Malaysia's Personal Data Protection Department (JPDP) today opened a public consultation on a draft Artificial Intelligence (AI) and Personal Data Protection Framework, a text of 43 numbered sections arranged in 10 parts, with written submissions accepted until 23 October 2026, according to Public Consultation Paper No. 1/2026.

In Short

Malaysia's data protection authority has published draft guidance on how organisations may use personal information inside AI tools, and it has asked the public to respond. It matters because the draft covers AI that organisations build themselves, buy from vendors or receive through apps and cloud services, so many businesses holding customer data fall within its reach. Nothing changes immediately: replies are accepted until 23 October 2026, and the final text, its issue date and any transition period have not been set.

What the consultation paper sets out

Status and scope

The draft is labelled Version 1.0 of a Personal Data Protection Guideline, with its date of issuance still shown as a placeholder. According to the draft, the Framework is issued by the Personal Data Protection Commissioner under subsection 48(g) of the Personal Data Protection Act 2010 (Act 709). The consultation paper describes it as a "primary reference document" for data controllers and data processors, with three stated aims: clarifying regulatory obligations, outlining best practices, and strengthening data governance across the AI system lifecycle.

Scope is drawn widely. Section 1.5 of the draft applies the Framework whether an AI system is developed in-house, procured from third parties (including off-the-shelf, customised or open-source systems) or embedded in broader platforms such as software-as-a-service, cloud services and application programming interfaces. Section 1.6 adds general-purpose AI models that are incorporated into specific applications processing personal data. Section 1.4 extends the controller-facing duties, where applicable, to processors and third parties that procure, develop, customise, provide or operate AI systems, including providers with access to the data.

The draft does not displace the statute. Section 1.7 states that it supplements Act 709 and that nothing in it limits, replaces or modifies an obligation under that Act or other written law. Section 1.9 allows the Commissioner to review and amend the text "from time to time".

JPDP says it benchmarked the draft against the EU's AI legislation and the OECD's AI governance principles, as well as guidance and advisories from the data protection authorities of Hong Kong (PCPD), the Philippines (NPC), Singapore (PDPC) and the United Kingdom (ICO), according to the consultation paper.

The problem statement

The paper names three risks that unclear governance could produce. The first is ethical risk and bias, meaning outputs that are unfair, arbitrary or discriminatory, which it labels "algorithmic bias". The second is privacy intrusion and data breaches, where the scope of training data collection is ambiguous and access controls and encryption are not followed. The third is opaque automated decision-making: AI-driven decisions that are hard to explain and may affect data subjects' rights under Act 709.

The ten parts

The consultation paper summarises the Framework as ten parts, Part A to Part J, ordered by lifecycle stage. The table of contents of the draft numbers the sections as follows.

PartSectionsSubject
A1-2Introduction, background, legal provisions
B3-4Definitions and AI-specific concepts
C5-10Legal basis, notice, consent, sensitive data, exemptions
D11-14Development and testing
E15-19Deployment, use, monitoring, retraining, decommissioning
F20-23Procurement and external AI systems, cross-border transfers
G24-29Data subject rights
H30-34Fairness, security, breaches, accuracy
I35-39Governance, risk management, transparency
J40-43Documentation, audit, demonstrating compliance

Part B defines nine terms, among them AI system, AI service provider, external AI system, general-purpose AI model and general-purpose AI system, together with four terms on how identifiable data remains. An AI system is described as a machine-based system that operates with varying levels of autonomy, may adapt after deployment, and generates outputs such as predictions, recommendations, content or decisions.

Technical detail by lifecycle stage

Section 5.1 settles the threshold question. The use of AI, it states, "does not create a separate legal basis for the processing of personal data", so every AI use case must still fit within Act 709 and its principles. A controller must identify the purpose and legal basis before processing, and the data processed must be necessary, adequate and not excessive (section 6.1). Where data comes from third-party, publicly available or external datasets, responsibility for lawful collection stays with the controller (section 6.3).

Notice is treated in detail. Under section 7, written notice given under Section 7 of Act 709 must say, where applicable, whether an AI system makes or supports decisions about the person, generates recommendations or predictions, or produces personalised outputs from the person's data. A new purpose requires a new or revised notice before processing starts, and fresh consent where consent is required (section 7.4). The draft illustrates this with a fitness application that tells users their name, age and fitness preferences are used to generate personalised workout recommendations with AI and may be shared with a cloud provider.

