Data Protection Impact Assessment (DPIA) under the JPDP Guideline

On 30 April 2026 the Personal Data Protection Department released its Data Protection Impact Assessment Guideline, alongside guidelines on data protection by design and on automated decision-making and profiling. The DPIA guideline sets quantitative thresholds, processing the personal data of more than 20,000 individuals or the sensitive personal data of more than 10,000, and qualitative triggers such as automated decision-making, children's data, systematic monitoring and decisions that affect a person's legal or financial position. It sets out a five-step method: describe the processing, evaluate its necessity and proportionality, identify the risks, consider the safeguards, and assess the residual risk that senior management must then accept or reduce. For banks, insurers, hospitals, telcos, e-commerce platforms and any organisation with a sizeable customer base, the question is no longer whether to do DPIAs but whether the ones you do would stand up.

This two-day course is built for the people who will run and sign off those assessments: DPOs, privacy and compliance teams, product owners and IT and data architects. Day one covers screening and the method step by step. Day two is practical, taking a live scenario from screening to a signed-off assessment and then wiring the DPIA into change management and vendor onboarding so it happens without being chased. It pairs with Data Protection by Design and Automated Decision-Making and Profiling, and the background is set out in our article on the three 2026 guidelines.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

Day 1, 9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

Day 1, 9:15 AM - 10:15 AM

Where the DPIA Sits in the Amended PDPA

The 2024 amendments, the seven PDPA principles, and how the three April 2026 guidelines fit together. What the DPIA guideline expects of the data controller and its DPO, and why a DPIA is the record that shows accountability after something goes wrong.

03

Day 1, 10:15 AM - 10:30 AM

Break

04

Day 1, 10:30 AM - 11:30 AM

Screening: Does This Processing Need a DPIA?

The quantitative thresholds of 20,000 data subjects and 10,000 for sensitive personal data, and the qualitative triggers that apply regardless of volume, including automated decision-making and profiling, children's data, systematic monitoring and biometric processing. Building a screening questionnaire that product and project teams can complete themselves, and recording a decision not to proceed to a full DPIA.

05

Day 1, 11:30 AM - 12:30 PM

Step One: Describe the Processing

Data inventory, flows, systems, recipients, processors, retention and cross-border transfers for the activity being assessed. How much detail is enough, and the common failure of describing the system rather than the processing.

06

Day 1, 12:30 PM - 1:30 PM

Lunch

07

Day 1, 1:30 PM - 3:15 PM

Step Two: Evaluate Necessity and Proportionality

Testing purpose, data minimisation, retention, notice and choice, and data subject rights against the processing as designed. When consultation with data subjects or their representatives adds value, and how to record it.

08

Day 1, 3:15 PM - 3:30 PM

Break

09

Day 1, 3:30 PM - 4:45 PM

Step Three: Identify the Risks

Risks to individuals rather than to the organisation: loss, misuse, discrimination, financial harm, loss of control and chilling effects. Likelihood and severity scales that different assessors apply consistently, and worked examples from banking, healthcare, HR and retail.

10

Day 1, 4:45 PM - 5:00 PM

Day 1 Close

Recap and what to review before day two.

11

Day 2, 9:00 AM - 9:15 AM

Day 1 Review

Recap of day one and the questions it left open.

12

Day 2, 9:15 AM - 10:15 AM

Step Four: Consider the Safeguards

Technical, organisational and contractual measures, and how to show each one actually reduces a named risk. Security controls, pseudonymisation, access restriction, retention automation, human review, processor terms and transfer mechanisms.

13

Day 2, 10:15 AM - 10:30 AM

Break

14

Day 2, 10:30 AM - 12:30 PM

Step Five: Residual Risk, Sign-Off and Records

Assessing what is left, who in senior management accepts it, and what happens when the residual risk is too high to accept. The DPO's advice and how disagreements are recorded. DPIA records, retention and the review triggers that should reopen an assessment.

15

Day 2, 12:30 PM - 1:30 PM

Lunch

16

Day 2, 1:30 PM - 3:15 PM

Making DPIA Routine

Embedding screening in project intake, change advisory boards, procurement and vendor onboarding. A DPIA register, metrics for the board, and how DPIA links to breach response and data protection by design.

17

Day 2, 3:15 PM - 3:30 PM

Break

18

Day 2, 3:30 PM - 4:45 PM

Workshop: A Full DPIA on a Live Scenario

Teams take a realistic proposal, such as a customer loyalty app with location tracking or an AI-assisted hiring shortlist, from screening through all five steps to a sign-off recommendation, then present and defend it.

19

Day 2, 4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Screen proposed processing against the JPDP quantitative thresholds and qualitative triggers
  • Run a DPIA through the five steps: describe, evaluate, identify, consider and assess
  • Rate risks to individuals consistently and link each safeguard to the risk it reduces
  • Present residual risk to senior management for an informed accept or reduce decision
  • Keep DPIA records and know which changes should reopen an assessment
  • Embed DPIA screening into project, change and vendor processes

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate. For DPOs, privacy and compliance officers, product owners, IT and data architects, and risk managers. Basic PDPA knowledge assumed; attend DPO Basic first if new to the Act.

Duration   2 Days (16 Hours)  |  9:00 AM to 5:00 PM daily

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A completed DPIA on a supplied scenario, presented and defended in the workshop, plus a written knowledge check

Certificate   Certificate of Completion issued to all participants upon full attendance

Enquiries   Contact us to register or discuss scheduling

Frequently Asked Questions

Yes. Data Protection Impact Assessment (DPIA) under the JPDP Guideline is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

Data Protection Impact Assessment (DPIA) under the JPDP Guideline runs for 2 days (16 hours) | 9:00 AM to 5:00 PM daily. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Intermediate. For DPOs, privacy and compliance officers, product owners, IT and data architects, and risk managers. Basic PDPA knowledge assumed; attend DPO Basic first if new to the Act. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.