In brief

On 5 October 2026, Malaysia's Personal Data Protection Department (PDPD) published a consultation paper on a proposed Artificial Intelligence and Personal Data Protection Framework ("Framework"). The Framework would guide how organisations that develop, procure, deploy or support AI systems should comply with the Personal Data Protection Act 2010 (PDPA) when processing personal data. It proposes lifecycle-based expectations covering lawful processing, system development and monitoring, third-party oversight, data subject rights, security, governance and demonstrable compliance. Submissions are due by 23 October 2026.

Who is affected?

The Framework will be relevant to data controllers and processors that develop, procure, customise, deploy, operate or support AI systems involving personal data.

In more detail

The Framework takes a lifecycle-based approach. The PDPD's principal proposed expectations are summarised below.

  • Lawful and transparent processing
    AI does not create a separate legal basis for processing personal data. Organisations should identify and document the applicable legal basis, ensure that processing is necessary and proportionate, provide clear privacy notices, and obtain fresh consent where personal data will be used for a materially different purpose.

  • AI development, testing and deployment
    Organisations should embed data protection into the design, training, testing and validation of AI systems. This includes applying Data Protection by Design, using adequate and relevant datasets, maintaining accuracy, considering anonymisation or pseudonymisation, validating systems before deployment, monitoring them in use, and reassessing material changes.

  • Third-party AI systems and cross-border transfers
    Before procuring or integrating third-party AI systems, organisations should conduct due diligence, define roles and data-processing responsibilities contractually, assess cross-border transfers and applicable safeguards, and maintain ongoing vendor oversight.

  • Data subject rights, fairness and security
    Existing PDPA rights would continue to apply, including access, correction, withdrawal of consent and data portability. Organisations should provide clear processes for exercising those rights, including in relation to AI-generated or derived personal data, where applicable.

  • Governance, risk management and demonstrable compliance
    Organisations should assign accountability for AI systems; establish policies, procedures and training; conduct proportionate risk and impact assessments, including DPIAs where appropriate; test, monitor and audit systems; and retain records of processing, assessments, reviews, corrective actions and third-party oversight. The emphasis is not only on compliance, but on maintaining evidence that governance arrangements operate effectively.

Observations and next steps

In addition to submitting feedback to the Framework (due by 23 October 2026 at the designated Google Forms platform link or Unified Public Consultation Platform link), organisations should begin preparing for Malaysia’s broader emerging AI governance regime. This includes the proposed AI Governance Bill (expected to be tabled in Parliament, at the latest by Q1 20271) which is intended to establish overarching governance principles, institutional responsibilities and safeguards for the responsible development and deployment of AI. Our previous client alert on it is found here.

Against this backdrop and with focus at this time on the proposals in the Framework, organisations that develop, procure or use AI systems involving personal data should, among other things:

  • Assess the proposals in the Framework against existing and planned use cases for AI. This may include mapping each specific AI use case to track compliance with the PDPA.
  • Assess if Data Protection by Design is embedded in practice, into the organisation’s AI utilisation lifecycle.
  • Relook its vendor review and contracting process against the proposals within the Framework.

Taken together, the Framework and the proposed AI Governance Bill signal Malaysia's move towards a more structured and coherent AI governance regime that seeks to foster responsible innovation while safeguarding, amongst others, users and their personal data.

-----------

1 AI Governance Bill to be tabled in dewan rakyat early 2027 - Gobind

* * * * *

Karen Ting, Associate, has contributed to this legal update.

© 2026 Wong & Partners. All rights reserved. Wong & Partners, member of Baker & McKenzie International. This may qualify as “Attorney Advertising” requiring notice in some jurisdictions. Prior results do not guarantee a similar outcome.

Explore More Insight