Malaysia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Malaysia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Data can leave Malaysia, but you have to justify it yourself. Until 2024 the country ran an approved-destinations list; that list was scrapped and nothing replaced it. You now decide whether the destination protects data well enough, and you carry the risk if the regulator disagrees. Breaking the core duties is a crime, not a fine, and it can mean prison.
Data governance in Malaysia
The eight things that decide how you handle data about people in Malaysia. Same eight on every country page, so you can compare.
Who has to follow these rules
It reaches you only if you are set up in Malaysia, or if you use equipment inside Malaysia to process the data. Simply selling to Malaysians from abroad, with all your servers elsewhere, is not obviously enough. We found no size or revenue threshold in the law, checked on 18 August 2026. If the equipment test is what catches you, you must appoint a representative who is established in Malaysia.
- What you have to do here:
- Appoint a representative
Section 2 of the Personal Data Protection Act 2010 applies the Act to a person set up in Malaysia who handles personal data. It also applies to a person not set up in Malaysia who uses equipment in Malaysia to handle personal data, other than to pass it through the country. Section 2(3) makes that second group name a representative set up in Malaysia. This is the old European 'use of equipment' test. It is not the modern 'targeting' test used by the European Union General Data Protection Regulation. So the Act reaches foreign companies far less widely than most trackers assume. Two further limits matter more than the reach itself. Section 3 excludes the Federal Government and the State Governments entirely. Section 4 limits the Act to data handled 'in respect of commercial transactions'. That is defined to cover supply or exchange of goods or services, agency, investment, financing, banking and insurance.
Sources
- Official sourceDepartment of Personal Data Protection, Ministry of DigitalPersonal Data Protection Act 2010 (Act 709), sections 2, 3 and 4
pdp.gov.my
“tidak ditubuhkan di Malaysia, tetapi menggunakan kelengkapan di Malaysia bagi memproses data peribadi itu selain bagi maksud transit melalui Malaysia”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionAkta Perlindungan Data Peribadi 2010 (Akta 709) — legislation index
pdp.gov.my
Link checked 18 August 2026
Where the data is allowed to live
Yes, but you must do the homework yourself. Malaysia used to publish a list of countries you were allowed to send data to. That list was abolished by the 2024 amendment and no replacement list has appeared. You may now send data abroad if the destination's law is substantially similar to Malaysia's, or protects the data at least as well. If it does not, you fall back on a short set of narrow exceptions.
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent · Needed for a contract
The amended section 129 is a two-part test. Part one: the destination country has a law that is substantially similar to the Personal Data Protection Act 2010, or protects the data at least as well as that Act. Part two, where part one fails: you fall back on other grounds. Those include the person's consent, need for a contract, legal proceedings, vital interests, and having taken all reasonable precautions and exercised all due diligence. Industry overrides we could verify: (a) FINANCE (banks, insurers, takaful operators). Bank Negara Malaysia's Risk Management in Technology policy document of 28 November 2025 makes a financial institution consult the Bank before it first puts critical systems on a public cloud. The Bank must have access rights over any record, file or data held at a third party. Data at third-party providers must be recoverable in good time. There is no rule that data must stay in Malaysia, but there is a real approval gate. Rating data can leave only if conditions are met (b) GOVERNMENT. The privacy law does not apply to the Federal or State Governments at all. Public sector hosting runs off the National Cloud Computing Policy, approved by Cabinet on 18 June 2025, and the MyGovCloud public sector data centre arrangements. We could not verify whether those require data to stay in Malaysia, so we rate this unknown rather than guess. (c) DESIGNATED CRITICAL INFRASTRUCTURE. The Cyber Security Act 2024 puts duties on organisations designated as National Critical Information Infrastructure. We found no rule there that data must stay in Malaysia, but the power to designate is broad. We searched specifically for storage-location rules in payments, insurance, securities, health, telecoms, education, gambling and mapping. We could not confirm any from an official Malaysian source as at 18 August 2026. Several of those regulators' websites blocked automated access. So treat this as unconfirmed, not as proof that no rule exists.
