Biometric and Sensitive Personal Data under the Amended PDPA

Fingerprint time clocks, face recognition at the office door, voice authentication in the call centre and selfie checks in onboarding apps are everywhere in Malaysia. Since 1 April 2025 the data they collect is sensitive personal data. The amended PDPA defines biometric data as personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person, and adds it to the list of sensitive personal data alongside health, political opinions, religious beliefs and offences. Sensitive personal data can only be processed with explicit consent or under one of the specific conditions in section 40, and breaches of the principles can now be punished by a fine of up to RM1 million, up to three years' imprisonment, or both.

This one-day course is for HR, payroll, facilities and security, IT, customer onboarding and product teams, and the DPOs who advise them. It covers what counts as biometric and other sensitive data, when a biometric system is justified at all, how to obtain consent that is genuinely explicit, especially from employees, and how to secure, retain and delete templates. Planning a new biometric system should also involve a Data Protection Impact Assessment, which the JPDP guideline treats biometric processing as a trigger for.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

9:15 AM - 10:15 AM

What Counts as Biometric and Sensitive Data

The amended definitions, what technical processing means in practice, the difference between a photo and a face template, and the full list of sensitive personal data. Exercise: classify twelve common workplace and customer data types.

03

10:15 AM - 10:30 AM

Break

04

10:30 AM - 11:30 AM

Explicit Consent and the Section 40 Conditions

What makes consent explicit, why consent from employees is hard to make genuinely free, and the other conditions that allow processing of sensitive data, such as employment law obligations, vital interests and legal claims.

05

11:30 AM - 12:30 PM

Is Biometrics Necessary and Proportionate?

Testing a proposed system against its purpose, alternatives such as cards or PINs, offering a choice, and when a DPIA is required. Case studies: attendance clocks, building access, customer eKYC and voice authentication.

06

12:30 PM - 1:30 PM

Lunch

07

1:30 PM - 2:20 PM

Security, Retention and Vendors

Protecting templates, encryption and access, on-device versus central storage, retention and deletion when staff leave or customers close accounts, and the vendor contract terms that matter for biometric processors.

08

2:20 PM - 3:15 PM

Rights, Breaches and Workplace Practice

Access and correction for sensitive data, handling objections, breach notification when biometric data is exposed, and communicating a biometric deployment to staff and unions.

09

3:15 PM - 3:30 PM

Break

10

3:30 PM - 4:45 PM

Workshop: Reviewing a Biometric Deployment

Teams review a realistic biometric time-and-attendance rollout and produce the purpose statement, consent approach, alternative option, retention rule and vendor requirements.

11

4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Identify biometric and other sensitive personal data under the amended PDPA
  • Obtain explicit consent, or identify another valid condition, for sensitive data
  • Assess whether a biometric system is necessary and proportionate
  • Secure, retain and delete biometric templates appropriately
  • Handle rights requests and breaches involving sensitive data
  • Review a biometric deployment before it goes live

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Foundation. For HR, payroll, facilities and security, IT, onboarding and product teams, and DPOs and compliance staff.

Duration   1 Day (8 Hours)  |  9:00 AM to 5:00 PM

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A biometric deployment review completed in the workshop, plus a written knowledge check

Certificate   Certificate of Completion issued to all participants upon full attendance

Enquiries   Contact us to register or discuss scheduling

Frequently Asked Questions

Yes. Biometric and Sensitive Personal Data under the Amended PDPA is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

Biometric and Sensitive Personal Data under the Amended PDPA runs for 1 day (8 hours) | 9:00 AM to 5:00 PM. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Foundation. For HR, payroll, facilities and security, IT, onboarding and product teams, and DPOs and compliance staff. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.