Live — in production Privacy POLICY audit · Malaysia PDPA

Your privacy policy, published statements and notices, graded against the statute it claims to satisfy; with the exact quote behind every finding.

Paste the full text or upload a pdf copy of your company’s privacy policies, notice, or statement you already publish. Praxis Privacy scores it against the Malaysia PDPA statutory text in three never-blended layers, weights the sensitive-data categories you under-disclose, and returns a Praxis Grade with a ruled evidence ledger. Every finding cites its provision and the exact passage. A grade, not a certification, and plainly labelled as such.

One complete audit free · company email, no card Validated on 137 real Malaysian notices across 12 sectors Every finding quotes its exact passage
137Malaysian organizations covering 12 sectors were evaluated using published privacy policies, notices and statements in the validation corpus
42scored items across three statutory layers
6sensitive-data categories checked for disclosure
EN / BMbilingual intake at the notice level
The problem

A notice that reads well is not the same as a notice that discloses what the Act requires.

The generic checklist

A flat checklist counts items. It does not tell you which sensitive-data categories you are under-disclosing, or which gap carries the largest statutory exposure.

Findings without a quote

“Retention not adequately addressed” is an opinion. A finding that cites the provision and quotes the exact passage — or its absence — is evidence a DPO or counsel can act on.

Best practice mistaken for law

Data-protection-by-design maturity is guidance, not obligation. When the two are blended into one score, a maturity gap looks like a violation and a violation hides in the average.

What you get

Findings you can act on, in the order that matters.

Citation-linked, not checklist-linked

A defensible audit trail against actual PDPA statutory text — every finding cites its provision and an exact quote from your notice.

Obligation kept apart from guidance

Statutory layers (PDPA 2010 core, Act A1727 readiness) are never blended with non-binding Data Protection by Design guidance, so maturity gaps are never mistaken for legal violations.

Remediation prioritised by risk

The category layer surfaces exactly which sensitive-data categories are under-disclosed, weighted more heavily than a flat item count.

Financial stakes made visible

An illustrative exposure ceiling mapped against the verified PDPA penalty schedule helps a DPO prioritise fixes by what they could cost.

No silent assertions

Low-confidence findings route to a documentary-verification review queue rather than being stated as fact — fewer false-positive compliance claims.

Board- and counsel-ready output

A branded PDF with grade cards, exposure, per-principle disclosure bars and a ruled evidence ledger — worded so it cannot be mistaken for a certification.

How it works

Upload the Policy. Read the ledger.

The pipeline is deterministic where it can be and reviewed where it must be — and every rating carries the passage it rests on.

01
Intake

Paste the notice URL, text or upload the document. English and Bahasa Malaysia notices are segmented at intake so a bilingual notice is never under-scored.

02
Three-tier detection

A deterministic keyword sweep, then retrieval ranking, then semantic adjudication with exact-quote verification; a finding is only kept if its quote appears in your notice.

03
Three never-blended layers

L1 PDPA 2010 core (six principles), L2 Act A1727 readiness, L3 Data Protection by Design; reported separately, never averaged into one number.

04
Category layer

Six special data categories (socio-economic, lifestyle and behaviour, tracking, financial, authenticating, medical and health) checked for disclosure, with a capped, penalty-only deduction where disclosure is weak.

05
Confidence and review

Every finding carries a High, Medium or Low confidence band. Low-confidence findings go to a review queue for documentary verification before they are relied on.

06
Grade, ledger, export

A Praxis Grade A–D, illustrative statutory exposure, per-principle disclosure bars and a ruled evidence ledger with verbatim quotes and character offsets, exported as a branded PDF.

What is inside

Every score has a passage behind it.

Three-layer scoring

L1 PDPA 2010 Core (72 points, six principles), L2 Act A1727 Readiness (48 points), L3 DPbD Readiness (26 points, explicitly non-mandatory). Never blended.

Disclosure-weighted category layer

Six special data categories detected and checked; a capped, penalty-only deduction for weak disclosure so sensitive gaps outweigh cosmetic ones.

Exact-quote verification

Deterministic sweep → retrieval ranking → semantic adjudication, with the quoted passage verified against the notice text before a finding is kept.

Confidence bands and review queue

High / Medium / Low on every finding; Low routes automatically to documentary verification.

