Data Governance, PDPA & Information Risk Management
Your organisation collects, stores, and shares personal data every day — but most staff don't know what PDPA requires of them, what constitutes a notifiable breach, or what their personal and organisational liability is when data is mishandled.
Participants develop a working understanding of Malaysia's Personal Data Protection Act 2010 and practical data governance principles — covering data collection, consent, retention, transfer, and breach response. Organisations reduce personal data risk, build data handling discipline, and meet the compliance obligations that PDPA imposes on every data processor and controller.
Key Outcomes
Apply the seven principles of PDPA 2010 to your organisation's personal data processing activities
Obtain, document, and manage valid consent for data collection and processing in compliance with PDPA
Respond correctly to a data breach — identification, containment, notification, and remediation
Design a personal data audit and a data retention schedule aligned to PDPA requirements
What Makes it Different
Data Audit Workshop: participants map their organisation's personal data flows and identify PDPA compliance gaps
Breach Response Simulation: participants manage a realistic personal data incident from discovery to notification
PDPA Compliance Toolkit: consent templates, a data retention schedule, and a breach response checklist
Data audit and compliance scenarios can be tailored to your organisation's specific data environment — customer records, employee data, healthcare information, financial data, or cross-border data transfers.
A statutory compliance requirement for all PDPA-regulated commercial entities — delivered to HR, marketing, IT, operations, and legal teams across financial services, healthcare, retail, and technology organisations.