PDPA Codes of Practice for Regulated Sectors (Section 23)
Most organisations comply with the Personal Data Protection Act 2010 as written. Some also have to comply with a code of practice. Under section 23 of the Act, a data user forum for a sector can prepare a code, and once the Commissioner registers it, every organisation in that class is bound by it under section 25. Failing to comply with an applicable code is an offence in its own right under section 29, punishable by a fine of up to RM100,000, imprisonment of up to one year, or both. JPDP currently publishes codes for banking and financial institutions, insurance and takaful, the communications sector, electricity, water, aviation and private hospitals, plus a General Practice for classes that have no forum of their own. Codes registered before the 2024 amendments remain in force.
This one-day course is for DPOs, compliance and risk teams in those sectors, and for groups that span more than one of them, such as a financial group with banking and insurance arms. It explains how a code sits alongside the amended Act, walks through what each registered code adds to the seven principles, and shows how to evidence compliance with the code rather than just the Act. Sector editions go deeper for banking and financial institutions and private hospitals, and in-house editions for the other sectors can be arranged on request.
HRD Corp SBL-Khas Claimable
Programme Agenda
9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
9:15 AM - 10:15 AM
How Section 23 Codes Work
Data user forums, how a code is prepared and registered, the Register of Codes of Practice, and why a registered code binds the whole class under section 25 whether or not an organisation took part in drafting it. The section 29 offence for non-compliance, and what happens where a code and the amended Act say different things.
10:15 AM - 10:30 AM
Break
10:30 AM - 11:30 AM
The Registered Codes Today
A tour of the codes JPDP publishes: banking and financial institutions, insurance and takaful, communications, electricity, water, aviation and private hospitals, and the General Practice for classes without a forum. Who each one covers, who it excludes, and how to confirm which code applies to each entity in a group.
11:30 AM - 12:30 PM
What Codes Add to the Seven Principles
The recurring themes: sector-specific notice and consent practice, direct marketing rules, disclosures to regulators and industry bodies, retention periods, handling next of kin and third parties, and staff obligations. Comparing how different codes treat the same issue.
12:30 PM - 1:30 PM
Lunch
1:30 PM - 2:20 PM
Reading a Pre-Amendment Code After Act A1727
Many codes predate the 2024 amendments. How to apply a code's terms, such as data user or its transfer-abroad provisions, alongside the amended Act's data controller, data processor, DPO, breach notification and cross-border rules, and where the Act now sets a higher bar.
2:20 PM - 3:15 PM
Evidencing Code Compliance
Mapping each mandatory code provision to a control, an owner and a piece of evidence. Staff training and awareness requirements in the codes, internal monitoring, and preparing for a JPDP inspection that asks about the code, not just the Act.
3:15 PM - 3:30 PM
Break
3:30 PM - 4:45 PM
Workshop: Code Gap Assessment
Participants map their own organisation against the code that applies to it, identify the provisions they cannot currently evidence, and leave with a prioritised remediation list.
4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Explain how registered codes of practice work and why they bind every organisation in the class
- Identify which registered code applies to each entity in your group
- Describe what the registered codes add to the seven PDPA principles
- Apply a pre-amendment code alongside the amended Act
- Map mandatory code provisions to controls, owners and evidence
- Produce a prioritised code compliance gap list for your organisation
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Foundation. For DPOs, compliance, risk and legal teams in banking, insurance and takaful, communications, utilities, aviation and private healthcare. Basic PDPA knowledge helpful.
Duration 1 Day (8 Hours) | 9:00 AM to 5:00 PM
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A code gap assessment for the participant's organisation, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance