Data inventory snapshot
The main personal data you hold, where it comes from, where it goes and who can see it, captured at the level needed to judge risk.
A short, fixed-fee review that tells you where you stand under the amended PDPA and what to do first. It is the right starting point before you commit to an audit, a DPO or a policy rebuild.
A structured review of how your organisation collects, uses, shares, secures and keeps personal data, measured against the PDPA as amended in 2024 and the JPDP guidelines. It ends with a readiness rating and a prioritised action plan.
The amendments that took effect in 2025 made data protection officers, breach notification to the Commissioner and processor security duties mandatory, and raised penalties to RM1 million or three years' imprisonment. Most organisations have never checked themselves against the new rules. A readiness assessment answers the basic questions quickly: are we registered if we need to be, do we need a DPO, could we notify a breach within 72 hours, and do our notices match what we actually do.
The main personal data you hold, where it comes from, where it goes and who can see it, captured at the level needed to judge risk.
Whether your privacy notices, in both Malay and English as the Act requires, and your consent practices match reality.
Whether you must appoint a DPO and register as a data controller, and whether you have.
Whether you could detect, assess and notify a breach within 72 hours.
Vendors who handle your data and any transfers outside Malaysia.
Access, retention and deletion practices at a practical level.
You know exactly where you stand before spending on bigger work.
No open-ended consulting bill.
A one-page rating directors can understand.
What to fix first, second and later.
Findings carry straight into a full PDPA Compliance Audit if you need one.
Scope, contacts and a short document request.
Short sessions with HR, sales, operations and IT.
Notices, forms, contracts and policies.
Rating each area against the amended Act and guidelines.
Findings, rating and action plan presented to management.
An overall and per-area rating.
Gaps with plain explanations.
Prioritised actions with owners and effort.
Whether each applies to you.
A one-page summary for the board.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
Usually two to three weeks from kick-off to report, depending on the size of the organisation.
The readiness assessment is a fixed-fee snapshot of where you stand. The audit is a deeper engagement that tests obligations against actual security controls and builds an evidence pack.
A list of the systems and forms you use, your current notices and policies, and time with a few key people.
Yes. We assess it against the Commissioner's DPO guideline thresholds and tell you plainly.
The assessment is a consulting service. Any training we recommend afterwards is HRD Corp SBL-Khas claimable.
Tell us your industry, headcount and the main personal data you handle. We will confirm the fixed fee and a start date.