Guide
PDPA 2010 for hoteliers
A hotel collects more personal data before a guest reaches their room than most businesses collect all year. Malaysia's regime was amended in 2024 and phased in across 2025. The duty hoteliers miss most often is older than that amendment — and the one that bites hardest is about proving what happened.
Last reviewed 27 August 2026. Statutory positions here reflect published guidance as at August 2026. Malaysian guidance in these areas has been revised more than once, so confirm anything you are about to act on against the current guidance of the agency that administers it — Royal Malaysian Customs for tourism tax and service tax, LHDN for e-invoicing, the Personal Data Protection Commissioner for personal data — or with your tax agent. Check the agency’s own index page rather than a search result, which can return a superseded file under the current version’s title. This is general information about the rules KAI implements, not tax or legal advice for your property.
Which law applies, and what is it called?
Malaysia’s data protection regime is the Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727). Act A1727 was brought into force in three stages by P.U.(B) 522: 1 January 2025, 1 April 2025 and 1 June 2025.
The staging matters, because different duties started on different days. The change from “data user” to “data controller” and the direct security obligations on data processors took effect on 1 April 2025. The data breach notification duty and the data protection officer duty took effect on 1 June 2025.
Act 709 applies to personal data processed in respect of commercial transactions.
The name is worth getting right, because the wrong one is everywhere. Act A1727 is an amending act — it changes the 2010 Act rather than replacing it. There is no principal “PDPA 2024”. If a document you have been given cites one, that document has not been checked, which is a reasonable signal about the rest of it.
What counts as guest data in a hotel?
Most properties, asked to list the personal data they hold, name the check-in fields and stop. The actual set is wider:
- Identity — name, passport or IC number, nationality, date of birth, address
- Contact — phone, email, and whatever was typed into a booking note
- Financial — payment card details, folio and billing records
- Behavioural — stay history, room and service preferences, loyalty records
- Environmental — CCTV footage, door-access logs, in-room service records
- Compliance-derived — the nationality and identification data captured to classify a guest for Tourism Tax
That last line catches people out. Data collected to satisfy one statutory obligation is still personal data governed by another.
Does a hotel have to register under the PDPA?
This is the obligation hoteliers miss most often, and it is older than the amendment. Act 709 requires prescribed classes of data controller to register with the Commissioner. The classes are set by the Personal Data Protection (Class of Data Users) Order 2013 [P.U.(A) 336], and class 5 is “Tourism and hospitalities”. Limb (b) reads:
“A person who carries on or operates a registered tourist accommodation premises under the Tourism Industry Act 1992.”
Personal Data Protection (Class of Data Users) Order 2013 [P.U.(A) 336], class 5, limb (b)
That names accommodation operators directly, in subsidiary legislation. The test turns on whether the premises you operate are registered as tourist accommodation under the Tourism Industry Act 1992. The limb bites on that registration, so establish whether your property holds it rather than assuming it either way.
Processing personal data without registration is an offence carrying a fine up to RM500,000 or up to three years’ imprisonment. That is double the exposure attached to failing to notify a breach, which is the duty most properties think of first when they hear “PDPA compliance”.
Act A1727 renamed the register: it is now the Register of Data Controllers. The Commissioner has also issued Circular No. 1/2026 on the registration of data controllers. This page does not set out the registration procedure — check the Department’s current circular, or your counsel, before assuming your property is on the register.
How do you satisfy the PDPA and seven-year tax retention at once?
This is the genuine conflict in a hotel back office, and the one most often resolved badly. It is also three obligations rather than two, because the tax side runs on two clocks that do not start together.
| Obligation | What it requires | What it points to |
|---|---|---|
| PDPA 2010 | Personal data must not be kept longer than necessary for its purpose. | Delete guest-identifying records once processed. |
| Service tax and tourism tax records | Seven years from the latest date to which the record relates, in Malay or English, and kept in Malaysia unless the Director General of Customs approves otherwise. | Keep the figures, and keep them in Malaysia unless you hold that approval. |
| Income tax records | Seven years, but running from the end of the year of assessment. | Keep the figures past the point the Customs clock alone would suggest. |
Service tax and tourism tax records must be kept for seven years from the latest date to which the record relates, in Malay or English, and kept in Malaysia unless the Director General of Customs approves otherwise (Service Tax Act 2018 section 24; Tourism Tax Act 2017 section 17). Income tax records must be kept for seven years under section 82A of the Income Tax Act 1967, but that period runs from the end of the year of assessment, so the two clocks do not expire together.
Read as a choice, one obligation always loses. Read properly, they are not in conflict at all — they apply to different data. Tax law wants the figures. It does not want the guest’s passport number.
So the resolution is separation: purge raw guest-identifying source documents on a short cycle once they have been processed, and retain an anonymised financial record — revenue, Service Tax, Tourism Tax — until the later of the two tax clocks has run. The auditor gets everything they can ask for; the personal data is gone long before.
