Breach management and response plan
The plan the guideline expects you to have: roles, escalation, decision points and who speaks to the Commissioner, joined up with your IT incident process so the two run in parallel rather than in sequence.
Containing a breach and notifying one are different jobs, done by different people, often at the same time. Section 12B and JPDP's guideline set the second job a clock, a harm test and a paper trail. We build the process, the templates and the register before you need them, and stand beside you when you do.
A readiness programme for the legal notification side of a personal data breach. We put in place the breach management and response plan the guideline expects, a significant harm assessment your team can apply under pressure, notification templates for the Commissioner and for individuals, a breach register, processor contract terms and a simulation exercise to prove it works.
Section 12B of the amended PDPA requires a data controller to notify the Personal Data Protection Commissioner of a personal data breach as soon as practicable, and to notify affected individuals without unnecessary delay where the breach causes or is likely to cause significant harm. Failing to notify the Commissioner is an offence carrying a fine of up to RM250,000, imprisonment of up to two years, or both. JPDP's guideline puts numbers on it: 72 hours to the Commissioner, seven days to data subjects after that, and a register kept for at least two years. A technically well-handled incident can still be a notification failure.
Where you already have an Incident Response Retainer, this is the notification layer that sits alongside it. Where you do not, it stands on its own.
The plan the guideline expects you to have: roles, escalation, decision points and who speaks to the Commissioner, joined up with your IT incident process so the two run in parallel rather than in sequence.
A structured test your DPO can apply quickly: physical harm, financial loss, a negative effect on credit records, damage to or loss of property, and scale above 1,000 affected individuals. Each decision recorded with its reasons, including decisions not to notify.
Pre-drafted notices to the Commissioner and to affected individuals, with the content the guideline asks for, plus the written explanation needed if the Commissioner is notified late.
A register that records every personal data breach, notified or not, kept for at least two years, in the form an investigator would expect to see.
Clauses requiring your data processors to tell you promptly about a breach and to help you meet your notification duties, plus a check of your key processor contracts against them.
A tabletop exercise that runs a realistic breach through the harm test, the notification decision and the drafting, against the clock, with the people who would actually do it.
With the harm test, templates and roles agreed in advance, the time on the clock goes into understanding the breach rather than deciding who writes to whom.
A recorded significant harm assessment is what shows the Commissioner you took the duty seriously, especially when you decided a breach did not need notifying.
Containment and notification run in parallel with clear owners, so neither waits for the other and nobody promises the regulator something the technical team cannot support.
Most breaches start at a vendor. Contract terms that make them tell you promptly are the difference between 72 hours and finding out from the news.
An investigator's first request is usually your breach history. A maintained register answers it in minutes and shows a pattern of control rather than a single bad day.
The guideline asks for periodic training and simulation. A realistic drill is the fastest way to find the gap between the plan and what people actually do.
How breaches are reported, assessed and escalated today, who holds the relationship with the Commissioner, and what your processor contracts say.
The response plan, harm assessment method, roles and escalation, fitted to your existing incident process rather than replacing it.
Notification templates for the Commissioner and individuals, the late-notice explanation, and the breach register set up and populated with any recent breaches.
Model clauses and a review of your key processor contracts against them.
A tabletop exercise against the clock, with a short report on what worked and what did not.
Notification support during a live breach, alongside your IT team or our incident responders, to make and document the notification decisions.
Roles, escalation, decision points and communication, aligned with your IT incident process.
A structured method and record for deciding whether and whom to notify.
Commissioner notice, data subject notice and late-notification explanation.
Set up, populated and kept in a form suitable for at least two years' retention.
Model breach notification and assistance clauses, and a gap list for key processor contracts.
What happened in the exercise, the gaps found and the fixes, with owners.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
No. Under the guideline you notify the Commissioner where the breach causes or is likely to cause significant harm, which includes physical harm, financial loss, a negative effect on credit records, damage to or loss of property, or a breach affecting more than 1,000 individuals. Every breach should still go in your register, with the reasons for the decision.
The Act says as soon as practicable. JPDP's guideline sets 72 hours for the Commissioner, with a written explanation and supporting evidence if you are late, and seven days after that for affected individuals where significant harm is likely.
Failing to notify the Commissioner under section 12B is an offence carrying a fine of up to RM250,000, imprisonment of up to two years, or both. The reputational cost of individuals hearing about it first is usually larger.
The duty to notify the Commissioner sits with the data controller. Processors are expected to tell their controllers promptly and help them meet the deadline, and controllers are expected to write that into the contract. We help processors build that escalation too.
The retainer puts responders on call to contain a security incident. This builds the notification process, the harm test, templates, register and processor terms that the PDPA requires. Many clients have both, and they are designed to work together.
The notification is made by your organisation, usually through your DPO. We prepare the assessment and the drafting and support the decision, and we work alongside your legal counsel where legal advice is needed.
Tell us how a breach would be reported inside your organisation today and who would decide whether to notify. We will come back with a readiness view, a scope and a fixed quotation.