PDPA consultation and staff training · Malaysia

We do PDPA compliance, as an engineering job.

The Personal Data Protection (Amendment) Act 2024 landed through 2025: a 72-hour breach clock, processors directly on the hook for security, and an appointed DPO for everyone over the Commissioner’s thresholds. Then, on 30 April 2026, a mandatory impact assessment on those same thresholds. We find your personal data, write it down, fix the systems holding it and train the people handling it.

In short

Does ZYNTEIRO provide PDPA consultation and training?

Yes. ZYNTEIRO provides PDPA compliance consultation and staff training for companies in Malaysia, under the Personal Data Protection (Amendment) Act 2024 and the Commissioner’s guidelines to April 2026. Six engagements: a data inventory workshop, staff training co-delivered with a law lecturer, DPO support or a named officer, impact and transfer assessments, breach-response readiness, and technical remediation in the systems themselves. Neither the work nor the training is legal advice on your circumstances.

Why this is now a deadline

Six facts, none of them ours.

Every figure below is from the Act and the Commissioner’s guidelines, and each one is unpacked in the guide.

1 Jun 2025
DPO and breach rules in force
The penalties and the cross-border rewrite landed earlier, on 1 April 2025. All three tranches
30 Apr 2026
Impact assessments made mandatory
The newest guidelines, and the ones almost nobody has acted on. Whether it reaches you
72 h
Breach notification deadline
From the occurrence, not from the meeting where it was raised. The failure mode
1,000
Data subjects that make a breach notifiable on scale alone
More than 1,000 data subjects is “significant scale”. Below that it turns on significant harm, and plenty of breaches are not notifiable at all. The significant-harm test
20,000
Data subjects before a DPO and a DPIA are mandatory
Or 10,000 for sensitive data, or any regular and systematic monitoring. Below all three you need neither. Whether you are in scope
RM1m
Maximum penalty, any of the seven Principles
And up to three years — not only for a security failure. What it attaches to

What we deliver

Six engagements, each with something you keep.

Buy them together or separately. The inventory is the one to start with — the other five are difficult to scope honestly until it exists, and we will say so rather than quote around it.

Data inventory workshop

On site, interviewing the people who actually handle the data rather than the people who own the systems. Produces the seven-column register and a gap list ranked by exposure, not by how easy it is to fix.

  • Register of every personal-data holding
  • Written gap list, ranked
  • A flag if you sit in a registrable class
  • Fixed fee, quoted before it starts

Staff training

For the people at reception, in HR, in sales and on delivery — in English, Malay or Mandarin, on site, using your own forms and screens as the examples. Co-delivered with a law lecturer who previously practised as a litigation lawyer.

  • Co-delivered with a law lecturer
  • Your systems as the worked examples
  • English, Malay or Mandarin
  • Attendance record for the file
Why the reception desk matters most

DPO support, or the appointment itself

First we check whether you are over the thresholds at all — 20,000 data subjects, 10,000 for sensitive data, or regular and systematic monitoring — because below them you do not need one. Above them we usually help the person you appoint do the job rather than doing it for them. Where nobody inside has the time, we can field a named officer instead.

  • A straight answer on whether you are in scope
  • Where you are not: the written record of why
  • Registration with the Commissioner within 21 days
  • Policy and privacy-notice templates
  • A named DPO where you have nobody

Impact and transfer assessments

Two written assessments, same discipline, different clocks. The DPIA was made mandatory on 30 April 2026, on the same thresholds that make a DPO mandatory — so if you needed one of those, you now need these — and anything involving automated decisions or profiling is in scope whatever its size. The transfer assessment is what replaced the Minister’s approved-country list in 2025: since it was abolished, the judgement about each destination is yours to make and yours to defend.

  • A completed DPIA per processing operation
  • Residual-risk report for management to sign
  • A transfer assessment per destination country
  • Valid two years and three years respectively
The one nobody has heard of yet

Breach-response readiness

One internal route with a name on it, a notification drafted while calm, and a tabletop exercise run against the clock — so the first time somebody works out who to call is not the real time. Including the part most companies miss: knowing which breaches you do not have to report, and being able to show why you decided that.

  • Named internal reporting route
  • Pre-written notification, and who confirms receipt
  • The two-year breach register, non-notifiable ones included
  • Tabletop exercise, timed
Not every breach is notifiable

Technical remediation

The gap list, actually closed. Retention periods and deletion implemented rather than documented, access narrowed to who needs it, and the former employee’s account that still works, closed.

  • Retention and deletion in the systems
  • Access review and narrowing
  • Inside Odoo, file storage and mail

Who delivers it

Two disciplines in the room, on purpose.

Most PDPA training fails on one side or the other: a legal briefing nobody can act on, or an IT talk that gets the obligation wrong. We split it deliberately, and the split is also where the boundary of what we sell sits. The Commissioner’s July 2025 competency guideline now describes the same arrangement: a Data Protection Officer may meet the expected competencies through their own expertise, an internal team, or by engaging outside experts for specific areas — provided the appointed officer keeps oversight of all six. Which is exactly the shape below, and the reason we support the person you appoint rather than replacing them.

ZYNTEIRO — the operational half

The engineers who operate ERP tenants, file storage and mail for other companies, doing the part that has to be true inside a system rather than in a policy: where the data is, who can reach it, when it gets deleted, and who gets told within 72 hours.

  • The inventory, the register and the ranked gap list
  • Retention, access and deletion implemented
  • The breach route, and the drill against the clock
  • Contracting party for the whole engagement
Beston Tan Yon Chin

Beston Tan Yon Chin — the legal grounding, from outside

An external consultant — a law lecturer who previously practised as a litigation lawyer, engaged by us to be in the room for the training: what the Act actually requires, what its terms mean, and the questions your staff will not ask an engineer.

  • What the Act requires, taught rather than paraphrased
  • Live Q&A your team can push back on
  • Available as your named DPO where you have nobody
  • Teaching the law — not advising your company on it

You contract with ZYNTEIRO, and Beston is an external consultant we engage for the training — not an employee of ours. That distinction matters: he is teaching what the Act requires, not advising your company on its own circumstances. Advice on your circumstances is a practising lawyer’s work, you engage them directly, and we will tell you when you have reached that point.

How the engagement runs

Six engagements, and you keep every artefact.

No discovery that produces only a document. The register exists from the first week and is the thing every later step is measured against.

01

Scoping call

With the person who would run the workshop. We ask what personal data you hold and who touches it, and give you a straight answer about whether you need us at all.

  • Written scope
  • Fixed quote for the workshop
02

Data inventory workshop

On site. Every inventory turns up a spreadsheet on somebody’s laptop, a chat group with scanned identity cards in it, and an account that should have been closed. That discomfort is the deliverable.

  • The seven-column register
  • Gap list ranked by exposure
03

Impact assessments

Where the inventory shows you over the thresholds, or shows an automated decision being made about somebody. Done the Commissioner’s way, before the processing rather than after it, with the residual risk written down for management to accept or refuse. A DPIA expires two years after completion, so this one comes back — which is what the review cadence at the end is for.

  • A DPIA per processing operation
  • Residual-risk report, signed
04

Remediation

The technical half done properly and the policy half written to match. Quoted against the gap list, so the number comes after the scope rather than before it.

  • Retention and deletion implemented
  • Access narrowed and documented
  • Privacy notice and policies updated
05

Training and the drill

Staff sessions in the language the team works in, then a tabletop breach exercise with the clock running. Both are where behaviour changes; everything before this is preparation.

  • Staff trained, attendance recorded
  • Breach route rehearsed
06Quarterly

Review cadence

A register written once is wrong within months — a new system, a new form, a new supplier. A short scheduled review is the difference between a compliance programme and a compliance project.

  • Register kept current
  • New systems assessed on arrival

The training, specifically

A session with the reception desk beats a seminar for managers.

