KUALA LUMPUR, 4 AUG 2026 — Malaysia has told organisations that an automated system should not be the only thing deciding something significant about a person, that people should be able to refuse such a decision, and that a formal assessment should be completed before high-risk processing goes live. It has done all of it without passing an AI law, and the documents saying so are not binding.

On 30 April the Personal Data Protection Commissioner issued three guidelines: one on data protection impact assessments, one on data protection by design, and one on automated decision-making and profiling. They follow public consultations run through 2025. They are, in legal terms, recommended best practice.

That combination of substantive expectations in a non-binding instrument is becoming the region's default way of regulating AI. In July we reported on privacy statutes in three US states reaching into AI training. Malaysia has reached the same territory from the same direction, and stopped one step short of law.

What the automated-decision guideline asks for

The ADMP guideline confers what it describes as rights on data subjects. A person should be able to refuse a decision based solely on automated processing where that decision produces legal effects or otherwise significantly affects them. They should be told that automated decision-making is being carried out at all. The disclosure is also expected to be specific, covering the processes involved, the types of decision being made, the justification, the consequences, and the scope of AI use.

Alongside the notice duties sit operational ones. Explicit consent is expected where sensitive personal data is processed through automated decision-making. Security measures named include encryption, anonymisation and pseudonymisation. And organisations are told to adopt AI best practices, which the guideline frames as including staff training and human oversight — the practical form of the principle that a model should not be the sole factor in a decision about someone.

30 April 2026three guidelines issued: DPIA, data protection by design, automated decisions
20,000data subjects above which an impact assessment is expected
10,000subjects, where the data is sensitive financial information
RM1mmaximum penalty under the Act since 1 April 2025

The impact assessment has actual numbers in it

The DPIA guideline is the more unusual document, putting firm figures where comparable regimes rely on judgement. An assessment is expected when new processing operations are introduced, and the guideline sets both a quantitative and a qualitative trigger.

The quantitative trigger is processing involving more than 20,000 data subjects, or sensitive financial data belonging to 10,000 or more. The qualitative trigger is high risk to the protection of personal data, with processing involving children, automated decision-making, or innovative technologies such as AI named as examples.

Europe's equivalent test is almost entirely qualitative, which leaves every controller arguing about whether its processing is high-risk. A number does not settle whether an assessment was any good, but it does settle whether one was required, making its absence much harder to explain.

The process is set out as a five-step framework the guideline calls DEICA: describe, evaluate, identify, consider, assess. The data protection officer runs the assessment; senior management decides whether to accept the residual risk and what mitigation to put in place. That allocation makes acceptance of AI risk an executive act with a name attached, not something a compliance team absorbs quietly.

Computed by RECATOOLS4 August 2026
What the guideline expectsLegal status
Sole automated decisionsA person may refuse one with legal or significant effectAdvisory
DisclosureProcesses, decision types, justification, consequences, scope of AI useAdvisory
Sensitive data in automated decisionsExplicit consentAdvisory
Impact assessmentAbove 20,000 subjects, or 10,000 for sensitive financial dataAdvisory
Who signs offDPO assesses; senior management accepts residual riskAdvisory

RECATOOLS summary of the guidelines issued 30 April 2026. Every row is advisory: these are recommended best practices, not obligations created by the guidelines themselves. Underlying duties in the Personal Data Protection Act are unaffected and continue to apply.

What Malaysia did legislate

The advisory status of the AI guidance looks different next to what the regime chose to put into statute during its recent legislative round.

The Personal Data Protection (Amendment) Act 2024 received royal assent on 9 October 2024, was gazetted eight days later and came into force in three phases across the first half of 2025. From June 2025 a controller must notify the Commissioner of a personal data breach within 72 hours of becoming aware of it, and must tell affected individuals without unnecessary delay where the breach is likely to cause significant harm. Appointing a data protection officer became mandatory, with the appointment notified to the Commissioner. Data subjects gained a portability right, subject to technical feasibility and format compatibility. The maximum penalty rose to one million ringgit on 1 April 2025.

Those are obligations with deadlines, offices and numbers attached. They went through Parliament. The expectations about automated decisions — disclosure, human involvement, the right to refuse — did not, and arrived instead as guidance ten months later.

The sequencing is informative. Breach notification and DPO appointment are settled questions internationally; a legislature can copy them with confidence. What an automated decision is, and what a person may demand when one is made about them, is not settled anywhere. Malaysia has written down its answer while leaving itself room to change it, which is a defensible way to handle a moving target and a weaker guarantee for the person on the receiving end of the decision.

Why advisory is not the same as optional

It would be easy to read all this as a press release with a compliance section, and wrong. Guidance from a regulator that also decides enforcement priorities does not create an obligation, but it does describe what that regulator considers compliance to look like.

The context sharpens that. The maximum penalty under the Act rose to one million ringgit on 1 April 2025, and the Commissioner has been consulting on amendments that would widen its inspection powers and reach data processors directly. An organisation that skipped an impact assessment on a system affecting fifty thousand people, and then had a breach, would be explaining that decision to a regulator that had published a document saying an assessment was expected at twenty thousand.

That is a weaker instrument than a statute, and it is not nothing. Malaysia has set an expectation it can point to later, without yet accepting the burden of legislating it.

What this does and does not settle

A business running automated decisions on Malaysian data — credit scoring, insurance pricing, fraud screening, hiring, tenant selection — now has a practical checklist. Tell people the system exists and what it does. Give them a route to a human where the decision matters. Get explicit consent before running sensitive data through it. Assess before deployment, above stated thresholds, and have someone senior sign off on the residual risk.

What the guidelines do not do is define an automated decision, set an appeal timetable, or say what happens when a person exercises the right to refuse one. Those questions determine whether a right is usable, and they are questions for a statute, not for guidance.

Read against the region, the position is consistent with what is emerging elsewhere. Nobody in ASEAN has passed a comprehensive AI act. Several jurisdictions have found that data protection law already reaches most of what an AI act would cover, because almost every consequential automated decision is a decision about a person, and that means it is processing of personal data. Malaysia has now written down what that reach implies. Whether it becomes enforceable is a separate decision, and it has not been made.