If your phone shop collects IC and payslip photos on WhatsApp, PDPA rules apply to every copy: tell customers why you need them, collect only what the financing partner requires, keep the files out of staff phones and group chats, and delete them on a fixed schedule. Since the 2024 amendments, a breach can mean notifying the Commissioner within 72 hours and fines up to RM1 million.
Examples show a proposed workflow, not a guarantee that every account or plan supports it. Ask our team to confirm the channel, integration, permissions and delivery method for your setup. Staff-group notifications and group assistants require separate eligibility and integration checks; a standard one-to-one WhatsApp API account should not be assumed to access every existing staff group. Use approved individual notifications or a staff dashboard if group delivery is unavailable. Test the workflow and human handover before use.
WhatsApp's Business Messaging Policy says not to share or request full personal ID numbers, financial account numbers or other sensitive identifiers. Use WhatsApp for a checklist and appointment, not for full MyKad, bank-statement or payslip uploads. Collect required documents through your authorised secure portal or in person, with a privacy notice, limited access and a documented retention period. Healthcare chats should remain administrative; do not request clinical records or diagnose through the bot.
- An IC or payslip photo is personal data under the PDPA the moment it lands in your WhatsApp — and so is every forwarded or downloaded copy.
- Collect only what your financing partner actually asks for; if the partner has its own secure upload or eKYC link, use that instead.
- Move documents out of staff phones and group chats into one restricted folder, and mask IC numbers in your tracking sheet.
- Set a written retention rule (for example: delete rejected applications after 30 days) and follow it.
- Since 1 June 2025, a data breach may need to be reported to the Commissioner within 72 hours and to affected customers within 7 days.
- This is general information, not legal advice — confirm your process with a lawyer or your DPO.
Why do IC and payslip photos on WhatsApp need special care under PDPA?
An IC photo plus a payslip is almost everything a fraudster needs to open an account in someone else's name.
Phone shops that offer instalment plans — whether through a bank, a financing company or a buy-now-pay-later partner — usually need proof of identity and income. In Malaysia that often means a customer sends a photo of their MyKad (front and back) and one to three months of payslips on WhatsApp.
Under the Personal Data Protection Act 2010, all of this is personal data processed in a commercial transaction. Strictly speaking, an IC number and a salary figure are not in the Act's list of "sensitive personal data" (that list covers health, religious and political beliefs, criminal records and, since 2024, biometric data). But in practice they are high-risk: a leaked IC copy can be misused for scams, SIM-card fraud or fake loan applications.
The problem is not WhatsApp itself. The problem is what happens after the photo arrives:
- It is auto-saved into a salesperson's personal phone gallery.
- It is forwarded to a staff WhatsApp group so "someone can check".
- It is downloaded to the shop PC and emailed to the financing partner.
- Nobody deletes any of the copies when the application is rejected.
Each copy is another place where the data can leak. Handling IC and payslip photos on WhatsApp under PDPA is really about controlling copies.
What changed in the PDPA amendments for phone shops?
The Personal Data Protection (Amendment) Act 2024 came into force in phases between January and June 2025. For a phone shop handling IC and payslip photos on WhatsApp, these are the changes that matter most (summarised from Mayer Brown and DLA Piper):
| Change | What it means for your shop | In force |
|---|---|---|
| Higher penalties | Breaching the data protection principles: fines up to RM1,000,000 and/or up to 3 years' jail (previously RM300,000 / 2 years) | 2025 |
| Data breach notification | Notify the Commissioner within 72 hours; notify affected customers within 7 days if significant harm is likely | 1 June 2025 |
| Data Protection Officer (DPO) | Required if you process data of more than 20,000 people, sensitive data of more than 10,000, or do regular and systematic monitoring | 1 June 2025 |
| Data portability | Customers can ask for their data to be sent to another organisation, where technically feasible | 1 June 2025 |
| Security principle for processors | Service providers that process data for you must also keep it secure | 2025 |
A single outlet may well be below the DPO thresholds, but a chain with years of instalment customers might not be. Count your records before you assume you are exempt.
