A Comparative Analysis of the Personal Data Protection Act 2010 in Mitigating Identity Theft and Online Fraud: Malaysia and the United States

Authors

Nurul Adli bin Rahmat

Universiti Teknologi MARA (UiTM), UiTM Shah Alam (Malaysia)

Nur Khalishah Maisarah binti Mohammad

Universiti Teknologi MARA (UiTM), UiTM Shah Alam (Malaysia)

Nur Sarah Afiqah binti Azman

Universiti Teknologi MARA (UiTM), UiTM Shah Alam (Malaysia)

Nur Aqila binti Sablihan

Universiti Teknologi MARA (UiTM), UiTM Shah Alam (Malaysia)

Lim Jing Xie

Universiti Teknologi MARA (UiTM), UiTM Shah Alam (Malaysia)

Koh Huan

Universiti Kebangsaan Malaysia (Malaysia)

Article Information

DOI: 10.47772/IJRISS.2026.100700514

Subject Category: Law

Volume/Issue: 10/7 | Page No: 7565-7578

Publication Timeline

Submitted: 2026-07-24

Accepted: 2026-07-30

Published: 2026-08-06

Abstract

This qualitative study compares data protection and identity theft laws in Malaysia and the United States to address escalating online fraud. It evaluates the effectiveness of Malaysia’s Personal Data Protection Act (PDPA) 2010 alongside the U.S. Identity Theft and Assumption Deterrence Act 1998. Through document analysis and expert interviews, the research reveals critical structural limitations within the Malaysian framework. The PDPA’s applicability is restricted solely to commercial transactions, explicitly excludes government entities, lacks independent prosecutorial authority, and fails to provide direct civil remedies or financial restitution for individual victims. Conversely, the U.S. framework employs a multi-agency, victim-centric approach with mandatory restitution. The study concludes that Malaysia should adopt a hybrid model, incorporating victim-oriented remedies, expanding the scope of data protection, and integrating automated credential filtering to strengthen legal deterrence.

Keywords

N/A

Downloads

References

1. Newhouse, Johnson et al., Multifactor Authentication for E-Commerce Risk-Based, FIDO Universal Second Factor Implementations for Purchasers Includes Executive Summary (A); Approach, Architecture, and Security Characteristics (B) (2019) <https://doi.org/10.6028/NIST.SP.1800-17> accessed in 1 May 2025 [Google Scholar] [Crossref]

2. Penal Code, s 415. [Google Scholar] [Crossref]

3. Guan, G. . Phishing: A growing challenge for Internet banking providers in Malaysia. Academia.edu. (2010, August 25) <https://www.academia.edu/308460/Phishing_A_growing_challenge_for_Internet_banking_providers_in_Malaysia?utm_source> accessed in 3 May 2025 [Google Scholar] [Crossref]

4. Mok, O. CyberSecurity Malaysia reports a steep jump in data thefts last year. Malay Mail.(2024, April 13) <https://www.malaymail.com/news/malaysia/2022/11/23/penang-cops-investigating-claims-of-ic-abuse-during-ge15/41472> accessed in 10 May 2025 [Google Scholar] [Crossref]

5. Mail, M. MCMC received 744 online scam reports involving Facebook since January. (2023, June 4) <https://www.malaymail.com/news/malaysia/2023/06/04/teo-nie-ching-mcmc-received-744-online-scam-reports-involving-facebook-since-january/72492> accessed in 10 May 2025 [Google Scholar] [Crossref]

6. Hong, H. Recent Developments in Malaysia’s Personal Data Protection Act. (2024, November 14). <https://hhq.com.my/posts/recent-developments-in-malaysias-personal-data-protection-act/> accessed in 13 May 2025 [Google Scholar] [Crossref]

7. Kiteworks. Everything You Need to Know About the Malaysia Personal Data Protection Act (PDPA) (n.d.). <https://www.kiteworks.com/risk-compliance-glossary/malaysia-personal-data-protection-act/> accessed in 13 May 2025 [Google Scholar] [Crossref]

8. Harrell, Data breach notifications and identity theft, 2021. (2023, October 2) <https://bjs.ojp.gov/data-breach-notifications-and-identity-theft-2021> accessed in 11 May 2025 [Google Scholar] [Crossref]

