Donor Data & Privacy
The PDPA 2024 amendments: what changed, and what it means for an NPO holding donor data
Reference material, not legal or tax advice. Confirm with LHDN or your own advisor before acting.
On this page
The short answer
Does the PDPA even apply to an NPO?
A committee member asks "are we even covered by this?" and it's fair — nobody sent your temple or clan association a letter telling you the Act applies.
The Personal Data Protection Act 2010 (Act 709) applies to a person who processes, or controls the processing of, personal data "in respect of commercial transactions" [3, s.2(1)] — defined broadly as "any transaction of a commercial nature, whether contractual or not, which includes any matters relating to the supply or exchange of goods or services, agency, investments, financing, banking and insurance" [3, s.4]. Nothing in the 2024 amendments touched this definition, and neither the Act nor the JPDP's published FAQ addresses non-profit organisations by name [6].
What that leaves you with, honestly:
- If your organisation sells anything — tickets, merchandise, tablet dedications for a fee, memberships, hall rentals — that data is "in respect of a commercial transaction" without much argument. (Whether a ritual offering is a donation or a sale is its own question — see Donation or sale?.)
- A pure donation, given with nothing expected in return, sits less clearly inside "any transaction of a commercial nature." No JPDP guideline, circular or FAQ we could find takes a position on this specifically.
- In practice, most NPOs' data processing is mixed, so treating the whole organisation as in scope is the safer working assumption.
Practical tip: don't wait for a definitive answer before you act. Apply the Act's principles — notice, consent, security, retention — to donor data as practice, and confirm your position with a data protection consultant or the JPDP (03-7456 3888, [email protected]) if you need a firm answer for board minutes or a funder's due diligence.
What the 2024 amendments actually changed
The Personal Data Protection (Amendment) Act 2024 (Act A1727) received Royal Assent on 9 October 2024 and was gazetted on 17 October 2024 [1]. It didn't commence all at once — the Minister of Digital appointed three separate commencement dates by gazette notification on 19 December 2024 (published 24 December 2024, P.U.(B) 522/2024) [2]:
| Commencement date | Sections of Act A1727 | What it changed |
|---|---|---|
| 1 January 2025 | 7, 11, 13, 14 | Procedural only: a drafting fix, fee collection, electronic-means compliance, savings provisions. No new NPO obligations. |
| 1 April 2025 | 2, 3, 4, 5, 8, 10, 12 | "Data user" split into "data controller"/"data processor"; biometric data added to sensitive personal data; "personal data breach" defined; deceased individuals excluded from "data subject"; Security Principle now binds processors directly; penalty for breaching any of the seven Personal Data Protection Principles rises from RM300,000/2 years to RM1,000,000/3 years; cross-border transfer rules reworked. |
| 1 June 2025 | 6, 9 | The two changes people usually mean by "the PDPA changed": mandatory Data Protection Officer appointment (new s.12A) and data breach notification (new s.12B); plus a new data portability right (new s.43A). |
Source: Act A1727 itself [1] for what each section does, and P.U.(B) 522/2024 [2] for the dates — the gazetted answer to "when did this actually start."
Two smaller changes, neither a new obligation:
- Deceased individuals are no longer "data subjects" [1, s.3(f)]. Records naming deceased family members — a memorial tablet, an ancestor listing — fall outside the Act's protections, though your own retention practices are still your call.
- Cross-border transfer was reworked. The old s.129 gave the Minister sole power to specify, by Gazette, which countries a controller could transfer data to. The amended section drops that step: a controller may transfer directly where the destination's law is substantially similar to Act 709 or offers equivalent protection — or under specific grounds including consent, contractual or legal necessity, vital interests, or the controller's own due diligence, among others (one narrower ground, "public interest," was removed) [1, s.12; 3, s.129]. Relevant if you use an overseas email platform, cloud backup or payment processor.
Do you need a Data Protection Officer?
"Who would even be our DPO?" is the real question behind this one, for an organisation run mostly by volunteers.
Section 12A requires a data controller (and, separately, a processor) to appoint one or more DPOs "accountable... for the compliance with this Act" [1, s.6]. The JPDP's Guideline on the Appointment of Data Protection Officer (v1.0, 25 Feb 2025) sets the mandatory conditions [4]: appoint a DPO if your processing involves —
- personal data exceeding 20,000 data subjects; or
- sensitive personal data (including financial information) exceeding 10,000 data subjects; or
- activities requiring regular and systematic monitoring of personal data — the guideline's examples are behavioural-advertising tracking, wearable health data, or CCTV, not the kind of processing a typical donor database does [4, §4.2–4.3].
