Did you ask your visitors before tracking them?
If your site runs Google Analytics, a Facebook pixel or any ad tool, it is collecting data about the people who visit. Under Malaysian law you are supposed to tell them and ask first.
Most Malaysian sites never ask. We put the consent popup on yours for free and install it ourselves.
Most banners just tell you. Ours actually stops the tracking.
You looked at shoes once. Now shoes follow you.
That is a tracking cookie doing its job. Not magic, and not illegal by itself. It becomes your problem when it happens on your site, to your customers, without anyone asking first.
Under the PDPA, anything that can single out a person is personal data. Collecting it needs a reason and a heads-up.
One visit. Three websites. Nobody asked permission.
"Please delete my data."
One day a customer asks what you hold about them, or tells you to delete it. Under the PDPA you have to answer, and there is a deadline.
Most businesses handle this in a shared inbox until one gets forwarded twice and quietly missed. That is the one that becomes a complaint.
Siti L.
"What information do you have about me?"
Ahmad R.
"Please correct my phone number."
Jia Ting
"Delete my account and everything in it."
We give you one page that catches these, with a clock on each.
Start free. Pay only to keep it current.
The popup costs nothing and we install it. You pay to keep it honest afterwards, because the moment marketing adds a tool the popup is out of date and you are back where you started.
See what you are collecting
We list what your site collects, in plain words. This is how you find out whether you have a problem at all.
Cookie scannerAsk for consent, free
Asks before anything loads, and records who said yes. Free on one site, installed by us. The one on this page is ours.
Consent banner / CMPKeep it current
Add a tool and your popup is suddenly lying about what you collect. We re-check monthly and keep the policy matching reality.
Auto-updated consentAnswer data requests
Customers can legally ask to see, correct or delete what you hold. One page catches those, with the clock running on each.
DSAR portalShow customers you're clean
A public page listing what your site collects and why. Useful when a tender asks you to prove it.
Trust / transparency pageNo PDPA on your site at all?
Most Malaysian SMEs are. We do the whole thing and keep it running. You do nothing.
Fully managedThe popup is free. Proving it is what you pay for.
Asking for consent should not cost anything, so it does not. You pay when you want the record of who agreed to what, kept somewhere you can get at it, because that is what you would have to produce if anyone asked.
Roughly half what the international tools charge, billed in Ringgit so there is no card surprise. No setup fee, cancel any time. Several sites or a group of companies works out cheaper per site.
Consent popup
The popup on one website, asking before anything loads. We install it.
- Consent popup on one website, installed by us
- Actually blocks trackers until someone agrees
- Consent log, last 30 days, so you can prove someone said yes
- English or Bahasa Malaysia
- "Powered by Orbix Compliance" on the banner
Consent records
A login where you can see every consent, and proof you can hand over.
- Everything in the free popup
- Log in and see every consent: what each visitor allowed, and when
- Records kept 12 months, exportable as a spreadsheet
- Monthly re-scan, and the popup list updated when your site changes
- We email you when a new tracker appears
Kept current
Your privacy policy written and maintained, and the banner tuned per country.
- Everything in Consent records
- Privacy policy written for you and kept matching what your site does
- Geo-targeting, so Malaysian, EU and UK visitors each see what applies
- Weekly re-scan instead of monthly
- Orbix branding removed from your banner
Data requests
Somewhere for "show me my data" and "delete my data" to land, with the clock running.
- Everything in Kept current
- A page where customers send data requests: see, correct, delete, or move their data
- 21-day countdown on every request, the deadline the PDPA sets
- A written record of each request and how you answered it
- Someone to call when you are not sure
Group or multi-site
Several brands, subsidiaries, or an agency looking after client sites.
What gets saved when someone clicks
If a customer ever complains, or the Commissioner asks, this is what proves they agreed. None of it identifies anybody.
| Who | A random code for that browser, like a cloakroom ticket. Not a name, not an email, not a phone number.a1f7c2e9-4b |
| When | The date and time they chose, down to the second.26 Aug 2026, 2:32:07pm |
| What they said | Which boxes they allowed and which they refused.Analytics: no · Marketing: no |
| What they were shown | Which version of the popup was on screen, so nobody can argue later that the wording was different.Popup version 3 |
| Roughly where from | Their rough location, blurred on purpose so it cannot be traced back to a person.Malaysia |
Saved on our server, not on the visitor's computer. If they clear their browser, your proof is still there. That is how the serious consent tools do it, and it is the part a screenshot of your banner cannot replace.
A cookie popup is not full compliance.
It covers your website, which is one slice. Your staff files, CCTV, customer database, supplier contracts and retention are all still sitting there untouched.
Anyone selling a banner as "PDPA done" is overselling. The rest needs a human, and that is the other half of what Orbix does.
Send us your link. We will put the popup on it.
This opens WhatsApp with your details ready to send, so you are not waiting on an email that never comes back.
Usually back the same working day, from Kuala Lumpur.
- Run by Orbix Tech Sdn Bhd from Kuala Lumpur, not a reseller
- The consent popup on this page is our own product, running live
- See a real scan report before you ask for one
- A person answers WhatsApp, usually the same working day
Are you already breaking it?
Plain answers about what the PDPA actually asks of you, so you can work out where you stand.
General information, not legal advice. Still stuck? Message us on WhatsApp, a person replies.
How do I know if I'm already breaking it?
Open your website. If anything loads before you are asked, and your site runs Google Analytics, a Facebook or TikTok pixel, or any ad tool, then you are collecting data about visitors without asking. Under the PDPA that is the gap most Malaysian sites have. It takes about a day to fix.
What can a customer legally ask me for?
More than most owners expect. Under the PDPA they can ask to see the data you hold on them, correct it, withdraw consent they gave earlier, and stop you using it for marketing. The 2024 amendments added moving it to another provider. You have to answer, and "we don't keep records like that" is not an answer.
How long do I have to answer them?
Twenty-one days from the day the request arrives, for someone asking to see their data. Limited situations let you take longer. Doing nothing is not one of them. The usual failure is not the deadline, it is the request sitting in a shared inbox with nobody watching the clock.
What happens if I just ignore all this?
Breaching the PDPA carries penalties, including fines and imprisonment for some offences. Realistically the first step is one annoyed customer complaining to the Commissioner. You then fix everything anyway, on someone else's deadline, with your name on it. This is not legal advice; if you think you have a live problem, speak to a lawyer as well as to us.
Is the popup really free?
Yes. One website, installed by us, yours to keep, no card. We are not charging you to ask your own customers a question. Paid plans start at RM 19 a month, about half what the international tools charge, and what you get for that is a login showing every consent you have collected, kept for twelve months and exportable, which is the proof you need if anyone ever asks.
I'm not technical. Do I have to install anything?
No. Send your website address and we handle it. WordPress and Shopify have a plugin; anything else is one small piece of code we add for you. You should not have to check on it afterwards either.
Will this make me fully PDPA compliant?
No, and we would rather say so now. It covers your website, which is the part customers see. It does nothing about staff records, CCTV, your customer database, supplier contracts or how long you keep files. That needs a person, and it is a separate service.