PDPA, CCTV and Biometrics in a Malaysian Office
🏠 Renovation🏢 Office Fit-Out🛍 Shop Fit-Out💦 Waterproofing❄ Aircon⚡ Electrical & Plumbing🔨 Carpentry🧹 Deep CleaningGuidesToolsAbout🔍 SearchInstant Quote
CCTV & Security Systems

PDPA, CCTV & Biometrics
Compliance for a Malaysian Office (2026)

Which cameras the Act reaches, what the amended Act says about biometric door access, and where the widely quoted penalties and deadlines actually attach.

An office reception with a fingerprint access terminal and a privacy notice
The picture is different for a business: an office, shop, factory or other commercial operator running cameras is processing personal data in respect of commercial transactions and is inside the Act. The RM1,000,000 maximum fine under Malaysia’s Personal Data Protection Act 2010 is the penalty for breaching the seven personal data protection principles, not for anything to do with breach notification. This guide sets out which duties reach an office running cameras. Send photos or a floor plan on WhatsApp and we will quote after a site survey.

Which cameras the Act reaches at all

Before any compliance question is worth answering, settle the prior one: does the Personal Data Protection Act apply to these cameras in the first place? It does not apply to everything with a lens on it, and the filters are specific.

Verified wording, quoted exactly: Malaysia’s Personal Data Protection Act 2010 does not apply to everything a camera records, and there are TWO separate filters. Section 2(1) applies the Act only to a person who processes, or who has control over or authorises the processing of, ‘any personal data in respect of commercial transactions’, and section 4 defines a commercial transaction as ‘any transaction of a commercial nature, whether contractual or not, which includes any matters relating to the supply or exchange of goods or services, agency, investments, financing, banking and insurance’.

Read the definition rather than the label. The gate is not “are you a company”; it is whether personal data is being processed in respect of commercial transactions, and the definition of that phrase is quoted above in the Act’s own words.

The household exemption, and why a homeowner should not rely on the Act

Verified wording, quoted exactly: Separately, section 45(1) provides: ‘There shall be exempted from the provisions of this Act personal data processed by an individual only for the purposes of that individual’s personal, family or household affairs, including recreational purposes.’ A householder pointing a camera at their own property can therefore fall outside the Act on both grounds at once — there is no commercial transaction, and the purpose is a personal or household one.
The consequence people find uncomfortable: It is not safe to tell homeowners that the PDPA protects them against a neighbour’s CCTV. Whether any particular domestic camera is caught is a question no published guidance from the Personal Data Protection Department answers, and a neighbour dispute is usually pursued through other channels rather than the PDPA.

For a camera in a strata building, the by-laws are a separate question again and are covered in condo CCTV rules and the JMB.

We include this on a business page for two reasons. Directors ask about their own homes as often as about their offices. And it is the clearest way to see the shape of the Act: the same camera, on the same street, can be inside or outside the legislation depending on who is running it and why.

An office is on the other side of that line

Verified wording, quoted exactly: The picture is different for a business: an office, shop, factory or other commercial operator running cameras is processing personal data in respect of commercial transactions and is inside the Act.

So for a shop, an office, a clinic, a factory or a warehouse, the question is not whether the rules apply. It is which of them apply to what you are already doing, and that is the rest of this page.

The seven principles — and where the million-ringgit figure actually attaches

If you have read anything about the amended Act, you have probably seen a million ringgit attached to a seventy-two hour deadline. That pairing is wrong, and getting it right changes what you should actually spend your attention on.