Consent rules follow the statute. For a data subject under 18, consent comes from the person authorised under Act 709 (section 8.4). When consent is withdrawn, the controller must stop processing, including through AI systems, and take steps to delete data that is no longer required unless the law permits retention (section 8.5). For sensitive personal data, section 9 calls for explicit consent where Act 709 requires it, and an assessment of necessity and proportionality before processing.

Section 10 lists processing that may proceed without consent, including performance of a contract, compliance with a legal obligation, protection of vital interests, administration of justice and the exercise of statutory functions. Section 10.4 notes that exemptions may apply to processing for crime prevention, tax assessment, physical or mental health, research or statistics, journalism, literature or the arts, but only to the extent and under the conditions Act 709 provides.

Development and testing (Part D)

Development is tied to Data Protection by Design, with section 11.3 pointing to the Commissioner's existing Guidelines on Data Protection by Design. Section 12.2 limits training, testing and validation data to what is adequate, relevant and necessary, a data minimisation test in all but name. Where the purpose can reasonably be met without directly identifying anyone, section 12.4 directs controllers to consider anonymised or pseudonymisation techniques, subject to the safeguards in Part H.

The draft is careful about the limits of those techniques. Section 4.5 treats de-identification as a broad concept that includes pseudonymisation and anonymisation, representing different levels of protection. Section 4.8 adds that pseudonymised data can still carry re-identification risk, especially when combined with additional or publicly available information.

Pre-deployment testing is a gate. Under section 14.2, validation assesses, where appropriate, whether the system performs consistently with its intended purpose, produces sufficiently reliable outputs, works under reasonably foreseeable conditions, shows material errors or unexpected behaviour affecting personal data, and operates effectively with its intended safeguards. Material issues must be corrected before deployment, and a system proceeds only once the controller is "reasonably satisfied" that testing is complete (section 14.5). Personal data used in testing must itself be appropriate and necessary (section 14.3).

Deployment, monitoring and retirement (Part E)

Operational rules are procedural. Deployment must be authorised under the organisation's own policies (section 15.4), and personal data may not be entered into an AI system whose use the controller has not authorised (section 16.4). That second provision is aimed at staff-level use of external tools, though the draft does not name any.

Monitoring is continuous. Controllers set up processes to detect changes in operation, data or environment that could affect compliance, and periodically test whether the data processed remains adequate, relevant and not excessive (sections 17.1 and 17.2). The draft's worked example describes an e-commerce platform whose recommendation engine, after a system update, begins using personal data never intended for that purpose; the platform restricts the affected processing until the issue is corrected. A second example covers a customer-service chatbot retrained on additional customer data with new functions, where the controller assesses whether the change is material and, if so, repeats Part D testing (section 18).

Retirement closes the loop. Before decommissioning, the controller decides whether data is retained, transferred, anonymised or securely disposed of, and section 19.3 bars keeping personal data merely because a retired AI system used it.

External AI systems and cross-border transfers (Part F)

Part F is the longest on vendor management. Section 20.2 lists eight due diligence factors before an external AI system is procured or integrated: purpose and limitations; categories and sensitivity of data; sources and quality of datasets or pre-trained models, where information is reasonably available; whether data will be retained, reused or used for model training, fine-tuning, optimisation or analytics beyond the service; other processors involved; cross-border processing; the provider's technical and organisational measures; and known risks, biases or limitations. Depth is meant to be proportionate to data sensitivity and risk (section 20.3).

Roles must be defined according to actual involvement in processing, including whether the provider acts as a processor or as a third party (section 21). Where a provider processes data on the controller's behalf, section 21.3 expects arrangements covering seven items, among them the nature and purpose of processing, the controller's instructions, security measures, sub-processors, breach handling, and return or deletion at termination. A controller may request model cards, system cards or technical documentation (section 21.4). On liability the text is blunt: engaging a provider "does not transfer or diminish the responsibilities of the data controller" under Act 709 (section 21.5).

