Malaysia's Jabatan Perlindungan Data Peribadi, the Department of Personal Data Protection, released Kertas Konsultasi Awam Bil. 1/2026, the Public Consultation Paper on the Artificial Intelligence (AI) and Personal Data Protection Framework, on 5 October 2026. The paper is at the public consultation stage and attaches a draft text at Version 1.0 in Lampiran 1, set out in ten parts lettered A to J that track the AI lifecycle. Written feedback closes on 23 October 2026.
The Commissioner issues the draft under subsection 48(g) of the Personal Data Protection Act 2010, Act 709. The draft applies duties that already sit in Act 709 to AI processing rather than creating new statutory obligations, working through the Notice and Choice Principle in section 7, the data breach notification duty in section 12B, the cross-border transfer rule in section 129, and the Security and Data Integrity Principles. The draft states that deploying an AI system does not itself supply a legal basis for processing personal data, so a controller must identify one under Act 709 and obtain consent where the Act requires it, with explicit consent for sensitive personal data unless an exception applies.
The draft reaches data controllers, and the processors and third parties acting for them, that obtain, develop, customise, deploy or operate AI systems processing personal data. Coverage runs to in-house builds, off-the-shelf products and embedded AI, including software-as-a-service and API offerings and general-purpose models placed inside applications. Notices would have to disclose AI use and whether the system makes or supports a decision. A controller buying AI from a vendor would owe due diligence, contractual allocation of processor and third-party roles, cross-border transfer assessment and continuing vendor oversight, and appointing a provider would not move the controller's own duties. Rights of access, correction, withdrawal of consent and data portability apply to AI processing, and controllers would need usable channels for them. Governance expectations cover risk assessment, a data protection impact assessment where appropriate, explainability, record keeping, internal review and audit, and involvement of a data protection officer where one is appointed.
Feedback closes on 23 October 2026 and is taken through the Unified Public Consultation platform or the paper's online form, with enquiries directed to risiko@pdp.gov.my. The paper asks respondents whether its scope, definitions, exemptions and use cases are complete, whether the governance and risk requirements are practical and proportionate, what enforcement constraints organisations would face, and whether transition periods, further guidance or a sandbox are needed. The circulated text is Version 1.0 and the Commissioner has not set a date from which a final version would apply.
Licentium advises controllers and AI vendors on the data protection duties that attach to AI systems across Asian and European regimes, and can prepare a submission before the 23 October 2026 close. Work we undertake includes AI and personal data gap assessments against Act 709, data protection impact assessments, vendor and processor contract review, cross-border transfer analysis, automated decision disclosure drafting, and consultation response preparation.