Note

PDPA duties that show up inside a payment app

Consent banners are easy to screenshot. Retention of IC images and the path to withdraw consent are harder — and that is where we spend time.

Laptop with a padlock symbol suggesting data protection

Malaysian payment apps collect more than an email. National registration identity card images, selfies, device data, and transaction histories pile up because a vendor or a risk rule once asked for them. The Personal Data Protection Act cares about purpose, notice, and the ability to act on a request — not about whether your privacy page uses the word ‘robust’.

In reviews we look for three practical things. First, whether the in-app notice matches what is actually stored. Second, whether a customer can see a way to ask for access or deletion that a human will receive. Third, whether KYC images outlive the decision they supported, sitting in a bucket nobody owns.

None of this replaces advice from counsel. It does give counsel something sharper than a generic questionnaire: screen names, vendor names, and retention that we observed rather than retention that was hoped for.

If you are preparing a product for a wider audience in Malaysia, fix the request path before you polish the policy PDF. A policy that cannot be carried out in the app is a finding, not a decoration.

All notes · Request a review