Breaches in small companies are overwhelmingly ordinary: the wrong attachment, the reused password, the visitor book with a photocopy of every visitor’s identity card, the chat-group forward. None of that is prevented by a legal briefing given to people who never touch the data. Our sessions are co-delivered with a law lecturer who previously practised as a litigation lawyer — he grounds what the Act requires, we ground what it means at the counter on a Tuesday.

01

Who should be in the room

The people who handle personal data every day, not the people accountable for it on paper. Reception, HR, sales, delivery, customer service and whoever runs the company’s social accounts.

  • 15–30 people per session
  • Managers welcome, but not the point
02

What it covers

Four things, all of them concrete: what counts as personal data here, what may and may not be done with it in the four situations that come up weekly, who to tell immediately, and why nobody is in trouble for reporting within the hour.

  • Your own forms and screens as examples
  • The four weekly situations, named
03

How it is delivered

Two voices: a law lecturer on what the Act actually requires, and our engineers on what that means inside the systems your team uses. On site, in English, Malay or Mandarin, scaled to how much handling the group actually does.

  • Law lecturer plus engineer, together
  • On site, any of three languages
  • Shift-friendly repeat sessions
  • Attendance record for your file

What we do not do

Three things we will decline, so nobody is surprised later.

We do not give legal advice

Training with a law lecturer in the room is still training. Whether a particular consent clause covers what you are doing, how to answer an enforcement notice, what a processor contract must say — those are questions for a practising lawyer with a current certificate, engaged by you, and we will say so and stop rather than guess. Where the lawyer and this page disagree, believe the lawyer.

We do not sell a certificate

There is no PDPA certification for a company that means anything today, and any supplier offering one is selling a PDF. Be precise about the exception: since July 2025 the Commissioner has published standards for organisations that train Data Protection Officers, and sketched a framework under which it may formally recognise providers. Prospective, not granted — nobody holds that recognition yet, ourselves included, and we will say so before anyone else does. What exists is a register that is current, controls that are implemented, staff who know what to do, and a breach route that has been rehearsed. That is the whole product.

ZYNTEIRO will not be your DPO

We hold data for many of our clients, and a processor supervising its own processing is the conflict every guideline warns about. So the company never takes the appointment. Where you have nobody with the time, the DPO we field is the law lecturer — contracted through us, reporting to your management, and never appointed at a company whose systems we operate. An internal DPO with real executive backing still beats both.

We hold the processor obligation ourselves, on every zynAIR tenant we operate. It is a large part of why database copies for development are sanitised as a matter of course rather than on request.

Questions

Before you call.

Yes. We deliver on-site PDPA awareness training for the people who actually touch personal data all day — reception, HR, sales, delivery, customer service — in short, focused sessions, in English, Malay or Mandarin. The worked examples are your own systems and your own forms, not a generic slide deck about the GDPR. A session covers four things: what counts as personal data in this company, what may and may not be done with it in the situations that come up weekly, who to tell immediately when something goes wrong, and why nobody is in trouble for reporting it in the first hour.

Only above the Commissioner’s thresholds, and a good number of Malaysian SMEs sit below them. Under the Guideline on Appointment of Data Protection Officer, appointment is mandatory if you process the personal data of more than 20,000 data subjects, or sensitive personal data — including financial information — of more than 10,000 data subjects, or if your processing requires regular and systematic monitoring. That third limb is the one that surprises people: CCTV, tracking and behavioural profiling can pull in a company well under either headcount. Note also that the duty is not the data controller’s alone — a data processor handling personal data on someone else’s behalf has its own obligation under section 12A(2). Where you are appointing, the officer is registered with the Commissioner within 21 days, a change within 14 days, and the business contact details published on your site, in your privacy notice and in your security policies. If you are below all three thresholds we will tell you so, and you should not buy a DPO from us or from anyone else — but do keep the written record of why you concluded that, which the guideline asks for and which is the only thing that makes the decision defensible two years later.