Transfers abroad must comply with section 129 of Act 709, and, where appropriate, controllers are to carry out a Transfer Impact Assessment with reference to the Commissioner's Guidelines on Cross-Border Personal Data Transfer (sections 22.1 and 22.2). Five factors feed that assessment: the countries where data is stored or processed, the parties with access, the provider's handling practices, the safeguards applied, and onward transfers to other processors. Records of transfers and safeguards are to be kept (section 22.4). Section 23.2 requires a fresh look whenever an external system, its terms of service, its processing activities or its sub-processors change significantly.

Data subject rights (Part G)

Existing rights carry over. Access under section 25 may cover personal data generated or derived through the AI system, where it can reasonably be identified and retrieved. Under section 26.2, if an AI system causes or contributes to an inaccuracy, the controller must verify and correct the data and, where appropriate, address the source. Withdrawal of consent reaches the AI processing for the relevant purpose (section 27), and portability requests must be handled without compromising security or integrity (section 28).

One provision speaks to opacity. Where AI processes personal data "in ways that may not be apparent to the data subject", section 29.1 calls for additional transparency measures, and section 29.2 names account settings, online forms and electronic communications as possible channels for exercising rights.

Safeguards, fairness and breach handling (Part H)

Fairness is framed around foreseeable risk. Section 31.1 refers to unfair, biased or discriminatory outcomes arising from characteristics such as race, gender, religion, age and disability. Controllers are to assess training, testing and operational data for quality, representativeness and bias, review outputs for discriminatory patterns, correct material problems, and set up review or escalation where outputs may significantly affect a person (section 31.2).

Security measures follow the Security Principle, with six general examples in section 32.4 and five AI-specific additions in section 32.5: Data Loss Prevention (DLP) controls to detect and stop unauthorised transmission of personal data, including identifiers, to external AI models or APIs; encrypted communication with external AI services, including large language models; need-to-know access; segregation or encryption of sensitive data during training, testing, deployment or inference; and security reviews of embedded AI at device and system level.

Breaches involving AI systems fall under section 12B of Act 709 and the Commissioner's Circular and Guidelines on Data Breach Notification. Where a processor or AI provider is involved, arrangements must allow timely information flow so the controller can meet its own notification duties (section 33.5).

Governance, risk and records (Parts I and J)

Governance is to be proportionate, with clearly assigned roles and, where a Data Protection Officer is appointed or required, that officer's involvement in oversight (section 35). Controllers are to configure systems with "privacy-preserving settings by default" where appropriate (section 36.4). Risk assessment under section 37.2 weighs eight factors, from data sensitivity and system complexity to the likelihood and severity of harm, and may include a Data Protection Impact Assessment (section 37.3). Significant risks must be mitigated before deployment or continued operation, and assessments are reviewed after retraining or integration changes (section 37.5). Notices must explain AI-related processing in plain language (section 38).

Part J turns to evidence. Records under section 40.4 cover eight areas, among them purpose and design, data types and sources, legal basis, assessments and approvals, significant changes, incidents and provider oversight. Section 40.5 states that these records are to be made available to the Commissioner upon request. Audits may examine, among other things, "model drift" and the adequacy of transparency and human oversight measures (section 41.3), and section 42.3 lists eight types of evidence a controller may hold to show compliance.

The seven questions and how to respond

JPDP asks for written feedback on seven questions, numbered 4.1.1 to 4.1.7 in the paper:

  • Adequacy of Act 709 compliance: whether the Framework adequately supports compliance and what needs improvement.
  • Scope, terms and exemptions: whether further concepts, limitations or exemptions are needed, with justifications and use cases.
  • AI lifecycle principles: whether the approach ensures lawful, fair, transparent, secure and responsible processing.
  • Governance and feasibility: whether requirements are clear, practical and proportionate to risk, roles and capabilities.
  • Constraints and enforcement challenges: what organisations might face if the Framework's requirements are enforced.
  • Industry readiness and regulatory support: which preparations are needed, and whether "supplementary guidelines, transition periods or sandboxes" are required.
  • International references and standards: which local or international instruments could inform the text.

Submissions go through the Unified Public Consultation Platform at https://upc.mpc.gov.my/view-consultation/296 or an official Google Form at https://forms.gle/GKfBZXgGZUevgWa79. Enquiries are handled at risiko@pdp.gov.my and +603-2021 1183, 1184 or 1185. The mailing address is Level 8, Galeria PjH, Jalan P4W, Persiaran Perdana, Precinct 4, Federal Government Administration Center, 62100 Putrajaya, Malaysia.

