Biometric and Sensitive Personal Data under the Amended PDPA
Fingerprint time clocks, face recognition at the office door, voice authentication in the call centre and selfie checks in onboarding apps are everywhere in Malaysia. Since 1 April 2025 the data they collect is sensitive personal data. The amended PDPA defines biometric data as personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person, and adds it to the list of sensitive personal data alongside health, political opinions, religious beliefs and offences. Sensitive personal data can only be processed with explicit consent or under one of the specific conditions in section 40, and breaches of the principles can now be punished by a fine of up to RM1 million, up to three years' imprisonment, or both.
This one-day course is for HR, payroll, facilities and security, IT, customer onboarding and product teams, and the DPOs who advise them. It covers what counts as biometric and other sensitive data, when a biometric system is justified at all, how to obtain consent that is genuinely explicit, especially from employees, and how to secure, retain and delete templates. Planning a new biometric system should also involve a Data Protection Impact Assessment, which the JPDP guideline treats biometric processing as a trigger for.
HRD Corp SBL-Khas Claimable
Programme Agenda
9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
9:15 AM - 10:15 AM
What Counts as Biometric and Sensitive Data
The amended definitions, what technical processing means in practice, the difference between a photo and a face template, and the full list of sensitive personal data. Exercise: classify twelve common workplace and customer data types.
10:15 AM - 10:30 AM
Break
10:30 AM - 11:30 AM
Explicit Consent and the Section 40 Conditions
What makes consent explicit, why consent from employees is hard to make genuinely free, and the other conditions that allow processing of sensitive data, such as employment law obligations, vital interests and legal claims.
11:30 AM - 12:30 PM
Is Biometrics Necessary and Proportionate?
Testing a proposed system against its purpose, alternatives such as cards or PINs, offering a choice, and when a DPIA is required. Case studies: attendance clocks, building access, customer eKYC and voice authentication.
12:30 PM - 1:30 PM
Lunch
1:30 PM - 2:20 PM
Security, Retention and Vendors
Protecting templates, encryption and access, on-device versus central storage, retention and deletion when staff leave or customers close accounts, and the vendor contract terms that matter for biometric processors.
2:20 PM - 3:15 PM
Rights, Breaches and Workplace Practice
Access and correction for sensitive data, handling objections, breach notification when biometric data is exposed, and communicating a biometric deployment to staff and unions.
3:15 PM - 3:30 PM
Break
3:30 PM - 4:45 PM
Workshop: Reviewing a Biometric Deployment
Teams review a realistic biometric time-and-attendance rollout and produce the purpose statement, consent approach, alternative option, retention rule and vendor requirements.
4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Identify biometric and other sensitive personal data under the amended PDPA
- Obtain explicit consent, or identify another valid condition, for sensitive data
- Assess whether a biometric system is necessary and proportionate
- Secure, retain and delete biometric templates appropriately
- Handle rights requests and breaches involving sensitive data
- Review a biometric deployment before it goes live
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Foundation. For HR, payroll, facilities and security, IT, onboarding and product teams, and DPOs and compliance staff.
Duration 1 Day (8 Hours) | 9:00 AM to 5:00 PM
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A biometric deployment review completed in the workshop, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance