WorldPrivacyAtlas
Laws by country

Comprehensive Privacy Law

Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024

Malaysia PDPA

Malaysia · November 15, 2013; the 2024 amendments were phased in between January 1 and June 2025

Verify details

Section 2 applies the PDPA to a person established in Malaysia processing personal data (including where processing happens abroad, if the data is intended to be further processed in Malaysia), and to a person not established in Malaysia who uses equipment in Malaysia for processing otherwise than for mere transit — an equipment/establishment test, not a GDPR targeting test, so the trigger below is modeled on established presence only. Section 3 excludes the federal and state governments and processing outside Malaysia not intended for further processing in Malaysia. The Personal Data Protection (Amendment) Act 2024 was the first substantial overhaul since 2010, phased in across the first half of 2025: mandatory data-protection officer appointment (notified to the Commissioner) for qualifying controllers, mandatory breach notification to the Commissioner within 72 hours (and to affected individuals where significant harm is likely), a new data-portability right, direct statutory obligations on data processors, and the relabeling of 'data user' as 'data controller'. Supporting guidelines on DPO appointment, breach notification, and cross-border transfers followed in 2025.

Act 709, s. 2 (application), s. 3 (exclusions); amended by Act A1722 (Personal Data Protection (Amendment) Act 2024)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.