Consulting · PDPA compliance and general IT · Malaysia

Advice you can act on, from the people who would do the work.

Two things sit here. PDPA compliance consultation and staff training under the Personal Data Protection (Amendment) Act 2024, whose obligations landed through 2025 — and whose newest guidelines, on impact assessments, are dated April 2026. And general IT consultation — what to buy, what to keep, what is quietly exposed — plus the ordinary operations work that decides whether anything else survives.

In short

Does ZYNTEIRO provide PDPA and IT consultation?

Yes, both. PDPA compliance consultation and staff training under Malaysia's Personal Data Protection (Amendment) Act 2024: a data inventory workshop producing a register and a ranked gap list, training co-delivered with a law lecturer, DPO support, the impact assessments made mandatory in April 2026, and breach-response readiness. General IT consultation: a written assessment of what you run and what is exposed, ranked by real damage, plus backup, network, security and hosting run as ongoing operations. Neither is legal advice.

Compliance

PDPA consultation and staff training.

The 2024 amendments brought a 72-hour breach notification clock, processors directly on the hook for security, and a mandatory Data Protection Officer for everyone over the Commissioner’s thresholds. April 2026 added a mandatory impact assessment on those same thresholds. We find your personal data, write it down, fix the systems holding it and train the people handling it.

Data inventory workshop

On site, interviewing the people who actually handle the data rather than the people who own the systems. Produces a register of every personal-data holding and a gap list ranked by exposure. Fixed fee, quoted before it starts, and yours whether or not you continue.

  • The register
  • A ranked gap list
  • Fixed fee, quoted up front

Staff training

For reception, HR, sales, delivery and customer service — the people who touch personal data all day. On site, in English, Malay or Mandarin, using your own forms and screens as the worked examples. Co-delivered with a law lecturer who previously practised as a litigation lawyer.

  • Two disciplines in the room
  • Your systems as the examples
  • Attendance record for the file

DPO, assessments, breach route and remediation

Whether you are over the thresholds at all, then support for the person you appoint — or a named officer where nobody inside has the time. The impact assessments those same thresholds now require. A rehearsed breach route against the clock, and the gap list actually closed inside the systems.

  • A straight answer on whether you are in scope
  • Impact assessments, done before the processing
  • A breach route that has been drilled
  • Retention and deletion implemented, not documented

ZYNTEIRO will not act as your Data Protection Officer as a company — we hold data for many of our clients, and a processor supervising its own processing is the conflict the guidelines exist to prevent. Where you have nobody inside with the time, the officer we field is a named individual, and never at a company whose systems we operate. The three things we decline are set out in full.

General IT consultation

What to buy, what to keep, and what is quietly exposed.

The deliverable is a written assessment rather than a proposal. If the conclusion is that your current setup is fine and your current provider is good, that is a legitimate outcome and we will write it down.

01

A current picture, drawn from the cabinet

What you own, where it is, what it costs, when the warranties and licences expire, and a network diagram taken from the actual room rather than from somebody’s memory. Most companies have never had this written down, and almost every later decision depends on it.

02

Exposure, ranked by real damage

Not a vulnerability scan printed and bound. The exposed remote desktop port, the backup nobody has restored from, the shared administrator password, the account of somebody who left in 2023 that still works. Ranked by what it would actually cost you.

03

Buy, keep or stop

A straight recommendation on each thing you currently pay for, including the ones we would sell you. Where the answer is that a subscription beats a purchase, or that your incumbent provider should keep the contract, that is what the document will say.

04

A sequence, not a wish list

The next three things to do, in order, with what each one costs and what it removes. A twenty-item roadmap nobody starts is worth less than three items somebody finishes.

Ongoing operations

The ordinary work, listed without ceremony.

None of this is interesting and all of it decides whether the interesting projects survive. If your current provider does it well, keep them — we will say so in the assessment.

Backup and disaster recovery

Three copies, two media, one offsite — and a scheduled test restore with the elapsed time written down, because the number you need in a crisis is “how long until I can open the file”.

  • Offsite encrypted replica
  • Quarterly tested restores
  • Documented recovery time

Network, WiFi and cabling

Coverage surveys and real access points rather than a consumer router and three range extenders. In a warehouse this is not comfort — it is whether scanning works in the far aisle.

  • Site survey
  • Managed switching and access points
  • Labelled, documented cabinets

Servers and virtualisation

Consolidating the ageing machines under desks into one properly specified host with backups, or moving the workload to where it belongs.

