Data Controller Registration and Renewal (JPDP Circular 1/2026)
Some organisations cannot lawfully process personal data at all until they hold a certificate of registration from the Personal Data Protection Commissioner. Personal Data Protection Commissioner's Circular No. 1/2026, in force since 1 June 2026, restates who that applies to and how it works: a business that processes personal data in commercial transactions, falls within one of the classes listed in the Class of Data Users Orders of 2013 and 2016, and operates as a sole proprietorship, a partnership, a private limited company or a public company. Applications go through the online SPDP system, a complete application is considered within fourteen working days, and renewal must be filed within ninety days before the certificate expires. Processing without a valid certificate is an offence under section 16(4) of the Act, with a fine of up to RM500,000, up to three years' imprisonment, or both.
This one-day course is for compliance managers, DPOs, company secretaries and business owners who need a straight answer to three questions: are we required to register, is our registration complete and current, and who owns keeping it that way. It covers the circular clause by clause, the fees and certificate periods, the per-licence rule, the compliance notices JPDP can serve, and the change events that quietly break a registration, such as a new subsidiary or a new regulatory licence. Registration is the entry ticket, not the whole of PDPA compliance, so the course closes by mapping what else a registered controller must have in place, and points to DPO Basic for the wider programme.
HRD Corp SBL-Khas Claimable
Programme Agenda
9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
9:15 AM - 10:15 AM
Why Registration Matters and What Changed on 1 June 2026
Registration under sections 14 to 16 of the Personal Data Protection Act 2010 and the Personal Data Protection (Registration of Data User) Regulations 2013. Why registration is the obligation JPDP most often enforces, and why a missing certificate is an easy case to prove. What Circular 1/2026 sets out, and the fact that it revokes Circular 1/2024, so older internal guidance may now be out of date.
10:15 AM - 10:30 AM
Break
10:30 AM - 11:30 AM
Are You in a Registrable Class?
The three conditions in the circular, applied one at a time: processing in commercial transactions in Malaysia, membership of a class under P.U.(A) 336/2013 or P.U.(A) 326/2016, and business form. Walking the classes, from banking, insurance, healthcare and communications to education, real estate, direct selling, professional services, pawnbrokers and moneylenders. Why limited liability partnerships sit outside the business forms listed. Exercise: participants classify their own group entities.
11:30 AM - 12:30 PM
Making the Application Through SPDP
Registering online through the Personal Data Protection System, the supporting documents from your sector regulator that prove your class and business type, and the rule that registration follows each licence or certificate issued by that regulator, except for the Services class. Annual fees of RM100 for a sole proprietorship, RM200 for a partnership, RM300 for a private limited company and RM400 for a public company, a certificate period of one to five years, and the fact that fees are not refunded once approved.
12:30 PM - 1:30 PM
Lunch
1:30 PM - 2:20 PM
Keeping the Certificate Valid
Displaying the certificate at the principal place of business, renewal within the ninety days before expiry, and the reminder notices JPDP may send at ninety, sixty and thirty days. Compliance notices and the ways the Commissioner may serve them, by registered post, at your premises, by hand or by email. The separate offence under regulation 5(2) for continuing to process after a certificate lapses, with a fine of up to RM250,000, up to two years' imprisonment, or both.
2:20 PM - 3:15 PM
Change Events and Group Structures
What breaks a registration in practice: a new subsidiary, a restructure, a new or renamed licence, a change of business form, or an acquisition. Assigning ownership so renewals are not left to one person's calendar. Building registration checks into company secretarial, licensing and M&A processes.
3:15 PM - 3:30 PM
Break
3:30 PM - 4:45 PM
Beyond Registration: What a Registered Controller Still Needs
Registration does not make an organisation compliant. A short map of the rest: the seven principles, a DPO where the thresholds apply, breach notification, data processor contracts and records. Workshop: each participant leaves with a registration status check for their own entities, a renewal calendar and a named owner.
4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Decide whether each entity in your group must register as a data controller under Circular 1/2026
- Prepare and submit a complete SPDP application with the right supporting documents
- Apply the per-licence rule, fee schedule and certificate periods correctly
- Keep certificates valid through renewals, reminders and compliance notices
- Identify the change events that require a registration to be updated
- Explain the offences and penalties for processing without a valid certificate
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Foundation. For compliance managers, DPOs, company secretaries, legal, finance and business owners. No prior PDPA training required.
Duration 1 Day (8 Hours) | 9:00 AM to 5:00 PM
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A registration status check and renewal calendar for the participant's own entities, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance