WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

Personal Data Protection Act 2010 — cross-border transfer of personal data

Malaysia PDPA s. 129

Malaysia · January 1, 2025 (the amended s. 129)

Verify details

Malaysia removed its whitelist. The old s. 129 let the Minister gazette permitted destination countries; the 2024 amendment repealed that mechanism outright — and, with it, the public-interest limb the Minister could invoke — replacing it with a conditions-based test. A transfer is now permitted where the destination has a law in force that is substantially similar to the PDPA, or otherwise ensures an adequate level of protection at least equivalent to the PDPA's, or where one of the other prescribed conditions is satisfied. The Commissioner's Guidelines on Cross Border Personal Data Transfer, issued April 29, 2025, set out how the assessment is expected to be run. Marked 'check': this is a recent structural change and the guidelines are the operative document — read them rather than the bare statute.

Act 709, s. 129, as substituted by the Personal Data Protection (Amendment) Act 2024 (Act A1717); Guidelines on Cross Border Personal Data Transfer (April 29, 2025)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.