, by Gabriel
Since 1 June 2025, every data user organisation in Malaysia has been legally required to appoint a Data Protection Officer under the amended Personal Data Protection Act 2010, now reinforced by Act 854. Yet most Malaysian organisations still treat PDPA training as a one-off tick-box exercise rather than a continuous compliance function. That gap is now a liability.
This article explains exactly what PDPA training must cover in 2026, who is responsible, how the 2024 amendments change the stakes, and how organisations can fund structured programmes through HRD Corp claimable schemes.
Key Takeaways
The Personal Data Protection (Amendment) Act 2024 did not merely update procedural rules. It restructured accountability across three phases of enforcement. The Jabatan Perlindungan Data Peribadi confirmed that Phase 1 took effect on 1 January 2025, covering revised definitions of "data controller," biometric data as sensitive personal data, and the appointment of forum data controller leads.
Phase 2, effective 1 April 2025, raised fines for breaches of the seven data protection principles and tightened rules on cross-border personal data transfers. Phase 3, from 1 June 2025, activated the mandatory DPO appointment requirement, data breach notification obligations, and the right to data portability.
For HR Managers, this means employee data, payroll records, health information, and recruitment data are all in scope. For Compliance Officers, it means documented processes, not just policies, are required. Training is the mechanism that bridges the two.
Act 709, as amended, holds organisations accountable for seven data protection principles: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, and Access. A breach of any one of these principles now carries higher financial penalties than existed before April 2025.
Effective PDPA training must go beyond naming these principles. Staff need to understand how each principle applies to their daily role. An HR executive who shares a candidate's salary history with a hiring manager without a lawful basis may be breaching the Disclosure Principle. A finance officer who retains terminated employee records indefinitely may be breaching the Retention Principle.
Role-specific training, not generic awareness sessions, is what regulators and auditors are looking for when they assess whether an organisation has taken reasonable steps to comply.
As of 1 June 2025, organisations processing personal data in commercial transactions are required to appoint a Data Protection Officer. The DPO must understand the Act, be capable of advising on compliance, and serve as the internal point of contact for data subjects and the regulator.
Many Malaysian SMEs do not have a dedicated DPO and cannot justify a full-time hire. DPO-as-a-Service arrangements address this directly, providing qualified external DPOs who fulfil the statutory role while the organisation builds internal capability over time.
Whether the DPO is internal or external, the broader compliance team, particularly HR Managers and Compliance Officers, must understand what the DPO requires from them. That means documented data inventories, incident response procedures, and staff who know when to escalate. Training is how that knowledge transfers.
A credible PDPA training programme in 2026 should address the amended Act directly, not the pre-2024 version. Many courses on the market have not been updated to reflect the phased enforcement timeline or the new obligations around breach notification and data portability.
The core curriculum should include the following areas:
Cybersecurity training belongs alongside PDPA training, not as a separate initiative. A security breach that exposes personal data triggers PDPA breach notification obligations. Staff who understand both the technical and legal dimensions respond faster and more accurately when an incident occurs.
Malaysian employers registered with HRD Corp can claim PDPA training costs under the SBL-Khas scheme, provided the programme is delivered by an approved training provider and the application is submitted correctly. This makes structured, high-quality PDPA training financially accessible, even for organisations with constrained L&D budgets.
The key condition is that the programme must be claimable-eligible, meaning it must meet HRD Corp's content and delivery standards. Organisations should confirm this status with their training provider before committing, and submit applications before the training date rather than retrospectively.
HR Managers are typically the ones who manage HRD Corp claims. Understanding the intersection between HRD Corp process requirements and PDPA training content puts HR in the strongest position to build a compliance training calendar that is both effective and cost-neutral.
Compliance Officers and HR Managers should approach PDPA training as a structured programme, not a single event. The amended Act creates ongoing obligations, and a workforce trained once in 2023 is not a compliant workforce in 2026.
Start by auditing what your staff currently know against what the amended Act now requires. Identify the gaps, prioritise the roles with the highest data exposure, and design a training calendar that addresses those gaps systematically. Build in refresher cycles, at minimum annually, and align training records with your broader compliance documentation.
The organisations that will navigate PDPA enforcement confidently in 2026 are not those with the most sophisticated technology. They are the ones where every person who touches personal data understands their obligations and knows what to do when something goes wrong. Schedule your first session before that knowledge gap costs more than the training would have.