Melur Chambers
Get Advice
Privacy law advisory
KUALA LUMPUR · MALAYSIA

Data Protection Counsel
That Speaks Plainly

PDPA compliance, advisory retainers, and breach response for organisations that take data stewardship seriously — without the 120-page audit few will read.

+60 3 7729 4853 [email protected] PDPA 2010 (as amended)
Our Services

Three Areas of Practice

Each engagement is scoped to your actual situation — not packaged to sell hours you do not need.

PDPA Compliance Review
Service 01

PDPA Compliance Review & Notice Drafting

A measured review of your data handling practices against the Personal Data Protection Act 2010 and PDP Regulations 2013. Includes data flow mapping, privacy notice drafting, consent mechanism review, and a plain-language compliance roadmap.

  • Data flow mapping exercise
  • Bilingual Personal Data Notices
  • Retention schedule drafting
  • Cross-border transfer review
From RM 780 Enquire
DPO Advisory Retainer
Service 02

Data Protection Officer Support & Advisory

Standing advisory for DPOs and compliance teams in financial services, healthcare, e-commerce, and education. Monthly check-ins, data subject request reviews, DPIA assistance, and practical guidance on analytics, consent, and AI-assisted processing.

  • Monthly advisory call included
  • Data subject request reviews
  • DPIA on new projects
  • Processing records drafting
From RM 2,200/mo Enquire
Data Breach Response
Service 03

Data Breach Response & Regulator Engagement

Structured support from containment through regulator notification. We assess mandatory notification triggers under the 2024-amended PDPA, prepare JPDP submissions, draft affected individual communications, and provide continuing representation where complaints or civil matters arise.

  • Containment advisory & coordination
  • JPDP notification preparation
  • Bilingual individual notifications
  • Regulator follow-up representation
From RM 3,600 Enquire
Why Melur Chambers

What Makes the Difference

Plain-Language Outputs

Compliance roadmaps and policy documents written to be read and acted on — not stored in a folder and forgotten.

PDPA-Specific Expertise

Our practice centres on the Personal Data Protection Act 2010 and the 2024 Amendment Act, including JPDP regulatory practice.

Practical, Not Prescriptive

We provide advisory that fits your organisation's actual operations — not a checklist of obligations with no pathway for implementation.

Bilingual Documentation

Personal Data Notices, breach communications, and key policies prepared in both Bahasa Malaysia and English as required by law.

Responsive in Breach Situations

Data incidents do not keep office hours. Our breach response engagements are structured to move quickly when containment decisions matter.

Respectful of Client Autonomy

We present options clearly and explain trade-offs. Decisions remain yours — our role is to make sure they are well-informed.

Start a Conversation

Have a Specific Compliance Question?

Whether your organisation is preparing for a first PDPA review, managing a standing compliance programme, or working through a data incident, we are glad to discuss your situation without obligation.

Common Questions

Frequently Asked

Does the PDPA apply to my organisation?
The Personal Data Protection Act 2010 applies to any person who processes personal data in the course of commercial transactions — broadly interpreted. If your organisation collects names, contact details, identification numbers, financial data, or health information from customers, employees, or any natural persons in Malaysia, the Act is likely engaged. Government bodies are excluded from most provisions. A quick review of your data flows will clarify the picture.
What did the 2024 PDPA Amendment Act change?
The 2024 amendments introduced, among other changes, mandatory data breach notification to the Department of Personal Data Protection (JPDP) within prescribed timeframes, an expanded definition of sensitive personal data, updated consent and processing principles, and strengthened enforcement provisions including higher penalties. Organisations that aligned with the 2010 Act but have not revisited their practices since 2023 will likely have gaps to address.
What is involved in a PDPA compliance review engagement?
A typical review begins with a data flow mapping exercise — understanding what personal data enters your organisation, how it is processed, stored, shared, and eventually disposed of. We then review your existing privacy notices, consent mechanisms, internal policies, and any data processor or sharing agreements in place. The output is a prioritised compliance roadmap, updated or new Personal Data Notices in Bahasa Malaysia and English, and where relevant, revised consent forms and retention schedules.
My organisation has just discovered a potential data breach. What should we do first?
Document what you know and when you learned it. Preserve logs and any evidence of the incident. Avoid making public statements or notifying affected individuals before understanding the scope and your legal obligations — early, uncoordinated communication can complicate matters. Contact us as soon as you are able; early involvement allows us to help assess notification triggers and coordinate with IT and forensic teams while the situation is still being assessed.
What does a DPO support retainer include?
Our retainer is structured around what DPOs and compliance teams actually encounter on a recurring basis: a monthly check-in call, review and drafting support for data subject access and erasure request responses, advice on specific processing use cases as they arise (including analytics, marketing consent, and AI-assisted tools), assistance with Data Protection Impact Assessments on new projects, and drafting of internal processing records. The scope can be adjusted at renewal based on what has actually been useful.
Do you handle personal data protection matters for foreign companies operating in Malaysia?
Yes. Where a foreign company processes personal data of individuals in Malaysia in the course of commercial transactions, the PDPA may apply. We work with regional headquarters and compliance teams to understand the applicable obligations and to prepare documentation that satisfies Malaysian legal requirements, including notices and agreements that may need to align with the PDPA alongside other regional frameworks.
Our Location

Visit Melur Chambers

Unit 11-3, Glomac Damansara, Jalan Damansara, 60000 Kuala Lumpur

Contact

Get in Touch

Fill in the form and a member of our team will respond within one business day.

Contact Details

Address
Unit 11-3, Glomac Damansara
Jalan Damansara
60000 Kuala Lumpur
Office Hours
Mon – Fri: 9:00 AM – 6:00 PM
Sat: 9:00 AM – 1:00 PM
Sun & Public Holidays: Closed

Information you share through this form is used only to respond to your enquiry. It is not added to any marketing list. See our Privacy Policy for full details.

Send an Enquiry

By submitting this form, you agree to our Privacy Policy and Terms & Conditions.