PDPA Basics
Sensitive Personal Data
Data Subject Rights
Data Security
Enforcement and Penalties/Compliance
100

What does PDPA stand for?

Personal Data Protection Act

100

Give an example of sensitive personal data under the PDPA.

(Any of) Religious beliefs, political opinions, health information, sexual life, biometric data, genetic data

100

What is the right of access under the PDPA?

The right of a data subject to request access to their personal data held by a data user.

100

What is a "data leak"?

The unauthorized or accidental disclosure of personal data

100

Who is responsible for enforcing the PDPA in Malaysia?

The Commissioner of the Personal Data Protection Department (PDPD)

200

When did the PDPA come into effect in Malaysia?

2010

200

True or False: A company can process sensitive personal data without consent if it is necessary to comply with a legal obligation.

True

200

If a data subject believes their personal data is inaccurate, what right can they exercise under the PDPA?

The right to correction.

200

Name one security measure that data users should implement to protect personal data.

(Any of) Access controls, encryption, data masking, regular backups, security awareness training

200

What is the maximum fine that can be imposed on a company for a serious breach of the PDPA?

RM 500,000

300

What is the main purpose of the PDPA?

To regulate the processing of personal data in commercial transactions

300

What is the general rule regarding the processing of sensitive personal data?

It requires explicit consent from the data subject.

300

True or False: A data subject can withdraw their consent to the processing of their personal data at any time.

True

300

True or False: A data user is not required to report a data breach to the authorities if it is unlikely to cause harm to the data subjects.

False (Data breaches must be reported to the Commissioner)

300

True or False: A company can be held liable for a data breach even if it was caused by a third-party vendor.

True (if the company failed to take reasonable steps to prevent the breach)

400

True or False: The PDPA applies to all organizations in Malaysia, regardless of size or industry.

False (It only applies to commercial transactions)

400

Can a company collect information about an employee's religious beliefs for the purpose of organizing a company event?

No, this would likely be considered excessive and unnecessary.

400

What is the purpose of the right to data portability?

To allow data subjects to transfer their personal data from one data user to another.

400

What is the purpose of a Data Protection Impact Assessment (DPIA)?

To identify and assess the risks to personal data associated with a particular processing activity.

400

What is a "compliance notice" under the PDPA?

A notice issued by the Commissioner requiring a data user to take specific steps to comply with the PDPA.

500

What is a "data user" under the PDPA?

A person or organization who processes personal data.

500

A hospital wants to share a patient's medical records with a research institution. What must they obtain from the patient before doing so?

Explicit consent.

500

A data subject wants to prevent a company from using their personal data for direct marketing purposes. What right can they exercise?

The right to prevent processing for direct marketing

500

A company stores customer data on a cloud server. What security measures should they consider to protect this data?

Encryption, access controls, strong passwords, regular security assessments of the cloud provider.

500

What are some of the consequences a company might face for non-compliance with the PDPA?

Fines, imprisonment, reputational damage, loss of customer trust.