What did the 2024 amendment change for hotels?
Act A1727 made several changes. The four that reach a hotel’s day-to-day operation:
- Breach notification — a duty to notify the Personal Data Protection Commissioner of a data breach, and to notify affected individuals where the breach is likely to cause them significant harm.
- Data protection officer — a duty on the data controller to appoint one and to notify the Commissioner of the appointment. A data processor acting on the controller's behalf appoints its own officer, but the notification duty is the controller's alone.
- Data processor obligations — parties processing data on your behalf carry direct security obligations, rather than the duty resting entirely with the hotel.
- Terminology — 'data user' became 'data controller' on 1 April 2025. A document still using the old term either predates the amendment or has not been revised for it.
This page numbers a provision only where the number is doing work in the sentence it sits in, and otherwise names the duty. The provisions are confirmed, not pending counsel — but a section number quoted in a summary invites reliance on the summary instead of the Act. Read the provision you are about to act on in Act 709 itself, or with counsel.
Does a hotel need a data protection officer?
A data controller must appoint one or more data protection officers, and a data processor acting on its behalf must appoint its own. The duty to notify the Commissioner of the appointment falls on the data controller only.
The Commissioner’s Guideline on the Appointment of a Data Protection Officer (Version 1.0, 25 February 2025) sets the threshold: personal data of more than 20,000 data subjects; or sensitive personal data, including financial information, of more than 10,000 data subjects; or activities requiring regular and systematic monitoring of personal data. A hotel of any operating history will pass the 20,000 threshold.
The appointed officer must be registered with the Commissioner within 21 days of appointment, and the registration updated within 14 days if the officer changes. The officer must be resident in Malaysia, or easily contactable, and proficient in Bahasa Melayu and English.
The same thresholds carry a second duty that is easy to miss. The Commissioner’s guideline on data protection impact assessments, issued in 2026, makes a DPIA mandatory at those same thresholds — so a property that needs a DPO also needs a DPIA. Guidelines on cross-border personal data transfer (29 April 2025), data protection by design, and automated decision-making and profiling have also been issued. This page does not summarise them, and does not claim to list them all.
What must a hotel do after a data breach?
The Act requires notification to the Commissioner whenever the controller has reason to believe a breach has occurred, with no harm threshold. The “significant harm” test appears in the Act only for notifying the individual.
The Commissioner’s Guideline narrows the Commissioner-notification duty to breaches causing or likely to cause significant harm; a guideline cannot cut down a statutory duty, so notify the Commissioner on the statutory test.
The offence — a fine up to RM250,000 or two years’ imprisonment or both — attaches to failing to notify the Commissioner. There is no penalty in the Act for failing to notify the individual, and none attached to the DPO duty.
How fast must you report a breach?
The Act sets no fixed period: it requires notification to the Commissioner “as soon as practicable” and to affected individuals “without unnecessary delay”.
The 72-hour figure comes from the Commissioner’s Data Breach Notification Guideline (Version 1.0, 25 February 2025), which also gives seven days to notify affected data subjects after the Commissioner has been notified.
The Guideline is inconsistent about when the 72 hours starts — paragraph 6.1 runs it from the breach itself, while its worked examples run it from the moment the controller is informed of or detects the incident. Work to the earlier of the two and notify as soon as you can substantiate a breach.
Why breach notification is really an access-trail problem
A notification duty sounds like a communications requirement. In practice it is an evidence requirement, and it is where most properties would fail.
To notify credibly you have to answer: what data was involved, whose, who accessed it, when, and how you know. A hotel whose systems record logins but not record-level access can describe a breach only in the vaguest terms — which is both a poor notification and, to a regulator, an admission about the controls that preceded it.
A clock that may start at the breach itself makes this sharper. You cannot begin counting from an event you never detected, and you cannot substantiate one you cannot reconstruct. The obligation therefore starts long before any incident. It starts with keeping an access trail good enough to reconstruct what happened.
Where KAI fits
KAI is built so the long-lived record contains no guest personal data at all. The seven-year statutory vault holds anonymised tax metadata — revenue, Service Tax, Tourism Tax figures. Guest names, passport numbers and IC numbers are never written to it. Raw uploaded reports are processed and then purged on a short retention cycle.
Access to compliance records is logged, so the question a breach notification asks — who touched what, and when — has an answer that does not depend on anyone’s recollection. Read how KAI handles data.
Common questions
- What data protection law applies to hotels in Malaysia?
- The Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727). Act A1727 was brought into force in three stages by P.U.(B) 522: 1 January 2025, 1 April 2025 and 1 June 2025. The change from 'data user' to 'data controller' and the direct security obligations on data processors took effect on 1 April 2025. The data breach notification duty and the data protection officer duty took effect on 1 June 2025. Act 709 applies to personal data processed in respect of commercial transactions. Note the name: Act A1727 amends the 2010 Act — there is no separate 'PDPA 2024' principal act, despite the phrase appearing widely.