Verified wording, quoted exactly: The RM1,000,000 maximum fine under Malaysia’s Personal Data Protection Act 2010 is the penalty for breaching the seven personal data protection principles, not for anything to do with breach notification. Section 5(1) requires a data controller to comply with the General Principle, the Notice and Choice Principle, the Disclosure Principle, the Security Principle, the Retention Principle, the Data Integrity Principle and the Access Principle.
The penalty, and what changed: Section 5(2), as amended by the Personal Data Protection (Amendment) Act 2024 with effect from 1 April 2025, makes a contravention an offence carrying, on conviction, a fine not exceeding one million ringgit or imprisonment for a term not exceeding three years, or both. Before that amendment the same offence carried a fine not exceeding three hundred thousand ringgit or two years’ imprisonment. The amendment also extended that liability to a data processor who contravenes the Security Principle.
Why that matters for a camera system: For an office running CCTV and biometric door access, this is the figure that matters — it is the penalty for failing to give notice, to secure the data, or to stop retaining footage you no longer need.

Notice what the last sentence points at: giving notice, securing the data, and not keeping footage you no longer need. Those are the three things an office with cameras can act on this week, and they are exactly the three the next sections cover. None of them require a compliance product; they require a decision, written down, and a recorder configured to match it.

Notice: the sign at the door and the document behind it

Among the principles named in the wording above is the Notice and Choice Principle. In practice, for a camera system, that turns into two separate artefacts and most offices have neither.

The first is the visible one: a notice where people can see it before they are recorded, at each entrance and in any area under camera. Our recommendation, as a matter of ordinary practice rather than as a statement of what the law demands in your case, is that the sign says who operates the cameras and what they are for, and points to somewhere fuller.

The second is the fuller statement it points to — a short document you can hand over or publish, saying what is recorded, why, roughly how long it is kept, who can see it and how to contact you about it. Write it once, keep it with your other policies, and review it when the system changes.

What your own notice must contain is a question for your adviser and your own circumstances; what we can tell you is that having nothing at all is the position hardest to defend, and that writing it costs an afternoon.

How long to keep footage

This is the most-asked question on this page and we are going to answer it honestly: we have no verified Malaysian source that sets a retention period for ordinary commercial CCTV footage, so we are not going to print one and dress it up as a rule. What the Act does name, in the list quoted further up this page, is a Retention Principle.

What you can do — and this is our engineering recommendation, not a legal requirement — is make it a decision instead of an accident:

  • Decide a period deliberately, based on how long it realistically takes your business to discover an incident. A retail shrinkage problem surfaces on a different timescale from a car-park dispute.
  • Write it down in the same document as your notice, so the answer to “how long do you keep it” is a policy rather than a shrug.
  • Make the recorder actually do it. Most systems overwrite when the disk fills, which means the real retention period is whatever the disk size happens to produce, and it changes every time a camera is added. Set the retention explicitly if the recorder supports it, and size the storage to the period you chose rather than the other way round — our CCTV installation cost guide covers what moves that number.
  • Handle exports separately. A clip copied to somebody’s phone or a USB stick does not get overwritten with the rest. Decide who may export, where exports are kept and when they are deleted.
  • If a specific obligation applies to your sector — a licensing condition, a client contract, an insurer’s requirement — that is the number to follow, and it is one to obtain in writing from whoever imposes it.

Securing the recorder, which is where most of the real risk is

Among the principles named above is the Security Principle. For a camera system, this is not an abstract obligation — the realistic incident is not a regulator walking in, it is a recorder reachable from the internet with the password it left the factory with.

  • Change every default password on the recorder and on each camera at commissioning, and keep the credentials somewhere other than a note taped to the rack.
  • Give named people their own logins rather than sharing one administrator account, so the access log means something.
  • Avoid exposing the recorder directly to the internet through port forwarding. If remote viewing is needed, ask the installer what method they are using and why.
  • Ask who at the supplier can reach your system remotely for support, and have that written into the arrangement rather than discovered later.
  • Keep firmware current, and ask at handover how updates will be applied and by whom.
  • Put the recorder somewhere physically secure and ventilated. A recorder anyone can unplug and carry out is a data loss and an evidence loss at the same time.
  • Restrict who can view live and recorded footage, and write down who that is.

