1-Day Intensive · In-House or Public Session

AI Governance & PDPA Compliance

A practical, one-day programme for Malaysian businesses whose teams are already using AI. Understand what the law asks of you, and leave with your own written AI use policy drafted — not a folder of slides.

At a glance

1Intensive Day
6Learning Blocks
Take-HomeAI Policy Draft
HRDCSBL-Khas Claimable
Why This Matters Now

Your Team Is Already Using AI. Your Policy Probably Says Nothing About It.

Most Malaysian companies discovered AI through their own staff, not through a plan. That gap between what people are already doing and what the organisation has actually approved is where the risk sits.

Staff Are Already Pasting Data In

Customer lists, salary tables, contracts, medical records — copied into free AI chatbots to "just summarise this". Usually with good intentions, almost always without approval, and often without anyone knowing where that data ends up.

The Rules Changed in 2025

Amendments to Malaysia’s Personal Data Protection Act came into force in June 2025, introducing mandatory Data Protection Officer appointment, breach notification, and data portability obligations. Many SMEs have not revisited their practices since.

A Written Policy Is the Practical Fix

There is no requirement to ban AI — and banning it does not work anyway. What works is a clear, written policy on what may and may not go into these tools, backed by staff who understand the reasoning. That is what this day produces.

The Programme

Six Blocks. You Leave With a Written Policy.

This is not a lecture on regulation. Roughly half the day is spent drafting your own organisation’s AI use policy in the room, using a working template, so the output is a document you can actually take to your management team.

Foundations45–60 min

The Exposure You Cannot See

Establish, in plain language, what actually happens to information once it is typed into an AI tool — and where the everyday exposure in a Malaysian business really comes from.

  • What happens to your data after you paste it into a public AI tool
  • "Shadow AI" — the tools your team uses that IT has never approved
  • What counts as personal data, in practical business terms
  • Realistic exposure scenarios: HR records, customer lists, quotations, contracts
PDPA Essentials60–75 min

PDPA, Explained for People Who Are Not Lawyers

The obligations that apply when personal data passes through an AI tool, covered in business language rather than legal language.

  • The PDPA principles, translated into everyday operational terms
  • The June 2025 amendments: Data Protection Officer, breach notification, data portability
  • Consent, notice and purpose — what changes when AI is in the loop
  • Cross-border transfer: where your AI vendor actually stores and processes data
Landscape45 min

Malaysia’s AI Governance Direction

What is voluntary guidance today, what is already binding, and what is likely coming — so your policy is built to survive the next two years rather than the next two months.

  • The National AI Governance & Ethics Guidelines (AIGE) and their principles
  • Voluntary guidance versus existing legal obligation — telling them apart
  • Where Malaysia’s AI regulation appears to be heading, and how to prepare
  • When your sector carries stricter overlays than the general baseline
Hands-On Build~2 hours

Draft Your Own AI Use Policy

The core working session. Starting from a structured template, each participant drafts a policy scoped to their own organisation — not a generic sample to file away unread.

  • Acceptable use: what staff may and may not put into AI tools
  • Building and maintaining an approved-tools list
  • Human-in-the-loop rules for decisions that affect people
  • Writing rules people will actually follow, in language they understand
  • Scoping the policy to your real headcount, sector and systems
Controls45–60 min

Vendors, Settings & Incidents

The operational controls that sit underneath the policy — choosing tools, configuring them properly, and knowing what to do on a bad day.

  • Vetting an AI vendor: the questions to ask before you sign anything
  • Retention settings and training-data opt-outs most companies never check
  • Recognising and responding to an AI-related data incident
  • Record-keeping that holds up when someone asks for evidence
Roll-Out30–45 min

Adoption, Ownership & Review

A policy nobody reads changes nothing. Close the day by planning how the document gets adopted, owned and kept current.

  • Briefing staff so the rules make sense rather than feel arbitrary
  • Assigning ownership across DPO, IT, HR and department heads
  • Handling the "but this slows me down" objection
  • Setting a review cadence as guidance and legislation evolve
Who Should Attend

The People Who Sign Off, and the People Who Implement

This programme works best when a decision-maker and an implementer attend together — the policy then leaves the room with both authority and a practical owner.

Business Owners & Directors

Understand the organisation’s exposure well enough to make a decision, and approve a policy you actually understand

Data Protection & Compliance

Extend existing PDPA practice to cover AI tools, with documentation that stands up to scrutiny

HR & Admin Leads

Handle employee and candidate data responsibly when AI is used for screening, drafting and summarising

IT & Operations Managers

Turn an approved policy into real controls — tool selection, settings, access and incident handling

What You Take Away

A Document, Not Just Notes

Every participant leaves with drafted work in hand, plus the reasoning to defend it to their own management.

  • A drafted AI use policy scoped to your own organisation, ready to refine and approve
  • A plain-language understanding of PDPA obligations when AI processes personal data
  • Clarity on the June 2025 amendments — DPO appointment, breach notification and data portability
  • A vendor assessment checklist to use before signing with any AI supplier
  • An outline incident response process for AI-related data exposure
  • A staff briefing plan so the policy is understood rather than ignored
  • Familiarity with the AIGE principles and Malaysia’s likely regulatory direction
  • A review schedule to keep the policy current as the rules develop
Inside an AISynergy Session

Delivered in Your Room, at Your Pace

Photographs from AISynergy training sessions. This programme runs the same way — in-house, practitioner-led, small enough that every participant can raise the awkward questions their own organisation actually faces.

AISynergy trainer presenting at the screen while participants follow on their laptops
Practitioner-Led

Worked through live, with the room following

Training session delivered in a client’s own training room
In-House Delivery

Delivered in the client’s own training room

Wide view of a training room with the trainer at the front and participants at desks
Small Cohorts

Kept small enough for everyone to be heard

Participants from different departments seated together during a session
Mixed Teams

Departments working through it in the same room

Participants following a demonstration on the room’s main screen
Step by Step

Shown on screen, then tried on their own laptops

Participants working along on their own laptops during a hands-on session
Hands-On

Everyone on a laptop, working along

HRD Corp SBL-Khas Claimable

Claimable Training, Plus Budget 2026’s Extra Deduction.

This programme is claimable under the HRD Corp SBL-Khas scheme for registered Malaysian employers. Budget 2026 also introduced a 50% additional tax deduction for MSME spending on AI and cybersecurity training, administered through TalentCorp — ask us and we will point you to the current terms.

  • Training Provider Reg. 202403037477
  • Full supporting documents provided for HRDC claim submission
  • Attendance records and trainer profile included
  • Dedicated guidance for the HRDC claim process
  • Delivered in-house at your premises, or as a public session

Write the Policy Before You Need It.

Available as an in-house programme at your premises, or as a scheduled public session. Talk to us about dates.

Chat on WhatsApp Now
1-Day IntensiveIn-House or PublicHRD Corp Claimable

+603 6087 5252 · aisynergy.my

This programme provides general guidance and practical templates for building internal AI governance practice. It is training, not legal advice, and it does not create a solicitor-client relationship. Regulatory requirements change and vary by sector — organisations should confirm their specific obligations with a qualified legal adviser before relying on any policy produced during the session.

© 2026 AISynergy Malaysia · Registration No. 202403037477