27Gems
Are we registered under Malaysia's PDPA?
Last updated: 15 September 2026
27Gems complies with the rules of PDPA, and GDPR. We are however, not required to be registered with the respective authorities.
The short version
The Personal Data Protection (Class of Data Users) Order 2013 lists the specific kinds of businesses that must register: banks, insurers, telcos, private hospitals and clinics, licensed tour operators, seven named airlines, registered private schools, licensed direct-selling companies, law/audit/accountancy/engineering/architecture firms, retail and wholesale dealers, employment agencies, licensed housing developers, and a named list of water and electricity companies.
27Gems is not one of the listed categories.
What this doesn't mean
Not being on the registration list isn't the same as being outside the law. The Personal Data Protection Act's actual rules — how personal data can be collected, used, and kept — apply to us regardless. We follow them, and we follow the EU's GDPR on top, voluntarily. See our Privacy Policy for what we collect, why, and how to ask us to change or delete it.
Checking this yourself
This page reflects our own reading of the published Order — Personal Data Protection (Class of Data Users) Order 2013, P.U. (A) 336 — not a formal ruling from the Department of Personal Data Protection. If you want to verify it, the Order is public, or you can ask us directly at admin@27gems.com.