Malaysian payment apps collect more than an email. National registration identity card images, selfies, device data, and transaction histories pile up because a vendor or a risk rule once asked for them. The Personal Data Protection Act cares about purpose, notice, and the ability to act on a request — not about whether your privacy page uses the word ‘robust’.
In reviews we look for three practical things. First, whether the in-app notice matches what is actually stored. Second, whether a customer can see a way to ask for access or deletion that a human will receive. Third, whether KYC images outlive the decision they supported, sitting in a bucket nobody owns.
None of this replaces advice from counsel. It does give counsel something sharper than a generic questionnaire: screen names, vendor names, and retention that we observed rather than retention that was hoped for.
If you are preparing a product for a wider audience in Malaysia, fix the request path before you polish the policy PDF. A policy that cannot be carried out in the app is a finding, not a decoration.