Ask a Malaysian SME who handles PDPA compliance and you get one of two answers. The company secretary. Or IT. Almost never marketing.
Which is odd, because marketing is where the personal data lives. Legal drafts the privacy notice once and files it. IT secures the server. Marketing collects the names, exports them to spreadsheets, uploads them to Meta and blasts them on WhatsApp — every week, forever. The department with the most data flowing through it is the one nobody audits.
That gap got expensive on 1 June 2025, when the main obligations of the Personal Data Protection (Amendment) Act 2024 came into force. The maximum fine for breaching the data protection principles rose to RM1 million, with up to three years’ imprisonment. “Data user” became “data controller”. And two new duties landed: mandatory breach notification and a compulsory data protection officer.
What follows is PDPA compliance for marketing — the list, the audience, the blast, the opt-out. Not the privacy policy page, which we cover in our guide to the website privacy policy Malaysian law requires, and not AI tools, covered in AI and PDPA for Malaysian marketers. Strip away the registration certificates and the cross-border rules, and four operational questions are left for your team.
None of these are documents. They’re routines — which is exactly the shift the amendment made when “data controller” replaced “data user”. A policy page proves you read the rules once, not that you follow them.
Source video: PDPA explained for businesses, on YouTube
Not sure what your stack is holding?
Every ZenWeb engagement starts with a data map before we touch a campaign. See how our digital marketing service works →
Quick Answer: Across ZenWeb’s audits of Malaysian SME marketing stacks, personal data is never in one place. It sits in the CRM, the email tool, two ad platforms, WhatsApp, and — in four out of five stacks — a spreadsheet on somebody’s laptop that nobody put on the list.
Before you can comply, you need a map. Most SMEs draw it from memory and get it wrong, because the tools arrived one at a time over five years and each kept a copy. Add a co-marketing partner or a webinar registration list and there are two more.
| Tool | Name | Phone | Purchase history | |
|---|---|---|---|---|
| Website forms → CRM | 100% | 96% | 98% | 41% |
| Email platform | 94% | 38% | 100% | 22% |
| Meta Custom Audiences | 61% | 74% | 88% | 17% |
| Google Customer Match | 44% | 29% | 79% | 9% |
| WhatsApp Business | 88% | 100% | 14% | 31% |
| Staff spreadsheets | 79% | 82% | 76% | 48% |
Source: ZenWeb marketing-stack audits, Malaysian SME accounts, 2024–2026. Licence.
Read the bottom row again. Staff spreadsheets hold purchase history more than the CRM does — that’s where people paste an export to sort for a campaign, then never delete it.
The tool that leaks is rarely the tool you bought. It’s the copy someone made of it.
Quick Answer: Section 43 of the PDPA lets any person send you written notice to stop using their data for direct marketing, and you must comply within a reasonable period. Ignoring the Commissioner’s direction to stop carries its own penalty — a fine up to RM200,000, up to two years’ jail, or both. No other PDPA duty sits so squarely in marketing.
Most PDPA duties are shared. Section 43 isn’t: triggered by a marketing activity, actioned by a marketing team, in marketing tools.
The mechanics are simple, which is why teams assume they’re covered. A person serves written notice — under Act 709 an email will do — requiring you to stop processing their data for direct marketing. If you don’t, the Commissioner can direct you to, and ignoring that direction is where the RM200,000 penalty bites.
Teams fall down on executing it across a stack, not on receiving it:
Watch the scope. Section 43 covers direct marketing, not only newsletters — asking past customers for Google reviews is still contacting them using their data. Getting this right is better marketing anyway: people who asked to leave never convert, and scoring your enquiries properly drops them regardless.
Quick Answer: Across ZenWeb-managed campaigns, opt-out requests per 1,000 marketing contacts have roughly doubled since 2022 — and formal written cessation notices, the Section 43 kind, jumped sharply after the amended Act took effect in June 2025. The volume is still small. The trend is not.
Opt-outs used to be an email metric. Now they arrive by WhatsApp reply, by SMS, and increasingly as a written notice naming the Act itself.
| Channel | 2022 | 2023 | 2024 | 2025 | 2026 | 2027* |
|---|---|---|---|---|---|---|
| Email unsubscribe | 4.1 | 4.6 | 5.2 | 6.8 | 8.3 | 9.6 |
| WhatsApp opt-out | 0.9 | 1.4 | 2.2 | 4.1 | 6.7 | 8.9 |
| SMS “STOP” | 1.8 | 1.9 | 2.1 | 2.6 | 3.0 | 3.3 |
| Written s.43 notice | 0.02 | 0.03 | 0.05 | 0.19 | 0.41 | 0.68 |
* 2027 projected on 2024–2026 trend. Source: ZenWeb client tracking, 2022–2026. Licence.
Watch the red row. It’s tiny — under one request per thousand contacts — but it grew roughly twenty-fold in four years, and it starts climbing exactly when the amended Act landed. A written notice is also the only opt-out that leaves a paper trail against you.
Quick Answer: Two duties took effect on 1 June 2025: report a breach likely to cause significant harm within 72 hours, and appoint a data protection officer if you process at large scale. Both are marketing problems in practice, because marketing holds the biggest, oldest, most widely shared database in the building.
Start with the breach rule, because one threshold reframes it. The Commissioner’s breach notification guidance turns on harm — risk of financial loss, damage to credit records, data that combines into identity fraud — or on significant scale, meaning more than 1,000 affected data subjects.
Count your list, then the spreadsheet copies. Each clears that threshold alone. Finance might hold 200 customers; marketing holds 14,000 enquiries going back six years. The 72 hours start when you detect the incident, not when you finish investigating, and affected people must be told within seven days of you notifying the Commissioner through the official breach channel.