Sources
- Official sourceDepartment of Personal Data ProtectionPublic Consultation Paper No. 05/2024 — Cross-Border Personal Data Transfer Guideline
pdp.gov.my
“Klausa 12 Rang Undang-Undang Pindaan memperkenalkan beberapa pindaan kepada Seksyen 129 APDP, iaitu: (a) pemansuhan senarai putih dengan memotong Seksyen 129(1)”
Link checked 18 August 2026
- Official sourceBank Negara MalaysiaRisk Management in Technology (RMiT) policy document, 28 November 2025
bnm.gov.my
“A financial institution is required to consult the Bank prior to the first-time adoption of a public cloud ... for critical systems.”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection (Amendment) Act 2024 (Act A1727)
pdp.gov.my
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Malaysia.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
There is no list to check and no permission to ask for. You assess the destination yourself, write down why you think it is safe enough, and keep that record. If you cannot show the destination is good enough, you need one of the narrow exceptions, such as the person's consent or genuine need to perform a contract. Standard contract templates and group-wide rules were proposed in 2024 but the final guideline still had not been published on 18 August 2026.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent · Needed for a contract · Legal claims · To save someone’s life
The model is: no government list, no government approval, you assess it yourself. The old approved-country list in section 129(1) was cut by the 2024 amendment, and we could find no replacement list from the Minister. The regulator's consultation paper 05/2024 ran from 1 to 18 October 2024 and proposed the supporting machinery. It suggested transfer impact assessments where you rely on the protection test. It suggested recognising group-wide rules without pre-approval, where they contain set minimum content. It suggested two families of standard contract clauses: a Malaysian minimum-clause set, and international model clauses such as the Association of Southeast Asian Nations and European Union templates. It suggested recognising certifications such as the Asia-Pacific Economic Cooperation Cross-Border Privacy Rules, alongside a binding agreement. And it suggested record-keeping to show you complied. Treat all of that as a proposal, not as law. The consultation closed in October 2024 and we found no final guideline on the regulator's own site as at 18 August 2026. A separate consultation, paper 4/2025, opened on 25 August 2025. It proposes changes to the Personal Data Protection Regulations 2013, which is where the binding detail is expected to land.
Sources
- Official sourceDepartment of Personal Data ProtectionPublic Consultation Paper No. 05/2024 — Cross-Border Personal Data Transfer, proposed mechanisms
pdp.gov.my
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPublic Consultation Paper No. 4/2025 — proposed amendments to the Personal Data Protection Regulations 2013
pdp.gov.my
Link checked 18 August 2026
The regulator, and whether it actually acts
The Department of Personal Data Protection, which sits under the Ministry of Digital, is the privacy regulator. It is properly staffed. A new Commissioner took office on 3 September 2025. The department published binding guidance and ran two public consultations during 2024 and 2025. What it has not done is punish much. The newest case on its own published penalty list dates from 2018.
Rating: a regulator just getting started Not dormant, and not active. Evidence that it is staffed and working: gazette notice P.U. (B) 341 appointed Shariffah Rashidah binti Syed Othman as Personal Data Protection Commissioner with effect from 3 September 2025. The department issued the Data Breach Notification guideline and circular, and the Data Protection Officer appointment guideline, both dated 25 February 2025. It runs a live breach reporting portal and a registration system for organisations that handle personal data. It opened public consultation 4/2025 on 25 August 2025. Evidence against an active enforcement record: the department's own 'Senarai Kes Kompaun' page, refreshed on 18 February 2025, lists compounds of RM10,000 each against two companies. Both are from 2018, and both were for failing to hold a registration certificate. We found no published fine or prosecution under the new 2024 duties. Other regulators that matter here and are clearly working: Bank Negara Malaysia for banks, insurers and takaful operators; the National Cyber Security Agency for designated critical infrastructure and for licensing cyber security service providers; the Malaysian Communications and Multimedia Commission for communications services; and the National Digital Department for public sector digital policy.
Sources
- Official sourceDepartment of Personal Data ProtectionP.U. (B) 341 — Appointment of the Personal Data Protection Commissioner
pdp.gov.my
“Menteri telah melantik Shariffah Rashidah binti Syed Othman sebagai Pesuruhjaya Perlindungan Data Peribadi berkuat kuasa mulai 3 September 2025.”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionTindakan Penguatkuasaan — list of compound cases under Act 709
pdp.gov.my
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencyCyber Security Act 2024 — National Cyber Security Agency
nacsa.gov.my
Link checked 18 August 2026
How long you must keep it — and when to delete it
The ceiling is a general one: do not keep personal data longer than you need it for the reason you collected it. Two very specific deadlines sit under that. Paper forms used to collect personal data in a commercial deal must be destroyed within fourteen days. And you must run a disposal schedule that clears out data that has been inactive for twenty-four months. Other laws that force you to keep records for longer win over all of this.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep records of how you use data
WHAT YOU MUST DELETE. The Retention Principle in section 10 of the Personal Data Protection Act 2010 says personal data must not be kept longer than you need it for the purpose. The Personal Data Protection Standard 2015 adds hard numbers. The Commissioner issued it on 23 December 2015 under regulations 6, 7 and 8 of the Personal Data Protection Regulations 2013. It says: destroy personal data collection forms used in commercial deals within fourteen days; prepare a disposal schedule for inactive data on a twenty-four month cycle; and keep a proper record of disposals, to be produced to the Commissioner on demand. WHAT YOU MUST KEEP. The Standard itself resolves the clash in favour of keeping. You keep personal data no longer than necessary, unless another law requires you to keep it. So a tax, company law, anti-money-laundering or industry record-keeping duty overrides the duty to delete. We could not verify the specific Malaysian retention periods against a government source. Those are commonly cited as seven years for tax and company records, and six years for anti-money-laundering records. See the unconfirmed list, and check them yourself before you set a schedule.