Almost every one of those is a decision made at installation and never revisited. They are also the cheapest items on this page.

Biometric door access is a separate and stricter category

If your office uses a fingerprint or face reader — for entry, for time-attendance, or both — a different and tighter set of rules is engaged, and it applies to the templates rather than to the door.

Verified wording, quoted exactly: Fingerprint and face-recognition door access now sits in the Personal Data Protection Act’s most tightly controlled category. The Personal Data Protection (Amendment) Act 2024 inserted a definition of ‘biometric data’, meaning ‘any personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person’, and added biometric data to the definition of ‘sensitive personal data’ in section 4 of the Act. Both changes took effect on 1 April 2025.

That change matters because it moves the data into the category the Act treats most carefully, and because a great many Malaysian offices installed these readers before the change and have not revisited the paperwork since.

Verified wording, quoted exactly: Section 40(1) then provides that a data controller shall not process any sensitive personal data of a data subject except in accordance with the conditions it lists, the first of which is that ‘the data subject has given his explicit consent to the processing of the personal data’. Explicit consent is not the only route — section 40(1)(b) permits processing that is necessary for specified purposes, including exercising or performing a right or obligation which is conferred or imposed by law on the controller in connection with employment, and section 40(1)(c) covers information the data subject has deliberately made public.
The practical standard: But ordinary implied consent is not enough for a biometric reader, and an employer rolling out fingerprint or face time-attendance should have a clear privacy notice and explicit consent on file.

Two misquotes to watch for, because both are common and they err in opposite directions. The word in the provision is explicit, not written — writing it down is good practice and worth doing, but do not let anyone tell you the Act says “written”. And explicit consent is not the only condition listed, so “you can never run a biometric reader without every employee agreeing” overstates it just as badly. Where your own workforce raises something unusual, that is a question to take advice on. The technology choice itself is covered in face recognition versus fingerprint door access.

When something goes wrong: what the Act requires, and where the 72 hours comes from

This is the area with the most misinformation attached to it, so here is the wording itself.

Verified wording, quoted exactly: The Personal Data Protection Act 2010 itself sets no deadline in hours. Section 12B(1), inserted by the Personal Data Protection (Amendment) Act 2024 and in force since 1 June 2025, requires a data controller who has reason to believe that a personal data breach has occurred to notify the Commissioner ‘as soon as practicable’, in the manner and form the Commissioner determines.
Where the 72 hours actually comes from: The 72-hour figure comes from the Commissioner’s guideline rather than the statute: paragraph 6.1 of the Personal Data Protection Guideline on Data Breach Notification (Version 1.0, issued 25 February 2025 under section 48(g) of the Act) states that ‘the notification shall be made as soon as practicable and no later than seventy-two (72) hours from the occurrence of the personal data breach’, and paragraph 7.7 requires a written explanation with supporting evidence if that is missed. Affected individuals are on a different clock: section 12B(2) requires notice to the data subject ‘without unnecessary delay’ where the breach causes or is likely to cause significant harm, and paragraph 9.1 of the guideline sets that at not later than seven days after the Commissioner was notified.
The offence, and what it looks like for a security system: Only failure to notify the COMMISSIONER is an offence: under section 12B(3) a data controller who contravenes section 12B(1) is liable, on conviction, to a fine not exceeding two hundred and fifty thousand ringgit or imprisonment for a term not exceeding two years, or both. For a security system this bites when an NVR is hacked or an access-control database holding fingerprint or face templates is exposed.

Put the two blocks above beside the penalty section earlier on this page and the popular version falls apart: the seventy-two hours is the Commissioner’s guideline rather than a deadline in the statute, and the figure attached to failing to notify is not the million-ringgit one. Both facts matter, and neither of them is a reason to be relaxed — they are a reason to know which duty you are actually dealing with.