We are not lawyers. This article is general information to help you ask the right questions. For your exact obligations, speak to a lawyer or check the guidelines published by the Personal Data Protection Department.
Which documents should a phone shop actually ask for?
The first PDPA habit is also the cheapest: collect less. Ask your financing partner for their exact document list and do not ask for more "just in case".
- MyKad: front and back, only if the partner needs it. Do not ask for a selfie holding the IC unless the partner's process requires it.
- Income proof: the number of payslips the partner asks for — often the latest one to three months. Customers can cover unrelated details such as bank account numbers if the partner allows it.
- No extras: no photos of bank cards, no passwords, no screenshots of banking apps. Ever.
If your financing partner offers its own eKYC app or secure upload link, send the customer that link instead of collecting documents yourself. The best copy to protect is the one you never had.
If you run instalment plans in-house rather than through a partner, check separately whether you need a licence under the Consumer Credit Act 2025. The Act came into force on 1 March 2026 and licensing under Part V started on 1 June 2026, with a transition period whose end date you should confirm with the Consumer Credit Commission (SKP). If your plan is a hire-purchase agreement, the Hire-Purchase (Amendment) Act 2026 (in force 1 June 2026, with a provider grace period to 31 March 2027 per Bank Negara Malaysia) may apply to consumer goods such as phones sold on hire purchase – confirm with KPDN or your lawyer. Either way, avoid interest-free or guaranteed-approval claims.
How should a phone shop handle IC and payslip photos on WhatsApp, step by step?
Notify → Collect → Move → Mask → Share → Delete → Log
Here is a practical routine that keeps the PDPA risk of IC and payslip photos on WhatsApp low without slowing down sales:
- Notify before you collect. Before asking for any document, send a short notice: what you need, why (the instalment application), who will see it (your team and the named financing partner) and how long you keep it. This is the PDPA Notice and Choice principle in one message.
- Collect only the list. Send the exact checklist and nothing else.
- Move documents to one place. Save them into a single restricted folder (for example a Google Drive folder only two staff can open), then delete them from the chat device and from any phone gallery.
- Mask in your tracking sheet. Your CRM or Google Sheet only needs the last 4 digits of the IC, not the full number, and never the salary figure.
- Share through the partner's channel. Upload to the financing partner's portal rather than forwarding photos in WhatsApp groups.
- Delete on schedule. Set a retention rule, for example: rejected or abandoned applications deleted after 30 days; approved ones kept only as long as the partner agreement or law requires.
- Keep a simple log. Record when documents were received, shared and deleted. If something goes wrong, this log is what you will need within 72 hours.

What should the customer see in the WhatsApp chat?
A good document request is short, polite and transparent, and it comes after the customer has decided to apply. The customer should know what happens to their IC before they send it — not after. Here is an illustrative conversation for a fictional shop, Nova Mobile in Seremban, where an AI assistant handles the first enquiry and a staff member takes over for the application.

Three details matter in this chat. The purpose and the partner are named. The customer is told how to withdraw. And the AI does not make approval promises — it says the team will review and the partner decides.
Because ChatsHero replies 24/7 in English, Bahasa Melayu and Chinese, the same PDPA notice can be given in the customer's own language – even when the question itself mixes all three (see how that works).
Want to see how this looks with your own business? WhatsApp us and chat with the ChatsHero AI.
Where should IC and payslip photos be stored — and who can see them?
