Malaysia's Personal Data Protection Commissioner has published a written test for when a Data Protection Impact Assessment is required. Most organisations have not run it against their projects.
It takes about a minute. Answer four questions and find out where you stand.
This follows the test set out in the Commissioner's DPIA Guideline and ADMP Guideline. It is not legal advice and it does not record anything until you choose to send yourself the result.
A DPIA is an assessment you carry out before you start processing personal data, not after.
You take a planned activity, describe exactly what personal data it will involve and why, work out what could go wrong for the people whose data it is, and decide whether the risks are acceptable. If they are not, you change the plan or add safeguards before anything goes live.
That is the whole idea. It is a structured way of asking "should we be doing this, in this way?" while there is still time to change the answer.
The Commissioner's DPIA Guideline describes it as a process for analysing and reducing personal data protection risk, based on how your organisation actually functions. It is deliberately practical. It is not a legal opinion and it is not a policy document.
Two things follow from the timing, and they catch people out:
It is prospective. A DPIA is for a planned processing operation. If the system is already live, you are no longer doing a DPIA in the way the Guideline intends. You are doing remedial work.
It has an owner. The obligation sits on the data controller, and ultimate responsibility for the assessment and for whatever is decided as a result sits with senior management. Not with IT. Not with the vendor.
This deserves a careful answer, because the honest one is more useful than a simple one.
The Personal Data Protection Act 2010 does not contain a section that says "you must carry out a DPIA". There is no standalone statutory DPIA duty in the Act itself.
What exists is this. Section 12A of the Act requires data controllers and data processors to appoint a Data Protection Officer. The Commissioner's Circular No. 1/2025 sets out what that officer is responsible for, and one of those responsibilities is supporting and advising on DPIAs. The DPIA Guideline is then issued by the Commissioner under section 48(g) of the Act to set out the requirements for carrying them out.
The Guideline itself is written in obligatory language. Where a data controller foresees that a planned processing operation is likely to result in a high risk to personal data protection, it states that a DPIA shall be carried out.
In our view, the practical position is straightforward even if the statutory route is indirect. A data controller who processes personal data in the circumstances the Guideline describes, and who has carried out no DPIA, would be in a difficult position if the Commissioner asked why. Whether or not you characterise it as a strict statutory duty, it is the standard against which your decision-making will be measured.
Our advice to clients is to treat it as a requirement and to keep a written record of the decision either way. Where you have concluded that no DPIA was needed, that conclusion is itself worth documenting.
Four roles, and they are commonly confused.
The data controller carries the obligation. The Guideline is explicit that this is because a data processor does not process personal data for its own purposes, so it is the controller who decides whether an activity proceeds and who must make sure the risks are addressed.
Senior management carries ultimate responsibility for the assessment and for the decisions that follow from it. Where the overall residual risk comes out as high, the findings must be reported to them. In practice most organisations report all findings regardless of level, so that management is not partially informed.
The Data Protection Officer supports rather than executes. Under the Guideline the DPO's role is to identify whether a DPIA is needed at all, advise on carrying it out and on the mitigation measures, and develop templates and checklists suited to the organisation.
The DPIA Lead runs the exercise. This may be the DPO, but it may equally be the project manager or someone else the controller considers appropriate. The Lead gathers input from the people who actually understand the processing.
Beyond those four, the Guideline expects input from the project manager, IT, legal, any relevant subject matter experts, the data processor, and relevant third parties.
Look at the first item on the DPO's list again: identifying whether a DPIA is needed at all.
That is a judgment call, it has to be made by someone with the standing to make it, and it has to be made before the project starts rather than after. If your organisation has not appointed a DPO, or has appointed one in name without the time or the background to make that call, then nobody is making it. The question is not being answered wrongly. It is not being asked.
There are three ways to get to yes, and you only need one of them.
If the activity involves automated decision-making or profiling, a DPIA is required. The Commissioner's ADMP Guideline treats this as a trigger regardless of the nature or extent of the intended use, and states that the DPO is to ensure a DPIA is carried out for any planned processing containing these elements.
There is no volume threshold attached to this one. Read section below for what counts.
A DPIA is required where the processing is expected to involve:
These are hard numbers. If you meet either, the analysis stops and a DPIA is required.
If neither threshold is met, the DPO exercises judgment against a list of factors that suggest high risk. The Guideline lists six, and is clear that the list is neither exhaustive nor exclusive:
Note how wide the third one is. "New to your organisation" is enough. It does not have to be new to the market.
The Guideline takes the sensible position that where it is not obvious whether a DPIA is required, it is prudent to carry one out anyway. It remains useful for managing risk and for building trust, whether or not it was strictly required.
The volume thresholds are what most people notice first. The automation trigger is what actually catches them.
Broadly, any system that evaluates, scores, ranks, segments, or predicts something about a person, or that reaches a decision about them without a human making the final call. From the examples in the Commissioner's ADMP Guideline and in ordinary commercial practice, this covers a great deal of what businesses already run:
If you have adopted an AI tool anywhere in a process that touches people, you are very likely inside this category.
Because it does not scale with size. A company with 500 customers running a recommendation engine is caught. A company with 200,000 customers running nothing but a mailing list may not be. The volume thresholds are the intuitive test and the automation trigger is the one that actually decides most cases.
