Skip to content
← Back to guide LawServa PDPA Register

LawServa · LawServa: Legal Practice Manual

LawServa PDPA Register

VYROX Wiki · Updated 23 September 2026 · https://www.vyrox.com/wiki/lawserva-pdpa-register

The PDPA Register in LawServa lets a Malaysian law firm keep the five records the Personal Data Protection Act 2010 and its 2024 Amendment expect it to produce on demand: data access and correction requests, consents, transfers of personal data out of Malaysia, personal data breaches, and the appointment of a Data Protection Officer. It is used by compliance officers, partners and practice managers, and each register prints as an A4 PDF on the firm's letterhead.

Before You Start

  • Open the register from Compliance > Registers > PDPA Register. The screen has five tabs: Requests, Consents, Transfers, Breaches and Officer. It opens on Requests, the register with a running clock.
  • Reading the register needs permission to view it. Adding entries, answering requests, withdrawing consents and ending appointments need permission to manage it.
  • Recording that the Commissioner or the people affected were notified is a reserved act with its own separate permission. If you do not hold it, the Record Notice button does not appear.
  • The tab you are on shows one button for adding an entry, next to Download PDF.

Five counters sit at the top of every tab: Consents in Force, Open Requests, Open Breaches, Transfers Out of Malaysia and Data Protection Officers. The officer counter also says how many current appointments have not yet been notified to the Commissioner.

Note

LawServa records what your firm did and when. It does not decide whether a request may be refused, whether a breach causes significant harm, or whether your firm must appoint an officer. Those are decisions for the responsible person in the firm.

Requests

The Requests tab holds data access and correction requests under s.30 and s.34.

Recording a Request

  1. Open the Requests tab and press Record Request.
  2. Enter Who Asked (required).
  3. Choose What They Asked For: Data Access, Data Correction, Withdraw Consent or Limit Processing.
  4. Optionally enter How to Reach Them.
  5. Enter Received On (required). This must be the date the request actually arrived, not today's date.
  6. Choose who it is Handled By, or leave it as Nobody yet.
  7. Record What They Said, then press Record Request.

LawServa sets the due date to 21 days after the Received On date and confirms it when you save. A received date in the future is refused.

Important

The clock runs from the day the request was received, not the day it was typed in. A letter found in a drawer a week late already has only 14 days left.

Answering a Request

  1. Press Answer Request on the request's row.
  2. Choose the Outcome: Complied, Complied in Part or Refused.
  3. For Complied in Part or Refused, enter the ground under s.32 in Ground or Note. LawServa will not save a refusal or partial answer without it.
  4. Press Answer Request.

The request closes with today's date as its response date. If it is answered after the due date, LawServa says so and records it as answered after the statutory period.

StateMeaning
Days leftOpen, with that many days until the due date
Overdue by N daysOpen and past the due date
Complied, Partly or RefusedAnswered, showing the outcome chosen

Consents

The Consents tab records what each person agreed the firm may do with their data, and any withdrawal.

  1. Open the Consents tab and press Record Consent.
  2. Fill in the fields below and press Record Consent.
FieldWhat It MeansExample
Whose DataThe person the data belongs to (required)Tan Mei Ling
What It Will Be Used ForThe purpose they agreed to (required)Conveyancing of their property
BasisThe ground for processingThe person consented
How It Was GivenThe channelSigned form
Given OnThe date given; today if left blank2026-09-01
Where the Evidence IsWhere the signed form or email is keptMatter file, correspondence folder

The Basis options are: The person consented; Necessary to perform a contract with the person; A legal obligation on the firm; To protect the person's vital interests; For legal proceedings or legal advice.

Withdrawing a Consent

  1. Press Withdraw on the consent's row.
  2. Add a Note if useful and press Withdraw Consent.

The consent is marked withdrawn from today. The record is kept, because the firm processed data under it. Stop the processing it covered.

Transfers

The Transfers tab records personal data sent outside Malaysia, which needs a recorded basis under s.129.

  1. Open the Transfers tab and press Record Transfer.
  2. Enter Who Receives It, Country, What Data and Why. All four are required.
  3. Choose the Basis, add a Note if needed, and enter Sent On (today if left blank).
  4. Press Record Transfer.

The Basis options are: The person consented; Necessary to perform a contract; For legal proceedings or legal advice; That place has a comparable data protection law; Necessary to protect the person's vital interests.

Tip

Be specific under What Data, for example "Name, NRIC, bank account, title particulars". A vague entry such as "Client file" is not accepted as an answer by an inspector.

Breaches

The Breaches tab records breaches of security and whether the Commissioner and the people affected were told.

Recording a Breach

  1. Open the Breaches tab and press Record Breach.
  2. Enter What Happened, in One Line and Discovered At (both required).
  3. Optionally enter Happened At, If Known, What Data and How Many People.
  4. Choose the Severity: Still Assessing, Low, Medium or High.
  5. Add Detail and What Has Been Done to Contain It, then press Record Breach.

On saving, LawServa tells you the deadlines: 72 hours from discovery for the Commissioner and 7 days from discovery for the people affected. A discovery time in the future is refused.

The Commissioner and People Affected columns show a countdown such as "16h left" or "Overdue by 5h", with the deadline beside it, until a notice is recorded. They then show "Told" with the date and time.

Important

The Commissioner is told about every breach. The people affected are told only where the breach causes, or is likely to cause, them significant harm. Their column counts down on the assumption that it does. If the firm decides it does not, record that decision rather than letting the column answer for you.

Recording a Notice

  1. Press Record Notice on the breach's row.
  2. Choose Who Was Told: The Commissioner or The People Affected.
  3. For the Commissioner, enter the Commissioner Reference. For the people affected, enter How the People Were Told, such as Letter by post.
  4. Press Record Notice.

The notice is stamped with the current date and time, and LawServa records whether it was inside the statutory window. Record it only once the notification has actually been made.

Officer

The Officer tab records the firm's Data Protection Officer under s.12A. The screen explains who has to appoint one; check the Commissioner's current guideline before relying on the thresholds it reports.

Recording an Appointment

  1. Open the Officer tab and press Record Officer.
  2. Fill in the fields below and press Record Officer.
FieldWhat It Means
Somebody in This FirmThe staff member appointed; leave as Not a seat in this firm for an outside adviser
Name as NotifiedThe name that goes to the Commissioner; taken from the staff member if left blank
Position in the FirmFor example Partner, or Office manager
Business Email, Business TelephoneAt least one is required
Business AddressThe officer's business address
Appointed FromThe appointment date; today if blank, and never in the future
Why the Firm AppointedRequired: the firm is over one of the thresholds, or Appointed anyway, without being over a threshold
Which Threshold, or Why Without OneThe firm's own reasoning, written down now so it can be answered later

Recording the Notice to the Commissioner

Recording the appointment and recording that the Commissioner was told are two separate acts.

  1. Press Record Notice on the officer's row.
  2. Enter Notified On. It cannot be before the appointment or in the future.
  3. Enter Acknowledgement or Reference (required). It is the firm's only proof of when it notified.
  4. Optionally enter How It Was Notified and Where the Acknowledgement Is Filed, then press Record Notice.

Ending an Appointment

  1. Press End Appointment on the officer's row.
  2. Enter Why It Ended (required) and press End Appointment.

The appointment ends today and the row stays. Appoint a successor and notify the Commissioner of the new appointment.

StatusMeaning
CurrentThe appointment has not ended
EndedThe appointment ended on the date shown
ToldThe Commissioner was notified on the date shown, with the reference
Not yet notifiedCurrent and not yet notified; shows how many days since appointment
Never notifiedEnded without the Commissioner ever being notified

Printing a Register

Press Download PDF on any tab to print that register as an A4 document on the firm's letterhead, marked Confidential. It shows the firm as data controller, the date, the number of entries and who prepared it. Up to 200 entries are printed; the PDF says so if the register holds more.

Frequently Asked Questions

When Is a Data Access Request Due?

21 days from the date it was received, as entered in Received On. LawServa shows the days left and turns the entry to overdue once the date passes.

Why Can I Not Refuse a Request Without a Note?

A refusal or partial answer must be justified by a ground under s.32. LawServa requires the ground in Ground or Note before it will save.

Why Do I Not See Record Notice?

Recording a statutory notification needs a separate permission. Ask a partner or the firm owner to grant it if your role requires it.

Can I Delete a Consent or an Officer?

No. A consent is withdrawn and an appointment is ended, and both records stay on the register.

Related Guides

  • STR, Unclaimed Moneys, Accountant's Report and PDPA Registers
  • Compliance, Reports and Automations
  • Firm Management and Access
  • Enquiries and Clients
  • Troubleshooting and FAQ