Donor Data & Privacy
Can we email our donors? PDPA rules on donor newsletters, consent and unsubscribes
Reference material, not legal or tax advice. Confirm with LHDN or your own advisor before acting.
On this page
The short answer
Are you even covered? The "commercial transactions" question
This is the question that comes up in almost every committee meeting where someone proposes an email newsletter: "Are we even allowed to do this — we're not a business." It's a fair question, and the honest answer is that Malaysian law doesn't spell it out for organisations like yours.
Section 2 of the PDPA states that the Act applies to a person who processes personal data "in respect of commercial transactions" [1, 2]. Section 4 defines "commercial transactions" as "any transaction of a commercial nature… which includes any matters relating to the supply or exchange of goods or services, agency, investments, financing, banking and insurance" [3]. A pure donation — money given with nothing supplied in exchange — sits awkwardly against that wording. JPDP's own website confirms the Act does not apply to the Federal or State Government [1], but its FAQ and guidance pages don't address non-profit, society or religious-body donor data one way or the other [1, 2, 4]. We could not find a JPDP guideline or public statement that resolves this for NPOs specifically — if one exists, it should replace this section on the next review.
What isn't ambiguous: the moment your organisation sells something — a memorial tablet, an event ticket, a cookbook, hall rental — that transaction is plainly "of a commercial nature," so the data behind it is covered regardless of how the rest of your income arrives. Most NPOs running any paid activity alongside pure donations are, in practice, already partly inside PDPA's scope.
Practical tips:
- Don't treat "we're a non-profit" as a blanket exemption — it isn't stated as one anywhere in the Act or on JPDP's own site, and any commercial activity you also run is covered regardless.
- If your donor list mixes people who only ever donated with people who bought a ticket or a tablet, treat the whole list the same way rather than trying to split hairs by transaction type.
- When in doubt, follow the principles below anyway. They cost little to apply and protect you either way — as good practice if PDPA turns out not to apply to pure donations, and as compliance if it does.
The seven principles, if you're following them (and you probably should)
The pain here shows up as a donor calling to say "I never agreed to this" — or a committee member asking what your organisation's actual policy is, and nobody having an answer beyond "we've always done it this way."
JPDP's own summary states that data users must observe seven data protection principles, set out in sections 5 to 12 of the Act: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access [4]. In JPDP's own plain-language description [4]:
- General Principle — you may not process someone's personal data without their consent.
- Notice and Choice Principle — the data subject must be told, before or at the time you collect their data, what it will be used for, and given a choice about it.
- Disclosure Principle — data may not be disclosed for a purpose other than the one it was collected for (or a directly related one) without further consent.
- Security Principle — you must take practical steps to keep the data secure from loss, misuse or unauthorised access.
- Retention Principle — you may not keep personal data longer than necessary for the purpose it was collected for.
- Data Integrity Principle — the data must be accurate, complete and kept up to date for its purpose.
- Access Principle — the person has the right to see what you hold on them and ask for corrections.
Two of these carry the most weight for a donor newsletter. Notice and Choice turns "we found your email in the receipt book" into something defensible: if you collect an address to issue a receipt, and later want to use it for appeals too, the honest reading is that you should have said so up front and given the donor a way to decline. Disclosure is the one that matters the moment a spreadsheet of donor emails gets forwarded to a volunteer or mailing house for a joint appeal — that's a use for a new purpose, and it needs its own basis.
Practical tips:
- Add one line to your donation form and event sign-up form: what you'll use the contact details for (receipts, updates, appeals) and how to opt out later. This single sentence does most of the Notice and Choice work.
- Treat "the receipt book" and "the mailing list" as two different purposes in your own head, even if they end up as the same spreadsheet — it changes what you're allowed to assume.
- Never hand a raw donor spreadsheet to a volunteer, printer or mailing house without checking whether that counts as a disclosure your donors were told about.
The one right every donor has, regardless: stopping direct marketing
This is the pain of the donor who unsubscribed, or asked a committee member directly to stop emailing them, and got another appeal three months later anyway — usually because whoever ran the campaign wasn't the person who took the request, and there was nowhere it was written down.
