Comprehensive Privacy Law
Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024
Malaysia · November 15, 2013; the 2024 amendments were phased in between January 1 and June 2025
Verify detailsSection 2 applies the PDPA to a person established in Malaysia processing personal data (including where processing happens abroad, if the data is intended to be further processed in Malaysia), and to a person not established in Malaysia who uses equipment in Malaysia for processing otherwise than for mere transit — an equipment/establishment test, not a GDPR targeting test, so the trigger below is modeled on established presence only. Section 3 excludes the federal and state governments and processing outside Malaysia not intended for further processing in Malaysia. The Personal Data Protection (Amendment) Act 2024 was the first substantial overhaul since 2010, phased in across the first half of 2025: mandatory data-protection officer appointment (notified to the Commissioner) for qualifying controllers, mandatory breach notification to the Commissioner within 72 hours (and to affected individuals where significant harm is likely), a new data-portability right, direct statutory obligations on data processors, and the relabeling of 'data user' as 'data controller'. Supporting guidelines on DPO appointment, breach notification, and cross-border transfers followed in 2025.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.