Skip to content

Releases: AltByteSG/personal-data-protection-skill

v0.3.0 — Malaysia PDPA (Act 709 + Act A1727)

Choose a tag to compare

@obiot obiot released this 04 May 03:53

Adds Malaysia PDPA 2010 (with the 2024 Amendments — Act A1727) as the fourth populated jurisdiction. Reflects the staged commencement of Act A1727 under P.U.(B) 522/2024 (1 January 2025, 1 April 2025, 1 June 2025) and the operative JPDP guidelines on DPO appointment and data breach notification (issued 25 February 2025, effective 1 June 2025). Templates and checklists rewired to support the MY breach lane and processor regime; top-level divergence table extended with two new engineering-affecting rows (B2B SaaS processor; high-risk processing / DPIA); existing TH and ID obligation files trimmed to align with the engineering-first framing rule that the MY draft was written to. Philippines DPA and Vietnam PDPD now deferred to v0.4.

Added — Malaysia jurisdiction content

New jurisdiction directory skills/personal-data-protection/jurisdictions/my-pdpa/ with:

  • README.md — statute metadata, critical thresholds, application / territorial reach (s2–s3), mental model
  • statute-map.md — reverse lookup from section number → obligation file → universal layer
  • 7 obligation files mirroring the SG / TH / ID structure: 01-accountability.md (s12A DPO + s23–29 codes of practice + vendor flow-down), 02-consent.md (General Principle s6, withdrawal s38, sensitive PD s40, direct marketing s43), 03-purpose.md (Notice & Choice s7 incl. bilingual BM/EN requirement, Disclosure s8, s39, s41), 04-access-correction.md (s30–37 access/correction, s42 prevention, s43A data portability — new 2024), 05-care.md (Security s9 incl. processor direct duty, Retention s10, Data Integrity s11, Record s44, Cross-border s129 post-whitelist removal), 06-breach-notification.md (s12B + JPDP Guideline 25 Feb 2025: 72h Commissioner / 7d subject), 07-offences.md (penalty matrix incl. s133 directors' deeming liability)

Added — divergence-table rows (engineering-affecting)

The top-level developer-view divergence table gained two new rows in addition to the new Malaysia column:

  • "Is a B2B SaaS / processes personal data on behalf of other businesses" — captures MY's new processor direct duty under s5(1A) (Security Principle, 1 April 2025) and s12A(2) (DPO appointment, 1 June 2025), against TH s40, ID Pasal 51–52, and SG's narrower data-intermediary regime.
  • "Ships a new feature involving high-risk processing" — captures ID's mandatory Pasal 34 DPIA as a pre-launch engineering gate (the only one of the four jurisdictions with a statutory DPIA requirement).

Changed — cross-jurisdiction docs

  • SKILL.md — frontmatter description and jurisdiction table updated to include Malaysia; "Critical thresholds" table grew a fourth column.
  • jurisdictions/_index.md — cross-jurisdiction comparison grew a fourth column; status table marks my-pdpa populated; PH/VN now flagged for v0.4.
  • README.md — divergence table extended; Sources section gained a Malaysia subsection (Act 709 PDF, Act A1727 PDF, JPDP guidelines, JPDP regulator); audience line broadened to "any app or service" with headless API in the stack list.
  • AGENTS.md — Codex / Cursor / Copilot entry point mirrored; "all four jurisdictions" wording aligned with SKILL.md.
  • CONTRIBUTING.md — JPDP added to the regulator list for statute-update PRs; v0.4 milestone now lists PH and VN only.

Changed — templates and checklists (engineer-facing artefacts)

  • templates/INCIDENT_RESPONSE.md.template — statutory-clocks table grew a Subject-notification column and a Malaysia row (72h Commissioner from discovery / 7d subject post-Commissioner per JPDP Guideline); the "Indonesia / Thailand" assessment + filing sections now also cover Malaysia; quick-reference table grew a Malaysia column; penalty-summary footer gained the MY entry.
  • checklists/breach-response.md — critical-timer table replaced "(planned coverage)" placeholders with the live MY 72h+7d row and a Subject-notification column.
  • checklists/new-vendor.md — DPA breach-flow-down clause tightened to reference all four jurisdictions' clocks; cross-border-basis section split per-jurisdiction including MY s129(3)(f) due diligence post-whitelist; jurisdiction-notes table grew a MY row.
  • checklists/new-feature.md — jurisdiction-specific section expanded from "(if active) — once populated" stubs into fully drafted TH / ID / MY sub-blocks.
  • checklists/new-data-field.md — jurisdiction check items split per jurisdiction with concrete TH / ID / MY references.

Changed — TH and ID obligation files (engineering-first audit)

The MY draft was written to a stricter "engineering-first" rule than the SG/TH/ID files predated. A focused audit identified governance over-emphasis in 6 of 14 TH/ID obligation files; the following targeted trims bring them in line with the same bar (no content removed that an engineer needs):

  • th-pdpa/obligations/01-accountability.md — s41/s42 DPO designation + duties collapsed into a 3-bullet engineering-surface section.
  • th-pdpa/obligations/05-care.md — adequacy-decision narrative trimmed; processor cross-reference trimmed.
  • th-pdpa/obligations/06-breach-notification.md — risk-to-rights-and-freedoms section flipped to engineer-checklist-first format.
  • id-pdp/obligations/01-accountability.md — Pasal 53/54 governance prose collapsed into 3-bullet engineering surface.
  • id-pdp/obligations/05-care.md — Pasal 37 supervision section reframed to lead with the engineering control.
  • id-pdp/obligations/07-offences.md — Pasal 70 corporate-criminal narrative collapsed; mental-model bullet refocused on engineering-relevant audit-trail framing.

Changed — disclaimer

  • DISCLAIMER.md — Malaysia named in "What this skill is" and "Not licensed to practise law" sentences. "Authoritative sources" gained a Malaysia entry. The "Copyright in source materials" section now flags Malaysia separately because the PNMB-published Act 709 / Act A1727 PDFs carry a notably restrictive publisher's copyright notice that goes beyond the SSO / PDPC Thailand / peraturan.go.id terms. Reusers planning redistribution should treat MY source-copyright posture as the strictest of the four.
  • Top-level disclaimer banner mirrored to README.md, SKILL.md, and AGENTS.md: this skill does not reproduce or republish any underlying statute; it provides engineer-facing interpretation and short attributed quotations under fair-dealing, with the MY PNMB notice flagged as the strictest of the four for redistribution purposes.

Plugin manifest

  • .claude-plugin/plugin.jsonversion 0.2.2 → 0.3.0; description and keywords expanded to include Malaysia.
  • .claude-plugin/marketplace.json — plugin description expanded to include Malaysia.

Statute coverage matrix

Jurisdiction Statute version Last verified
Singapore PDPA 2012 Current as at 1 May 2026 (reflects 2020 Amendments) 2026-05-02
Thailand PDPA B.E. 2562 (2019) Original 2019 text (PDPC Thailand English translation) 2026-05-03
Indonesia UU PDP No. 27/2022 Original 2022 text (in force from 17 Oct 2024) 2026-05-03
Malaysia PDPA 2010 (Act 709) Act 709 as amended by Act A1727 (all provisions in force as at 1 June 2025) 2026-05-04

Install

Claude Code:

```
claude plugin marketplace add AltByteSG/personal-data-protection-skill
claude plugin install personal-data-protection@altbyte-plugins
```

Codex / Cursor / Copilot: clone the repo and reference `AGENTS.md` from your project's existing agent-instructions file. See the README for full install paths.

v0.2.0 — repackage as Claude Code plugin

Choose a tag to compare

@obiot obiot released this 03 May 06:12

Reference material — not legal advice. See DISCLAIMER.md before relying on any content here for compliance decisions.

Repo restructured to enable distribution via the official Anthropic plugin marketplace (platform.claude.com/plugins). No content changes — same SG / TH / ID jurisdictions, same layers, same checklists, same templates as v0.1.0. Statutes cited are byte-for-byte identical.

What changed

  • Layout: all skill content (SKILL.md, layers/, jurisdictions/, checklists/, templates/) moved from the repo root into skills/personal-data-protection/. Required by the plugin loader, which only auto-discovers skills in a skills/<name>/ subdirectory at the plugin root.
  • Plugin manifest: added .claude-plugin/plugin.json declaring name, version, author, repository, license, keywords.
  • Relative-path links: the 41 markdown / template files inside the skill folder had their links to root-level meta files repointed by 2 additional ../ hops. Mechanical fix only.
  • Root files: README.md, LICENSE, DISCLAIMER.md, CHANGELOG.md, CONTRIBUTING.md, SECURITY.md, AGENTS.md, PRIVACY.md, .gitignore remain at the repo root. AGENTS.md updated to reference paths under skills/personal-data-protection/ so Codex CLI / Cursor / Copilot still work.
  • README install section: rewritten around three install paths (Claude Code via /plugin install, Claude Code via direct clone, Codex / Cursor / Copilot via clone-and-reference).
  • PRIVACY.md added — formalises the no-data-collection stance for the marketplace submission.