The text pulls in two directions. Section 1.8 describes the document as setting out "high-level best practices and practical measures", yet the operative sections are written in the language of obligation: a controller "shall" test, document, assess and review. The consultation paper's own summary table uses verbs such as "requires" and "mandates" for Parts F and J. And question 4.1.5 asks about constraints that could arise "if the requirements in this Framework are enforced under Act 709", which implies that enforcement is contemplated but not yet decided.

Question 4.1.6 appears to leave open how quickly any of this would apply. Neither the paper nor the draft gives an effective date or a transition period, and the issuance date remains a placeholder.

Regional context and relevance for marketers

The draft arrives in a region that has been filling in its data protection rules for AI over the past two and a half years. Singapore's PDPC published advisory guidelines on personal data in AI recommendation and decision systems on 1 March 2024, a step recorded in a review of regulators' AI training guidance. South Korea's data protection commission unveiled draft guidelines in August 2025 on processing personal data for generative AI, and on 31 March 2026 it cut the forms needed for pseudonymous data processing from 24 to 10 under a three-tier risk system. Vietnam issued Decree 356/2025/ND-CP on 31 December 2025, effective the next day. And Indonesia signed a 225-article implementing regulation on 16 July 2026 that sets 72-hour deadlines for rights requests and requires impact assessments for large-scale profiling.

Several mechanisms in the Malaysian draft have counterparts in Europe. The EDPB adopted its first standardised DPIA template on 10 March 2026 under the GDPR; Malaysia's section 37.3 likewise points to a Data Protection Impact Assessment where appropriate. The EDPB also adopted Guidelines 03/2026 on web scraping for generative AI on 7 July 2026, with consultation open until 30 October 2026, a week after Malaysia's closing date.

Why does a consultation on a national data protection text matter to advertisers and agencies? Three reasons stand out.

First, the draft's own examples are marketing-adjacent. Personalised workout recommendations, product recommendations built on purchase and browsing history, and a chatbot retrained on customer data are all functions that sit inside marketing technology stacks. The draft contains no section devoted to advertising or audience targeting, and the paper does not say how the Framework would apply to ad delivery surfaces. That is notable because Malaysia is already an AI advertising market: Google extended ads in AI Overviews to Malaysia on 19 December 2025, and OpenAI has begun placing ads in ChatGPT in Malaysia.

Second, vendor terms sit at the centre of Part F. The due diligence list asks whether a provider retains, reuses or trains on customer data, and section 23.2 requires a reassessment when a provider's terms or sub-processors change. Contract changes of that kind are already visible in the market; Microsoft's data protection addendum update of 22 May 2026 shortened its notice period for new AI subprocessors to 30 days.

Third, the notice-and-consent provisions would change the paperwork around personalisation. Under sections 7.4 and 8.3, a materially new AI purpose needs fresh notice and, where consent is the basis, fresh consent, while section 8.5 extends consent withdrawal into AI processing. How firms would reconcile that with marketing data flows is among the matters question 4.1.5 invites respondents to describe.

What remains unknown is the weight the final text will carry. The consultation closes on 23 October 2026; JPDP has not said when a final version will follow.

Timeline

Summary

Who: Malaysia's Personal Data Protection Department (JPDP), acting for the Personal Data Protection Commissioner; the draft addresses data controllers, data processors and AI service providers handling personal data under Act 709.

What: Public Consultation Paper No. 1/2026, which circulates a draft AI and Personal Data Protection Framework (Version 1.0) of 10 parts and 43 sections, along with seven consultation questions on adequacy, scope, lifecycle principles, governance, enforcement constraints, readiness and international references.

When: The consultation opened today and closes on 23 October 2026. The draft carries no issuance date or transition period.

Where: Malaysia, under the Personal Data Protection Act 2010 (Act 709). Feedback goes through the Unified Public Consultation Platform or an official Google Form; the department is based in Putrajaya.

Why: According to the consultation paper, the aim is to clarify obligations, outline best practices and strengthen governance, accountability, security and risk management, in response to the risks of algorithmic bias, privacy intrusion and breaches, and opaque automated decision-making.