Since 30 April 2026, yes, if you cross either quantitative threshold in the Commissioner’s DPIA Guideline — processing expected to involve more than 20,000 data subjects, or sensitive personal data including financial information of more than 10,000 data subjects. Those are the same two figures that make a DPO mandatory, so the practical rule is simple: if you needed a DPO, you now need impact assessments too. Below the numbers it becomes a judgement your DPO has to make against qualitative factors — systematic monitoring, AI, children’s data, anything with a significant effect on someone’s finances, health, reputation or access to services. One trigger overrides the numbers entirely: automated decision-making or profiling requires a DPIA regardless of scale. A completed assessment is valid for two years, the residual risk is reported to senior management, and the records outlive the project by at least two years.

Two people, and deliberately so. Beston Tan Yon Chin — an external consultant, not one of our staff — is a law lecturer who previously practised as a litigation lawyer, and he grounds what the Act requires and why. One of our engineers grounds what that means inside the systems your team touches: which screen, which form, which chat group. Most PDPA training fails on one side or the other, either a legal briefing nobody can act on or an IT talk that gets the obligation wrong. Note what this is and is not: he is teaching the law, not acting as your lawyer, and the session is not legal advice on your circumstances. For that you need a practising lawyer with a current certificate, and we will tell you when you have reached that point.

We quote after a free scoping call rather than before it, because the price is driven by how many systems hold personal data and how many people touch them, and neither is knowable from a website. What is fixed is the shape: the data inventory workshop is quoted as a fixed fee before it starts, and it produces a register and a written gap list that are yours whether or not you continue with us. Remediation and training are quoted separately against that gap list, so you are never asked to approve a number for work nobody has scoped yet.

The company itself, no — we hold data for many of our clients, and a processor supervising its own processing is exactly the conflict the guidelines are written to prevent. What we can field is a named individual: Beston Tan Yon Chin, an external consultant — the law lecturer who co-delivers our training — contracted through ZYNTEIRO, notified to the Commissioner as your DPO and reporting directly to your management rather than through us. We decline that appointment entirely for any company whose systems we operate, and we tell you plainly that ZYNTEIRO pays him. Our first recommendation is still an internal appointment — someone in operations, finance or HR with genuine executive backing, because they can stop something and an outsider cannot. The external option exists for the common case where nobody inside has the calendar time, and that stalls the appointment altogether.

The inventory workshop comes first, on site, because every other obligation is downstream of knowing what personal data you hold. Remediation of what it finds follows, and how much there is depends entirely on how much sits in systems versus in habits. Training runs alongside. The DPO appointment and the breach route are deliberately put in place early rather than at the end, because those are the two that carry a statutory clock. Impact assessments come after the inventory and before any new system goes live — a DPIA is meant to be done in advance, so one written after launch is a report rather than an assessment. Compliance is not a state you reach and keep, though: the register goes stale within months, a DPIA expires at two years, a transfer assessment at three, and the Commissioner has proposed a further round of amendments to the regulations. That is why the engagement ends with a review cadence rather than a certificate.

No — and a law lecturer co-delivering the training does not change that, because teaching what the Act requires is not the same thing as advising you on your own circumstances. We are an IT and operations company, and the work is operational: finding where personal data is, writing down what happens to it, fixing the systems that hold it, and training the people who handle it. Where a question is genuinely legal — whether a particular consent clause is adequate, how to answer an enforcement notice, what a contract with a processor must say — we will tell you it is a lawyer's question and stop. Most SMEs need one conversation with a lawyer and a great deal of the operational work; the common mistake is buying it the other way round.

It makes the inventory longer and the remediation more interesting, which is normal. Personal data in an SME is rarely in one place: it is in the ERP, in a shared drive, in an export somebody made in 2023, and in a WhatsApp group where identity-card photographs get forwarded. We can implement retention, access control and deletion inside Odoo and on your file storage directly, because we operate those systems for other clients. The WhatsApp group is a training and policy problem, and it is usually the one that matters most.

Start with the inventory.

A free scoping call, then a fixed quote for the workshop. If what you actually need is one conversation with a lawyer and nothing from us, we will tell you that.