Written by the ITG Telecommunication team · Published 13 Aug 2026
If you run outbound campaigns in Malaysia, confirming seven concrete trust signals for any predictive dialer (like XPERT Dialer) saves downtime, fines, and unhappy customers.
- Confirm your vendor’s MCMC licence and written 99%+ uptime SLA — a licence shows regulatory standing; a clear SLA explains how 99% is measured and what credits you get if it fails.
- Ask for PDPA‑ADMP / DPIA evidence: Malaysia’s JPDP guidance (April 2026) treats automated profiling and decisioning as a DPIA trigger — predictive dialing often qualifies.
- Check measurable QoS limits (latency, packet loss, jitter, MOS) and an independent monthly report — ITU guidance recommends one‑way delay ≤150 ms for acceptable voice quality.
You want a predictive dialer that actually increases agent talk time — not one that creates compliance risk, noisy calls, or finger‑pointing when service dips. Predictive dialers like XPERT Dialer deliver efficiency by dialling multiple numbers and connecting agents only on live answers. But that automation also concentrates operational, data‑protection and regulatory risk into a single vendor contract. Before you sign, your CX, legal and IT teams should verify seven specific trust signals so “99% SLA” and “MCMC‑licensed” are more than marketing lines. This post gives a practical checklist (with the exact evidence to request), shows what 99% uptime usually hides, explains why Malaysia’s April 2026 PDPA guidelines matter for dialers, and points you to the contract clauses and live metrics you should insist on.
1. Is the vendor MCMC‑licensed and in what class? Ask for the licence number
Direct answer: A vendor’s MCMC registration or class licence is the first trust filter: it proves the provider accepts regulatory obligations under the Communications and Multimedia Act (CMA) and the MCMC licensing framework. Ask the vendor for the exact licence type and licence number and confirm it against MCMC’s licence guidance or by direct enquiry to MCMC.
Why this matters: class licences and licence conditions determine audit powers, reporting obligations, and whether the vendor must comply with sector‑specific technical codes. For example, the MCMC Licensing Guidebook explains the ASP (Applications Service Provider) class licence and the difference between individual and class licences — the registration type affects your rights and the regulator’s powers over the vendor. Request the licence reference and a copy of the registration certificate; if the vendor hesitates, escalate.
Further reading: MCMC Licensing Guidebook (annexes and class licence overview)
2. Does the 99% SLA define measurement windows, exclusions and remedies?
Direct answer: “99% uptime” is only useful if the SLA spells (a) the measurement period (monthly vs calendar), (b) exactly which systems are included (telephony gateway, SIP trunk, management console, web UI), (c) planned maintenance windows and permitted force‑majeure, and (d) the financial or service credits that trigger when uptime drops below target.
Practical checks: demand the SLA’s uptime definition, the monitoring method (probe locations and frequency), and an example calculation for a failed month. Make sure the SLA has an objective credit formula (e.g., X% credit for each 1% below 99%) and an incident escalation/resolution timeline. If high‑availability is business‑critical, require monthly SLA reports and a P1 escalation path to named contacts.
For legal review, align SLA language with telecom expectations in Malaysia and include an onshore dispute resolution clause where possible. For technical teams, add an annex that defines acceptable failover behaviour (session persistence, call requeueing).
3. Has the vendor completed a DPIA or documented how predictive dialing triggers ADMP rules under PDPA?
Direct answer: Malaysia’s JPDP guidance (April 2026) treats automated decision‑making and profiling as an automatic DPIA trigger. Because predictive dialers profile call lists, prioritise leads, or adjust dial pacing using algorithms, the vendor must either support your DPIA or provide its own DPIA evidence and contractual cooperation.
What to request: a copy of the vendor’s DPIA template or completed DPIA for your use case, a privacy notice draft that explains ADMP/automated profiling, and explicit contractual cooperation for JPDP audit requests. If the vendor processes sensitive data or runs profiling at scale, verify whether a Data Protection Officer (DPO) is appointed and reachable.
Further reading: JPDP Data Protection Impact Assessment Guideline (DPIA)
4. Is call recording, storage and retention PDPA‑compliant (consent, retention limits, access)?
Direct answer: Predictive dialers commonly record calls and store metadata. You must verify where recordings are stored, retention windows, encryption in transit & at rest, deletion procedures, and that the privacy notice and consent capture meet PDPA notice and retention principles.
Evidence to demand: encryption standards used (e.g., TLS/SRTP for media, AES‑256 at rest), a data retention schedule mapped to your legal needs, a deletion proof process (how deletions are logged), and a sample privacy notice and consent text the vendor will display or record. Also confirm cross‑border transfer arrangements and subprocessors used for storage or AI transcription.
5. Do voice quality and network QoS metrics meet ITU recommendations (latency, jitter, packet loss, MOS)?
Direct answer: Good voice experience is measurable: one‑way latency should aim ≤150 ms (ITU guidance); packet loss should be low (ideally <1–2% average), and jitter should be bounded with jitter buffers. Ask your vendor for monthly QoS reports and the MOS or E‑Model figures they observe for peak campaigns.
What to include in the contract: target thresholds (one‑way latency ≤150 ms, packet loss <2%, jitter <30 ms), a reporting cadence, test methodology (where probes are located) and corrective actions for sustained breaches. If voice quality is the business metric, require sample call traces or pcap exports on request so your network team can root‑cause errors.
