Eligibility assessment
Class, business form and licence analysis for each entity.
Two filings on JPDP's SPDP system trip organisations up: registering as a data controller, and registering the DPO once appointed. We check what each entity must file, prepare and submit it, and keep renewals and DPO changes from slipping.
A fixed-scope service to confirm registration obligations under Circular 1/2026 and the Class of Data Users Orders, register appointed DPOs with the Commissioner, prepare and submit everything through SPDP, and manage renewals and changes.
Circular 1/2026, in force since 1 June 2026, restates who must register: businesses in commercial transactions within a listed class, operating as a sole proprietorship, partnership, private limited or public company. Processing without a valid certificate is an offence carrying a fine of up to RM500,000, up to three years' imprisonment, or both, and continuing to process after a certificate lapses is a separate offence. Separately, where a DPO must be appointed, JPDP requires the data controller to notify the Commissioner within 21 days of the appointment by registering the DPO on SPDP, with a dedicated business email for the DPO and the appointment letter uploaded.
Class, business form and licence analysis for each entity.
Supporting documents and SPDP submission.
Registering the appointed DPO on SPDP within 21 days, with the dedicated business email and appointment letter JPDP requires.
Separate registrations where each regulatory licence requires one.
Calendar and filing within the 90 days before expiry.
Display at the principal place of business and a registration register.
New entities, licences, restructures and changes of DPO.
A clear yes or no for each entity.
Renewals tracked for you.
Fixed fee for a narrow task.
One register for all entities.
A natural start before a wider PDPA review.
Licences, business registration and group structure.
Registration obligations per entity.
Applications and supporting documents.
Filing through SPDP and tracking.
Ongoing calendar and reminders.
Per entity and licence.
With supporting documents.
Certificates, DPO registrations, expiry dates and owners.
Dates and reminders.
Events that require updates.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
No. Only data controllers in the listed classes and business forms. We check each entity.
JPDP requires the data controller to notify the Commissioner within 21 days of appointing a DPO, by registering the DPO on SPDP. We prepare the dedicated email, appointment letter and submission.
Circular 1/2026 states a complete application is considered within fourteen working days.
JPDP fees are RM100 to RM400 a year depending on business form, for certificates of one to five years, plus our service fee.
Generally yes, registration follows each licence issued by your sector regulator, except for the Services class.
Continuing to process after expiry is an offence. We prioritise renewal and advise on next steps.
Send us your group structure and licences. We will confirm which entities must register and quote a fixed fee.