Who is this for?
People whose data is processed in commercial transactions and who want to understand requests or complaints.
Jurisdiction and scope
Personal-data processing in commercial transactions covered by Act 709. JPDP notes exclusions for Federal and State Governments; not all processing is covered.
What does the law and official guidance say?
Section 30: data access request
Act 709 provides for data access requests under specified procedures. Conditions and grounds of refusal exist; not every record must necessarily be disclosed.
Section 34: correcting inaccurate data
Section 34 provides a correction-request route for personal data that is inaccurate, incomplete, misleading or not current, subject to the Act.
Section 12B: data breach notification
JPDP guidance explains statutory obligations on data controllers to notify the Commissioner and affected data subjects in qualifying breaches. This is a controller obligation, not a guarantee of cash compensation for every incident.
Practical first steps
Identify the organisation and relevant data
Note the organisation, data-use purpose, dates and disputed inaccuracies. Never submit passwords or full security details through unofficial channels.
Make a clear written request
Specify access or correction, provide relevant supporting evidence and retain correspondence. Use the organisation's official privacy channel.
Use JPDP's complaint channel if needed
If you believe processing breaches Act 709, JPDP explains the right to lodge a complaint with the Commissioner. Review enforcement scope and complaint requirements.
Important limitations
The Act does not apply to every party or situation
Its principal scope concerns commercial transactions. JPDP states Federal and State Government exclusions. Do not assume identical rights for every government-held dataset.
Access rights do not guarantee damages
JPDP states the Act does not specifically provide a right to claim damages. Other causes of action would require separate legal analysis.
Official evidence and references
Each source supports particular statements above. Some dated reprints are older versions, not evidence of every current amendment.
- JPDP · Akta Perlindungan Data Peribadi 2010 (naskhah 2022)
Act 709 sections 30 and 34; earlier text, check A1727 amendments
Open original source ↗ - JPDP · Soalan Lazim Perlindungan Data Peribadi
Data subject rights, scope/exclusions and complaint routes
Open original source ↗ - JPDP · Garis Panduan Pemberitahuan Pelanggaran Data (2025)
Guidance implementing section 12B and breach notification duties
Open original source ↗