9. Nguyen, S. T, New FTC data show a big jump in reported losses to fraud to $12.5 billion in 2024. Federal Trade Comission. (2025, March 10). <https://www.ftc.gov/news-events/news/press-releases/2025/03/new-ftc-data-show-big-jump-reported-losses-fraud-125-billion-2024> accessed in 11 May 2025 [Google Scholar] [Crossref]

10. FBI, FBI warns public to beware of scammers impersonating FBI agents and other government officials.. (2024, June 5) <https://www.fbi.gov/contact-us/field-offices/portland/news/fbi-warns-public-to-beware-of-scammers-impersonating-fbi-agents-and-other-government-officials> accessed in 11 May 2025 [Google Scholar] [Crossref]

11. United States Congress, Dodd-Frank Wall Street Reform and Consumer Protection Act, Public Law 111–203, 21 July 2010 <https://www.govinfo.gov/content/pkg/PLAW-111publ203/html/PLAW-111publ203.htm> accessed in 14 May 2025 [Google Scholar] [Crossref]

12. Consumer Financial Protection Bureau, About Us, Mar. 12, 2025 <https://www.consumerfinance.gov/about-us/the-bureau/> accessed in 14 May 2025 [Google Scholar] [Crossref]

13. Mok, O. CyberSecurity Malaysia reports a steep jump in data thefts last year. Malay Mail.(2024, April 13) <https://www.malaymail.com/news/malaysia/2022/11/23/penang-cops-investigating-claims-of-ic-abuse-during-ge15/41472> accessed in 10 May 2025 [Google Scholar] [Crossref]

14. Section 3(1), Personal Data Protection Act 2010 (Act 709). [Google Scholar] [Crossref]

15. Personal Data Protection (Amendment) Act 2024, s 4. [Google Scholar] [Crossref]

16. Personal Data Protection (Amendment) Act 2024, s 12B. [Google Scholar] [Crossref]

17. Noor Sureani, N. B., Awis Qurni, A. S. B., Azman, A. H. B., Othman, M. B. B., & Zahari, H. S. B. The Adequacy of Data Protection Laws in Protecting Personal Data in Malaysia. Malaysian Journal of Social Sciences and Humanities (MJSSH), 6(10), 488–495. (2021). <https://doi.org/10.47405/mjssh.v6i10.1087> accessed 27 December 2025 [Google Scholar] [Crossref]

18. Ibid. [Google Scholar] [Crossref]

19. Identity Theft. Richard Wee Chambers. (2020, September 3). <https://www.richardweechambers.com/identity-theft/> accessed 27 December 2025 [Google Scholar] [Crossref]

20. Ibid [Google Scholar] [Crossref]

21. Identity theft investigations | EBSCO. (2024). EBSCO Information Services, Inc. | Www.ebsco.com. <https://www.ebsco.com/research-starters/law/identity-theft-investigations> accessed 27 December 2025 [Google Scholar] [Crossref]

22. Ibid [Google Scholar] [Crossref]

23. Identity Theft and Assumption Deterrence Act of 1998. The IT Law Wiki; Fandom, Inc. <https://itlaw.fandom.com/wiki/Identity_Theft_and_Assumption_Deterrence_Act_of_1998 (2025)> accessed 27 december 2025 [Google Scholar] [Crossref]

24. Department of Personal Data Protection (JPDP), ‘Department Profile’ (Official Portal, 2024) <https://www.pdp.gov.my/ppdpv1/en/mengenai-jpdp/profil-jabatan/> accessed in 31 December 2025. [Google Scholar] [Crossref]

25. Ibid et 23, s 47. [Google Scholar] [Crossref]

26. Sonny Zulhuda, ‘The Personal Data Protection Act 2010: A Leap Forward or a Half-Step?’ [2011] 4 Malayan Law Journal i. [Google Scholar] [Crossref]

27. Jillian Chia and Nicole Oh, ‘Data Protection & Privacy 2020’ (Skrine, 1 January 2020) <https://www.skrine.com/insights/publications/2020/january/data-protection-privacy-2020> accessed 31 December 2025. [Google Scholar] [Crossref]

