PDPA Obligations for Data Processors, Vendors and Outsourced Service Providers
Until 2025, a Malaysian vendor that handled personal data for its clients could treat PDPA as the client's problem. The Personal Data Protection (Amendment) Act 2024 ended that. From 1 April 2025, data processors are directly bound by the Security Principle, and from 1 June 2025 the new section 12A requires a data processor to appoint its own data protection officer where the Commissioner's DPO guideline thresholds are met. Appointing a DPO does not discharge the processor from its other duties under the Act. Penalties for breaching the principles rose to RM1 million, up to three years' imprisonment, or both. Every payroll bureau, recruitment agency, BPO, SaaS provider, cloud reseller, marketing agency and managed IT provider in Malaysia now carries obligations of its own.
This one-day course is written for those vendors, and for the procurement and vendor managers who oversee them. It starts with the question most processors get wrong, whether they are a processor at all for a given service, and works through the processor's own security duty, the DPO decision, what to do in the first hours of a breach so the client can meet its 72-hour notification to the Commissioner, and the contract, audit and sub-processor terms that clients are now pushing down the supply chain. Controllers who want the wider programme should attend DPO Basic, and firms that need a DPO without hiring one can look at DPO as a Service.
HRD Corp SBL-Khas Claimable
Programme Agenda
9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
9:15 AM - 10:15 AM
Controller, Processor or Both?
How the amended Act uses data controller and data processor, and why the same company is often a processor for one service and a controller for its own staff and marketing data. Tests that settle the question: who decides the purpose, who decides the means, and what happens when a vendor starts using client data for its own analytics or product improvement. Exercise: classify eight common vendor services.
10:15 AM - 10:30 AM
Break
10:30 AM - 11:30 AM
The Processor's Own Security Duty
What being directly bound by the Security Principle from 1 April 2025 means for a processor: practical steps to protect personal data from loss, misuse, unauthorised access and disclosure, proportionate to the harm that could result. Access control, encryption, logging, staff vetting and training, and the evidence a client or JPDP will ask for.
11:30 AM - 12:30 PM
Appointing a Processor DPO Under Section 12A
When a processor must appoint a DPO under the Commissioner's DPO guideline thresholds, what "one or more" DPOs allows, the skills and independence expected, notifying the Commissioner of the appointment, and realistic options for a small vendor, including an outsourced DPO. Why the appointment does not transfer the processor's legal duties to the DPO.
12:30 PM - 1:30 PM
Lunch
1:30 PM - 2:20 PM
Breach Escalation to the Controller
Mandatory breach notification under section 12B sits with the controller, which must notify the Commissioner within 72 hours under the Data Breach Notification Guideline. The processor's job is to make that possible: detection, triage, what to tell the client and how fast, preserving evidence, and not notifying individuals or the media on the client's behalf without instruction. Tabletop: a ransomware incident at a payroll processor.
2:20 PM - 3:15 PM
Contracts, Audits and Sub-Processors
The clauses clients now expect: processing only on instructions, confidentiality, security standards, breach notice periods, audit and inspection rights, return and deletion at the end of the contract, and flow-down to sub-processors. Negotiating terms a small vendor can actually meet. Managing your own sub-processors, including cloud and offshore support, and cross-border transfer questions.
3:15 PM - 3:30 PM
Break
3:30 PM - 4:45 PM
Processor Readiness Clinic
Participants build a one-page processor compliance pack for their own service: role mapping, security controls summary, DPO position, breach escalation contacts and a standard response to client due diligence questionnaires.
4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Determine whether you act as a data processor, a data controller, or both, for each service you provide
- Explain the Security Principle duties that now apply directly to processors
- Decide whether section 12A requires you to appoint a DPO, and how to resource the role
- Escalate a breach to the controller fast enough for the 72-hour notification to be met
- Negotiate processing, audit and sub-processor clauses you can comply with
- Answer client due diligence questionnaires with a consistent processor compliance pack
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Foundation. For owners, operations, IT and compliance leads at SaaS and technology vendors, BPOs, payroll and HR outsourcing providers, recruitment and marketing agencies, cloud resellers and managed service providers, and the procurement teams who manage them.
Duration 1 Day (8 Hours) | 9:00 AM to 5:00 PM
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A processor compliance pack for the participant's own service, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance