DPIA Malaysia

Do you need a DPIA?

Malaysia's Personal Data Protection Commissioner has published a written test for when a Data Protection Impact Assessment is required. Most organisations have not run it against their projects.

It takes about a minute. Answer four questions and find out where you stand.

Four questions

This follows the test set out in the Commissioner's DPIA Guideline and ADMP Guideline. It is not legal advice and it does not record anything until you choose to send yourself the result.

4
questions in the self-check
1 min
to find out where you stand
Free
self-check and drafting tool
35
questions in the full Assistant

What a DPIA actually is

A DPIA is an assessment you carry out before you start processing personal data, not after.

You take a planned activity, describe exactly what personal data it will involve and why, work out what could go wrong for the people whose data it is, and decide whether the risks are acceptable. If they are not, you change the plan or add safeguards before anything goes live.

That is the whole idea. It is a structured way of asking "should we be doing this, in this way?" while there is still time to change the answer.

The Commissioner's DPIA Guideline describes it as a process for analysing and reducing personal data protection risk, based on how your organisation actually functions. It is deliberately practical. It is not a legal opinion and it is not a policy document.

When a DPIA is required

There are three ways to get to yes, and you only need one of them.

1. Automated decision-making or profiling

If the activity involves automated decision-making or profiling, a DPIA is required. The Commissioner's ADMP Guideline treats this as a trigger regardless of the nature or extent of the intended use, and states that the DPO is to ensure a DPIA is carried out for any planned processing containing these elements.

There is no volume threshold attached to this one. Read section below for what counts.

2. The volume thresholds

A DPIA is required where the processing is expected to involve:

  • more than 20,000 data subjects, or
  • more than 10,000 data subjects, where sensitive personal data is involved. Financial information counts for this purpose.

These are hard numbers. If you meet either, the analysis stops and a DPIA is required.

3. The qualitative factors

If neither threshold is met, the DPO exercises judgment against a list of factors that suggest high risk. The Guideline lists six, and is clear that the list is neither exhaustive nor exclusive:

  • potential legal or significant effects on a person, meaning a noticeable impact on their legal position, finances, health, reputation, or access to services and opportunities
  • systematic monitoring
  • use of innovative technology, which includes a new or significantly improved product, process, marketing method, organisational method, or way of organising work
  • denial or restriction of a person's rights
  • tracking of location or behaviour
  • targeting of children or other vulnerable individuals

Note how wide the third one is. "New to your organisation" is enough. It does not have to be new to the market.

If none of them apply

The Guideline takes the sensible position that where it is not obvious whether a DPIA is required, it is prudent to carry one out anyway. It remains useful for managing risk and for building trust, whether or not it was strictly required.

If you use AI, this section is the one that matters

Last reviewed: August 2026.

The volume thresholds are what most people notice first. The automation trigger is what actually catches them.

What counts as automated decision-making or profiling

Broadly, any system that evaluates, scores, ranks, segments, or predicts something about a person, or that reaches a decision about them without a human making the final call. From the examples in the Commissioner's ADMP Guideline and in ordinary commercial practice, this covers a great deal of what businesses already run:

If you have adopted an AI tool anywhere in a process that touches people, you are very likely inside this category.

How a DPIA is carried out

The Guideline sets out a five-step approach, abbreviated as DEICA.

Describe.
Set out the processing operation and its purpose.
Evaluate.
Test whether the plan is necessary and proportionate.
Identify.
Work out the specific risks to the people whose data it is.
Consider.
Decide what to do about each risk.
Assess.
Score each risk on likelihood and impact using a three by three matrix.

Each risk is scored low, medium or high on both axes, and the resulting score places it in a band. The Guideline provides criteria for each score, so this is not a matter of instinct.

What happens after

A DPIA is not a document you file and forget.

Report to senior management. Where the overall residual risk is assessed as high, the findings must go to senior management. Most organisations report everything, so that management has the full picture rather than half of it. Management then decides: accept the residual risk, require further mitigation, or do not proceed.

Implement the mitigation. The measures identified in the assessment have to actually be built. This is where the Commissioner's Data Protection by Design Guideline becomes the working document, since it sets out what good practice looks like under each of the seven data protection principles.

It expires. A completed DPIA is valid for two years from the date of completion. After that, a refreshed assessment is required.

It is monitored in between. The Guideline is clear that a DPIA is not a one-off activity. Regardless of the validity period, the processing has to be monitored and reviewed throughout its life. A material change to the processing means revisiting the assessment before the two years are up.

You may publish it. Publication is optional, but the Guideline encourages it as a way of building trust, and allows a redacted version or a summary where the full document would expose commercially sensitive information or create security risk.

The practical consequence

If you carried out a DPIA in 2026, it expires in 2028. If you have several, they expire on different dates. Somebody has to be tracking that, monitoring the processing in the meantime, and refreshing each one before it lapses.

That is ongoing work rather than a project, which is why organisations that treat data protection as a series of one-off exercises tend to find themselves out of date without noticing.

Talk to us

We use these details to respond to your enquiry. Enquiries that do not become client matters are deleted 24 months from last contact. See our privacy notice.

Common Questions

Frequently asked questions

Last reviewed: August 2026. Penalty figures verified against the gazetted Personal Data Protection (Amendment) Act 2024 (Act A1727).

What is a DPIA?

A Data Protection Impact Assessment is a structured review of a planned processing activity, carried out before it begins, to identify and reduce risks to the people whose personal data is involved.

Is a DPIA mandatory in Malaysia?

The Personal Data Protection Act 2010 contains no express DPIA section. The Commissioner's DPIA Guideline, issued under section 48(g), states that a DPIA shall be carried out where a planned operation is likely to result in high risk. In practice it should be treated as a requirement.

What is the DPIA threshold in Malaysia?

More than 20,000 data subjects, or more than 10,000 where sensitive personal data is involved. Financial information counts towards the lower threshold.

Does using AI mean I need a DPIA?

Generally yes. The Commissioner's ADMP Guideline treats automated decision-making and profiling as a trigger regardless of the extent of intended use, with no volume threshold attached.

Who is responsible for carrying out a DPIA?

The data controller. Ultimate responsibility for the assessment and the resulting decisions rests with senior management. The Data Protection Officer advises and identifies when one is needed.

Does a data processor need to carry out a DPIA?

No. The obligation sits with the controller. A processor is expected to give reasonable assistance, and the controller should secure that through contract.

How long is a DPIA valid?

Two years from the date of completion. After that a refreshed assessment is required, and the processing should be monitored in the meantime.

What is DEICA?

The five-step approach in the DPIA Guideline: Describe, Evaluate, Identify, Consider, Assess.

Do I have to publish my DPIA?

No. Publication is encouraged as a transparency measure, and a redacted version or summary may be published where the full document would expose sensitive information.

What is the difference between a DPIA and a PDPA gap assessment?

A DPIA looks at one planned activity in depth. A gap assessment looks at your whole organisation against the Act. Most organisations need both, for different reasons.

When should a DPIA be carried out?

Before the processing begins. A DPIA is a prospective exercise. Carrying one out after a system is live is remedial work.

What happens if I do not carry out a DPIA?

The Act contains no offence of failing to carry out a DPIA as such. The exposure is indirect but substantial. Since the 2024 amendments, breaching the data protection principles carries a fine of up to RM1,000,000, imprisonment of up to three years, or both, and failing to notify a personal data breach under section 12B carries up to RM250,000, two years, or both. A missing DPIA is what makes those failures difficult to defend, because it shows the risks were never assessed.