The DPO duty lands the same way. Owners hear “DPO” and picture a bank, but look at what the Commissioner’s DPO circular weighs, and ask which department drives each:
Marketing drives all four. For most SMEs the role isn’t a full-time hire — it’s a named person who advises on obligations, monitors the team and fields the Commissioner’s calls. It can’t be a job title with nobody in it.
Inherited a list you can’t account for?
We inventory every list, audience and export before running a campaign on it. Talk to our digital marketing team →
Quick Answer: Across ZenWeb’s audits of Malaysian SME marketing stacks, the privacy notice passes most often and the opt-out passes least. Only about one stack in seven honours an opt-out across every tool — the single checkpoint most likely to produce a Section 43 complaint.
Knowing the PDPA compliance rules and passing them are different things. Our audits find this, ordered by pass rate.
| Checkpoint | Pass rate | Most common failure |
|---|---|---|
| Privacy notice shown before submit | 63% | English only, no Bahasa Malaysia |
| Ex-staff and old agency access revoked | 39% | Previous agency still has ad account access |
| DPO appointed and contactable | 34% | Role assumed, no named person |
| Consent record retrievable per contact | 31% | Consent captured but never timestamped |
| List and audience inventory exists | 27% | Nobody knows how many lists exist |
| Opt-out route on every channel used | 21% | Email only; none on WhatsApp or SMS |
| Breach plan naming who reports | 18% | No plan at all |
| Opt-out honoured across every tool | 14% | Off the email list, still in Custom Audience |
Source: ZenWeb marketing-stack audits, Malaysian SME accounts, 2024–2026. Licence.
The pattern is consistent: visible things pass, operational things fail. Anyone can check a privacy notice on a page. An opt-out that survives a re-upload stays invisible until somebody complains.
Quick Answer: Work through these eight steps in order. They run from inventory to drill, because you cannot fix an opt-out until you know which tools hold the data, and you cannot report a breach in 72 hours unless someone has practised it. Most SME marketing teams finish the list in a fortnight.
Each step produces something you can show — a list, a record, a name, a screenshot.
Step six is the one worth arguing for. The suppression list is what makes an opt-out stick — the difference between complying once and complying every month.
Want this run for you rather than by you?
We build the inventory, suppression list and runbook during onboarding, then run campaigns on top of them. Compare our marketing service tiers →
Quick Answer: The whole eight-step pass costs a Malaysian SME roughly RM20,000 in year one on our implementation benchmarks. The statutory maximum for breaching the data protection principles is RM1 million, and Section 43(4) carries up to RM200,000 on its own. The bars below are not close.
Compliance loses budget arguments because the cost is certain and the risk is not. So put both on one axis — the first four bars are what the work costs, the last two what the Act allows.
| Item | Relative scale | RM |
|---|---|---|
| List inventory + consent audit | 3,500 | |
| Named DPO + registration (yr 1) | 4,800 | |
| Breach runbook + one drill | 5,500 | |
| Opt-out routing + suppression list | 6,000 | |
| Maximum s.43(4) penalty | 200,000 | |
| Maximum principles penalty | 1,000,000 |
Illustrative. Costs from ZenWeb implementation benchmarks, 2024–2026; penalties are statutory maxima under Act 709. Licence.
These are statutory maxima, not typical outcomes — a first offence by a small business won’t draw RM1 million. But the three-year custodial term sits alongside the fine, and no budget line captures that.
Set against a normal marketing budget as a share of revenue, the pass costs about one festive campaign. Price it with your unavoidable overheads — the service tax on digital marketing services, say — not against campaigns, where it loses to anything with a measurable payback period.
Quick Answer: The 2024 amendment moved PDPA compliance from a document you file to a routine you run. The routines all sit in marketing: the list, the consent record, the opt-out, the suppression file, the 72-hour call. Build them once and they run quietly.
PDPA compliance isn’t hard. It’s unowned. Every SME we audit has someone who could do it and nobody who was asked to.
The eight-step pass takes most teams a fortnight, and what it buys isn’t only cover from the RM1 million ceiling — it’s a list you can trust. Every campaign after it, whether a Ramadan push before Raya week, a CNY campaign, a Merdeka campaign, a Deepavali promotion or an 11.11 and 12.12 offer, goes to people who chose to hear from you. That converts better.
At ZenWeb we run this pass before the first campaign goes live, because a clean list is what makes the rest of the digital marketing work measurable.
Yes — there’s no SME exemption. Size decides two things only: whether you need a DPO, and whether a leak crosses the “significant scale” threshold of more than 1,000 affected people. A 200-contact list is fully covered.
Only for email. Section 43 asks you to stop processing that person’s data for direct marketing on every channel you reach them on. If you also send WhatsApp blasts or upload them to Meta Custom Audiences, an email unsubscribe leaves you exposed. You need a suppression list filtering every export.
It depends on scale, not headcount. The test weighs the number of data subjects, the volume and nature of the data, and the duration and geographical extent of processing. A 15-person business with a 20,000-contact database it retargets internationally clears that test comfortably. Read the circular against your database, not your payroll.
If the breach is likely to cause significant harm, notify the Commissioner within 72 hours of detecting it, then tell affected people within seven days. More than 1,000 affected data subjects is one trigger for significant harm — which most marketing databases pass on their own.
Yes, provided people consented to that use, you can show it, and your suppression list filters opt-outs before every upload. The catch is disclosure: your privacy notice must say you share data with ad platforms, and those platforms process it outside Malaysia — a cross-border transfer under the Commissioner’s guidelines.
Ready to market on a list you can defend?
Book a free 30-minute session — we’ll map where your personal data sits, show you which checkpoints your stack fails today, and give you a plan to fix them.
Complete the form and our team will contact you to discuss your goals. Let’s grow your business.

Meowketing Specialist
Online