Malaysian compliance and IT team in a PDPA and Data Protection Officer training session
HRDC Registered
SBL-Khas
HRD CORP CLAIMABLE · SBL-KHAS

PDPA & Data Protection
Officer (DPO) Training

The Personal Data Protection (Amendment) Act 2024 came into force in stages through 2025. Since 1 June 2025, both data controllers and data processors must appoint at least one Data Protection Officer. This programme prepares appointed or prospective DPOs, and the compliance, IT and HR staff who support them, to meet that duty with confidence.

Typically 2 DaysOn-site or In-houseCertificate of CompletionEnglish & Bahasa Malaysia
How HRDC Claiming Works
HRDC Approved Training Provider
HRD Corp Claimable Programme
Why It Matters

Appointing a DPO Is No Longer Optional

A New Mandatory Appointment

Since 1 June 2025, both data controllers and processors must appoint at least one Data Protection Officer — this is no longer discretionary.

Fines Now Reach RM1,000,000

The amendment raised the maximum fine for a data protection principle breach substantially, changing the cost of getting this wrong.

A Strict 72-Hour Clock

Mandatory breach notification within 72 hours means your internal escalation process has to actually work under pressure.

Its Own Recognised Training Framework

DPO training sits under the Personal Data Protection Department's own competency guideline and training roadmap, separate from general courses.

Programme Overview
DURATIONTypically Delivered as a 2-Day Programme
DELIVERY FORMATOn-Site (Public) or In-House at Your Premises
LANGUAGE OF DELIVERYEnglish & Bahasa Malaysia
CERTIFICATIONCertificate of Completion, HRD Corp SBL-Khas Claimable
Who It's For

Designed for those responsible for personal data governance under the amended Act:

Appointed / Prospective DPOs
Legal & Compliance Officers
IT & Cybersecurity Staff
HR Data Handlers
Risk & Audit Teams
Company Secretaries
Programme Objectives

By the end of the programme, participants will be able to:

  • Explain the 2024 amendment's requirements and the 2025 mandatory DPO appointment.
  • Build an internal breach notification process capable of meeting the 72-hour window.
  • Handle cross-border data transfers and data subject rights requests correctly.
ALIGNED TO THE OFFICIAL DPO FRAMEWORK

Built Around the Department's Own Guidelines

Malaysia's Personal Data Protection Department has published its own DPO Competency Guideline, Professional Development Pathway and Training Roadmap. We structure this programme's content and case studies with direct reference to that published framework.

Competency-Aligned

Mapped to the DPO Competency Guideline

Content is structured against the published competency areas a DPO is expected to demonstrate.

Scenario-Based

Breach Simulation Exercise

A tabletop exercise walks participants through a simulated breach from discovery to the 72-hour notification deadline.

Practical Templates

Register & Notification Templates

Participants leave with draft templates for data processing registers and breach notification documentation.

Cross-Functional

Built for Mixed Audiences

Legal, IT and HR participants work through the same case studies from their own functional perspective.

Interactive Curriculum Exploration

Click on any module to preview its targeted topics and learning outcomes.

OUTCOMES • MODULE 01Applied Practice Standard

The Personal Data Protection (Amendment) Act 2024

What changed as the amendment came into force in stages through 2025, including the mandatory DPO appointment requirement that took effect on 1 June 2025.

Targeted Training Competencies

Summarise the key changes introduced by the 2024 amendment and their 2025 phase-in dates
Explain why both data controllers and data processors must now appoint a DPO
Identify the raised maximum fine of RM1,000,000 for a data protection principle breach
Map which of your organisation's functions count as controller versus processor activities
Certificate of Completion Included

2-Day Programme Agenda

Moving from the 2024 amendment's requirements to a working breach notification process and cross-border transfer checklist.

01

The 2024 Amendment in Context

What changed, the 2025 phase-in timeline, and why both controllers and processors are now caught by the mandatory DPO requirement.

02

Scoping the DPO Role

Applying the Personal Data Protection Department's DPO Competency Guideline and Professional Development Pathway to your organisation.

03

PDPA Principles Refresher

A working refresher on the core data protection principles the DPO is responsible for upholding day to day.

04

Breach Notification Workshop

Building an internal escalation process capable of meeting the mandatory 72-hour breach notification requirement.

05

Cross-Border Transfer Rules

Practical guidance on when personal data can move overseas and what safeguards are required first.

06

Data Subject Rights Handling

Responding correctly and on time to access, correction and other data subject rights requests.

Investment

HRD Corp Claiming & Delivery Options

Recommended

HRD Corp SBL-Khas

100% levy deduction when your training plan is pre-approved through e-TRiS. No cash outlay required.

Request Quotation

Customisable

In-House / Group

Delivered on-site at your premises, tailored to your data processing footprint and industry.

Contact Us

Open Enrolment

Public Session

Join a scheduled public cohort alongside participants from other Malaysian organisations.

Contact Us

FAQ

Frequently Asked Questions

Need your DPO appointed and trained before the next audit?

We deliver PDPA and DPO training as an in-house or public programme, fully claimable against your HRD Corp balance.