  • Sizing against measured load
  • UPS and clean shutdown
  • Monitoring that pages someone

Security, practically

MFA on mail and remote access, current patches, offline backups, and closing the exposed remote desktop port. Three controls stop most of what actually happens to companies this size.

  • Firewall and endpoint
  • Patching on a schedule
  • Documented exceptions, not silent ones

Hosting and web maintenance

Including the certificate that expires on a Sunday and the content management system nobody has updated since 2021.

  • Managed hosting and certificates
  • Update and backup cadence
  • Uptime monitoring

Asset register and documentation

What you own, where it is, what it costs, when its warranty ends — and a network diagram drawn from the cabinet rather than from memory. The register is what makes an offboarding checklist finish instead of nearly finish.

  • Hardware, licence and renewal register
  • Current network diagram
  • Offboarding that completes

How an engagement runs

Assessment first, and you keep it either way.

The order is the same whichever half you came for, because both halves start by finding out what is actually there rather than what the org chart says is there.

01

Scoping call

Free, and with the person who would do the work. We ask what you run, who touches it and what has gone wrong recently, then tell you plainly whether you need us.

  • Written scope
  • Fixed quote for the assessment
02

Assessment on site

The inventory, the cabinet, the accounts and the people. Every assessment turns up a spreadsheet on somebody’s laptop, an account that should have been closed and a backup nobody has ever restored. That discomfort is the deliverable.

  • Register and current-state picture
  • Gap list ranked by real damage
03

The recommendation

Buy, keep or stop, on each item, with the next three things in order. Where the answer is that your incumbent provider should keep the contract, the document says that.

  • Written recommendation
  • Quotes only for what you chose
04

Remediation and training

Closing the gaps in the systems themselves, and training the people whose habits are the other half of the problem. Quoted against the gap list rather than before it exists.

  • Controls implemented
  • Staff trained, attendance recorded
05Quarterly

Review cadence

A register written once is wrong within months — a new system, a new form, a new supplier, a new starter. A short scheduled review is the difference between a programme and a project.

  • Register kept current
  • New systems assessed on arrival

Who owns what

Three boundaries, written down before anything breaks.

Most of the pain in a multi-supplier setup is not technical. It is that nobody agreed in advance who is called first.

01

The network and the building

Cabling, switching, wireless, the firewall and the internet line. Whoever holds this holds the thing every other supplier depends on, and they should be named in writing.

02

The servers and the data

Hosts, virtual machines, storage, backups and the restore test. This is where an outage becomes a loss, and it is the boundary most often assumed rather than assigned.

03

The applications

Your ERP, your website, your mail. Where we operate a zynAIR tenant, this half is unambiguously ours and the first two can stay entirely with somebody else.

Questions

Before you call.

Yes, and we are candid about why: an ERP is not resilient if the server beside it has no tested backup, and a web application is not secure if the deploying account uses a reused password. Where a client already has a competent IT provider we say so and stay in our lane. Where they do not, someone has to hold the backups.

Routinely, and it is usually the right arrangement. The boundary that matters is written down at the start: who owns the network, who owns the servers, who owns the application, and who is called first when something is down. Ambiguity there is what turns an outage into a conversation about whose fault it is.

Not primarily. Where hardware is needed we specify, supply and install it, and we will tell you plainly what our margin structure is on request. We do not lead with a product because the product is rarely the deliverable — the record it produces, and what that record is wired into, is.

A written assessment you keep, whether or not you continue with us: what you currently run, what state it is in, what is exposed, what is about to expire, and a list of the next things to do ranked by real damage rather than by how modern they sound. It is deliberately boring and deliberately yours. A consultation that produces only a proposal is a sales call wearing a different name.

Usually they are the same conversation, which is why they sit on one page. Almost every gap a PDPA data inventory finds is closed with an ordinary IT control — retention and deletion actually implemented, access narrowed, the former employee's account closed, backups that are encrypted and tested. The compliance work names what has to be true; the IT work makes it true. You can buy either half alone, and companies with a competent existing IT provider frequently should — we do the inventory and they close the gaps.

No, and a law lecturer co-delivering the training does not change that. Our work is operational: finding where personal data is, writing down what happens to it, fixing the systems that hold it, and training the people who handle it. Where a question is genuinely legal — whether a consent clause is adequate, how to answer an enforcement notice, what a processor contract must say — we say it is a lawyer's question and stop. The PDPA page sets out that boundary in full.

Start with the assessment.

A free scoping call, then a fixed quote for the piece of work that produces something you keep. If what you actually need is one conversation with a lawyer, or nothing from us at all, we will tell you that.