The practical preparation is short. Know who in your organisation would be told first if a recorder or an access database were compromised, know who decides whether to notify, and know where the system documentation is. An incident is a bad time to discover that only the installer knows how the system is put together.

Do you need a data protection officer? What the guideline actually says

Verified wording, quoted exactly: Section 12A of the Personal Data Protection Act 2010, in force since 1 June 2025, requires a data controller or data processor to appoint one or more data protection officers in certain cases. The Commissioner’s Guideline on the Appointment of Data Protection Officer (February 2025) states that the requirement applies where the processing of personal data involves personal data exceeding 20,000 data subjects; sensitive personal data, including financial information data, exceeding 10,000 data subjects; or activities that require regular and systematic monitoring of personal data.
What the guideline says about CCTV specifically: On CCTV specifically, the guideline says that a data controller or data processor carrying out activities such as operating a telecommunications network, monitoring wellness, fitness and health data via wearable devices, and activities involving closed-circuit television or connected devices such as smart cars and home automation systems ‘would be considered as carrying out activities that MAY CONSTITUTE regular and systematic monitoring’. So running cameras is a strong indicator that the appointment duty is engaged, but the guideline frames it as something that may constitute regular and systematic monitoring, not as an automatic trigger.
So the honest answer: An organisation running CCTV or biometric access at any scale should take advice on whether it needs a data protection officer.

We want to be careful here, because this is exactly the point where a security company would be tempted to sell you something. The guideline’s words are “may constitute”. It does not say that having cameras means you must appoint an officer, and anyone telling you otherwise — particularly as part of a hardware quotation — is going further than the document does. Whether the duty is engaged for your organisation depends on your processing as a whole, not on the number of cameras on your wall.

When somebody asks to see the footage

Sooner or later an employee, a customer, an insurer, a neighbouring tenant or the police will ask for a clip. Decide how you handle that before it happens rather than in the twenty minutes after the request arrives.

Who is askingWhat to do firstWhat to avoid
An employee about an incident involving themLog the request in writing with the date, time window and location; preserve the relevant footage before it is overwrittenHanding over a clip informally without knowing what else is in the frame
A customer or member of the publicLog it the same way, and route it to the named person who decidesLetting whoever is on the counter make the decision
The policeAsk what they need and record who asked, when, and under what referenceDeleting or overwriting the period in question while you work it out
An insurer or a lawyerTreat it as a formal request; preserve first, then decideAssuming a request from a professional is automatically one you must fulfil
Another tenant or a neighbouring businessPreserve, then decide, then reply in writing either wayAn informal favour that becomes a precedent

Get your exact price in minutes

Send us a photo of the job on WhatsApp — we reply with an instant quote.

💬 Get Your Instant Quote
Free quoteFlat price, no hidden chargesExperienced KL & Selangor contractor

Two habits make all of these easier: preserve first and decide second, because footage that has been overwritten cannot be un-overwritten; and have one named person who decides, so the answer does not depend on who happened to be in the office. What you must disclose in any particular case is a question for your adviser — what you can put in place today is the process.

A practical compliance file

Everything on this page reduces to a small folder that somebody can hand over. Building it is a morning’s work and it is the difference between a defensible position and an argument from memory.

DocumentWhat goes in itWho keeps it current
Camera scheduleEvery camera, where it is, what it sees, and why it is thereWhoever manages the premises
Notice and fuller privacy statementThe wording used on the signs and the longer version behind itThe same person, reviewed when the system changes
Retention decisionThe period you chose, the reason, and the recorder setting that enforces itThe person who administers the system
Access listWho can view live and recorded footage, and who administers the systemReviewed when staff join or leave
Biometric notice and consentsThe notice given to staff and the record of consent, where a reader is in useWhoever runs HR
Supplier and support arrangementWho can access the system remotely, and howWhoever holds the contract
Incident and request logEvery request for footage, and what was done about itThe named decision-maker
System documentationAs-installed drawings, camera and recorder models, credentials location, handover notesRequested from the installer at handover

What to ask your installer — and what is not their job

An installer is not your compliance adviser, and you should be wary of one who says otherwise. What they can be asked for is the technical foundation everything above sits on.