28. Ibid [Google Scholar] [Crossref]

29. Communications and Multimedia Act 1998 (Act 588), s 263. [Google Scholar] [Crossref]

30. Rahmah Ismail, ‘Legal Protection of Consumers against Online Scams in Malaysia’ (2020) 24(1) Journal of Information and Communication Technology Law 45. [Google Scholar] [Crossref]

31. Ibid. [Google Scholar] [Crossref]

32. Personal Data Protection Act 2010 (Act 709), s 3(1). [Google Scholar] [Crossref]

33. Federal Trade Commission, ‘Privacy and Security Enforcement’ (Official Website, 2025) <https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement> accessed 31 December 2025. [Google Scholar] [Crossref]

34. Congressional Research Service, ‘Data Protection Law: An Overview’ (R45631, 2019). [Google Scholar] [Crossref]

35. Ibid. [Google Scholar] [Crossref]

36. Federal Trade Commission Act, 15 USC § 45. [Google Scholar] [Crossref]

37. Identity Theft and Assumption Deterrence Act 1998, 18 USC § 1028; see also US Department of Justice, ‘Identity Theft’ (Criminal Division, 2023) <https://www.justice.gov/criminal/criminal-fraud/identity-theft/identity-theft-and-identity-fraud> accessed 31 December 2025. [Google Scholar] [Crossref]

38. Federal Bureau of Investigation, ‘White-Collar Crime’ (Official Website, 2025) <https://www.fbi.gov/investigate/white-collar-crime> accessed 31 December 2025. [Google Scholar] [Crossref]

39. Ibid. [Google Scholar] [Crossref]

40. Identity Theft Penalty Enhancement Act 2004, Pub L No 108-275, 118 Stat 831. [Google Scholar] [Crossref]

41. Personal Data Protection Act 2010 (Act 709), s 101-103. [Google Scholar] [Crossref]

42. Ibid. [Google Scholar] [Crossref]

43. Abu Bakar Munir and Siti Hajar Mohd Yasin, Personal Data Protection in Malaysia: Law and Practice (Sweet & Maxwell Asia 2010). [Google Scholar] [Crossref]

44. Ibid note [Google Scholar] [Crossref]

45. US Department of Justice, ‘Identity Theft’ (Criminal Division, 2023) <https://www.justice.gov/criminal/criminal-fraud/identity-theft/identity-theft-and-identity-fraud> accessed 31 December 2025. [Google Scholar] [Crossref]

46. Federal Bureau of Investigation, ‘Cyber Crime’ (Official Website, 2025) <https://www.fbi.gov/investigate/cyber> accessed 31 December 2025. [Google Scholar] [Crossref]

47. Personal Data Protection Act 2010 (Act 709), s 124. [Google Scholar] [Crossref]

48. Ibid [Google Scholar] [Crossref]

49. Ibid. [Google Scholar] [Crossref]

50. Ibid.. [Google Scholar] [Crossref]

51. US Constitution, amend V [Google Scholar] [Crossref]

52. Identity Theft and Assumption Deterrence Act 1998, 18 USC § 1028; Identity Theft Penalty Enhancement Act 2004, 18 USC § 1028A. [Google Scholar] [Crossref]

53. Ibid . [Google Scholar] [Crossref]

54. Personal Data Protection (Amendment) Act 2024, s 5 (amending s 5 of Act 709). [Google Scholar] [Crossref]

55. Ibid. [Google Scholar] [Crossref]

56. Abu Bakar Munir and Siti Hajar Mohd Yasin, Personal Data Protection in Malaysia: Law and Practice (Sweet & Maxwell Asia 2010). [Google Scholar] [Crossref]

57. Personal Data Protection Act 2010 (Act 709), s 2(1). [Google Scholar] [Crossref]

58. US Sentencing Commission, ‘Quick Facts on Section 1028A, Aggravated Identity Theft Offenses’ (2024) https://www.ussc.gov/research/quick-facts/aggravated-identity-theft accessed 31 December 2025. [Google Scholar] [Crossref]

59. Ibid at 46, 18 USC § 1028A. [Google Scholar] [Crossref]

60. Identity Theft Enforcement and Restitution Act 2008, Pub L No 110-326, 122 Stat 3560. [Google Scholar] [Crossref]

61. Ibid. [Google Scholar] [Crossref]

62. Personal Data Protection Act 2010 (Act 709), s 2. [Google Scholar] [Crossref]

63. Ibid. [Google Scholar] [Crossref]

64. Ibid. [Google Scholar] [Crossref]

65. Azmi & Associates, ‘Criminal and Civil Liability of Data Breaches under the Malaysian Law’ (Official Website,2025) <https://www.azmilaw.com/insights/criminal-and-civil-liability-of-data-breaches-under-the-malaysian-law/> accessed 31 December 2025. [Google Scholar] [Crossref]

66. Ibid. [Google Scholar] [Crossref]

67. Identity Theft Enforcement and Restitution Act 2008, Pub L No 110-326, 122 Stat 3560. [Google Scholar] [Crossref]

68. Ibid. [Google Scholar] [Crossref]

69. Ibid. [Google Scholar] [Crossref]

70. Ibid. [Google Scholar] [Crossref]

71. Federal Trade Commission, ‘IdentityTheft.gov’ (Official Website, 2025) <https://www.identitytheft.gov/> accessed 31 December 2025 [Google Scholar] [Crossref]

72. Identity Theft Enforcement and Restitution Act 2008 (n 12). [Google Scholar] [Crossref]

73. Ibid. [Google Scholar] [Crossref]

74. Ibid. [Google Scholar] [Crossref]

75. Ibid. [Google Scholar] [Crossref]

76. Ibid. [Google Scholar] [Crossref]

77. Saunders, K. M., & Zucker, B. Counteracting Identity Fraud in the Information Age: The Identity Theft and Assumption Deterrence Act. International Review of Law, Computers & Technology, 13(2), 183–192. (1999). <https://doi.org/10.1080/13600869955134> accessed 31 december 2025 [Google Scholar] [Crossref]

78. Ibid. [Google Scholar] [Crossref]

79. Ibid. [Google Scholar] [Crossref]

80. WT Development Sdn Bhd v Chow Cho Tai & Ors [2019] MLJU 1691 [Google Scholar] [Crossref]

81. Rogan v City of Los Angeles 668 F. Supp. 1384 (C.D. Cal. 1987) [Google Scholar] [Crossref]

82. Ibid. [Google Scholar] [Crossref]

83. Personal Data Protection Act 2010 (Act 709), s 131. [Google Scholar] [Crossref]

84. Personal Data Protection Act 2010 (Act 709), s 2. [Google Scholar] [Crossref]

85. Personal Data Protection Act 2010 (Act 709), s 5. [Google Scholar] [Crossref]

86. Ibid. [Google Scholar] [Crossref]

87. Identity Theft Enforcement and Restitution Act of 2008, 18 U.S.C. § 3663(b)(6) [Google Scholar] [Crossref]

88. Office for Victims of Crime (OVC).Expanding Services To Reach Victims of Identity Theft and Financial Fraud - Federal Identity Theft Laws. (2010) <https://ovc.ojp.gov/sites/g/files/xyckuh226/files/pubs/ID_theft/pfv.html> accessed in 23 December 2025 [Google Scholar] [Crossref]

89. Ibid at p 55. [Google Scholar] [Crossref]

90. Ibid at p 55. [Google Scholar] [Crossref]

91. Ibid at p 55. [Google Scholar] [Crossref]

92. Ibid at p 55. [Google Scholar] [Crossref]

93. Ibid at p 55. [Google Scholar] [Crossref]

94. Ibid at p 55. [Google Scholar] [Crossref]

95. Ibid at p 55. [Google Scholar] [Crossref]

96. Ibid at p 55. [Google Scholar] [Crossref]

97. Ibid at p 55. [Google Scholar] [Crossref]

98. Ibid at p 55. [Google Scholar] [Crossref]

99. Ibid at p 55. [Google Scholar] [Crossref]

100. Ibid at p 55. [Google Scholar] [Crossref]

101. Ibid at p 55. [Google Scholar] [Crossref]

102. Jillian Chia and Nicole Oh, ‘Data Protection & Privacy 2020’ (Skrine, 1 January 2020) <https://www.skrine.com/insights/publications/2020/january/data-protection-privacy-2020> accessed 31 December 2025. [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles