PULSEKITA / KNOW YOUR RIGHTS / AKTA 709

Your personal data: can you request access or correction?

Data-subject rights, access, correction and complaints are distinct from an organisation's breach-notification duties.

Source review: 2026-10-11Open Act record 709 →
KEY POINT

Act 709 provides access (section 30) and correction (section 34) procedures, subject to conditions and exceptions.

Who is this for?

People whose data is processed in commercial transactions and who want to understand requests or complaints.

Jurisdiction and scope

Personal-data processing in commercial transactions covered by Act 709. JPDP notes exclusions for Federal and State Governments; not all processing is covered.

What does the law and official guidance say?

Section 30: data access request

Act 709 provides for data access requests under specified procedures. Conditions and grounds of refusal exist; not every record must necessarily be disclosed.

Section 34: correcting inaccurate data

Section 34 provides a correction-request route for personal data that is inaccurate, incomplete, misleading or not current, subject to the Act.

Section 12B: data breach notification

JPDP guidance explains statutory obligations on data controllers to notify the Commissioner and affected data subjects in qualifying breaches. This is a controller obligation, not a guarantee of cash compensation for every incident.

Practical first steps

Identify the organisation and relevant data

Note the organisation, data-use purpose, dates and disputed inaccuracies. Never submit passwords or full security details through unofficial channels.

Evidence: jpdp-faq ↓

Make a clear written request

Specify access or correction, provide relevant supporting evidence and retain correspondence. Use the organisation's official privacy channel.

Use JPDP's complaint channel if needed

If you believe processing breaches Act 709, JPDP explains the right to lodge a complaint with the Commissioner. Review enforcement scope and complaint requirements.

Evidence: jpdp-faq ↓

Important limitations

The Act does not apply to every party or situation

Its principal scope concerns commercial transactions. JPDP states Federal and State Government exclusions. Do not assume identical rights for every government-held dataset.

Evidence: jpdp-faq ↓

Access rights do not guarantee damages

JPDP states the Act does not specifically provide a right to claim damages. Other causes of action would require separate legal analysis.

Evidence: jpdp-faq ↓

Official evidence and references

Each source supports particular statements above. Some dated reprints are older versions, not evidence of every current amendment.

  1. JPDP · Akta Perlindungan Data Peribadi 2010 (naskhah 2022)

    Act 709 sections 30 and 34; earlier text, check A1727 amendments

    Open original source ↗
  2. JPDP · Soalan Lazim Perlindungan Data Peribadi

    Data subject rights, scope/exclusions and complaint routes

    Open original source ↗
  3. JPDP · Garis Panduan Pemberitahuan Pelanggaran Data (2025)

    Guidance implementing section 12B and breach notification duties

    Open original source ↗