PDPA Code of Practice for Banking and Financial Institutions
Banks and financial institutions licensed under the Financial Services Act 2013, the Islamic Financial Services Act 2013 and the Development Financial Institutions Act 2002 are bound not only by the PDPA but by the Personal Data Protection Code of Practice for the Banking and Financial Sector. The code was developed by the Association of Banks in Malaysia as the designated data user forum, with the investment banking, Islamic banking and development finance associations, and is registered with the Commissioner. Under section 25 of the Act every institution in the class must comply, and a failure to comply with the code is an offence punishable by a fine of up to RM100,000, up to one year's imprisonment, or both. Institutions licensed only in Labuan fall outside it.
The code goes further than the Act on the issues banks deal with every day: when marketing counts as direct marketing, how credit reporting agency data may be used, which fraud and default databases a bank may keep and share, what staff may say when a call is answered by someone other than the customer, how archived and dormant account data is treated, and how access and correction requests must be handled. This one-day course works through those provisions clause by clause, for compliance, operations, contact centre, marketing and credit teams, and shows where the 2024 amendments now set a higher bar than the 2017 text. For the full cross-sector picture see PDPA Codes of Practice for Regulated Sectors.
HRD Corp SBL-Khas Claimable
Programme Agenda
9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
9:15 AM - 10:15 AM
The Code, Who It Binds and Its Legal Force
Scope across FSA, IFSA and DFIA licensees, the Labuan exclusion, the role of ABM and the other associations, registration and effect, and the section 29 offence. How the code's data user terms map to the amended Act's data controller and data processor.
10:15 AM - 10:30 AM
Break
10:30 AM - 11:30 AM
The Principles as the Code Applies Them
The General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access principles as the code interprets them for banking, including privacy notice content, disclosures to regulators, agents and group companies, and retention of account records.
11:30 AM - 12:30 PM
Direct Marketing and Customer Contact
What the code treats as direct marketing and what it does not, such as renewal reminders or material sent to an entire category of customers, consent and withdrawal, and the code's rules on contacting customers by phone, including what may be said when someone else answers.
12:30 PM - 1:30 PM
Lunch
1:30 PM - 2:20 PM
Credit Data, Fraud Databases and Pre-Existing Data
Using credit reporting agency data for applications, reviews and renewals, the fraud and default databases the code permits under section 45, sharing fraud data between institutions, and how the code treats dormant, archived and backup data.
2:20 PM - 3:15 PM
Customer Rights in Practice
Access and correction requests, preventing processing likely to cause damage or distress, withdrawing consent, stopping direct marketing, and the newer right to data portability, with the request forms and timelines the code and the Act expect.
3:15 PM - 3:30 PM
Break
3:30 PM - 4:45 PM
Staff, Breaches and Evidence of Compliance
The code's requirements on policies, staff training and control systems, how breach notification under the amended Act fits with the code, and a clause-by-clause evidence map for internal audit and JPDP. Case workshop on three customer complaints.
4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Explain who the banking code binds and the consequences of non-compliance
- Apply the code's interpretation of the seven principles to banking processes
- Distinguish direct marketing from service communications as the code defines them
- Use credit reporting agency data and fraud databases within the code's limits
- Handle customer rights requests to the standard the code and the Act require
- Evidence code compliance to internal audit and JPDP
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Foundation. For compliance, operations, contact centre, marketing, credit and branch teams, and DPOs in banks, Islamic banks, investment banks and development financial institutions.
Duration 1 Day (8 Hours) | 9:00 AM to 5:00 PM
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A case workshop on three customer complaints and a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance