Day 1: PDPA Foundations & Compliance
Session 1: Introduction to PDPA Malaysia
Overview of the Personal Data Protection Act 2010. Key definitions: personal data, sensitive personal data, data subject, data processor. Scope of application and exemptions. Penalties and enforcement under PDPA.
Session 2: Data Protection Principles
The seven principles of PDPA: General, Notice & Choice, Disclosure, Security, Retention, Data Integrity, and Access. Practical obligations for each principle. Case studies on common PDPA violations in Malaysia.
Session 3: Role of the Data Protection Officer
Responsibilities and authority of a DPO. When to appoint a DPO. Internal governance and reporting structures. Liaising with regulators and data subjects.
Session 4: Consent Management & Rights of Data Subjects
Obtaining, recording, and managing valid consent. Handling access requests and correction requests. Withdrawal of consent and data erasure. Practical templates and forms.
Day 2: Data Governance & Incident Management
Session 1: Data Inventory & Risk Assessment
Mapping personal data flows within your organisation. Conducting a Data Protection Impact Assessment (DPIA). Identifying and classifying data risks. Third-party vendor due diligence.
Session 2: Security Measures & Data Transfers
Technical and organisational security controls. Encryption, access control, and data minimisation. Cross-border data transfers: obligations and safeguards under PDPA.
Session 3: Data Breach Response
Identifying and classifying a data breach. Breach notification obligations. Building an incident response plan. Post-breach remediation and documentation.
Session 4: CDPO Assessment & Practical Workshop
Review of key PDPA concepts. Group exercise: drafting a Data Protection Policy. Written assessment for CDPO certification. Q&A with the trainer.
What's Included
- ✓ CDPO Digital Badge & Certificate
- ✓ Digital Course Handbook
- ✓ Policy & Consent Templates
- ✓ Post-training email support (30 days)
- ✓ HRD Corp Claimable