Hakobi

PDPA 2024 and Where Your Data Actually Lives: On-Prem vs Google Drive/OneDrive

Last updated: 31 August 2026

Malaysia's Personal Data Protection (Amendment) Act 2024 raised the stakes on data handling significantly — and one question it forces every business to actually answer is where their data lives, who can access it, and whether that can be proven after the fact.

What changed under the 2024 amendment

The amendment introduced a mandatory Data Protection Officer appointment for many organizations, a strict requirement to notify Malaysia's Personal Data Protection Commissioner within 72 hours of becoming aware of a breach, direct legal obligations on data processors (not just data controllers) around securing personal data, and a significant jump in penalties — up to RM1 million and three years' imprisonment, up from RM300,000 and two years previously. Confirm your specific obligations with the PDPA authority or counsel rather than treating this as a compliance guarantee — this is a summary, not legal advice.

Why storage location and access control matter here

A 72-hour breach notification requirement only works if you actually know what happened — what was accessed, by whom, and when. That's an access-log and audit-trail requirement as much as it's a security one, and it's exactly where general-purpose consumer cloud storage tends to fall short for business use.

Google Drive / OneDrive: convenient, not built for this

Both are genuinely good products for what they're designed for — everyday file sharing and collaboration. What they're not built for, particularly on lower-tier business plans, is granular administrative visibility into exactly who accessed what and when, or a tested, versioned offline backup independent of the platform itself. If Google or Microsoft has an outage or your account is compromised, your only copy of the data may be exactly as unavailable as the platform is.

On-premises storage: full control, documented access

A Synology NAS on your own premises, backed up on a schedule with Veeam or Synology's own tools, puts you in direct control of where data physically sits, who has access to it, and how quickly you can restore it — with a restore process you've actually tested rather than assumed. For any business handling client financial, legal or personal records, that combination of control and provable process is a meaningfully stronger PDPA compliance position.

A real example

We migrated a Sabah accounting and advisory firm off roughly 1TB of Google Drive storage onto an on-premises Synology NAS, with proper access control set up for around 30 users. Beyond the compliance angle, the move cut their recurring cloud subscription cost to zero and let staff keep working during internet outages, since their files no longer depended on a live connection to reach them.

This isn't all-or-nothing

Most businesses land somewhere hybrid — cloud tools for day-to-day collaboration, on-premises storage and backup for anything that needs a defensible access trail and a tested recovery path. The right split depends on what you're actually storing.

Source: Personal Data Protection (Amendment) Act 2024, Department of Personal Data Protection, Malaysia.

Related services

Ready to talk to an engineer?

Tell us about your site, your network, or your compliance deadline. We'll respond within one business hour.