There is a difference in wording across the two guidelines that has not yet been resolved.
The DPIA Guideline's narrative list of qualitative factors contains six items and does not mention automated decision-making separately. Its own assessment template, however, adds a seventh option covering automated decision-making and profiling that pose a high risk to the data subject. The ADMP Guideline attaches no such qualification, and applies the trigger regardless of the extent of intended use.
So the same regulator has expressed the same rule in three slightly different ways across two documents.
Our view is that the ADMP Guideline governs, because it is the specific instrument addressing the specific subject, and because it is the later and more detailed treatment. On that reading, automated decision-making or profiling triggers a DPIA without a separate high-risk assessment first.
That is our reading rather than a settled position, and we would expect it to be clarified. Until it is, the conservative course is to carry out the DPIA. The cost of doing one unnecessarily is a few weeks of work. The cost of having skipped one is explaining to the Commissioner why you took the narrower reading.
The Guideline sets out a five-step approach, abbreviated as DEICA.
Each risk is scored low, medium or high on both axes, and the resulting score places it in a band. The Guideline provides criteria for each score, so this is not a matter of instinct.
A DPIA is not a document you file and forget.
Report to senior management. Where the overall residual risk is assessed as high, the findings must go to senior management. Most organisations report everything, so that management has the full picture rather than half of it. Management then decides: accept the residual risk, require further mitigation, or do not proceed.
Implement the mitigation. The measures identified in the assessment have to actually be built. This is where the Commissioner's Data Protection by Design Guideline becomes the working document, since it sets out what good practice looks like under each of the seven data protection principles.
It expires. A completed DPIA is valid for two years from the date of completion. After that, a refreshed assessment is required.
It is monitored in between. The Guideline is clear that a DPIA is not a one-off activity. Regardless of the validity period, the processing has to be monitored and reviewed throughout its life. A material change to the processing means revisiting the assessment before the two years are up.
You may publish it. Publication is optional, but the Guideline encourages it as a way of building trust, and allows a redacted version or a summary where the full document would expose commercially sensitive information or create security risk.
If you carried out a DPIA in 2026, it expires in 2028. If you have several, they expire on different dates. Somebody has to be tracking that, monitoring the processing in the meantime, and refreshing each one before it lapses.
That is ongoing work rather than a project, which is why organisations that treat data protection as a series of one-off exercises tend to find themselves out of date without noticing.
We are a Kuala Lumpur law firm and data protection is our core practice.
Work out whether you need one. If you are not sure whether an activity crosses the line, we will tell you, and give you the reasoning in writing so the decision is documented either way.
Carry out the DPIA. We run the assessment with your project team, produce the report, and put it in a form your senior management can actually act on.
Act as your outsourced Data Protection Officer. Section 12A requires a DPO. For many organisations, appointing one internally means asking somebody to take on a role they were not hired for and have no background in. We do it as an ongoing engagement, which includes making the DPIA call on each new project as it comes up, and tracking the two-year refresh cycle.
Edwin Lee is the founder and managing partner of Edwin Lee & Partners.
He has worked on Malaysian data protection law since before the Act came into force. His LL.M at the University of Malaya analysed the Personal Data Protection Bill 2009, and he is a co-editor of Beyond Data Protection (Springer, 2013). He founded two technology companies before establishing the firm, and comments on privacy and cybersecurity law in the media.
In July 2026 the firm filed a submission to the National AI Office on Malaysia's proposed AI Governance Bill, arguing that AI governance should be wired into the existing PDPA machinery rather than built alongside it.
A Data Protection Impact Assessment is a structured review of a planned processing activity, carried out before it begins, to identify and reduce risks to the people whose personal data is involved.
The Personal Data Protection Act 2010 contains no express DPIA section. The Commissioner's DPIA Guideline, issued under section 48(g), states that a DPIA shall be carried out where a planned operation is likely to result in high risk. In practice it should be treated as a requirement.
More than 20,000 data subjects, or more than 10,000 where sensitive personal data is involved. Financial information counts towards the lower threshold.
Generally yes. The Commissioner's ADMP Guideline treats automated decision-making and profiling as a trigger regardless of the extent of intended use, with no volume threshold attached.
The data controller. Ultimate responsibility for the assessment and the resulting decisions rests with senior management. The Data Protection Officer advises and identifies when one is needed.
No. The obligation sits with the controller. A processor is expected to give reasonable assistance, and the controller should secure that through contract.
Two years from the date of completion. After that a refreshed assessment is required, and the processing should be monitored in the meantime.
The five-step approach in the DPIA Guideline: Describe, Evaluate, Identify, Consider, Assess.
No. Publication is encouraged as a transparency measure, and a redacted version or summary may be published where the full document would expose sensitive information.
A DPIA looks at one planned activity in depth. A gap assessment looks at your whole organisation against the Act. Most organisations need both, for different reasons.
Before the processing begins. A DPIA is a prospective exercise. Carrying one out after a system is live is remedial work.
The Act contains no offence of failing to carry out a DPIA as such. The exposure is indirect but substantial. Since the 2024 amendments, breaching the data protection principles carries a fine of up to RM1,000,000, imprisonment of up to three years, or both, and failing to notify a personal data breach under section 12B carries up to RM250,000, two years, or both. A missing DPIA is what makes those failures difficult to defend, because it shows the risks were never assessed.