Customnex

PDPA and AI: what your company stays responsible for

A plain guide to PDPA 2010, as amended in 2024, for companies using AI with personal data. General information, not legal advice.

AI makes it easy to work with customer lists, staff records and chat messages. Each of those contains personal data. In Malaysia, the Personal Data Protection Act 2010 (PDPA) sets the rules for personal data in commercial transactions, and the 2024 amendments added new duties.

This guide explains in plain terms what the law expects when AI is involved, whether it runs in the cloud or on your own server. For decisions about your company, speak to a lawyer who practises data protection law.

What PDPA covers

Personal data is information about a person who can be identified: names, IC numbers, phone numbers, salary records, and the contact persons at your customers and suppliers. Some personal data is sensitive, such as health information, and generally needs explicit consent. Since the amendments, biometric data, such as fingerprints or face scans, counts as sensitive too.

The Act sets out seven principles: general, notice and choice, disclosure, security, retention, data integrity and access. They apply in the same way when the work is done by AI.

Controller or processor?

The amendments renamed the data user as the data controller. That is your company whenever it decides why and how personal data is used. A data processor handles personal data only on the controller's behalf, such as a payroll bureau, an IT vendor or an AI provider working to your instructions.

The controller stays responsible. Choosing a vendor does not hand over your PDPA duties, and you still need to be satisfied that the processor keeps the data secure. Processors now also have a direct duty under the security principle. Written data-processor terms make both sides' roles clear.

What the 2024 amendments changed

The changes came into force in stages during 2025. These five matter most when AI is involved.

Breach noticeTell the Commissioner as soon as practicable, within 72 hours under the guideline, and sometimes the people affected.
Data protection officerControllers and processors above set thresholds must appoint one.
Transfers abroadThe whitelist is gone. Data may leave Malaysia under set conditions, so check where any AI service processes it.
Data portabilityPeople can ask for their data to be moved, where technically feasible.
Higher penaltiesFines of up to RM1 million for breaching the principles, and up to three years' imprisonment.

Good habits for any AI set-up

Whatever AI you use, a few habits keep you in line with the principles. Agree which kinds of personal data staff may use with AI, and write it down. Limit access by role, so HR records reach only HR. Keep a record of who did what. Keep chat history only as long as you need it. And tell customers and staff how their data is used.

Private AI on your own server keeps the data under your own controls, which can make several of these habits simpler. Your duties stay the same: you are still the controller. In the Agentic Centre, access follows roles, every action is recorded, and the agent asks in the chat before it sends anything outside the company. Customnex reaches the server only with your permission, works under PDPA data-processor terms, and removes its access and deletes client data when support ends.

Questions to ask any AI vendor

Ask these of every vendor, including us.

  • Where is our data processed and stored?
  • Is anything we send used to train or improve models?
  • How long are prompts, files and chat history kept, and can we delete them?
  • Who at your company can reach our data, and can we switch that off?
  • Will you sign data-processor terms under PDPA?
  • How, and how quickly, will you tell us about a breach?
  • What happens to our data when the contract ends?

Clear, written answers make the decision easier. Share them with your lawyer or data protection officer before you sign.

Put these questions to us

Invite your IT lead or data protection officer. We will show where data sits and who can reach it.