PDPA for clinics, after the 2024 amendment
The Personal Data Protection Act 2010 treats a clinic as a data controller of some of the most sensitive personal data there is, and the 2024 amendment — in force from 1 April 2025 — removed the old whitelist route for transferring data abroad, replacing it with an adequacy test.
What changed in 2025
The whitelist mechanism was removed. In its place is a test of whether the destination provides protection substantially similar to the Act, or whether specified conditions are met. In practice this means a clinic using a cloud system needs to know where its patient data physically sits and on what basis it is allowed to be there.
Why on-premises removes most of the question
If patient data never leaves the clinic, there is no cross-border transfer to justify. Klinira's backups are encrypted at the clinic before they leave, and the owner's remote view carries only aggregate counts and totals — never names, diagnoses or clinical detail.
What a clinic still has to do
- Issue a patient privacy notice, in Bahasa Malaysia and English
- Limit staff access to what each role needs
- Be able to answer a patient's access request
- Keep security measures proportionate to the sensitivity of the data
- Know where every copy of the data is, including backups
Watch it survive an outage
Leave your details and we will show you the clinic running with the network cable pulled out — registering patients, writing notes, printing labels.