On 16 February 2022, the Department of Personal Data Protection (JPDP) issued the following circulars:
The objective of the Registration Circular is to advise data users falling within the classes of data users specified under the Personal Data Protection (Class of Data Users) Order 2013 (Order) on the requirement to register with the JPDP as a data user pursuant to s 14 of the Personal Data Protection Act 2010 (PDPA). A “data user” is defined under the PDPA as a person, who either alone or jointly or in common with other persons, processes any personal data or has control over or authorises the processing of any personal data, but does not include a data processer. Pursuant to s 14, data users falling within the classes of data users as specified by the Minister of Communications and Multimedia must register themselves as such. These classes of data users are set out in the Order and include the following sectors:
Data users falling within two or more of the sectors listed above are required to make separate applications to register for each and every class they fall under.
Registration for data users can be made online and is subject to an annual fee ranging from RM100 to RM400, depending on the corporate structure of the data user. The validity period of the registration can be made for up to 10 years. A certificate of registration will be issued by the JPDP upon successful registration by the data user. Notwithstanding the aforementioned, the Personal Data Protection Commissioner (Commissioner) is empowered under s 16 of the PDPA to refuse an application.
Data users falling with the classes of data users specified under the Order that fail to register with the JPDP commit an offence under the PDPA, which is punishable by a fine not exceeding RM500,000 or imprisonment not exceeding three years, or both.
The Renewal Circular provides guidance on the process of renewing the certificate of registration of a data user. Pursuant to s 17 of the PDPA, renewal applications must be made prior to the expiry of the certificate of registration, being not later than 90 days before such expiry. Any renewal application submitted after 90 days will not be accepted, and the data user will need to apply afresh for a certificate of registration.
The term of the renewed certificate of registration may be made for up to 10 years, and will be subject to an annual fee ranging between RM100 and RM400, depending on the corporate structure of the data user.
Pursuant to s 17 of the PDPA, the Commissioner may refuse to renew a certificate of registration if:
A data user that fails to renew its certificate of registration and continues to process personal data following the expiry of such certificate commits an offence under the PDPA, and may be subject to a fine not exceeding RM250,000, imprisonment for a term not exceeding two years, or both.
The circulars serve as a timely reminder that organisations should examine whether they fall within any of the classes of data users specified in the Order and assess whether they are subject to the requirement to register with the JPDP pursuant to the PDPA. In addition to the issuance of circulars, we have seen licensees under the CMA receiving notification/reminder letters from the Malaysian Communications and Multimedia Commission to register with the Commissioner, which suggests that the authorities are taking proactive steps in monitoring the level of compliance with the PDPA by data users. Once registered, organisations should be mindful of the timelines in submitting the renewal application of the certificate of registration, so as to avoid the rejection of such application and exposing the organisation to the sanctions under the PDPA as specified above.
It should be noted that data users, whether subject to registration or not, are required to comply with the personal data protection principles under the PDPA in processing personal data. However, data users registered with the JPDP must comply with sectoral codes of practice which set out sector-specific guidance to be adopted and implemented by data users in its processing activities.
If you have any queries, please contact the author or her team partner Teo Wai Sum (tws@lh-ag.com).