Data Protection / Breach Notification

PDPA Data Breach Notification Readiness

Containing a breach and notifying one are different jobs, done by different people, often at the same time. Section 12B and JPDP's guideline set the second job a clock, a harm test and a paper trail. We build the process, the templates and the register before you need them, and stand beside you when you do.

PDPA section 12B, in force since 1 June 2025 Commissioner within 72 hours, data subjects within 7 days Plan, harm test, templates, register and drills
Overview

Breach Notification Readiness

What it is

A readiness programme for the legal notification side of a personal data breach. We put in place the breach management and response plan the guideline expects, a significant harm assessment your team can apply under pressure, notification templates for the Commissioner and for individuals, a breach register, processor contract terms and a simulation exercise to prove it works.

Why organisations need it

Section 12B of the amended PDPA requires a data controller to notify the Personal Data Protection Commissioner of a personal data breach as soon as practicable, and to notify affected individuals without unnecessary delay where the breach causes or is likely to cause significant harm. Failing to notify the Commissioner is an offence carrying a fine of up to RM250,000, imprisonment of up to two years, or both. JPDP's guideline puts numbers on it: 72 hours to the Commissioner, seven days to data subjects after that, and a register kept for at least two years. A technically well-handled incident can still be a notification failure.

Key features

What the engagement covers

Where you already have an Incident Response Retainer, this is the notification layer that sits alongside it. Where you do not, it stands on its own.

Breach management and response plan

The plan the guideline expects you to have: roles, escalation, decision points and who speaks to the Commissioner, joined up with your IT incident process so the two run in parallel rather than in sequence.

Significant harm assessment

A structured test your DPO can apply quickly: physical harm, financial loss, a negative effect on credit records, damage to or loss of property, and scale above 1,000 affected individuals. Each decision recorded with its reasons, including decisions not to notify.

Notification templates

Pre-drafted notices to the Commissioner and to affected individuals, with the content the guideline asks for, plus the written explanation needed if the Commissioner is notified late.

Breach register

A register that records every personal data breach, notified or not, kept for at least two years, in the form an investigator would expect to see.

Processor contract terms

Clauses requiring your data processors to tell you promptly about a breach and to help you meet your notification duties, plus a check of your key processor contracts against them.

Simulation exercise

A tabletop exercise that runs a realistic breach through the harm test, the notification decision and the drafting, against the clock, with the people who would actually do it.

Business value

What the business gets out of it

The first 72 hours go to decisions, not drafting

With the harm test, templates and roles agreed in advance, the time on the clock goes into understanding the breach rather than deciding who writes to whom.

Every decision is defensible

A recorded significant harm assessment is what shows the Commissioner you took the duty seriously, especially when you decided a breach did not need notifying.

IT and legal stop tripping over each other

Containment and notification run in parallel with clear owners, so neither waits for the other and nobody promises the regulator something the technical team cannot support.

Your processors are on the hook too

Most breaches start at a vendor. Contract terms that make them tell you promptly are the difference between 72 hours and finding out from the news.

The register answers the first question

An investigator's first request is usually your breach history. A maintained register answers it in minutes and shows a pattern of control rather than a single bad day.

Your people have done it before

The guideline asks for periodic training and simulation. A realistic drill is the fastest way to find the gap between the plan and what people actually do.

How it works

How the engagement runs

01

Current state review

How breaches are reported, assessed and escalated today, who holds the relationship with the Commissioner, and what your processor contracts say.

02

Design

The response plan, harm assessment method, roles and escalation, fitted to your existing incident process rather than replacing it.

03

Templates and register

Notification templates for the Commissioner and individuals, the late-notice explanation, and the breach register set up and populated with any recent breaches.

04

Processor terms

Model clauses and a review of your key processor contracts against them.

05

Simulation

A tabletop exercise against the clock, with a short report on what worked and what did not.

06

Standby (optional)

Notification support during a live breach, alongside your IT team or our incident responders, to make and document the notification decisions.

Deliverables

What you receive

Breach management and response plan

Roles, escalation, decision points and communication, aligned with your IT incident process.

Significant harm assessment tool

A structured method and record for deciding whether and whom to notify.

Notification templates

Commissioner notice, data subject notice and late-notification explanation.

Breach register

Set up, populated and kept in a form suitable for at least two years' retention.

Processor clause pack

Model breach notification and assistance clauses, and a gap list for key processor contracts.

Simulation report

What happened in the exercise, the gaps found and the fixes, with owners.

Who it is for

Who this is built for

Industries

Financial servicesHealthcareE-commerce and retailTelecommunicationsEducationProperty and hospitalityHR, payroll and BPO providersTechnology and SaaS

Company sizes

Large enterpriseMid-marketSMEs holding customer dataData processors serving controllers

Departments

Data protection and DPOLegalIT and securityRisk and complianceCorporate communicationsCustomer service
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Do we have to notify every breach?

No. Under the guideline you notify the Commissioner where the breach causes or is likely to cause significant harm, which includes physical harm, financial loss, a negative effect on credit records, damage to or loss of property, or a breach affecting more than 1,000 individuals. Every breach should still go in your register, with the reasons for the decision.

How quickly do we have to notify?

The Act says as soon as practicable. JPDP's guideline sets 72 hours for the Commissioner, with a written explanation and supporting evidence if you are late, and seven days after that for affected individuals where significant harm is likely.

What is the penalty for not notifying?

Failing to notify the Commissioner under section 12B is an offence carrying a fine of up to RM250,000, imprisonment of up to two years, or both. The reputational cost of individuals hearing about it first is usually larger.

We are a data processor. Does this apply to us?

The duty to notify the Commissioner sits with the data controller. Processors are expected to tell their controllers promptly and help them meet the deadline, and controllers are expected to write that into the contract. We help processors build that escalation too.

How is this different from your Incident Response Retainer?

The retainer puts responders on call to contain a security incident. This builds the notification process, the harm test, templates, register and processor terms that the PDPA requires. Many clients have both, and they are designed to work together.

Can you notify the Commissioner for us?

The notification is made by your organisation, usually through your DPO. We prepare the assessment and the drafting and support the decision, and we work alongside your legal counsel where legal advice is needed.

Get started

Find out whether your first 72 hours would hold

Tell us how a breach would be reported inside your organisation today and who would decide whether to notify. We will come back with a readiness view, a scope and a fixed quotation.