Sources
- Official sourcePersonal Data Protection CommissionerPersonal Data Protection Standard 2015 — retention and disposal standard
pdp.gov.my
“Dispose personal data collection forms used in commercial transactions within the period not exceeding fourteen (14) days”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection Act 2010 (Act 709), section 10 — Retention Principle
pdp.gov.my
“Data peribadi yang diproses bagi apa-apa maksud tidak boleh disimpan lebih lama daripada yang diperlukan bagi memenuhi maksud itu”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
You have seventy-two hours from the breach to tell the privacy regulator. If the breach is likely to cause serious harm, you have a further seven days to tell the people affected. If you cannot gather everything in time you may report in stages, but you must finish within thirty days. Missing the report is a crime carrying a fine of up to 250,000 Malaysian ringgit, roughly 59,000 US dollars, or up to two years in prison.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
- What it costs if you get it wrong:
- Criminal liability
Clock one, privacy. The Data Breach Notification circular and guideline were issued by the Personal Data Protection Commissioner on 25 February 2025 under section 12B of Act 709. You must tell the Commissioner as soon as practicable, and no later than seventy-two hours from the breach. You may report in stages, but you must finish no later than thirty days after the first report. Where the breach causes, or is likely to cause, significant harm, you must tell the affected people without unnecessary delay. That must happen no later than seven days after you notified the Commissioner. 'Significant harm' covers physical harm, financial loss, exposure of sensitive personal data, risk of identity fraud, or a breach affecting more than one thousand people. Clock two, cyber security. If you are designated as National Critical Information Infrastructure under the Cyber Security Act 2024, you must report cyber security incidents under the Cyber Security (Notification of Cyber Security Incident) Regulations 2024. We could not get the text of those regulations from a government source, so we do not state the hour count here. See the unconfirmed list. Clock three, financial. Banks, insurers and takaful operators also report technology and operational incidents to Bank Negara Malaysia, under the Risk Management in Technology and Operational Risk Reporting policy documents. The practical trap is the overlap: one incident, three regulators, three different formats.
Sources
- Official sourcePersonal Data Protection CommissionerPersonal Data Protection Guideline — Data Breach Notification, version 1.0, 25 February 2025
pdp.gov.my
“as soon as practicable and no later than seventy-two (72) hours from the occurrence”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionerData Breach Notification Circular (Pekeliling DBN)
pdp.gov.my
“masa tujuh (7) hari selepas pemberitahuan pelanggaran data dibuat”
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencyCyber Security Act 2024 subsidiary legislation, including the Notification of Cyber Security Incident Regulations 2024
nacsa.gov.my
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
First, the law does not apply to the Federal or State Governments at all, so a leak by a public body gives you no privacy remedy. Second, penalties here are criminal: breaking the core duties can mean up to one million Malaysian ringgit, roughly 235,000 US dollars, or three years in prison. Third, your data protection officer must speak both Malay and English. Fourth, you must shred paper collection forms within fourteen days.
- What you have to do here:
- Appoint a data protection officer · Delete data after a period · Register or notify
- What it costs if you get it wrong:
- Criminal liability
Trap 1 - the government is excluded. Section 3 of Act 709 says plainly that the Act does not apply to the Federal Government and the State Governments. Public sector data handling runs on policy, not on this law. You have no route to the privacy regulator against a ministry. Trap 2 - 'commercial transactions' only. Section 4 limits the Act to data handled in respect of commercial transactions. Anything outside a commercial context sits outside the Act. That is a very different design from the European model, and it catches people who assume the two are the same. Trap 3 - criminal, not administrative. The 2024 amendment raised the penalty for breaching the personal data protection principles. It went from 300,000 ringgit or two years, to one million ringgit (about 235,000 US dollars) or three years in prison, or both. Failing to report a data breach carries 250,000 ringgit (about 59,000 US dollars) or two years. These are prosecutions, and they can attach to individuals. Trap 4 - the data protection officer has personal qualifying conditions. The February 2025 guideline makes you appoint one where you handle the personal data of more than twenty thousand people. The same applies where you handle sensitive personal data, including financial data, of more than ten thousand people, or where you carry out regular and systematic monitoring. The officer must either live in Malaysia, meaning physically present at least one hundred and eighty days in a calendar year, or be easily contactable by any means. The officer must also be able to work in both the national language and English. You must register the appointment through the Personal Data Protection System within twenty-one days. Trap 5 - the small deadlines in the 2015 Standard. Destroy personal data collection forms used in commercial deals within fourteen days. Keep a written disposal schedule for data that has been inactive for twenty-four months. And do not use removable media to store personal data without written approval from your top management. An audit finds these instantly, and a compliance programme built to a European template never mentions them.
