Cross-Border Data Transfer
Personal Data Protection Act 2010 — cross-border transfer of personal data
Malaysia · January 1, 2025 (the amended s. 129)
Verify detailsMalaysia removed its whitelist. The old s. 129 let the Minister gazette permitted destination countries; the 2024 amendment repealed that mechanism outright — and, with it, the public-interest limb the Minister could invoke — replacing it with a conditions-based test. A transfer is now permitted where the destination has a law in force that is substantially similar to the PDPA, or otherwise ensures an adequate level of protection at least equivalent to the PDPA's, or where one of the other prescribed conditions is satisfied. The Commissioner's Guidelines on Cross Border Personal Data Transfer, issued April 29, 2025, set out how the assessment is expected to be run. Marked 'check': this is a recent structural change and the guidelines are the operative document — read them rather than the bare statute.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.