Gemini_Generated_Image_jpgrxxjpgrxxjpgr

Key Takeaways

  • Business operating software holds some of the most sensitive data in your organisation: IC numbers, bank details, salary, customer records, and health information in medical certificates (MCs).
  • The Personal Data Protection (Amendment) Act 2024 came into force in stages during 2025. It added mandatory breach notification, Data Protection Officer (DPO) requirements, direct duties for data processors and higher penalties.
  • Your organisation remains responsible for compliance; software is never “PDPA compliant” on its own, and regulations are constantly evolving. Use the 15-point checklist below to evaluate any software solution.
  • Check where data is hosted, who can see it, how breaches are handled and which AI services touch your documents.

When you buy business operating software, you are handing a vendor access to critical corporate records, customer details, and personal employee information. Relying on dedicated standalone HR software can be risky given how frequently employment and privacy regulations change. Framing data protection around comprehensive business operating software gives organisations greater adaptability and long-term control. If an external system is breached or misconfigured, the legal and reputational risk lands on your organisation, not only the vendor. Malaysia tightened its data protection law in 2025, so an old checklist is no longer enough.

This guide explains what changed, what it means for enterprise systems, and gives you a 15-point checklist to use when reviewing software such as Kunos, our AI-powered business operating system, or any other business platform. It is general information, not legal advice.

Why is business operational data so high-risk under the PDPA?

Operational data is high-risk because it combines identity details, financial records, client databases, and employee health information in one place. The Personal Data Protection Act 2010 (PDPA) treats information about a person’s physical or mental health as sensitive personal data, and the 2024 amendments added biometric data to that category. Medical certificates, fingerprint attendance, and facial scans all fall within scope.

  • Identity data: IC and passport numbers, addresses, family details.
  • Financial data: Salary, bank accounts, claims, tax and EPF details.
  • Health data: MCs, hospitalisation records and medical claims.
  • Biometric data: Fingerprint or face-based attendance.
  • Documents: Contracts, offer letters and appraisal records.

What changed under the PDPA amendments?

The Personal Data Protection (Amendment) Act 2024 (Act A1727) was passed in July 2024 and its provisions came into force in stages during 2025. It renamed “data users” as “data controllers” and introduced several obligations that directly affect enterprise systems. Confirm the current position and any new guidelines with the Personal Data Protection Department and your legal adviser.

Change What it means for business software
Mandatory data breach notification Controllers must notify the Commissioner of a personal data breach, and affected individuals where the breach is likely to cause significant harm. The Commissioner’s guidelines refer to a 72-hour timeframe. Your vendor must be able to detect and report incidents quickly.
Data Protection Officer (DPO) Controllers and processors that meet the thresholds in the Commissioner’s DPO guidelines must appoint a DPO and notify the Commissioner. Check whether your organisation meets them.
Direct duties for data processors Vendors that process data on your behalf now have their own legal duties, particularly on security. It does not remove your responsibility as the controller.
Biometric data as sensitive data Fingerprint and face attendance need stricter handling and explicit consent.
Higher penalties The maximum fine for breaching the data protection principles rose to RM1,000,000, with imprisonment of up to three years, or both.
Data portability Individuals gain a right to have their data transferred, subject to technical feasibility and format compatibility. Your systems should be able to export data in a usable format.
Cross-border transfers The transfer rules were revised and the Commissioner issued guidance. This matters if a vendor or its AI services process data outside Malaysia.

For deeper legal analysis, see the summaries from DLA Piper and DataGuidance. Both discuss the amendments and the supporting guidelines.

What is the PDPA checklist for business operating software?

Use these 15 checks to test any business system before you sign. A good vendor will answer each one clearly and in writing. Vague answers such as “we take security seriously” are a warning sign.

A. Data and consent

Check What good looks like Ask the vendor
1. Data map You know exactly which personal data the system collects and why. Can you provide a list of data fields and their purposes?
2. Notice and consent Staff are told what is collected and how it is used. Consent is recorded where required. How does the system record consent and notices?
3. Sensitive data handling MCs, medical claims and biometrics get stricter access and explicit consent. Which data is treated as sensitive, and how is it protected differently?
4. Retention and deletion Records are kept only as long as needed, then deleted or anonymised. Can we set retention rules and prove deletion?

B. Security controls

Check What good looks like Ask the vendor
5. Encryption Data is encrypted at rest and in transit. What encryption standards do you use, and who holds the keys?
6. Role-based access Staff see only their own data, managers only their teams, HR only what its role needs. Can permissions be set by department, grade and branch?
7. Audit logs Every view, change and export is logged and can be reviewed. Are logs tamper-resistant and how long are they kept?
8. Authentication Strong sign-in controls, such as multi-factor authentication, for admins at minimum. What sign-in protections are available?

C. Hosting and vendors

Check What good looks like Ask the vendor
9. Hosting location You know where data physically sits, with an on-premise or regional option if needed. Where is our data hosted, and can we choose?
10. Cross-border transfers Any transfer outside Malaysia is identified, assessed and documented. Does any data leave Malaysia, and under what safeguards?
11. Processor contract A written agreement covers security, breach notice, sub-processors and deletion on exit. Can we see the data processing terms before signing?
12. AI services You know which AI models process documents such as IC scans and MCs, where, and under what terms. Which AI providers are used, and is our data used to train models?

D. Incidents and accountability

Check What good looks like Ask the vendor
13. Breach response A tested plan to detect, contain and report incidents inside the required timeframe. How fast will you tell us about an incident, and how?
14. DPO and governance A named DPO or contact where required, with clear internal ownership. Who is your data protection contact?
15. Individual rights You can find, correct, export and delete a person’s data on request. How do we handle access, correction and portability requests?

Why “PDPA compliant” on a sales page is not enough

Compliance is a property of how an organisation handles personal data, not a badge a product can carry. Software can support your obligations through security features, access controls, logging and hosting choices, but you still need policies, consent, staff training and a breach plan. Treat any “100% compliant” claim, from any vendor, as a starting point for questions rather than proof.

Self-Hosted Security vs. Standard SaaS Subscriptions

Standard cloud software-as-a-service (SaaS) models often charge expensive recurring monthly fees. More critically, when you rely on multi-tenant SaaS platforms, your organisation’s sensitive records are stored alongside thousands of other businesses on vendor-controlled servers. If the software vendor’s central server is compromised, your corporate data is exposed regardless of your internal security practices.

In contrast, a self-hosted business operating system guarantees complete data sovereignty. All records are safely kept within your own dedicated server or private cloud environment. No external parties—including Kode Digital developers or third-party maintenance teams—can access your database without explicit server permissions granted directly by your IT administrator.

Additionally, self-hosting provides significant long-term financial advantages. Instead of endless monthly subscription fee inflation as your team grows, you pay for the source code once and own the system outright. In the future, you only incur costs if you choose to hire a developer for bespoke feature upgrades or custom extensions.

How does Kunos approach PDPA and data security?

Kunos is designed to support Malaysian organisations with their PDPA obligations, though compliance remains the responsibility of your organisation. According to the Kunos product page, you can choose dedicated on-premise installation or self-hosted deployment in Alibaba Cloud regional data centres, with data encrypted at rest and in transit. It includes role-based access controls, audit logs for every action, and granular permissions by department and grade, plus audit-ready document management.

Kunos also uses AI engines for document reading and analysis, and names them on its product page. That is the transparency you should expect from any vendor, and it is exactly why checklist item 12 exists. Our team will walk your IT and legal teams through the hosting options, access model and AI data handling during your demo. Most organisations are configured within 2 to 6 weeks.

Related reading: How to Digitise Leave Management in a Malaysian Company: A 7-Step Guide for handling health data, AutoCount vs SQL Accounting: Simplifying Financial Data Entry & E-Invoice Integration to connect operational data safely, and One-Off vs Subscription Business Software: What It Really Costs Over 5 Years when comparing hosting options and costs. Kunos is used by government-linked companies and education institutions that need strong governance.

Frequently Asked Questions

Is business operating software covered by the PDPA in Malaysia?

Yes. Business operating software processes personal data belonging to employees, clients, and partners, so the organisation using it is bound by the PDPA as a data controller. Medical certificates and biometric attendance data are sensitive personal data with stricter requirements.

What are the main PDPA changes for business data since 2025?

The amendments introduced mandatory data breach notification, Data Protection Officer requirements for organisations that meet the thresholds, direct security duties for data processors, biometric data as sensitive data, higher penalties of up to RM1,000,000 and imprisonment of up to three years, data portability and revised cross-border transfer rules.

How quickly must a data breach be reported in Malaysia?

Controllers must notify the Personal Data Protection Commissioner of a personal data breach, and notify affected individuals where the breach is likely to cause significant harm. The Commissioner’s guidelines refer to a 72-hour timeframe. Check the current guidelines and take legal advice, because the exact requirements can change.

Can we use self-hosted business software and stay PDPA compliant?

Yes. Self-hosting ensures your data remains completely on your own server or private cloud, isolated from vendor breaches and unauthorised external access.

Is a medical certificate sensitive personal data under the PDPA?

Yes. Information about a person’s physical or mental health is sensitive personal data under the PDPA. Store MCs with strict access controls, collect only what you need, and follow your retention policy.

Does using AI to read IC or MC scans create PDPA risk?

It can, so treat it like any other processing. Find out which AI providers handle the documents, where the processing happens, whether data is retained or used for training, and what the contract says. Keep a human review step for exceptions.

Next step: review hosting and security with our team

Bring your IT and compliance leads to a Kunos demo and ask any of the 15 questions above. Schedule a demo on WhatsApp, or explore Kunos. We support organisations across Penang, the Klang Valley and the rest of Malaysia from George Town and Petaling Jaya.

About the Author: Husna writes about business systems, compliance and digital transformation for Kode Digital.

Kode Digital Sdn Bhd is a Malaysian digital agency with offices in George Town, Penang and Petaling Jaya, Selangor. It builds Kunos, an AI-powered business operating system for Malaysian organisations.