Illustrative exposure mapping

Findings mapped against the verified PDPA penalty schedule to give a prioritisation ceiling — illustrative, and labelled as such.

Branded PDF export

Grade cards, exposure, per-principle disclosure bars and a ruled evidence ledger with verbatim quotes and character offsets.

EN / BM bilingual intake

Notices published in both national languages are segmented at intake and scored on what they actually say.

Share links with expiry

24-hour, rate-limited share links with a DPO override — send the ledger to counsel without sending the login.

Hash-chained audit log

Immutable, append-only record of every audit, plus a Data Inventory Seed that hands structured findings to Praxis DPIA and Frontier.

Built to be defended

A method you can inspect, validated on real notices.

Validation
Run across a 137-organisation corpus of real Malaysian privacy notices spanning 12 sectors. The v1.2 category layer was validated with zero drift in the statutory layers — every score movement attributed to the new layer.
Methodology
Frozen and versioned. 42 scored items across three layers, backed by 97 automated tests including a gold-fixture regression suite, so a grade means the same thing next quarter.
Grade, not certification
The user-facing output is a de-certified Praxis Grade A–D. Internal bands are computed but never shown, and the PDF is worded so it cannot be presented as a certificate.
Evidence
Every finding carries the provision, the verbatim quote and the character offsets in your notice — a ledger, not a list.
Handoff
Structured findings seed the data inventory a Praxis DPIA or a Frontier transfer assessment starts from, so a notice audit is the beginning of the record, not a dead end.
Praxis Integrity
Every issued audit report is listed for life in the suite's public verification registry as it ships.

Who runs it

Law firms

Grade a client's published notice against statutory text before you rewrite it — an evidenced starting point for a notice-drafting engagement or a portfolio review.

Enterprise DPOs

Every entity and brand graded the same way, with an illustrative exposure view that turns a list of gaps into a remediation order the board understands.

SMEs: Clinics, e-commerce, hotels & rentals

Start here. Grade the notice you already publish and see which sensitive-data categories you under-disclose, with the exact passages behind every finding.

How to get it

Audit one notice free. Then pay per audit or get a monthly subscription.

Every new organisation gets one complete audit free — the full pipeline and the issued PDF for one notice. After that, buy one at a time or take a suite plan. All prices in MYR, exclusive of applicable tax.

Free first run
RM0one complete notice audit

Grade, exposure, evidence ledger and the issued PDF for one notice. Company email required; no card needed.

Audit a notice free
Pay per assessment
RM599one notice audit · report validity registry included

One clean issued report, listed in Praxis Integrity for easy external audit validation. Credited against your first subscription if you subscribe within 90 days.

Buy one audit
Suite or single module
from RM299per month · Privacy Audit alone

Privacy Audit on its own from RM299/month, or the full suite from RM599/month — every Praxis application, licensed by client workspace.

Compare plans
Common questions

Before you commit.

No. It is a graded, evidence-cited assessment of what your notice discloses against PDPA statutory text. The output is deliberately worded so it cannot be mistaken for a certificate, and it does not assert legal compliance.

The URL of the privacy notice you already publish, or the document itself. Company email required for the free first run; no card.

Yes. English and Bahasa Malaysia notices are segmented at intake, so a notice that legitimately publishes in both national languages is scored on what it says rather than under-scored for language.

Because the detection could not verify them with certainty. Low-confidence findings are routed to a documentary-verification review queue instead of being asserted — the audit would rather ask than guess.

On a corpus of 137 real Malaysian privacy notices across 12 sectors. When the category layer was added, the statutory layers showed zero drift; every score movement was fully attributed to the new layer.

No. Praxis Privacy Audit structures and evidences professional analysis. Outputs require review by an appropriately qualified person before reliance or issue.

Praxis Privacy Audit structures and evidences professional analysis. It does not provide legal advice, and it does not replace the review and approval of an appropriately qualified person before reliance or issue.

PDPA Act 709 (Act A1727 amendments)Seven PDPA principles · Data Protection by DesignPraxis Compliance Methodology v1.2
Part of the Praxis suite

One subscription. Every application.

Every suite plan includes all seven applications as each ships — licensed by client workspace, never by seat. See plans.

Paste the URL. Read the ledger. Fix the gaps that matter first.

Grade the notice you already publish — free.

Praxis Privacy AuditAudit a notice free