3.4 Personal Data Protection in Insurance

Key Takeaways

  • PDPA requires lawful processing and observance of its seven principles.

  • Medical information is sensitive personal data; ordinary underwriting uses explicit consent.

  • The 2024 amendments commenced in stages during 2025.

Last updated: October 2026

Study Focus

PDPA requires lawful processing and observance of its seven principles. Medical information is sensitive personal data; ordinary underwriting uses explicit consent.

Data Privacy (PDPA) and AML/CFT Compliance


1. The Personal Data Protection Act 2010 (PDPA)

In Malaysia, the processing of personal data in commercial transactions is governed by the Personal Data Protection Act 2010 (PDPA), which came into force on 15 November 2013. The Act is administered by the Personal Data Protection Department (JPDP) under the Ministry of Digital.

The Personal Data Protection (Amendment) Act 2024 (Royal Assent 9 October 2024) came into force in three phases during 2025:

  • 1 April 2025: the term "data user" was replaced by "data controller"; biometric data became sensitive personal data; data processors became directly bound by the Security Principle; the whitelist for cross-border transfers was removed; and the maximum penalty for breaching the Personal Data Protection Principles rose to a fine of RM1 million and/or three years' imprisonment (previously RM300,000 and two years).
  • 1 June 2025: data controllers must appoint a Data Protection Officer where required, must notify reportable breaches to the Commissioner under the Act and notification guidelines; significant harm also triggers notification to affected individuals, and individuals gained a right of data portability.

In the insurance industry, vast quantities of sensitive financial, employment, and medical records are collected during underwriting, policy servicing, and claims assessment. Under the PDPA, both insurance companies and individual insurance agents act as data controllers (called "data users" before the 2025 amendments) when they process personal data relating to prospective or existing policyholders (Data Subjects).

Statutory Definitions under the PDPA

  • Data Controller (formerly "Data User"): A person who processes personal data, or has control over or authorizes its processing, in commercial transactions. Insurance companies, corporate agency firms, and individual agents all fall within this definition. A data processor processes data only on a data controller's behalf, such as an outsourced IT vendor.
  • Data Subject: The individual who is the subject of the personal data (e.g., the applicant, policyholder, life insured, named beneficiary, or claimant).
  • Personal Data: Any information in respect of commercial transactions that relates directly or indirectly to a data subject, who is identified or identifiable from that information (e.g., full name, National Registration Identity Card / MyKad number, passport details, residential address, telephone number, email, banking information, occupation, and financial standing).
  • Sensitive Personal Data: A specialized category of personal data encompassing physical or mental health or condition, medical history, religious beliefs, political opinions, the commission or alleged commission of any offense, and (since the 2024 amendments) biometric data. The processing of sensitive personal data is strictly prohibited unless explicit consent is obtained or specific statutory exemptions apply.

2. The Seven Data Protection Principles of the PDPA

The core of the PDPA comprises seven statutory principles that every insurance company and agent must observe:

PrincipleStatutory RequirementApplication to Insurance Agents
1. General PrincipleData processing ordinarily requires consent or an applicable statutory basis; processing must be for a lawful purpose directly related to an activity of the data controller.Establish the lawful basis, give the required notice and collect only relevant information. Ordinary medical underwriting uses explicit consent; statutory exceptions require actual justification.
2. Notice and Choice PrincipleData subjects must be given written notice informing them of the purposes of collection, data classes, access rights, and third-party disclosures.Standardized PDPA notices (in both Bahasa Malaysia and English) must be delivered to prospects before collecting application details.
3. Disclosure PrincipleDisclosure is restricted to the notified purpose and recipient classes unless consent or a statutory exception permits otherwise.An agent cannot disclose client details to third-party telemarketers, credit card issuers, or unaffiliated agencies without explicit client authorization.
4. Security PrinciplePractical technical and organizational safeguards must protect data against loss, misuse, modification, unauthorized access, or accidental disclosure.Physical proposal forms must be stored in locked cabinets; digital customer records, laptops, and tablets must have password protection and encryption.
5. Retention PrinciplePersonal data must not be kept longer than necessary for the fulfillment of its commercial or statutory purpose.Apply the retention schedule and legal holds. Policy termination does not itself authorise immediate destruction of claims, accounting or compliance records still required by law.
6. Data Integrity PrincipleReasonable steps must be taken to ensure personal data is accurate, complete, not misleading, and kept up-to-date.Agents must verify that client contact details, beneficiary updates, and financial declarations are recorded accurately and updated promptly with the insurer.
7. Access PrincipleData subjects have the statutory right to request access to their personal data and correct any inaccuracies upon written request.Clients are legally entitled to request copies of their policy files and amend outdated contact, banking, or beneficiary information.

Practical Compliance for Insurance Agents

  1. Prospecting and Direct Marketing: Establish that the source and intended use of a contact list are lawful. Give required notices, respect consent requirements and stop direct marketing when a valid objection is received. A public telephone number is not permission to sell medical or policy information.
  2. Proposal Stage: When completing life insurance applications, agents must obtain the applicant's explicit written signature authorizing the collection of medical records, consultation with attending physicians, and data sharing with reinsurers or Bank Negara Malaysia.
  3. Prohibition of Data Trading: Transferring, selling, or exchanging client databases between agents or agencies without explicit consent is a criminal offense under Section 130 of the PDPA, carrying fines up to RM 500,000, imprisonment for up to 3 years, or both.

Test Your Knowledge

For ordinary medical underwriting where no statutory exception applies, how does the PDPA classify health information and what consent is required?

A

It is classified as standard personal data and requires only implied verbal consent during the sales interview

B

It is classified as open public data and may be shared with any financial institution without restriction

C

It is classified as sensitive personal data and requires explicit consent from the data subject prior to processing

D

It is classified as proprietary insurer data and is entirely exempt from all PDPA statutory principles

Source checked 9 October 2026: JPDP amendment and commencement resources.

Sections you finish are checked off in the contents.