Malaysia PDPA 2010
Sensitive Data and Children - Malaysia PDPA

Malaysia PDPA 2010 MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent: Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent

Process sensitive personal data and children data only under Section 40 explicit consent or narrow exceptions. Sensitive categories include physical or mental health condition + political opinion + religious or other beliefs + commission or alleged commission of any offence + sexual orientation (added 2024 Amendment) + biometric data (added 2024 Amendment) + financial data (PDPC guidance). Processing prohibited unless explicit consent + necessary for legal claim + vital interests + manifestly made public by data subject + employment law obligation + medical purposes by health professional + insurance underwriting. Children below 18 require parental or guardian explicit consent (post 2024 Amendment alignment with EU GDPR Article 8). Marketing to children restricted. Special protections for biometric authentication + facial recognition processing under CSM Guidelines. Public Consultation 3/2024 on Sensitive Data + Children Processing.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 90 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27043 · 4 controls

ISO/SAE 21434 · 4 controls

  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response

MARS-E · 3 controls

  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

ISO 13485 · 2 controls

ISO 27799 · 2 controls

OWASP ASVS · 2 controls

OWASP MASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data

Bahrain PDPL · 1 control

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

ISO 19011 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/IEC 27400:2022 · 1 control

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

South Korea ISMS-P · 1 control

Turkey KVKK · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 90 it maps to, and the evidence behind each claim, over MCP and REST.