[Column] [ESG Strategies for Business] Vol.35 Amendments to Malaysia’s PDPA and Practical Responses for Japanese Companies—DPO Appointment, Data Breach Notification, and Cross-Border Data Transfer Guidelines

The article titled “[ESG Strategies for Business] Vol.35 Amendments to Malaysia’s PDPA and Practical Responses for Japanese Companies—DPO Appointment, Data Breach Notification, and Cross-Border Data Transfer Guidelines”, contributed by Attorney Mitsuru Misawa, has been published in the Jiji Press Malaysia Edition (issued on August 26, 2026).
While the previous issue examined the National Carbon Market Policy (NCMP) and the envisioned domestic Emissions Trading Scheme (ETS), this issue shifts to the governance (G) domain, addressing the amendments to the Personal Data Protection Act (PDPA) and the practical responses required of Japanese companies. It covers the phased enforcement and increased penalties under the amending Act (Act A1727), the obligation to appoint a Data Protection Officer (DPO) under the guidelines published in February 2025, the Data Breach Notification (DBN) obligation requiring notification within 72 hours, and the Cross-Border Personal Data Transfer Guidelines issued in April 2025 together with the right to data portability.
If you are interested, please contact us and we will be happy to share the article with you.
