What it is
Most PDPA work in Malaysia stops at documentation: a privacy notice, a consent form, a policy folder. That satisfies the visible obligations and leaves the Security Principle largely unaddressed, because nobody checked whether the safeguards the policies describe genuinely exist.
This engagement joins the two. We assess your obligations under the PDPA as amended against the controls actually in place, and produce a mapping that shows, obligation by obligation, whether it is evidenced, partial or missing. That covers the Security Principle, retention and disposal, data processor arrangements with your suppliers, data subject rights handling, the data protection officer duty, and the personal data breach notification requirement.
Where documentation is the gap we redraft it: acceptable use, password and authentication, remote and hybrid working, BYOD, incident response, data classification and handling, and increasingly an AI acceptable use position, since staff are pasting customer information into generative AI tools with no guidance either way. Where the control itself is the gap we say so and sequence the fix, because a policy asserting a safeguard that does not exist is worse than no policy at all.
Why organisations need it
The 2024 amendments raised the documentary and operational bar together. Personal data breaches must now be notified to the Commissioner, and affected individuals told where significant harm is likely. Organisations meeting the prescribed thresholds must appoint a data protection officer. Data processors carry direct obligations for the first time, which changes what your supplier contracts need to say.
None of that is satisfied by a policy folder. Meeting a notification window requires knowing what data you hold, where it is, who can reach it, and having audit logging good enough to establish what an attacker accessed. Those are security controls, and they are what an enquiry examines after the fact.
Commercially, the same evidence keeps being requested by different people. Enterprise clients ask during vendor due diligence. Insurers ask at renewal. Auditors ask during ISO 27001 certification. Building it once, properly, answers all three, which is why we structure the output as an evidence pack rather than a report.