🏠 Home ℹ️ About Us
📩 Contact Us 🔔 Notice
🔑 Log In 📝 Free Sign Up
HomeLegalPersonal Data Protection Act

Malaysia Personal Data Protection Act 2010 (PDPA)

Your obligations as an iSMS user under Malaysia's PDPA 2010 — and practical guidance on how to comply when using bulk SMS for marketing or communications.

About the PDPA 2010

The Personal Data Protection Act 2010 (Act 709) came into force on 15 November 2013. It regulates the processing of personal data of individuals in commercial transactions in Malaysia. The Act establishes seven core data protection principles that data controllers must follow.

Official reference: www.pdp.gov.my →

📋 Important distinction: Under the PDPA, MobiWeb Sdn Bhd acts as a data processor — we transmit messages on your instruction. You, the iSMS user, are the data controller — the party who determines why and how personal data (mobile numbers, names, etc.) is collected and used. This means PDPA compliance obligations rest primarily with you, not with MobiWeb.
📋 Updated in 2024. The PDPA was amended by the Personal Data Protection (Amendment) Act 2024, with provisions coming into force through 2025. The main changes affecting bulk SMS senders are summarised below. This page describes the position in general terms — it is not legal advice, and you should confirm your own obligations with your legal adviser or the Commissioner.

What the 2024 Amendment Changed

"Data user" is now "data controller"

The term used throughout the Act changed to align with international practice. If your internal policies, privacy notices or consent forms still say "data user", they are referring to the same role — but updating the wording is worthwhile when you next revise them.

Data breach notification is now mandatory

Where a personal data breach occurs, you are required to notify the Commissioner, and to notify affected individuals where the breach is likely to cause significant harm. Build a breach response process before you need one — including who decides, who notifies, and within what timeframe.

Data Protection Officer requirement

Certain data controllers and processors must appoint a Data Protection Officer and register the appointment with the Commissioner. Whether this applies to you depends on the volume and nature of the personal data you process.

Obligations extend to data processors

Security obligations now apply directly to processors, not only to controllers. MobiWeb acts as your data processor when transmitting your messages.

Data portability

Individuals gained a right to request that their personal data be transferred to another controller, where technically feasible.

The 7 PDPA Principles — What They Mean for You

As a data controller sending bulk SMS, you must comply with all 7 principles of the PDPA:

1. General Principle — Consent & Purpose

You must only process personal data (including mobile numbers) with the consent of the data subject, and only for the purpose for which consent was given. Do not use a mobile number collected for one purpose (e.g. a purchase) to send unrelated marketing without separate consent.

2. Notice & Choice Principle

When collecting personal data, you must inform individuals of your identity, the purpose of collection, their right to access and correct their data, and whether their data will be disclosed to third parties. This notice must be given before or at the time of collection.

3. Disclosure Principle

Personal data must not be disclosed to any third party without the consent of the data subject, unless required by law. Do not share, sell, or pass your contact database to other parties without consent.

4. Security Principle

You must take practical steps to protect personal data from loss, misuse, unauthorised access, disclosure, or alteration. Secure your iSMS account credentials and do not share login access with unauthorised parties.

5. Retention Principle

Personal data must not be kept longer than necessary for the purpose it was collected. Regularly review and purge your contact database of inactive, opted-out, or outdated records.

6. Data Integrity Principle

You must take reasonable steps to ensure that personal data is accurate, complete, and up to date. Do not send SMS to numbers you know to be incorrect or belonging to someone other than the intended recipient.

7. Access Principle

Data subjects have the right to request access to their personal data that you hold, and to request corrections. You must have a process in place to handle such requests.

Who Must Register with the Commissioner?

Organisations in the following industries that process personal data in commercial transactions are required to register with the Personal Data Protection Commissioner under the Personal Data Protection (Class of Data Users) Order 2013:

Communications
Banking & Financial Institutions
Insurance
Health & Medical
Tourism & Hospitality
Transportation (Malaysian airlines)
Education
Direct Selling
Professional Services (Legal, Audit, Accountancy, Engineering, Architecture)
Real Estate
Utilities
"A person who belongs to the class of data controllers as specified in the order made under subsection 14(1) and who processes personal data without a certificate of registration commits an offence and shall, on conviction, be liable to a fine not exceeding five hundred thousand ringgit or to imprisonment for a term not exceeding three years or to both."

— Laws of Malaysia Act 709, Personal Data Protection Act 2010

Practical Steps to Comply with PDPA When Using iSMS

✅ What you should do to comply:
⚠️ PDPA is not the only rule that applies. Separately from data protection, MCMC blocks SMS containing hyperlinks, callback numbers or requests for personal information for Malaysian destinations. A message can be fully PDPA-compliant and still be blocked. See SMS prohibited content.

Your Obligations as an iSMS User — Liability

All bulk SMS sending activities are logged and traceable to your iSMS account. As the data controller, you are solely responsible for:

⚠️ MobiWeb's Position: MobiWeb Sdn Bhd processes personal data solely on your instruction as a data processor. MobiWeb will not accept any liability for PDPA violations arising from your use of the iSMS platform — including unlawful data collection, lack of consent, or failure to honour opt-outs. You agree to fully indemnify MobiWeb against any fines, penalties, regulatory action, or third-party claims arising from your non-compliance.

How MobiWeb Handles Your Data

MobiWeb Sdn Bhd is committed to responsible handling of data entrusted to us by our users. The following describes our practices — though we do not make guarantees beyond what is reasonably practicable:

For full details on how MobiWeb handles your personal data, refer to our Privacy Policy.

📋 Registration: If your organisation falls under one of the regulated classes listed above, you are required to register with the Personal Data Protection Commissioner. Forms and guidance are available at www.pdp.gov.my. This is your organisation's obligation — not MobiWeb's.

📱 SMS Coverage — Every Country We Reach Jump to a country's rate by first letter

A B C D E F G H I J K L M N O P Q R S T U V Y Z