Section 43 of the PDPA gives a data subject the right to require, in writing, that an organisation stop processing their personal data for direct marketing [5]. Section 43 itself doesn't require writing back to confirm compliance — that duty sits in a neighbouring right, section 42, not this one — but JPDP's consumer-facing guidance recommends telling the donor once you've done it, which is good practice either way [5]. JPDP's own data subject rights page also states plainly that organisations must obtain permission before contacting someone by "facsimile machine or automated dialer… or via electronic mail" for direct marketing [5] — as close as the regulator comes to saying email marketing needs agreement up front, not an assumption that one gift means hearing from you forever. If the organisation doesn't act, the data subject can escalate to the Commissioner, who can direct compliance [5].
Practical tips:
- However someone tells you to stop — replying to an email, phoning the office, telling a volunteer at an event — write it down in one place the next person sending a campaign will actually check.
- Don't rely on a single committee member's memory or personal phone to hold your opt-out list; if they're unavailable, the next sender has no way to know who asked to be left alone.
- Treat "stop emailing me" as permanent until the donor says otherwise, not as something that resets when a new appeal season starts.
Do you need to register with the Commissioner?
Some organisations worry they need to register with JPDP before sending so much as one email. Under section 14 of the Act, the Minister — on the Commissioner's recommendation — can specify by Gazette order which classes of data users must register [1]. The current Personal Data Protection (Class of Data Users) Order 2013, as amended in 2016, lists 13 classes that must register: communications, banking and financial institutions, insurance, health, tourism and hospitality, transportation, education, direct selling, professional services, real estate, utilities, pawnbroking and moneylending [6]. Charities, societies, religious bodies and other non-profits are not among them [6]. On the current Order, most NPOs are not in a class that must register — but it's a subsidiary order the Minister can amend, so check JPDP's own list if your activities sit close to one of those 13 classes.
Practical tip: don't assume registration is required just because you handle personal data at scale — it's tied to being in one of the 13 listed classes, not to donor-list size.
What the 2024 amendments changed here
The Personal Data Protection (Amendment) Act 2024 (Act A1727) is a substantial update — mandatory breach notification, a Data Protection Officer requirement for some data controllers, and more, covered in full in What the 2024 PDPA amendments changed for your NPO. For this article's narrow question, one thing matters: the amendment renamed "data user" to "data controller" throughout the Act but did not change section 2's "commercial transactions" scope test [7]. So the scope question above is unchanged — if your pure donations were outside PDPA's reach before, the amendment doesn't bring them in; if you were covered because of a commercial activity, you still are.
What this means for your organisation
- Don't assume "we're a non-profit" puts you outside the law. Anything you sell alongside your donations is covered regardless of your other income.
- Tell donors, at the point you collect their email or phone number, what you'll use it for — receipts only, or receipts plus updates and appeals — on the form itself.
- Get agreement before sending marketing email, rather than assuming a past donation implies consent to every future appeal.
- Give every marketing email a working way to opt out, and make sure it stops future sends from every campaign anyone on your team sends afterwards, not just one inbox.
- Keep one record of who has asked to stop, not a memory held by whoever took the call.
- Don't hand raw donor spreadsheets to volunteers or printers without checking donors were told their data might be shared that way.
- Check whether you fall into one of the 13 registrable classes if you run an activity that resembles one — most pure fundraising and religious/community work doesn't.
Common questions
Do we need donors' consent before sending a newsletter?
The Act's Notice and Choice Principle expects you to tell a data subject what their data will be used for and give them a choice [4], and JPDP's own site states organisations need permission before contacting someone by email for direct marketing [5]. Whether the Act technically applies to a pure-donation relationship is unresolved (see above) — but getting agreement first is the safer practice regardless, and it's what donors expect.
A donor asked us to stop emailing them. What are we required to do?