The PDPA Security principle asks you to take practical steps to protect personal data from loss, misuse and unauthorised access. For a small shop, that mostly comes down to where the photos sit and who can open them.
| Where the photo ends up | Risk | Better practice |
|---|---|---|
| Salesperson's personal phone gallery | High — leaves with the phone and the staff member | Turn off media auto-download on work phones; delete after moving |
| Staff WhatsApp group | High — every member gets a copy | Post only "Docs received for Ahmad, IC ending 1234" |
| Shop PC downloads folder | Medium — shared logins, no deletion | Move to a restricted folder the same day |
| Restricted cloud folder (2 named staff) | Lower | Use 2-step verification; review access monthly |
| Financing partner's secure portal | Lowest for you | Upload, then delete your own copy when allowed |
Simple access rules help too: remove former staff from every folder and WhatsApp group on their last day, and never share one login between salespeople.
How can a WhatsApp chatbot help with PDPA when collecting IC and payslip photos?
A chatbot cannot make you compliant on its own, but it can make the good habits consistent. With ChatsHero, the AI can send the same purpose notice and document checklist every time, answer "why do you need my IC?" questions at 11pm, and hand the chat to a human when documents arrive.
- Same notice every timeNo salesperson forgets to explain purpose and retention.
- Human handoverA "Human Agent Needed" alert tells the assigned staff that documents are ready to review.
- Masked trackingThe Google Sheet records status and the last 4 IC digits only.

Your sheet becomes the checklist for deletion: every row has a "delete by" date. Plans and features are on our pricing page.
What should you do if IC or payslip photos leak?
A lost staff phone, a photo sent to the wrong group, or a hacked email account can all count as a personal data breach. Under the breach notification rules in force since 1 June 2025, the steps look like this:
- Contain it. Remotely wipe or lock the device, remove the wrong recipients, change passwords.
- Assess it. Whose documents were involved, how many people, and could it cause significant harm such as identity fraud?
- Notify. Where the rules apply, notify the Personal Data Protection Commissioner as soon as practicable and within 72 hours, and affected customers within 7 days if significant harm is likely.
- Record it. Keep a breach register entry with what happened and what you changed.
Write this plan down now, while nothing has gone wrong. If you want the notice and checklist built into your WhatsApp flow, our team can help.
Is it still worth collecting documents on WhatsApp at all?
Often, yes – WhatsApp is where the conversation already is, and asking a customer to install an unfamiliar app adds a step. But if your financing partner has a secure upload link, that is the better route. The goal is not to stop using WhatsApp, but to treat every IC and payslip photo as something you must justify, protect and eventually delete. A clear notice also builds trust: customers can see exactly what happens to their documents.
This week, write your retention rule on one page and add a "delete by" column to your tracking sheet. Related guides on instalment enquiries are in the ChatsHero blog.
Frequently Asked Questions
Is it legal to collect IC and payslip photos on WhatsApp under PDPA?
Use an authorised secure portal or an in-person check for required identity, bank or health documents. WhatsApp should provide the checklist and instructions, not request full identifiers or confidential records. Give a privacy notice, restrict access and delete data according to your lawful retention schedule.
Is an IC number sensitive personal data under the PDPA?
Not in the Act's legal definition, which covers health, religious and political beliefs, criminal records and biometric data. However, IC and payslip copies are high-risk for identity fraud, so they deserve strong protection.
How long can a phone shop keep customers' IC copies?
Only as long as needed for the purpose. A practical approach is a written rule, for example deleting rejected applications after 30 days and keeping approved ones only as long as the financing agreement or law requires.
Do I have to report a leaked IC photo?
Since 1 June 2025, a personal data breach may need to be notified to the Personal Data Protection Commissioner within 72 hours, and to affected customers within 7 days if significant harm is likely. Check the official guideline or a lawyer for your case.
Does my phone shop need a Data Protection Officer?
A DPO is required if you process personal data of more than 20,000 people, sensitive data of more than 10,000, or carry out regular and systematic monitoring. Most single outlets are below this, but chains should count their records.
Can a WhatsApp chatbot collect IC photos for me?
It can send the purpose notice and checklist consistently and hand the chat to your staff when documents arrive. Your team still decides where files are stored, who can open them and when they are deleted.
