PDPA compliance for psychologists in Malaysia
The notes and records a psychologist or counsellor keeps are among the most sensitive personal data anyone handles. Malaysia's Personal Data Protection Act 2010, as amended, is what governs how you're expected to handle it — and the amendments have been changing the practical detail in phases since the start of 2025.
What changed, and when
The amended Personal Data Protection Act 2010 (PDPA) has been coming into force in phases starting 1 January 2025. Rather than a single cut-over date, different obligations have taken effect at different points, which makes it worth checking the current state of the rollout rather than assuming everything changed at once.
The cross-border transfer rules changed on 1 April 2025
One of the most practically significant changes: from 1 April 2025, the regime for transferring personal data outside Malaysia moved away from the old model of a fixed "whitelist" of approved countries. In its place is an adequacy and transfer-impact-assessment (TIA) approach — you assess whether the destination offers comparable protection, with standard contractual clauses or binding corporate rules available as alternative safeguards where a straightforward adequacy finding isn't available. If your practice uses any software or service that stores or processes client data outside Malaysia — including cloud-based practice management software — this is the framework that now applies to that transfer.
No general data-localisation requirement — but check your sector
There is no general requirement under the PDPA to keep personal data physically inside Malaysia. That said, sectoral regulators, including in healthcare, can impose stricter conditions on top of the general PDPA framework. If part of your practice sits within a regulated healthcare context, it's worth checking whether any sector-specific rules add requirements beyond the general PDPA position, rather than assuming the general rule is the whole picture.
Practical takeaway: hosting client data in the European Union, for example, isn't prohibited by a localisation rule — but the cross-border transfer safeguards above (adequacy, TIA, SCCs or BCRs) are what make that transfer compliant, not an afterthought.
A practical PDPA checklist for a psychology or counselling practice
- 1Lawful basis and clear client consent. Be clear, and make it clear to the client, what data you collect, why, for how long, and what rights they have — set out in writing at the start of the work.
- 2Encryption in transit and at rest. Notes and files should be encrypted both while moving between systems and while stored.
- 3Know exactly where your data is hosted, and confirm any software you use can tell you plainly, rather than vaguely, where client data sits.
- 4If data leaves Malaysia, document the transfer basis — adequacy, a transfer impact assessment, or contractual safeguards such as SCCs or BCRs.
- 5Access control. Only people who need to see a record should be able to — enforced by the system, not just by agreement.
- 6A written retention policy. Decide, and document, how long you keep records and why, rather than keeping everything indefinitely "just in case."
- 7A process for client data-access requests. A clear internal process so you can respond within a reasonable time when asked.
- 8A breach response plan. Know in advance who does what if there's a breach, and check the current PDPA notification requirements that apply to your practice.
- 9Check for sector-specific healthcare rules that may sit on top of the general PDPA position for your particular registration.
See how the compliance side works day to day
Compare how practice-management software built for psychologists handles records, encryption and hosting.
What good software takes off your plate
Software built with data protection in mind resolves much of this checklist by default — encryption, clearly documented hosting, access control and a defensible cross-border transfer position, rather than something you bolt on yourself later. Nerela hosts client data encrypted in the European Union, which is a genuine cross-border transfer under the PDPA's post-April-2025 framework — one it's built to be transparent about, so you can document the basis for it rather than guess.
Bringing it together
Since 1 January 2025 the amended PDPA has been rolling out in phases, and since 1 April 2025 cross-border data transfers run on an adequacy/TIA model rather than a fixed country whitelist, with SCCs or BCRs as an alternative safeguard. There's no general data-localisation rule, but healthcare-sector regulators can add their own conditions. None of this changes the fundamentals of good practice: know where your data lives, document your basis for any cross-border transfer, and keep access tightly controlled.
Frequently asked questions
Do I have to store client data physically inside Malaysia?+
No — there's no general data-localisation requirement under the PDPA. That said, sectoral regulators, including in healthcare, can impose stricter conditions of their own, so it's worth confirming whether any apply to your specific registration.
What changed on 1 April 2025?+
The regime for transferring personal data outside Malaysia moved from a fixed whitelist of approved countries to an adequacy and transfer-impact-assessment (TIA) approach, with standard contractual clauses or binding corporate rules available as alternative safeguards.
Who regulates the PDPA in Malaysia?+
The Department of Personal Data Protection (Jabatan Perlindungan Data Peribadi, JPDP) is the regulator responsible for the PDPA.
Is hosting client data in the European Union compliant?+
It can be, provided the transfer is handled under the current framework — an adequacy basis, a transfer impact assessment, or contractual safeguards such as SCCs or BCRs — rather than assumed to be fine by default. Confirm the specific basis with whichever software or service you use.
Data protection handled by default, not bolted on afterward
Encrypted client records hosted in the EU, with a clear, documented basis for the cross-border transfer.
14 days free, no card · No lock-in · We answer directly
Nerela is practice management software built for psychologists and counsellors: scheduling and online booking, patient records and session notes, invoicing and reports — in one place, with data hosted in the European Union. You start with 14 days free, no card, and you talk directly to the people building the product.
Start on Nerela — 14 days free →