PDPA Obligations for Data Processors, Vendors and Outsourced Service Providers

Until 2025, a Malaysian vendor that handled personal data for its clients could treat PDPA as the client's problem. The Personal Data Protection (Amendment) Act 2024 ended that. From 1 April 2025, data processors are directly bound by the Security Principle, and from 1 June 2025 the new section 12A requires a data processor to appoint its own data protection officer where the Commissioner's DPO guideline thresholds are met. Appointing a DPO does not discharge the processor from its other duties under the Act. Penalties for breaching the principles rose to RM1 million, up to three years' imprisonment, or both. Every payroll bureau, recruitment agency, BPO, SaaS provider, cloud reseller, marketing agency and managed IT provider in Malaysia now carries obligations of its own.

This one-day course is written for those vendors, and for the procurement and vendor managers who oversee them. It starts with the question most processors get wrong, whether they are a processor at all for a given service, and works through the processor's own security duty, the DPO decision, what to do in the first hours of a breach so the client can meet its 72-hour notification to the Commissioner, and the contract, audit and sub-processor terms that clients are now pushing down the supply chain. Controllers who want the wider programme should attend DPO Basic, and firms that need a DPO without hiring one can look at DPO as a Service.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

9:15 AM - 10:15 AM

Controller, Processor or Both?

How the amended Act uses data controller and data processor, and why the same company is often a processor for one service and a controller for its own staff and marketing data. Tests that settle the question: who decides the purpose, who decides the means, and what happens when a vendor starts using client data for its own analytics or product improvement. Exercise: classify eight common vendor services.

03

10:15 AM - 10:30 AM

Break

04

10:30 AM - 11:30 AM

The Processor's Own Security Duty

What being directly bound by the Security Principle from 1 April 2025 means for a processor: practical steps to protect personal data from loss, misuse, unauthorised access and disclosure, proportionate to the harm that could result. Access control, encryption, logging, staff vetting and training, and the evidence a client or JPDP will ask for.

05

11:30 AM - 12:30 PM

Appointing a Processor DPO Under Section 12A

When a processor must appoint a DPO under the Commissioner's DPO guideline thresholds, what "one or more" DPOs allows, the skills and independence expected, notifying the Commissioner of the appointment, and realistic options for a small vendor, including an outsourced DPO. Why the appointment does not transfer the processor's legal duties to the DPO.

06

12:30 PM - 1:30 PM

Lunch

07

1:30 PM - 2:20 PM

Breach Escalation to the Controller

Mandatory breach notification under section 12B sits with the controller, which must notify the Commissioner within 72 hours under the Data Breach Notification Guideline. The processor's job is to make that possible: detection, triage, what to tell the client and how fast, preserving evidence, and not notifying individuals or the media on the client's behalf without instruction. Tabletop: a ransomware incident at a payroll processor.

08

2:20 PM - 3:15 PM

Contracts, Audits and Sub-Processors

The clauses clients now expect: processing only on instructions, confidentiality, security standards, breach notice periods, audit and inspection rights, return and deletion at the end of the contract, and flow-down to sub-processors. Negotiating terms a small vendor can actually meet. Managing your own sub-processors, including cloud and offshore support, and cross-border transfer questions.

09

3:15 PM - 3:30 PM

Break

10

3:30 PM - 4:45 PM

Processor Readiness Clinic

Participants build a one-page processor compliance pack for their own service: role mapping, security controls summary, DPO position, breach escalation contacts and a standard response to client due diligence questionnaires.

11

4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Determine whether you act as a data processor, a data controller, or both, for each service you provide
  • Explain the Security Principle duties that now apply directly to processors
  • Decide whether section 12A requires you to appoint a DPO, and how to resource the role
  • Escalate a breach to the controller fast enough for the 72-hour notification to be met
  • Negotiate processing, audit and sub-processor clauses you can comply with
  • Answer client due diligence questionnaires with a consistent processor compliance pack

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Foundation. For owners, operations, IT and compliance leads at SaaS and technology vendors, BPOs, payroll and HR outsourcing providers, recruitment and marketing agencies, cloud resellers and managed service providers, and the procurement teams who manage them.

Duration   1 Day (8 Hours)  |  9:00 AM to 5:00 PM

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A processor compliance pack for the participant's own service, plus a written knowledge check

Certificate   Certificate of Completion issued to all participants upon full attendance

Enquiries   Contact us to register or discuss scheduling

Frequently Asked Questions

Yes. PDPA Obligations for Data Processors, Vendors and Outsourced Service Providers is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

PDPA Obligations for Data Processors, Vendors and Outsourced Service Providers runs for 1 day (8 hours) | 9:00 AM to 5:00 PM. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Foundation. For owners, operations, IT and compliance leads at SaaS and technology vendors, BPOs, payroll and HR outsourcing providers, recruitment and marketing agencies, cloud resellers and managed service providers, and the procurement teams who manage them. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.