PDPA and AI chatbots: a checklist for Malaysian SMEs
An AI chatbot collects personal data on your behalf in every conversation. Under Malaysia’s Personal Data Protection Act, you remain responsible for it. This checklist covers what to put in place.
You are the data controller
When a customer gives their name, phone number or IC number to your chatbot, your business is the one collecting it. The 2024 amendments to the Act renamed the “data user” as the “data controller”, and the chatbot vendor processes the data on your behalf. That means the obligations below sit with you, and you need a vendor who makes them possible to meet.
1. Tell people what you collect and why
The Act requires a notice telling people what personal data you collect, the purpose, and their rights, and that notice must be in both Malay and English. For a chatbot, the practical version is a short opening line or a link to your privacy notice in both languages, shown before the customer gives personal details.
2. Record consent where you rely on it
Keep a record of what the customer was told, on which channel and when they agreed, and when they withdraw. This matters most for marketing and outbound calls. A customer who says “don’t contact me again” should be taken off every list, on every channel, and the chatbot should honour that without a staff member having to remember.
3. Collect only what you need
Decide what the chatbot actually needs for each job. Booking a viewing needs a name, number and time; it does not need an IC number. Where you do need sensitive identifiers, make sure they are masked in logs and not shown to staff who do not need them.
4. Be ready for access requests
A person can ask to see the personal data you hold about them, and the Act gives you 21 days to respond. With an AI chatbot, that data is spread across chats, call transcripts, bookings and recordings. Check that you can find everything for one person quickly, ideally because the system keeps one record per person across channels, and export it.
5. Know how long you keep things, and erase on request
- Set a retention period for call recordings and make sure they are deleted automatically after it.
- Know what happens to conversations and transcripts, and for how long.
- Have a way to erase one customer’s data when they ask, and know which records are kept on purpose (for example, financial records you must keep) and why.
6. Know where the data is stored
Ask every vendor where your customers’ data is physically stored. The 2024 amendments changed the rules on transferring personal data outside Malaysia: a transfer is allowed where the destination has laws substantially similar to the Act or an equivalent level of protection, among other grounds. If your vendor stores data abroad, understand the basis for the transfer and record it.
To be specific about our own product: Floee stores data in data centres in Singapore. Malaysian hosting is on our roadmap. We state this plainly in the privacy package every customer can print from the console.
7. Appoint someone responsible
The amendments introduced a requirement to appoint a data protection officer, which came into force on 1 June 2025. The accompanying guideline sets thresholds for which organisations must appoint one, based on the volume and kind of data processed. Even if you fall below them, name one person who owns privacy questions and publish a contact for them.
8. Plan for a breach
Since 1 June 2025, a data controller must notify the Commissioner as soon as possible after a personal data breach that causes or is likely to cause significant harm, and notify the affected people without unnecessary delay. Ask your vendor how they will tell you about a breach on their side, and how quickly.
9. Check the vendor, in writing
- Where is the data stored, and who at the vendor can see it?
- Is each customer’s data isolated from other businesses on the same platform?
- Is there an activity log of settings changes that cannot be edited?
- How do I export a customer’s data, and how do I erase it?
- How long are recordings and transcripts kept?
- Is there a data processing agreement I can sign?
- Is there a public status page, so I know when something is wrong?
Keep the evidence
Compliance is easier to show than to describe. Keep your notice text, your consent records, your erasure log and your vendor’s answers in one place. In Floee, the Compliance page produces a printable privacy package covering where data is stored, who can see it, consent records, retention, export and erasure, masking of sensitive numbers and the activity log. Our status page publishes uptime and incident history for anyone to check.
For regulated work, see how this applies to insurance and takaful and government and councils.