Bank Negara Malaysia has issued a Policy Document on Management of Customer Information and Permitted Disclosures introducing new breach notification requirements for financial service providers, including reporting to the central bank and notifying affected customers where harm is significant. Financial service providers must notify Bank Negara Malaysia of a customer information breach that causes or is likely to cause significant harm to customers, or where the breach involves or is likely to involve a large number of customers, and must notify affected customers where the breach causes or is likely to cause significant harm. The requirements are aligned with amendments to the Personal Data Protection Act 2010 introducing mandatory data breach notification to the Personal Data Protection Commissioner, and the policy document includes templates for breach reporting (Appendix I) and applications for disclosure of customer information (Appendix V). The policy takes effect immediately.
Bank Negara Malaysia 2025-10-31
Bank Negara Malaysia mandates reporting and customer notification for significant customer information breaches
Bank Negara Malaysia's Policy Document on Management of Customer Information requires financial service providers to report significant breaches to the central bank and notify affected customers. This aligns with amendments to the Personal Data Protection Act 2010, mandating breach notifications to the Personal Data Protection Commissioner. The policy includes templates for reporting and disclosure applications and is effective immediately.