For most temple committees, clan associations and mid-sized charities, the 20,000-donor threshold is the one to watch, and many won't cross it. If you do, the guideline still allows a DPO to be appointed "from among existing employees or through outsourcing services," and to serve part-time [4, §6.3–6.5]. That wording is built around "employees," not volunteers — for a body with no paid staff, our own reading is that an active committee member taking on the role would fit its spirit, but that's this article's interpretation, not a guideline quote; confirm with the JPDP if you need certainty. The DPO must be resident in Malaysia (180 days a year) or easily contactable, and bilingual (Bahasa Melayu/English) [4, §6.10]. Once appointed, you have 21 days to register their details via SPDP (daftar.pdp.gov.my) [4, §7.1].
Practical tip: even if you're comfortably under the thresholds, keep a short written note of your donor count and why a DPO isn't mandatory — the guideline explicitly allows organisations to "keep a record on the reasons for not appointing" one [4, §4.5].
If donor data leaks from a laptop or a spreadsheet
This is the scenario that keeps a treasurer up at night: a volunteer's laptop with the donor spreadsheet goes missing, or a donor list gets emailed to the wrong person.
Section 12B makes this a legal duty, and — unlike the DPO requirement — it applies to any data controller in the Act's scope, regardless of size. The JPDP's Guideline on Data Breach Notification (v1.0, 25 Feb 2025) sets out the mechanics [5]:
- A "personal data breach" is any breach, loss, misuse or unauthorised access of personal data — the guideline's own examples include "an employee accidentally losing/misplacing a company-issued laptop containing unencrypted personal data" [5, §4.2].
- You must notify the Commissioner if the breach causes or is likely to cause "significant harm" — financial loss, sensitive personal data being involved, risk of identity fraud, or affecting more than 1,000 data subjects ("significant scale") [5, §5.2–5.3].
- The deadline is 72 hours. §6.1's own wording sets the clock running "from the occurrence of the personal data breach" — but §6.2's worked examples run it from when you're informed or become aware instead (a lost USB key: the clock starts "as soon as the data controller is informed of the loss," not from whenever the key actually went missing) [5, §6.1–6.2]. Work to the awareness standard in §6.2 — that's the guideline's own applied rule.
- If the breach is likely to cause significant harm to the data subjects themselves, you must also notify them — within 7 days of your notification to the Commissioner [5, §9.1].
- You must keep a breach register for at least 2 years, covering every breach you assess — including ones that didn't meet the notification threshold [5, §14.1].
- Failing to notify the Commissioner is itself an offence: a fine of up to RM250,000 or up to 2 years' imprisonment, or both [1, s.6 (new s.12B(3))].
Practical tips:
- Write down, in one page, who assesses a missing laptop or USB drive, who decides whether it's notifiable, and who submits the form. The 72-hour clock is shorter than most committees' meeting cycle.
- Encryption matters: the guideline treats a lost laptop with unencrypted donor data very differently from one with encrypted data a thief can't actually read [5, §4.2, §5.4].
- Notify via the official form on pdp.gov.my, or by email to [email protected] [5, §7.1] — bookmark it before you need it.
Donors asking for their own data
A donor calls and asks: "what do you have on me, and can you send it to me, or to another organisation?"
The 2024 amendments added a data portability right (new s.43A): a data subject can ask a controller to transmit their personal data directly to another controller of their choice, subject to technical feasibility [1, s.9]. The transmission must happen "within the period as may be prescribed" [1, s.9] — we could not locate a regulation setting that period, so treat the timeline as not yet confirmed. This sits alongside the pre-existing data access and correction rights, unchanged by the 2024 amendments.
Practical tip: you don't need a formal portability request to answer "what do you have on me" quickly — see how DonorCARE handles that below.
What this means for your organisation
- Work out whether — and where — the Act applies to you. Any part of your income that's a sale is in scope without argument; treat donor data the same way as good practice elsewhere.
- Count your donor records. Nowhere near 20,000 total, or 10,000 with sensitive/financial data? You likely don't need a mandatory DPO — but write down that you checked.
- If you do cross the threshold, appoint someone, register within 21 days, and make sure they're contactable and bilingual.
- Write a one-page breach response plan now — who assesses, who decides on notification, and how you'd hit the 72-hour and 7-day deadlines.
- Encrypt what leaves the office — a laptop, a USB drive, an exported spreadsheet.
- Know how you'd answer a donor who asks what you hold on them, and be ready for a portability request even though its timeline isn't yet prescribed.
- Review your position whenever the JPDP issues something new — this area moved through three commencement dates and two guidelines in under a year.
Common questions
Is our NPO definitely covered by the PDPA?
Not definitely either way. The Act applies to data processed "in respect of commercial transactions" [3, s.2, s.4]. Selling anything puts that in scope; a pure donation is less clearly defined, and no JPDP guidance addresses NPOs specifically [6]. Treat donor data as in scope as good practice, and confirm with a consultant or the JPDP if you need certainty.
Do we need to appoint a Data Protection Officer?
Only if your processing involves more than 20,000 data subjects, more than 10,000 sensitive/financial-data subjects, or regular and systematic monitoring [4, §4.2]. Most small and mid-sized NPOs won't cross these thresholds, but should keep a record of the assessment.
What happens if a volunteer loses a laptop with donor data on it?
If it's likely to cause significant harm — unencrypted, sensitive, or affecting more than 1,000 people — notify the Commissioner within 72 hours of becoming aware (not of the loss itself), and affected donors within 7 days of that if significant harm applies to them too [5, §5–9]. This applies whether or not you have a mandatory DPO.
Can a donor ask us to hand over their data?
The 2024 amendments added a right for a data subject to ask you to transmit their data directly to another data controller [1, s.9, new s.43A], "within the period as may be prescribed" — we could not confirm a regulation has set that period, so check pdp.gov.my before quoting one.
When did all this actually start?
In three stages, all now in force: 1 January, 1 April and 1 June 2025, gazetted 19 December 2024 (P.U.(B) 522/2024) [2]. The DPO and breach-notification duties started 1 June 2025.
What are the penalties if we get this wrong?
Failing to notify the Commissioner of a notifiable breach: up to RM250,000 or 2 years, or both [1, s.6]. Breaching any of the seven Personal Data Protection Principles: up to RM1,000,000 or 3 years, or both, as of 1 April 2025 — up from RM300,000/2 years [3, s.5; 1, s.4].
Does this article cover anti-money-laundering rules for NPOs too?
No — a separate, unsettled area outside this article's scope.
Sources
- 1.Attorney General's Chambers of Malaysia / Jabatan Peguam Negara, Laws of Malaysia, Act A1727 — Personal Data Protection (Amendment) Act 2024, Royal Assent 9 October 2024. https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/11/Act-A1727.pdf — extends the Security Principle to processors; adds DPO appointment, breach notification, data portability and cross-border transfer changes.
- 2.Jabatan Peguam Negara / Ministry of Digital, Federal Government Gazette P.U. (B) 522, Appointment of Date of Coming into Operation (Personal Data Protection (Amendment) Act 2024), dated 19 December 2024, published 24 December 2024. https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/12/PENETAPAN-TARIKH-PERMULAAN-KUAT-KUASA.pdf — the three commencement dates (1 January, 1 April, 1 June 2025) and which sections of Act A1727 attach to each.
- 3.Personal Data Protection Commissioner of Malaysia (JPDP), Personal Data Protection Act 2010 (Act 709), consolidated Malay/English text (2022 printing). https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/07/UNDANG-UNDANG-MALAYSIA_AKTA_PERLINDUNGAN_DATA_PERIBADI_2010_709_MALAY_AND-ENG_V2022.pdf — pre-amendment text: "commercial transactions" scope and definition, the seven Principles and their penalties, and the prior cross-border transfer mechanism.
- 4.Personal Data Protection Commissioner of Malaysia (JPDP), Personal Data Protection Guideline: Appointment of Data Protection Officer, Version 1.0, Date of Issuance 25 February 2025. https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/08/GP_DPO_ENG.pdf — mandatory-appointment thresholds, part-time/outsourced appointment rules, and the 21-day SPDP registration deadline.
- 5.Personal Data Protection Commissioner of Malaysia (JPDP), Personal Data Protection Guideline: Data Breach Notification, Version 1.0, Date of Issuance 25 February 2025. https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/08/GP_DBN_ENG.pdf — "significant harm"/"significant scale" criteria, 72-hour Commissioner deadline, 7-day data-subject deadline, 2-year breach register retention.
- 6.Personal Data Protection Commissioner of Malaysia (JPDP), FAQ page, https://www.pdp.gov.my/ppdpv1/en/faq/ — reviewed for, and found to contain no guidance on, whether the Act applies to non-profit, charitable or religious organisations specifically. Cited to support the statement that this scope question is unaddressed by the regulator, not as a source for a specific rule.
Spotted something out of date? Let us know.

