PDPA 2024 Compliance Checklist
A practical, 38-point audit for Malaysian organisations preparing for the 2024 Amendment. Work through it in an afternoon, score your gaps, act on what matters.
Six sections, 38 audit points
Each section has 6–7 tickable items. You mark each as Yes, Partial, or No. The checklist gives you a section score and overall band.
Governance & accountability
DPO appointment, written policy, board endorsement, budget, staff responsibilities.
Collection & notice
PDPA notice language, consent mechanics, sensitive data, children's data, website forms.
Security & access control
Role-based access, staff training, encryption, physical security, breach response plan.
Retention & minimisation
Written retention schedule, rationale for periods, annual audits, email and backup coverage.
Destruction & disposal
Shredding level, tamper-evident certificates, storage media destruction, vendor audits, chain of custody.
Subject rights & breach
Access-request handling, breach register, JPDP notification, processor contracts, cross-border transfers.
Designed for three audiences
Compliance & risk leaders
DPOs, compliance officers, internal auditors who need a defensible audit trail and a board-ready scorecard.
Operations decision-makers
Office managers, HR directors, finance heads. The people who sign off on how records are kept and destroyed.
SMEs preparing for audit
Organisations that suspect the JPDP could call tomorrow and want to close the obvious gaps before they do.
Take it. Use it. Share it.
No email gate, no tracking pixel, no sales funnel. If it's useful, forward it to a colleague. If you want help closing the gaps, you know where to find us.
Download checklist (PDF, 22 KB)Frequently asked
Do I really not need to enter my email?
Correct. Click the button, the PDF downloads. We don't track you. The cost to us is tiny and the cost of a bad lead-gen form to you is annoyance, so we'd rather skip it. If you want to talk about your score, email us directly.
Is this legal advice?
No. It's a practical operations checklist drawn from real audits. It will help you ask the right questions and document the right things, but for anything with legal weight — breach notifications, regulatory filings, disputed subject requests — consult a qualified Malaysian data protection lawyer.
How often is this updated?
We revise annually or whenever the JPDP issues material guidance. The current edition is 2026-Q2, aligned to the Personal Data Protection (Amendment) Act 2024 (Act A1709). The edition number is on the cover.
Can I distribute this to my team or clients?
Yes, please do. Attribution appreciated but not required. We'd prefer you point people at this page rather than host the PDF yourself — it means they get the latest edition when we update.
What if we score below 24?
Most Malaysian SMEs we assess for the first time do. The biggest leverage points are usually appointing a DPO in writing, drafting a written retention schedule, and fixing the destruction workflow. Those three alone can move a score by 10+ points. Reply to our email if you want a 30-minute call walking through yours.