web team. It is a practical guide, not legal advice.
- Publish a privacy notice in both Bahasa Malaysia and English. Cover what you collect, why, who you share it with, and how people can contact you about their data.
- Link the notice at every form. Place a short line and link next to the submit button, not only in the footer.
- Collect only what you need. If a phone number is enough for a quotation, do not ask for an IC number.
- Separate marketing consent. If you plan to send newsletters or promotions, add a separate checkbox that is not ticked by default.
- Use HTTPS on every page. Form data should never travel over an unencrypted connection.
- Limit who sees form submissions. Review who receives enquiry emails and who can log in to the website and CRM.
- Decide how long you keep data. Delete old enquiries and job applications you no longer need.
- Know your plugins and tools. Form plugins, chat widgets, analytics and CRMs may store data on third-party servers. List them in your notice.
- Prepare a breach plan. Decide who investigates, who notifies the Commissioner, and how quickly. The 72-hour guideline leaves little time to plan during an incident.
- Check whether you need a DPO. Read the Commissioner’s DPO guideline, and publish the DPO’s contact details if you appoint one.
What the PDPA does not settle
The PDPA does not spell out rules for cookies or analytics tags in the way some other countries’ laws do. If your analytics or advertising tools identify individual users, treat that data with the same care as a form submission, and describe it in your privacy notice.
It also does not tell you exactly how to word your notice or which plugin to use. Those choices are yours, as long as the notice covers what section 7 requires and your security is reasonable for the data you hold.
The PDPA also covers commercial transactions. Federal and state government bodies are outside its scope, but a private company working on a government project is not.
For a website built with these points from the start, talk to our corporate web design team. If your site already exists, a website maintenance plan covers HTTPS, plugin updates and backups, and our website maintenance checklist shows what to check each month. Before you hire anyone, check who owns your website, because you cannot fix a form you cannot log in to.
Frequently Asked Questions
Does a website with only a contact form need a privacy notice?
Yes. A contact form collects names, emails or phone numbers, which are personal data. Under section 7 of the PDPA, you need to give a written notice when you first ask for that data.
Does the privacy notice have to be in Bahasa Malaysia?
Yes. Section 7(3) of the PDPA says the notice shall be in the national and English languages, so publish both versions.
What is the maximum PDPA fine now?
After the 2024 amendments, the maximum fine for breaching the data protection principles is RM1,000,000, up from RM300,000, with a maximum prison term of three years.
How fast must a data breach be reported?
Section 12B requires notice to the Commissioner as soon as practicable, and the Commissioner’s guideline of 25 February 2025 sets a 72-hour deadline.