Further reading: ITU‑T G.114 recommendation on one‑way delay and Cisco: Quality of Service for VoIP (guidance)
6. How does the dialer honour DNC lists, unsubscribe rules and anti‑spam laws in Malaysia?
Direct answer: Your predictive dialer must support Do‑Not‑Call lists, per‑campaign opt‑outs, and audit trails showing the vendor removed numbers as requested. For SMS or voice outreach, ensure the vendor enforces unsubscribe flows and keeps proof of prior consent where required.
Evidence to request: DNC/opt‑out handling documentation, a live sandbox showing suppression lists being applied, logs of opt‑out requests with timestamps, and a promise to honour regulatory takedown directives within a short window (e.g., 24–48 hours). Also confirm whether the vendor will perform number‑level MNP/DNC checks prior to large campaigns.
7. Is the vendor operationally supported in Malaysia (local support, runbook, backups, and incident reporting)?
Direct answer: Local operational support and a published incident runbook are core trust signals: ask for named escalation contacts in Malaysia, a sample runbook for P1 incidents, and evidence of local technical staff or onshore SLAs for onboarding and training.
Look for: a stated provisioning time for seats, documented onboarding and training scope, an incident response timeline, and a post‑incident RCA (root cause analysis) sample. For enterprise buyers, require a monthly performance dashboard and a quarterly service review, plus a dedicated onboarding and training plan for your agents.
“A trusted predictive dialer is where clear SLAs, documented PDPA/DPIA evidence, and measurable QoS meet—anything less raises operational or regulatory risk.” — ITGTEL product assurance
How to verify these 7 signals quickly: a 5‑minute vendor checklist
Direct answer: Use a focused vendor evidence request: (1) MCMC licence number & certificate, (2) copy of the SLA and an example monthly uptime report, (3) DPIA or DPIA‑support clause, (4) call‑recording security & retention policy, (5) monthly QoS report with MOS/latency/jitter, (6) DNC/consent logs and suppression demo, (7) local support contacts + incident runbook.
- Send a short RFI with the 7 items and a 7‑day deadline.
- Cross‑check the licence and key regulatory claims with your legal or with MCMC/JPDP contacts.
- Reject vendors who cannot show a DPIA or refuse to add a DPIA cooperation clause for ADMP activities.
How ITGTEL helps: what to ask ITGTEL for when evaluating XPERT Dialer
Direct answer: When you evaluate XPERT Dialer, ask ITG Telecommunications Sdn Bhd for the XPERT Dialer service page, a copy of its MCMC licence evidence, the precise SLA text, and sample DPIA/privacy notice drafts so your PDPA review is fast and conclusive.
If you want a hands‑on check, request a free demo and an evidence pack: SLA PDF, network QoS sample, retention schedule, and named onshore support contacts. ITG Telecommunications Sdn Bhd has over 20 years in Malaysia and provides predictive dialer packages — request the relevant subscription page for exact inclusions and trial terms.
Relevant product pages: XPERT Dialer (Predictive Dialer), Xpert Predictive Dialer 12 Month, Xpert Predictive Dialer 1 Month.
VoIP SLA Checklist 2026: 7 Contract Clauses Malaysian SMEs Must Require
Common mistakes Malaysian CX teams make (and how to avoid them)
Direct answer: The top mistakes are trusting marketing SLAs, ignoring DPIA/PDPA triggers for profiling, skipping real QoS tests, and failing to require DNC suppression demos. Avoid them by insisting on evidence, documented tests, and contractual cooperation clauses.
- Signing with “99%” without receiving sample monthly uptime reports — ask for three months of historic data.
- Assuming automated scoring is harmless — treat any automated profiling as a DPIA trigger under JPDP guidance.
- Not clarifying whether call recording is encrypted and how long recordings are retained — get the retention schedule in writing.
Do predictive dialers always trigger a DPIA under Malaysia’s PDPA?
Not always, but often. Malaysia’s JPDP guidance (April 2026) treats automated decision‑making and profiling as a qualitative DPIA trigger. If the dialer profiles, scores leads, or auto‑prioritises contacts, plan to run a DPIA or obtain vendor DPIA support before production.
Is a 99% SLA “good enough” for call centres?
It depends on measurement and impact. 99% monthly uptime still allows ~7 hours of downtime per month; confirm what systems are included, measurement method, and the credit/remedy schedule. For mission‑critical operations, consider 99.9% or multi‑region redundancy and test failover.
What voice quality numbers should I demand from a dialer vendor?
Ask for one‑way latency targets ≤150 ms (ITU guidance), packet loss averages <2%, jitter <30 ms, and a monthly MOS/E‑Model report. Require test methodology and probe locations so you understand where problems originate.
Who at my company should own these checks?
Make this a cross‑functional buy: IT/network owns QoS & failover tests; Legal/compliance owns PDPA/DPIA and MCMC checks; CX/operations owns SLA acceptance criteria, onboarding and agent training; Procurement owns contract language and remedies.
Further reading: MCMC Licensing Guidebook (licence types & class licence overview)
Further reading: ITU‑T Recommendation G.114 — One‑way delay guidance for voice
Further reading: Cisco — Quality of Service for VoIP (design & thresholds)