- What guest data does a hotel hold under the PDPA?
- More than most operators list when asked. Name, passport or IC number, nationality, address, phone, email and payment details are the obvious set. Less obvious, and equally in scope: stay history, room preferences, folio detail, loyalty records, CCTV footage, and anything written into a booking note. Guest data captured for Tourism Tax classification is personal data like any other.
- Does a hotel have to register under the PDPA?
- If your property is a registered tourist accommodation premises under the Tourism Industry Act 1992, yes — and this is the obligation hoteliers miss most often. Act 709 requires prescribed classes of data controller to register with the Commissioner, and the classes are set by the Personal Data Protection (Class of Data Users) Order 2013 [P.U.(A) 336]. Class 5, 'Tourism and hospitalities', limb (b) covers 'a person who carries on or operates a registered tourist accommodation premises under the Tourism Industry Act 1992' — accommodation operators named directly in subsidiary legislation. That limb bites on the registration, so establish whether your premises hold it rather than assuming either way. Processing personal data without registration is an offence carrying a fine up to RM500,000 or up to three years' imprisonment: double the exposure attached to failing to notify a breach. Act A1727 renamed the register the Register of Data Controllers.
- How long can a hotel keep guest records?
- The PDPA principle is that personal data must not be kept longer than necessary for the purpose it was collected for. That collides with tax record-keeping, and the tax side is two clocks rather than one. Service tax and tourism tax records must be kept for seven years from the latest date to which the record relates, in Malay or English, and kept in Malaysia unless the Director General of Customs approves otherwise (Service Tax Act 2018 section 24; Tourism Tax Act 2017 section 17). Income tax records must be kept for seven years under section 82A of the Income Tax Act 1967, but that period runs from the end of the year of assessment, so the two clocks do not expire together. The resolution is not to pick one: separate the two. Raw guest-identifying documents can be purged on a short cycle once processed, while the anonymised financial figures that tax law actually needs are kept until the later of the two clocks has run, with no personal data in them.
- Does a hotel need a data protection officer?
- A data controller must appoint one or more data protection officers, and a data processor acting on its behalf must appoint its own. The duty to notify the Commissioner of the appointment falls on the data controller only. The Commissioner's Guideline on the Appointment of a Data Protection Officer (Version 1.0, 25 February 2025) sets the threshold: personal data of more than 20,000 data subjects; or sensitive personal data, including financial information, of more than 10,000 data subjects; or activities requiring regular and systematic monitoring of personal data. A hotel of any operating history will pass the 20,000 threshold. The appointed officer must be registered with the Commissioner within 21 days of appointment, and the registration updated within 14 days if the officer changes. The officer must be resident in Malaysia, or easily contactable, and proficient in Bahasa Melayu and English. The same thresholds carry a second duty: the Commissioner's guideline on data protection impact assessments, issued in 2026, makes a DPIA mandatory at those thresholds, so a property that needs a DPO also needs a DPIA.
- What happens if a hotel has a data breach?
- The Act requires notification to the Commissioner whenever the controller has reason to believe a breach has occurred, with no harm threshold. The 'significant harm' test appears in the Act only for notifying the individual. The Commissioner's Guideline narrows the Commissioner-notification duty to breaches causing or likely to cause significant harm; a guideline cannot cut down a statutory duty, so notify the Commissioner on the statutory test. The offence — a fine up to RM250,000 or two years' imprisonment or both — attaches to failing to notify the Commissioner. There is no penalty in the Act for failing to notify the individual, and none attached to the DPO duty. The practical requirement behind all of it is an access trail: being able to show who touched which records and when.
- How fast must a hotel report a data breach in Malaysia?
- The Act sets no fixed period: it requires notification to the Commissioner 'as soon as practicable' and to affected individuals 'without unnecessary delay'. The 72-hour figure comes from the Commissioner's Data Breach Notification Guideline (Version 1.0, 25 February 2025), which also gives seven days to notify affected data subjects after the Commissioner has been notified. The Guideline is inconsistent about when the 72 hours starts — paragraph 6.1 runs it from the breach itself, while its worked examples run it from the moment the controller is informed of or detects the incident. Work to the earlier of the two and notify as soon as you can substantiate a breach.
- Does KAI store guest names or passport numbers?
- Not in its statutory vault. The seven-year vault holds anonymised tax metadata only — revenue, Service Tax and Tourism Tax figures. Guest names, passport numbers and IC numbers are never written to it. Raw uploaded reports are processed and then purged on a short retention cycle, so the long-lived record contains the figures an auditor needs and none of the personal data they do not.