PDPA Code of Practice for Banking and Financial Institutions

Banks and financial institutions licensed under the Financial Services Act 2013, the Islamic Financial Services Act 2013 and the Development Financial Institutions Act 2002 are bound not only by the PDPA but by the Personal Data Protection Code of Practice for the Banking and Financial Sector. The code was developed by the Association of Banks in Malaysia as the designated data user forum, with the investment banking, Islamic banking and development finance associations, and is registered with the Commissioner. Under section 25 of the Act every institution in the class must comply, and a failure to comply with the code is an offence punishable by a fine of up to RM100,000, up to one year's imprisonment, or both. Institutions licensed only in Labuan fall outside it.

The code goes further than the Act on the issues banks deal with every day: when marketing counts as direct marketing, how credit reporting agency data may be used, which fraud and default databases a bank may keep and share, what staff may say when a call is answered by someone other than the customer, how archived and dormant account data is treated, and how access and correction requests must be handled. This one-day course works through those provisions clause by clause, for compliance, operations, contact centre, marketing and credit teams, and shows where the 2024 amendments now set a higher bar than the 2017 text. For the full cross-sector picture see PDPA Codes of Practice for Regulated Sectors.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

9:15 AM - 10:15 AM

The Code, Who It Binds and Its Legal Force

Scope across FSA, IFSA and DFIA licensees, the Labuan exclusion, the role of ABM and the other associations, registration and effect, and the section 29 offence. How the code's data user terms map to the amended Act's data controller and data processor.

03

10:15 AM - 10:30 AM

Break

04

10:30 AM - 11:30 AM

The Principles as the Code Applies Them

The General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access principles as the code interprets them for banking, including privacy notice content, disclosures to regulators, agents and group companies, and retention of account records.

05

11:30 AM - 12:30 PM

Direct Marketing and Customer Contact

What the code treats as direct marketing and what it does not, such as renewal reminders or material sent to an entire category of customers, consent and withdrawal, and the code's rules on contacting customers by phone, including what may be said when someone else answers.

06

12:30 PM - 1:30 PM

Lunch

07

1:30 PM - 2:20 PM

Credit Data, Fraud Databases and Pre-Existing Data

Using credit reporting agency data for applications, reviews and renewals, the fraud and default databases the code permits under section 45, sharing fraud data between institutions, and how the code treats dormant, archived and backup data.

08

2:20 PM - 3:15 PM

Customer Rights in Practice

Access and correction requests, preventing processing likely to cause damage or distress, withdrawing consent, stopping direct marketing, and the newer right to data portability, with the request forms and timelines the code and the Act expect.

09

3:15 PM - 3:30 PM

Break

10

3:30 PM - 4:45 PM

Staff, Breaches and Evidence of Compliance

The code's requirements on policies, staff training and control systems, how breach notification under the amended Act fits with the code, and a clause-by-clause evidence map for internal audit and JPDP. Case workshop on three customer complaints.

11

4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Explain who the banking code binds and the consequences of non-compliance
  • Apply the code's interpretation of the seven principles to banking processes
  • Distinguish direct marketing from service communications as the code defines them
  • Use credit reporting agency data and fraud databases within the code's limits
  • Handle customer rights requests to the standard the code and the Act require
  • Evidence code compliance to internal audit and JPDP

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Foundation. For compliance, operations, contact centre, marketing, credit and branch teams, and DPOs in banks, Islamic banks, investment banks and development financial institutions.

Duration   1 Day (8 Hours)  |  9:00 AM to 5:00 PM

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A case workshop on three customer complaints and a written knowledge check

Certificate   Certificate of Completion issued to all participants upon full attendance

Enquiries   Contact us to register or discuss scheduling

Frequently Asked Questions

Yes. PDPA Code of Practice for Banking and Financial Institutions is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

PDPA Code of Practice for Banking and Financial Institutions runs for 1 day (8 hours) | 9:00 AM to 5:00 PM. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Foundation. For compliance, operations, contact centre, marketing, credit and branch teams, and DPOs in banks, Islamic banks, investment banks and development financial institutions. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.