27/02/2025
Challenges in Enforcing Data Privacy in Malaysia and Opportunities for Improvement.
Today's great initiative and thanks to the town hall organizer extending an invitation to attend to discuss Data privacy Act initiated by Jabatan Perlindungan Data Peribadi Malaysia (PPDP)
My suggestions to Honorable Digital Minister Gobind Singh Deo
1. Almost 90% of personnel data are held by gov agencies not private entities .
Government Agency Exemptions Undermine Adoption, it's similar to requesting your son not to smoke but you smoke in front of him.
Both Korea and Japan improved their foreign direct investment (FDI) by strengthening their data privacy regulations, which built international trust, ensured compliance with global standards, and facilitated smoother cross-border data transfers.
Results & FDI Growth
Japan
Achieved a record FDI inflow of $31 billion in 2022, with strong investments in IT, e-commerce, and digital health.
South Korea
FDI reached $30.5 billion in 2022, particularly in semiconductors, AI, and cloud computing sectors, fueled by trust in strong data governance.
By enforcing strong data privacy laws, Korea and Japan successfully increased FDI, particularly in technology and digital services, by providing a secure, compliant, and globally trusted investment environment.
Exempting government agencies from compliance creates an uneven regulatory landscape, discouraging private sector adherence. If government agencies are required to comply, it will build investor confidence, particularly among foreign investors seeking a strong and transparent data protection framework.
2.Minimal USD 120K Penalties to global companies for data breach is a piece of cake they earn in USD Billions ,global companies need to be penalized at a higher rate.
3.Independence of Data Protection Officers (DPOs)
DPOs should operate independently, reporting directly to the CEO and Board rather than being placed under HR, Legal, or IT departments to ensure impartiality and effectiveness.
4.Autonomy of the Data Protection Authority.
The department responsible for enforcing data privacy laws must function independently to avoid conflicts of interest and regulatory capture.
5.Strong Regulatory Enforcement is Essential.
Without an efficient and proactive enforcement agency, data privacy regulations risk becoming ineffective and irrelevant with all new laws enacted .
While on this we provide continuous blended and for gov agencies and corporate companies to be continuously comply and on alert at all times , give us a shout if you need further details .
What's your take on this ?