Data Protection / Registration

JPDP Registration Support: Data Controllers and DPOs

Two filings on JPDP's SPDP system trip organisations up: registering as a data controller, and registering the DPO once appointed. We check what each entity must file, prepare and submit it, and keep renewals and DPO changes from slipping.

Data controller registration and renewal DPO registration within 21 days of appointment One register for every entity and DPO
Overview

JPDP Registration Support

What it is

A fixed-scope service to confirm registration obligations under Circular 1/2026 and the Class of Data Users Orders, register appointed DPOs with the Commissioner, prepare and submit everything through SPDP, and manage renewals and changes.

Why organisations need it

Circular 1/2026, in force since 1 June 2026, restates who must register: businesses in commercial transactions within a listed class, operating as a sole proprietorship, partnership, private limited or public company. Processing without a valid certificate is an offence carrying a fine of up to RM500,000, up to three years' imprisonment, or both, and continuing to process after a certificate lapses is a separate offence. Separately, where a DPO must be appointed, JPDP requires the data controller to notify the Commissioner within 21 days of the appointment by registering the DPO on SPDP, with a dedicated business email for the DPO and the appointment letter uploaded.

Key features

What the engagement covers

Eligibility assessment

Class, business form and licence analysis for each entity.

Application preparation

Supporting documents and SPDP submission.

DPO registration

Registering the appointed DPO on SPDP within 21 days, with the dedicated business email and appointment letter JPDP requires.

Per-licence registrations

Separate registrations where each regulatory licence requires one.

Renewals

Calendar and filing within the 90 days before expiry.

Certificate display and records

Display at the principal place of business and a registration register.

Change management

New entities, licences, restructures and changes of DPO.

Business value

What the business gets out of it

Certainty

A clear yes or no for each entity.

No lapses

Renewals tracked for you.

Low cost

Fixed fee for a narrow task.

Group view

One register for all entities.

A first step

A natural start before a wider PDPA review.

How it works

How the engagement runs

01

Document request

Licences, business registration and group structure.

02

Assessment

Registration obligations per entity.

03

Preparation

Applications and supporting documents.

04

Submission

Filing through SPDP and tracking.

05

Renewal management

Ongoing calendar and reminders.

Deliverables

What you receive

Registration assessment

Per entity and licence.

Submitted applications

With supporting documents.

Registration register

Certificates, DPO registrations, expiry dates and owners.

Renewal calendar

Dates and reminders.

Change checklist

Events that require updates.

Who it is for

Who this is built for

Industries

Banking and financeInsuranceHealthcareEducationTourism and hospitalityReal estateDirect sellingProfessional servicesUtilitiesPawnbrokers and moneylenders

Company sizes

SMEsMid-marketLarge enterpriseGroup structures

Departments

Company secretaryComplianceLegalFinance
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Does every company need to register?

No. Only data controllers in the listed classes and business forms. We check each entity.

How quickly must we register our DPO?

JPDP requires the data controller to notify the Commissioner within 21 days of appointing a DPO, by registering the DPO on SPDP. We prepare the dedicated email, appointment letter and submission.

How long does JPDP take?

Circular 1/2026 states a complete application is considered within fourteen working days.

What does registration cost?

JPDP fees are RM100 to RM400 a year depending on business form, for certificates of one to five years, plus our service fee.

Do we need one registration per licence?

Generally yes, registration follows each licence issued by your sector regulator, except for the Services class.

What if our certificate already lapsed?

Continuing to process after expiry is an offence. We prioritise renewal and advise on next steps.

Get started

Confirm and file your registration

Send us your group structure and licences. We will confirm which entities must register and quote a fixed fee.