WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Asia-Pacific

Malaysia Privacy & Data Protection Laws

Every regime below can apply to a business handling Malaysia residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

November 15, 2013; the 2024 amendments were phased in between January 1 and June 2025
Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024
Malaysia PDPA
Verify details

Section 2 applies the PDPA to a person established in Malaysia processing personal data (including where processing happens abroad, if the data is intended to be further processed in Malaysia), and to a person not established in Malaysia who uses equipment in Malaysia for processing otherwise than for mere transit — an equipment/establishment test, not a GDPR targeting test, so the trigger below is modeled on established presence only. Section 3 excludes the federal and state governments and processing outside Malaysia not intended for further processing in Malaysia. The Personal Data Protection (Amendment) Act 2024 was the first substantial overhaul since 2010, phased in across the first half of 2025: mandatory data-protection officer appointment (notified to the Commissioner) for qualifying controllers, mandatory breach notification to the Commissioner within 72 hours (and to affected individuals where significant harm is likely), a new data-portability right, direct statutory obligations on data processors, and the relabeling of 'data user' as 'data controller'. Supporting guidelines on DPO appointment, breach notification, and cross-border transfers followed in 2025.

Act 709, s. 2 (application), s. 3 (exclusions); amended by Act A1722 (Personal Data Protection (Amendment) Act 2024)Read regulation →

Cross-Border Data Transfer · 1

January 1, 2025 (the amended s. 129)
Personal Data Protection Act 2010 — cross-border transfer of personal data
Malaysia PDPA s. 129
Verify details

Malaysia removed its whitelist. The old s. 129 let the Minister gazette permitted destination countries; the 2024 amendment repealed that mechanism outright — and, with it, the public-interest limb the Minister could invoke — replacing it with a conditions-based test. A transfer is now permitted where the destination has a law in force that is substantially similar to the PDPA, or otherwise ensures an adequate level of protection at least equivalent to the PDPA's, or where one of the other prescribed conditions is satisfied. The Commissioner's Guidelines on Cross Border Personal Data Transfer, issued April 29, 2025, set out how the assessment is expected to be run. Marked 'check': this is a recent structural change and the guidelines are the operative document — read them rather than the bare statute.

Act 709, s. 129, as substituted by the Personal Data Protection (Amendment) Act 2024 (Act A1717); Guidelines on Cross Border Personal Data Transfer (April 29, 2025)Read regulation →

Data Security & Breach Notification · 1

June 1, 2025 (the breach-notification provisions of the 2024 amendment)
Personal Data Protection Act 2010 — data breach notification
Malaysia PDPA breach duty
Verify details

Malaysia had no mandatory breach notification at all until the 2024 amendment commenced on June 1, 2025. The regime it introduced: notify the Commissioner within 72 hours of becoming aware, with written reasons required if that is missed, and notify affected individuals within seven days where the breach causes or is likely to cause significant harm. Controllers must also maintain a data breach register for at least two years recording the nature of the breach, the data affected, and remedial steps. Marked 'check': the amendment is recent, and the Commissioner's implementing guidelines should be read alongside the statute for the operative definitions of 'significant harm' and the register's required contents.

Act 709, as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1717)Read regulation →

Other Asia-Pacific jurisdictions