PUTRAJAYA: Guidelines on data breach notification as well as for data protection officers are among seven to be developed under the Personal Data Protection Act 2010 (Act 709), said Digital Minister Gobind Singh Deo (pic).
He said the guidelines would be drawn up by the Personal Data Protection Department (JPDP) through the Personal Data Protection Commissioner (PDP) and Futurise Sdn Bhd, a company under the Finance Ministry.
“It is to set the minimum requirements and practical steps in managing and protecting personal data under the control of any individual or organisation that processes personal data in the country,” he said in his speech at the signing of a memorandum of understanding (MOU) between JPDP and Futurise Sdn Bhd yesterday.
The other five guidelines are on data portability, cross-border data transfer, data protection impact assessment, privacy by design, profiling and automated decision-making guidelines.
Gobind said Futurise Sdn Bhd was seen as having the ability and skills to assist the PDP Commissioner in producing comprehensive standards and guidelines and improving the Personal Data Protection Standard that was developed in 2015, Bernama reported.
The minister added that rapid economic development and the latest technological innovation have caused an increase in the processing of personal data, in addition to creating a risk of personal data leakage that needs to be controlled.
Gobind said the appointment of a data protection officer and the existence of a personal data breach notification are internationally accepted practices.
“It is important that we create a robust framework to protect people’s personal data.
“This MOU is a crucial effort to support the country’s digitalisation initiative,” he said.
Gobind said the Act, which has been under review since 2018, was expected to be tabled at the Dewan Rakyat sitting this year, with the draft amendment to the Bill now being finalised by the Attorney-General’s Chambers.
“The amendments to Act 709 will focus on present needs, which is why the guidelines will be developed,” he said.
Act 709 is an act to regulate the processing of personal data in commercial transactions and to provide for matters connected therewith and incidental thereto. — Bernama