WorkBuddy and data compliance in Malaysia (PDPA)
If your Malaysian business handles personal data, WorkBuddy and PDPA sit in the same conversation. The Personal Data Protection Act 2010 governs how you collect, use and store personal data, and it applies to what you do with an AI tool just as it applies to what you do with email. The tool does not change your obligation. What changes is where the data flows and who needs to be careful.
This page is practical guidance, not legal advice. It explains what WorkBuddy handles, how the desktop app works with your files, and the questions to take to your data protection officer or DPO before you put customer data through any AI tool.
Key takeaways
- PDPA 2010 applies to you, not to the tool. Using AI does not move your legal duties.
- WorkBuddy's desktop app reads and writes files only in folders you authorise. Keep that scope narrow.
- WorkBuddy processes the text, files, audio and commands you give it — so share what the task needs and nothing more.
- For Malaysia, WorkBuddy's data controller is Tencent Cloud International Pte. Ltd. (Singapore), and Tencent's terms name no Malaysian data-residency guarantee.
- Treat the tool like a business email: send what the job requires, and keep personal data to the minimum.
What WorkBuddy handles
WorkBuddy acts on what you give it. That means the text of your requests, the files it reads from authorised folders, any audio you provide, and the commands it runs. The desktop app works inside directories you explicitly approve — it does not roam your whole drive unless you let it.
The practical effect is simple. The agent's reach is the folder you hand it. Narrow that folder and you narrow the data in play.
Text prompts
You type them — so you control what you choose to include.
Files
Read and written in authorised folders — you control which folders you approve.
Audio
Only if you provide it — you control whether you upload any.
Commands
The tasks you request — you control what you ask it to do.
What PDPA means for AI use in Malaysia
PDPA 2010 sets out principles for handling personal data — how you collect it, what you use it for, how long you keep it, and how you protect it. When you run customer or employee data through an AI tool, those principles still apply. The tool is a processor in your workflow; the responsibility for lawful handling stays with your business.
That is why the safe pattern is the one you would use for any third-party service: understand what data leaves your control, have a lawful basis for using it, and keep it to what the task needs.
For role-specific detail, see how teams handle this in practice on our HR use cases and finance use cases pages.
Practical steps before you send data
None of this needs to be complicated. Six habits cover most of the ground.
Authorise the narrowest folder possible
One project directory, not your shared drive.
Minimise
Give the agent the files the task needs, not the whole case file.
Classify first
Know which files contain personal data before they go anywhere near the tool.
Check the provider's terms
Read WorkBuddy's privacy policy and data-processing terms, and store a copy for your records.
Involve your DPO early
If you have one, ask before the first upload — not after.
Review before you send
Treat output as a draft; a human checks before anything goes to a client or a regulator.
Where your data goes, and what the terms say
Two points matter before you put personal data through the tool. First, the data controller for users outside mainland China is Tencent Cloud International Pte. Ltd. (Singapore), and Tencent's terms name no Malaysian data-residency guarantee — so data may be processed outside Malaysia. Second, Tencent's international terms contain no Malaysia-specific data-protection provisions, so your PDPA duties stay with your business.
WorkBuddy's inputs are processed by third-party large language models, and Tencent advises not to include personal information in your prompts. If data residency is a hard requirement for your business, raise it directly with Tencent or with a local partner who can get you an answer in writing — and check the position with your DPO before you rely on it.
Questions to take to your DPO
Bring these five and you will cover the decision:
- Which of our workflows would send personal data through an AI tool?
- Do we have a lawful basis for that use under PDPA?
- Where is the data processed, and for how long is it retained? (Tencent's terms name no Malaysian residency guarantee.)
- What is our retention and deletion practice on our own sides — the folders we authorise?
- Who reviews the output before it reaches a customer?
Using it without overexposing data
You do not need to avoid AI to comply with PDPA; you need to use it with the same care you apply to any data processor. Start on the free plan, keep folders narrow, and run tasks that do not carry sensitive personal data until your DPO has signed off on the rest. You can download the international edition and understand the free credits first, then read the FAQ for the practical questions.
This page is guidance, not legal advice. For your specific obligations, consult your DPO or a qualified adviser.
Is WorkBuddy PDPA-compliant?
Be careful with that phrase. Tencent's international terms contain no Malaysia-specific data-protection provisions, so there is no blanket "PDPA-compliant" label to rely on. Using the tool does not move your legal duties under PDPA 2010 — your business remains responsible for lawful handling.
Where is WorkBuddy's data controller?
For users outside mainland China, the data controller is Tencent Cloud International Pte. Ltd. (Singapore). Tencent's international terms name no Malaysian data-residency guarantee.
Does my data stay in Malaysia?
There is no such assurance. Tencent's terms name no Malaysian data-residency guarantee for WorkBuddy, and inputs are processed by third-party large language models. If residency is a hard requirement, raise it with Tencent or a local partner before you rely on it.
What must I do under PDPA before using WorkBuddy?
Obtain your own consents — PDPA duties stay with your business. Authorise the narrowest folder possible, keep personal data to what the task needs, involve your DPO before the first upload rather than after, and review output before it reaches a client or a regulator.
Next step
Set up on the free plan with a narrow authorised folder, run a non-sensitive task first, and take the questions above to your DPO before handling personal data.