Install (new)

Claude Code — via plugin marketplace (preferred, when approved)

/plugin install AltByteSG/personal-data-protection-skill

Claude Code — direct clone

git clone https://github.com/AltByteSG/personal-data-protection-skill.git ~/.claude/plugins/personal-data-protection-skill

Codex CLI / Cursor / Copilot

git clone https://github.com/AltByteSG/personal-data-protection-skill.git ~/.tools/personal-data-protection-skill

Then reference ~/.tools/personal-data-protection-skill/AGENTS.md from your project's existing AGENTS.md / .cursorrules / .github/copilot-instructions.md.

Migration from v0.1.0

  • The bare-clone-into-.claude/skills/ pattern from v0.1.0 no longer works — use the new install paths above
  • If you cloned v0.1.0 manually and want to keep the old layout, pin to the v0.1.0 tag — that snapshot is preserved
  • All content (statute citations, layer guidance, checklists) is byte-for-byte identical to v0.1.0; the only thing that moved is the directory tree

Statute coverage matrix (unchanged from v0.1.0)

Jurisdiction Statute version Last verified
Singapore PDPA 2012 Current as at 1 May 2026 (reflects 2020 Amendments) 2026-05-03
Thailand PDPA B.E. 2562 (2019) Original 2019 text (PDPC Thailand English translation) 2026-05-03
Indonesia UU PDP No. 27/2022 Original 2022 enactment (Bahasa Indonesia binding text) 2026-05-03

Roadmap — v0.3

Three additional SEA jurisdictions planned, each following the same shape as the existing v0.1 / v0.2 jurisdictions:

  • Malaysia — PDPA 2010 with the 2024 Amendments (mandatory DPO, mandatory breach notification, data portability, raised penalties)
  • Philippines — Data Privacy Act 2012 (RA 10173) plus NPC Circulars
  • Vietnam — PDP Decree 13/2023/ND-CP (full PDP Law drafted; will re-cut on enactment)

Track via CHANGELOG.md. Contributions welcome — see CONTRIBUTING.md.

v0.1.0 — initial release

Choose a tag to compare

@obiot obiot released this 03 May 04:27

Reference material — not legal advice. See DISCLAIMER.md before relying on any content here for compliance decisions. Always verify against the official statute and consult a qualified DPO or lawyer.

First public release of the personal-data-protection compliance skill for Claude Code and Codex CLI / Cursor / Copilot.

Tech-agnostic, organised by where in the stack each obligation lands rather than by statute section number. Engineers shouldn't need to learn statute references to ship features that comply.

Jurisdictions covered

Code Jurisdiction Statute version reflected
sg-pdpa Singapore PDPA 2012 Current as at 1 May 2026 (post-2020 Amendments)
th-pdpa Thailand PDPA B.E. 2562 (2019) Original 2019 text via PDPC Thailand English translation
id-pdp Indonesia UU PDP No. 27/2022 Original 2022 enactment (Bahasa Indonesia binding text)

Structure

  • 7 universal layer files — non-technical, architecture, data model, controls and processes, feature/UX, disclosure, operational
  • 3 jurisdictions × (README.md + statute-map.md + 7 obligation files mapping the statute to the layers)
  • 4 entry-point checklists — new-feature, new-data-field, new-vendor, breach-response
  • 2 templates — incident response runbook, PostToolUse nudge hook
  • Cross-jurisdiction comparison index — what's the same, what diverges, where the strictest rule wins

Multi-agent support

  • SKILL.md for Claude Code (auto-discovery via YAML frontmatter)
  • AGENTS.md for Codex CLI, Cursor, Copilot (mirrors SKILL.md for tools that don't read Claude's frontmatter)

Legal posture

  • MIT licence with explicit carve-out for verbatim statute text — see DISCLAIMER.md § Copyright in source materials
  • Per-jurisdiction source-copyright notices (SSO Terms of Use, PDPC Thailand, Komdigi)
  • "Reference material only — not legal advice" banner on every content file
  • DISCLAIMER, CONTRIBUTING, SECURITY aligned on a zero-liability stance with Singapore-courts dispute jurisdiction

Roadmap

v0.2 will add three more SEA jurisdictions:

  • Malaysia — PDPA 2010 with the 2024 Amendments (mandatory DPO, mandatory breach notification, data portability, raised penalties)
  • Philippines — Data Privacy Act 2012 (RA 10173) plus NPC Circulars
  • Vietnam — PDP Decree 13/2023/ND-CP (full PDP Law drafted; will re-cut on enactment)

Track via CHANGELOG.md. Contributions welcome — see CONTRIBUTING.md.