Section 43 gives the donor the right to require you to stop processing their data for direct marketing [5]. Confirming compliance back to them isn't a section 43 duty itself (that sits in the neighbouring section 42), but telling them is what JPDP's guidance recommends, and it's good practice regardless. There's no minimum formality to the donor's original request — a phone call or a reply email counts. Keep a record of it somewhere every future sender will check.
We got these emails from the receipt book and event sign-ups, not a mailing list. Does that matter?
Under the Disclosure Principle, using data for a purpose beyond the one it was collected for is the kind of thing that principle is meant to catch [4]. If your donation form only ever said "for issuing your receipt," using the same address for unrelated appeals without telling donors is the exact gap this article is about — fix it going forward by naming both purposes on the form.
Are we exempt because we're a registered society, not a company?
No blanket exemption for societies, charities or religious bodies is stated anywhere in the Act or on JPDP's site [1, 2]. What determines coverage is whether the specific data processing is "in respect of commercial transactions" [1] — a test that's unresolved for pure donations and squarely met for anything you sell.
Do we need to register with the Personal Data Protection Commissioner?
Only if you're in one of the 13 classes the current Order lists — none of which is a charity, society or religious body [6]. Most NPOs running ordinary fundraising and community activities are not required to register on the current Order.
Does the 2024 PDPA amendment change any of this?
Not the scope question above — section 2's "commercial transactions" test is unchanged [7]. The amendment brings in other obligations (breach notification, a Data Protection Officer for some organisations) covered in the 2024 amendments article.
If we're not legally required to do any of this, why bother?
Because a donor who feels their trust was abused over an unwanted email doesn't wait for a legal ruling before they stop giving — and because any activity you also run that sells something is covered regardless of how the rest of your income arrives.
Sources
- 1.Department of Personal Data Protection (JPDP), Application and Non-Application of the Act, pdp.gov.my. https://www.pdp.gov.my/ppdpv1/en/akta/application-and-non-application-of-the-act/ — section 2 "commercial transactions" scope test; section 3 non-application to Federal/State Government; section 14 registration power referenced generally.
- 2.Department of Personal Data Protection (JPDP), FAQ, pdp.gov.my. https://www.pdp.gov.my/ppdpv1/en/faq/ — the regulator's general framing that persons processing personal data must comply with the Act; does not address non-profit/society/religious-body donor data specifically.
- 3.Personal Data Protection Act 2010 [Act 709], consolidated text. https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/07/UNDANG-UNDANG-MALAYSIA_AKTA_PERLINDUNGAN_DATA_PERIBADI_2010_709_MALAY_AND-ENG_V2022.pdf — section 4's "commercial transactions" definition; section 43's five subsections; section 14(1) (registration order made by the Minister, not the Commissioner).
- 4.Department of Personal Data Protection (JPDP), Principles of Personal Data Protection, pdp.gov.my. https://www.pdp.gov.my/ppdpv1/en/principles-of-personal-data-protection/ — the seven principles (General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, Access) under sections 5–12; the FAQ page [2] additionally confirms the principles must be followed "under section 5(1)."
- 5.Department of Personal Data Protection (JPDP), Data Subject Rights, pdp.gov.my. https://www.pdp.gov.my/ppdpv1/en/data-subject-rights/ — the right to prevent processing for direct marketing (section 43); organisations must obtain permission before contacting a person by electronic mail for direct marketing; the rights to access, correct and withdraw consent.
- 6.Department of Personal Data Protection (JPDP), list of Class of Data Controller / Class of Data Users documents, pdp.gov.my. https://www.pdp.gov.my/ppdpv1/en/relevant-documents/ — the 13 registrable classes of data users, none of which is a charity, society or religious body.
- 7.Department of Personal Data Protection (JPDP), Personal Data Protection (Amendment) Act 2024, pdp.gov.my. https://www.pdp.gov.my/ppdpv1/en/akta/personal-data-protection-amendment-act-2024/ — the 2024 amendment renamed "data user" to "data controller" throughout the Act; commencement is staged by Ministerial notification; the amendment did not alter section 2's application test.
Spotted something out of date? Let us know.

