Personal Data Protection 17 investments, financing, banking and insurance, but does not include a credit reporting business carried out by a credit reporting agency under the Credit Reporting Agencies Act 2010. PART II PERSONAL DATA PROTECTION Division 1 Personal Data Protection Principles Personal Data Protection Principles 5. (1) The processing of personal data by a data user shall be in compliance with the following Personal Data Protection Principles, namely— (a) the General Principle; (b) the Notice and Choice Principle; (c) the Disclosure Principle; (d) the Security Principle; (e) the Retention Principle; (f) the Data Integrity Principle; and (g) the Access Principle, as set out in sections 6, 7, 8, 9, 10, 11 and 12. (2) Subject to sections 45 and 46, a data user who contravenes subsection (1) commits an offence and shall, on conviction, be liable to a fine not exceeding three hundred thousand ringgit or to imprisonment for a term not exceeding two years or to both. General Principle 6. (1) A data user shall not— (a) in the case of personal data other than sensitive personal data, process personal data about a data subject unless the data subject has given his consent to the processing of the personal data; or (b) in the case of sensitive personal data, process sensitive personal data about a data subject except in accordance with the provisions of section 40.

Select target paragraph3