Malaysia legislation

Section 43

of PERSONAL DATA PROTECTION ACT 2010

Section 43

(2)

Where the data subject is dissatisfied with the failure of the data user to comply with the notice, whether in whole or in part, under subsection (1), the data subject may submit an application to the Commissioner to require the data user to comply with the notice.

(3)

Where the Commissioner is satisfied that the application of the data subject under subsection (2) is justified or justified to any extent, the Commissioner may require the data user to take such steps for complying with the notice.

(4)

A data user who fails to comply with the requirement of the Commissioner under subsection (3) commits an offence and shall, on conviction, be liable to a fine not exceeding two hundred thousand ringgit or to imprisonment for a term not exceeding two years or to both.

(5)

For the purposes of this section, “direct marketing” means the communication by whatever means of any advertising or marketing material which is directed to particular individuals.

Record to be kept by data user