  • A camera schedule and as-installed drawing at handover, showing each camera’s position and field of view.
  • Confirmation that every default password has been changed, and where the credentials are recorded.
  • The retention setting the system was left on, and what it means in days at the current camera count.
  • Whether the recorder is reachable from the internet, by what method, and who can reach it.
  • Individual logins for named administrators rather than one shared account.
  • For biometric readers: where templates are stored, and what happens to them if a unit is replaced or returned.
  • Written handover: models, serial numbers, warranty terms and a support contact.

The physical side of the system — cameras, recorder, doors and readers — is covered in our office door access guide, and the office fit-out sequence in the office renovation cost guide.

Why ClickBina

ClickBina installs CCTV, door access and intercom systems for offices, shops and light industrial premises across Kuala Lumpur and Selangor. On this subject our job is narrow and we would rather say so: we build the system, we hand it over documented with the defaults changed and the retention set to the period you chose, and we tell you what we do not know. We are not your legal adviser, and a supplier who offers to be one alongside a hardware quotation is selling something. See our electrical and plumbing services, or send photos or a floor plan on WhatsApp and we will quote after a site survey.

This guide sets out what the wording we verified actually says, and what to do about it. It is information, not advice on your own situation. A specific situation — your building, your premises, your documents and your dates — needs a professional adviser who has read them, and you should take that advice before you rely on anything here.

