Skip to content
TrustList
News

Malaysia JPDP consults on an AI and Personal Data Protection Framework under Act 709, comments close 23 October 2026

Editorial

By TrustList Editorial

Malaysia's data protection department opened Consultation Paper 1/2026 on 5 October: a draft framework on personal data in AI systems, covering vendor due diligence, cross-border transfers and records. Comments are due by 23 October.

About Malaysia JPDP consults on an AI and Personal Data Protection Framework under Act 709, comments close 23 October 2026

Malaysia JPDP consults on an AI and Personal Data Protection Framework under Act 709, comments close 23 October 2026

5 October 2026 — Malaysia's Personal Data Protection Department (JPDP) opened a public consultation on 5 October 2026 on a proposed AI and Personal Data Protection Framework. Consultation Paper No. 1/2026 runs from 5 October to 23 October 2026 and attaches a full draft guideline, "Version 1.0", with the issue date still blank. The framework would sit under the Personal Data Protection Act 2010 (Act 709) and explain what data controllers and processors must do when personal data passes through AI systems, whether built in-house, bought off the shelf, customised, or embedded in a SaaS product or API.

Not yet independently verified. Both sources are the regulator's own, but they are one publication; no second outlet has been read. The draft guideline is undated (issue date shown as blank) and is a proposal, not yet binding. Its wording on several duties is 'where appropriate', so final obligations may differ. We will update this when it can be confirmed, and remove this note.

What changed

The draft is organised along the AI system lifecycle in ten parts, A to J. Part C covers the legal basis and exemptions. Part D sets standards for training data and testing before deployment. Part E covers monitoring, retraining and decommissioning. Part F deals with buying and managing external AI systems. Part G covers data subject rights, including access, correction, withdrawal of consent and data portability. Part H covers security, fairness and breach handling. Part I covers governance, risk assessment, transparency and explainability. Part J covers record-keeping, internal audit and demonstrating compliance.

Several provisions touch vendor relationships directly. The draft says a controller must define whether an AI provider is a processor or a third party, and that using a provider does not reduce the controller's own responsibilities under Act 709. Where a provider processes data for the controller, the draft lists arrangements to put in place, including purpose, data categories, instructions, sub-processors, breach handling, and return or deletion at the end of the service. Controllers may ask providers for model cards, system cards or technical documentation. For transfers outside Malaysia, the draft refers to section 129 of Act 709 and, where appropriate, a Transfer Impact Assessment. Breaches involving an AI system fall under the existing section 12B notification duty.

Who is affected

Any organisation that handles personal data in commercial transactions in Malaysia and uses AI: Malaysian companies, and foreign software and AI vendors whose products process Malaysian personal data on behalf of customers. SaaS and API providers are named in the scope. Customers that deploy third-party AI tools are in scope as controllers.

What to do

Comments go through the Unified Public Consultation platform (upc.mpc.gov.my, consultation 296) or the official Google Form, both linked from the paper, by 23 October 2026. Questions can go to risiko@pdp.gov.my. The paper asks seven questions, including whether the framework is proportionate, what exemptions are needed, what enforcement challenges organisations expect, and what transition periods or sandboxes would help.

Vendors with Malaysian customers can review their data processing agreements against the list of arrangements above, check whether they can supply model or system documentation on request, and map where Malaysian personal data is stored and processed. Buyers can ask their AI suppliers the same questions now rather than after the final text appears.

Why it matters

Malaysia is adding AI-specific expectations on top of an Act that is also being amended; a separate JPDP tender notice dated 17 September refers to a platform to support the implementation of the amendments to Act 709. The draft looks at the practical questions procurement teams ask: who is responsible, what must the contract say, and what records prove compliance. It remains a proposal, and the final wording and start date are not yet known.

Sources

Categories & features