Cyber Breach Counsel Update: One Year On: Malaysia’s Mandatory Data Breach Notification Regime and the Risks Beyond Compliance

Introduction

On 1 June 2025, Malaysia’s Personal Data Protection Act 2010 (“PDPA”) entered a new phase with the coming into force of the mandatory personal data breach notification requirement under section 12B. In broad terms, where a data controller has reason to believe that a data breach which results in significant harm has occurred, it must notify the Personal Data Protection Commissioner (“Commissioner”) as soon as practicable and, in any event, within 72 hours. Where the breach causes or is likely to cause significant harm to data subjects, the data controller also has the obligation to notify the affected data subjects without unnecessary delay, within seven days after the initial data breach notification is made to the Commissioner.

One year on from the introduction of Malaysia’s mandatory data breach notification regime, there has been no widely reported trend of public enforcement action by the Commissioner arising from notifications made under the regime. This, however, should not give companies a false sense of security. Enforcement risk is only one part of the broader risk landscape. The concern is that a data breach incident may escalate into consequences that extend far beyond regulatory scrutiny, including prolonged litigation, commercial disruption, reputational damage and financial exposure.

When a Data Incident Becomes a Prolonged Legal Battle

The dispute between Nuemera (M) Sdn Bhd (“Nuemera”) and the Malaysian Communications and Multimedia Commission (“MCMC”) illustrates the point. What began as a data breach incident involving millions of mobile phone subscribers evolved into a dispute. The dispute arose from the Public Cellular Blocking Service (“PCBS”) agreement entered between Nuemera and MCMC. 

In 2019, it was reported that MCMC ended the contract with Nuemera following a data leak incident affecting 46.2 million mobile phone accounts1. The arbitral tribunal issued a final award in October 2022, including declarations on the validity of the suspension and non-renewal of the agreement, as well as monetary awards in respect of charges and interest2. Further proceedings then arose concerning an addendum award pertaining to interest computation3.

The dispute did not end there. In March 2023, Nuemera pursued claims in civil court including misfeasance in public office and wrongful interference with trade against MCMC and MCMC officers. Nuemera’s case, in substance, was that allegations relating to the data leak had been used against it in a manner that contributed to the suspension and termination of the PCBS arrangement4. This Nuemera-MCMC dispute is one example of how a data breach incident can develop into a legal battle lasting several years.

Employee Leakage and Substantial Damages Exposure

In the more recent Federal Court’s decision involving Public Bank Bhd and National Feedlot Corporation Sdn Bhd (“NFCorp”)5, the claim arose from unauthorised disclosure of confidential customer banking details by a former clerical bank staff. The banking details were eventually made public. The Federal Court ordered Public Bank to pay RM90 million in damages (equitable damages, exemplary damages and aggravated damages) to NFCorp and related plaintiffs.

The decision is a reminder that data breach risk is not confined to external cyberattacks or failures in IT systems. A breach may also arise from employee misconduct, unauthorised internal access or leakage of confidential information by individuals within an organisation.

Beyond Compliance: Preparing for the Wider Consequences of a Data Breach

Before the mandatory breach notification regime, data breaches may have been managed internally, with little external visibility. The notification regime changes that position. Once a breach is reported, the incident may attract regulatory scrutiny and may no longer remain a matter that can be contained within the organisation. 

Companies should thus ensure that they have a clear and tested breach response protocol, not only to meet regulatory notification requirements, but also to manage the wider legal, operational and commercial issues that may arise if the incident later becomes the subject of regulatory scrutiny, litigation or other disputes. This includes taking early steps to preserve evidence, maintain legal privilege where appropriate, coordinate internal investigations, and manage communications with regulators, affected individuals and other stakeholders.

Prepared by
Lilien Wong
Cyber Breach Counsel

Footnotes:

  1. www.malaymail.com/news/malaysia/2019/10/14/report-mcmc-ends-contract-with-company-after-massive-2017-phone-data-leak/1800249.
  2. Malaysian Communications and Multimedia Commission & Ors v Nuemera (M) Sdn Bhd [2024] CLJU 2424.
  3. Nuemera (M) Sdn Bhd v Malaysian Communications and Multimedia Commission [2024] 7 CLJ 155.
  4. Malaysian Communications and Multimedia Commission & Ors v Nuemera (M) Sdn Bhd [2024] CLJU 2424.
  5. Public Bank Bhd v National Feedlot Corporation Sdn Bhd & ors and another appeal [2025] 9 CLJ 193; National Feedlot Corporation Sdn Bhd & Ors v Public Bank Bhd [2023] 10 CLJ 430.  

COPYRIGHT © 2026  SHEARN DELAMORE & CO. ALL RIGHTS RESERVED
THIS UPDATE IS ISSUED FOR THE INFORMATION OF THE CLIENTS OF THE FIRM AND COVERS LEGAL ISSUES IN A GENERAL WAY. 

THE CONTENTS ARE NOT INTENDED TO CONSTITUTE ANY ADVICE ON ANY SPECIFIC MATTER AND SHOULD NOT BE RELIED UPON AS A SUBSTITUTE FOR DETAILED LEGAL ADVICE ON SPECIFIC MATTERS OR TRANSACTIONS.