Malaysia's Personal Data Protection Commissioner has published a written test for when a Data Protection Impact Assessment is required. Most organisations have not run it against their projects.
It takes about a minute. Answer four questions and find out where you stand.
This follows the test set out in the Commissioner's DPIA Guideline and ADMP Guideline. It is not legal advice and it does not record anything until you choose to send yourself the result.
A DPIA is an assessment you carry out before you start processing personal data, not after.
You take a planned activity, describe exactly what personal data it will involve and why, work out what could go wrong for the people whose data it is, and decide whether the risks are acceptable. If they are not, you change the plan or add safeguards before anything goes live.
That is the whole idea. It is a structured way of asking "should we be doing this, in this way?" while there is still time to change the answer.
The Commissioner's DPIA Guideline describes it as a process for analysing and reducing personal data protection risk, based on how your organisation actually functions. It is deliberately practical. It is not a legal opinion and it is not a policy document.
There are three ways to get to yes, and you only need one of them.
If the activity involves automated decision-making or profiling, a DPIA is required. The Commissioner's ADMP Guideline treats this as a trigger regardless of the nature or extent of the intended use, and states that the DPO is to ensure a DPIA is carried out for any planned processing containing these elements.
There is no volume threshold attached to this one. Read section below for what counts.
A DPIA is required where the processing is expected to involve:
These are hard numbers. If you meet either, the analysis stops and a DPIA is required.
If neither threshold is met, the DPO exercises judgment against a list of factors that suggest high risk. The Guideline lists six, and is clear that the list is neither exhaustive nor exclusive:
Note how wide the third one is. "New to your organisation" is enough. It does not have to be new to the market.
The Guideline takes the sensible position that where it is not obvious whether a DPIA is required, it is prudent to carry one out anyway. It remains useful for managing risk and for building trust, whether or not it was strictly required.
Last reviewed: August 2026.
The volume thresholds are what most people notice first. The automation trigger is what actually catches them.
Broadly, any system that evaluates, scores, ranks, segments, or predicts something about a person, or that reaches a decision about them without a human making the final call. From the examples in the Commissioner's ADMP Guideline and in ordinary commercial practice, this covers a great deal of what businesses already run:
If you have adopted an AI tool anywhere in a process that touches people, you are very likely inside this category.
The Guideline sets out a five-step approach, abbreviated as DEICA.
Each risk is scored low, medium or high on both axes, and the resulting score places it in a band. The Guideline provides criteria for each score, so this is not a matter of instinct.
A DPIA is not a document you file and forget.
Report to senior management. Where the overall residual risk is assessed as high, the findings must go to senior management. Most organisations report everything, so that management has the full picture rather than half of it. Management then decides: accept the residual risk, require further mitigation, or do not proceed.
Implement the mitigation. The measures identified in the assessment have to actually be built. This is where the Commissioner's Data Protection by Design Guideline becomes the working document, since it sets out what good practice looks like under each of the seven data protection principles.
It expires. A completed DPIA is valid for two years from the date of completion. After that, a refreshed assessment is required.
It is monitored in between. The Guideline is clear that a DPIA is not a one-off activity. Regardless of the validity period, the processing has to be monitored and reviewed throughout its life. A material change to the processing means revisiting the assessment before the two years are up.
You may publish it. Publication is optional, but the Guideline encourages it as a way of building trust, and allows a redacted version or a summary where the full document would expose commercially sensitive information or create security risk.
If you carried out a DPIA in 2026, it expires in 2028. If you have several, they expire on different dates. Somebody has to be tracking that, monitoring the processing in the meantime, and refreshing each one before it lapses.
That is ongoing work rather than a project, which is why organisations that treat data protection as a series of one-off exercises tend to find themselves out of date without noticing.
Common Questions
Last reviewed: August 2026. Penalty figures verified against the gazetted Personal Data Protection (Amendment) Act 2024 (Act A1727).
A Data Protection Impact Assessment is a structured review of a planned processing activity, carried out before it begins, to identify and reduce risks to the people whose personal data is involved.
The Personal Data Protection Act 2010 contains no express DPIA section. The Commissioner's DPIA Guideline, issued under section 48(g), states that a DPIA shall be carried out where a planned operation is likely to result in high risk. In practice it should be treated as a requirement.
More than 20,000 data subjects, or more than 10,000 where sensitive personal data is involved. Financial information counts towards the lower threshold.
Generally yes. The Commissioner's ADMP Guideline treats automated decision-making and profiling as a trigger regardless of the extent of intended use, with no volume threshold attached.
The data controller. Ultimate responsibility for the assessment and the resulting decisions rests with senior management. The Data Protection Officer advises and identifies when one is needed.
No. The obligation sits with the controller. A processor is expected to give reasonable assistance, and the controller should secure that through contract.
Two years from the date of completion. After that a refreshed assessment is required, and the processing should be monitored in the meantime.
The five-step approach in the DPIA Guideline: Describe, Evaluate, Identify, Consider, Assess.
No. Publication is encouraged as a transparency measure, and a redacted version or summary may be published where the full document would expose sensitive information.
A DPIA looks at one planned activity in depth. A gap assessment looks at your whole organisation against the Act. Most organisations need both, for different reasons.
Before the processing begins. A DPIA is a prospective exercise. Carrying one out after a system is live is remedial work.
The Act contains no offence of failing to carry out a DPIA as such. The exposure is indirect but substantial. Since the 2024 amendments, breaching the data protection principles carries a fine of up to RM1,000,000, imprisonment of up to three years, or both, and failing to notify a personal data breach under section 12B carries up to RM250,000, two years, or both. A missing DPIA is what makes those failures difficult to defend, because it shows the risks were never assessed.