Common Questions

Does the PDPA apply to CCTV in my office?
Malaysia’s Personal Data Protection Act 2010 does not apply to everything a camera records, and there are TWO separate filters. Section 2(1) applies the Act only to a person who processes, or who has control over or authorises the processing of, ‘any personal data in respect of commercial transactions’, and section 4 defines a commercial transaction as ‘any transaction of a commercial nature, whether contractual or not, which includes any matters relating to the supply or exchange of goods or services, agency, investments, financing, banking and insurance’. The picture is different for a business: an office, shop, factory or other commercial operator running cameras is processing personal data in respect of commercial transactions and is inside the Act.
Does it apply to a camera at my own house?
Separately, section 45(1) provides: ‘There shall be exempted from the provisions of this Act personal data processed by an individual only for the purposes of that individual’s personal, family or household affairs, including recreational purposes.‘ A householder pointing a camera at their own property can therefore fall outside the Act on both grounds at once — there is no commercial transaction, and the purpose is a personal or household one. It is not safe to tell homeowners that the PDPA protects them against a neighbour’s CCTV.
Is it true that missing the 72-hour deadline means a fine of a million ringgit?
No, and this is the most repeated error about the amended Act. The RM1,000,000 maximum fine under Malaysia’s Personal Data Protection Act 2010 is the penalty for breaching the seven personal data protection principles, not for anything to do with breach notification. On the notification duty itself: The Personal Data Protection Act 2010 itself sets no deadline in hours. Section 12B(1), inserted by the Personal Data Protection (Amendment) Act 2024 and in force since 1 June 2025, requires a data controller who has reason to believe that a personal data breach has occurred to notify the Commissioner ‘as soon as practicable’, in the manner and form the Commissioner determines. The 72-hour figure comes from the Commissioner’s guideline rather than the statute: paragraph 6.1 of the Personal Data Protection Guideline on Data Breach Notification (Version 1.0, issued 25 February 2025 under section 48(g) of the Act) states that ‘the notification shall be made as soon as practicable and no later than seventy-two (72) hours from the occurrence of the personal data breach’, and paragraph 7.7 requires a written explanation with supporting evidence if that is missed. And the offence carries its own, different penalty: Only failure to notify the COMMISSIONER is an offence: under section 12B(3) a data controller who contravenes section 12B(1) is liable, on conviction, to a fine not exceeding two hundred and fifty thousand ringgit or imprisonment for a term not exceeding two years, or both.
How long must an office keep CCTV footage in Malaysia?
We have no verified Malaysian source that sets a retention period for ordinary commercial CCTV, so we will not print one as though it were a rule. What the Act names, in the list of principles quoted on this page, is a Retention Principle. Our engineering recommendation is to choose a period deliberately, based on how long it realistically takes your business to discover an incident; write it into the same document as your camera notice; and then make the recorder enforce it, because most systems simply overwrite when the disk fills and the real retention period ends up being whatever the disk size happens to produce. If a licensing condition, contract or insurer sets a period for your sector, that is the number to follow — get it in writing from them.
Do we need written consent before putting staff on a fingerprint reader?
Section 40(1) then provides that a data controller shall not process any sensitive personal data of a data subject except in accordance with the conditions it lists, the first of which is that ‘the data subject has given his explicit consent to the processing of the personal data’. Explicit consent is not the only route — section 40(1)(b) permits processing that is necessary for specified purposes, including exercising or performing a right or obligation which is conferred or imposed by law on the controller in connection with employment, and section 40(1)(c) covers information the data subject has deliberately made public. But ordinary implied consent is not enough for a biometric reader, and an employer rolling out fingerprint or face time-attendance should have a clear privacy notice and explicit consent on file. Note the word is “explicit”, not “written” — keeping it in writing is our record-keeping recommendation, not a quotation from the Act — and explicit consent is not the only condition listed.
Do we have to appoint a data protection officer because we have CCTV?
Section 12A of the Personal Data Protection Act 2010, in force since 1 June 2025, requires a data controller or data processor to appoint one or more data protection officers in certain cases. The Commissioner’s Guideline on the Appointment of Data Protection Officer (February 2025) states that the requirement applies where the processing of personal data involves personal data exceeding 20,000 data subjects; sensitive personal data, including financial information data, exceeding 10,000 data subjects; or activities that require regular and systematic monitoring of personal data. On CCTV specifically, the guideline says that a data controller or data processor carrying out activities such as operating a telecommunications network, monitoring wellness, fitness and health data via wearable devices, and activities involving closed-circuit television or connected devices such as smart cars and home automation systems ‘would be considered as carrying out activities that MAY CONSTITUTE regular and systematic monitoring’. So running cameras is a strong indicator that the appointment duty is engaged, but the guideline frames it as something that may constitute regular and systematic monitoring, not as an automatic trigger. An organisation running CCTV or biometric access at any scale should take advice on whether it needs a data protection officer. Be careful with anyone who flattens that into “if you have cameras you must appoint an officer”, especially as part of a hardware quotation.
What should our CCTV sign say?
What your own notice must contain is a question for your adviser and your own circumstances, so we will not draft it for you. As ordinary practice, we recommend a notice visible before someone is recorded — at each entrance and in any area under camera — that says who operates the cameras and what they are for, and points to a fuller statement you can hand over or publish covering what is recorded, why, roughly how long it is kept, who can see it and how to contact you. Having nothing at all is the hardest position to defend, and writing it costs an afternoon.
Who is responsible for compliance — us or the CCTV company?
Section 5(2), as amended by the Personal Data Protection (Amendment) Act 2024 with effect from 1 April 2025, makes a contravention an offence carrying, on conviction, a fine not exceeding one million ringgit or imprisonment for a term not exceeding three years, or both. The amendment also extended that liability to a data processor who contravenes the Security Principle. Which of those roles fits you and which fits your supplier in your particular arrangement is a question to take advice on. What you can do today is contractual and practical: get a written handover, get the defaults changed, get the retention set, get named logins, and agree in writing who at the supplier can reach your system remotely.

Get a Free Quote

Tell us what you need — we reply within the hour.

WhatsApp ClickBina← All Guides
💬 Get Your Instant Quote