Sources
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection (Amendment) Act 2024 (Act A1727) — increased penalties, data protection officer, breach notification, data portability, biometric data
pdp.gov.my
“satu juta ringgit atau dipenjarakan selama tempoh tidak melebihi tiga tahun”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionerGuideline on the Appointment of a Data Protection Officer, version 1.0, 25 February 2025
pdp.gov.my
“bermastautin di Malaysia (iaitu berada secara fizikal di Malaysia untuk sekurang-kurangnya 180 hari dalam satu tahun kalendar); atau mudah dihubungi melalui apa-apa cara; dan mahir dalam Bahasa Kebangsaan dan Bahasa Inggeris.”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection Act 2010 (Act 709), section 3 — non-application to the Federal and State Governments
pdp.gov.my
“Akta ini tidaklah terpakai bagi Kerajaan Persekutuan dan Kerajaan Negeri”
Link checked 18 August 2026
What's changing next
The detail that makes sending data abroad workable is still missing. A consultation on rewriting the 2013 regulations opened on 25 August 2025 and those regulations are where the real rules are expected. A final cross-border transfer guideline was consulted on in October 2024 and still had not appeared by 18 August 2026. A national cloud policy was approved by Cabinet on 18 June 2025 but its terms are not public.
Landing in the next twelve months, on current evidence. 1. Amended Personal Data Protection Regulations 2013, following public consultation paper 4/2025, opened 25 August 2025. These are expected to carry the working detail on transfers, data protection officers and breach handling. No start date has been announced. 2. A final cross-border personal data transfer guideline, following consultation paper 05/2024, which ran from 1 to 18 October 2024. Twenty-two months later nothing final has been published on the regulator's site. So treat standard clauses, group-wide rules and certification routes as unavailable today. 3. Rollout of the National Cloud Computing Policy, approved by Cabinet on 18 June 2025. 4. The Data Sharing Act, passed by the Dewan Rakyat on 12 December 2024 and listed among the National Digital Department's laws. It covers data sharing between public sector agencies. We could not verify its act number or start date. POWERS ALREADY HELD that can change the answer without consultation. (a) The Minister sets the start dates for the 2024 amendment by gazette notice, and can pick different dates for different parts. So any part that has not yet started can be switched on overnight. (b) The Commissioner can issue binding standards directly under the 2013 regulations. That is exactly how the detailed 2015 Standard came about, with its fourteen-day and twenty-four-month rules. (c) The Minister can decide which classes of organisation must register. That turns a registration duty into a licensing gate for a whole industry. (d) Under the Cyber Security Act 2024, in force since 26 August 2024, the government can designate further sectors and organisations as National Critical Information Infrastructure. That pulls private companies into audit, risk assessment and incident reporting duties.
Sources
- Official sourceDepartment of Personal Data ProtectionPublic Consultation Paper No. 4/2025 — proposed amendments to the Personal Data Protection Regulations 2013, 25 August 2025
pdp.gov.my
Link checked 18 August 2026
- Official sourceMinistry of Digital MalaysiaMinistry of Digital — Cabinet approval of the National Cloud Computing Policy on 18 June 2025 and passage of the Data Sharing Bill 2024 on 12 December 2024
digital.gov.my
“Memorandum Jemaah Menteri (MJM) Dasar Pengkomputeran Awan Negara telah diluluskan oleh Jemaah Menteri pada 18 Jun 2025”
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencyCyber Security Act 2024 — commencement 26 August 2024 and designation powers
nacsa.gov.my
“26 August 2024 as the date on which the Act comes into operation”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries1 rule
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: Risk Management in Technology (RMiT) · Bank Negara Malaysia policy document on Risk Management in Technology, issued 28 November 2025 · Regulator directive
Banks, insurers and takaful operators may host data abroad, but they must consult the central bank before first putting critical systems on a public cloud, must give the regulator contractual access to the data wherever it sits, and must show they can get it back quickly.
Enforced by Bank Negara Malaysia
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyConsult Bank Negara Malaysia before adopting a public cloud for critical systems for the first time; later adoptions require notification with updated documentation.
- Written vendor contractThe contract must give the regulator, and anyone the institution appoints, access to any record, file or data held by the provider.
- Secure the dataCloud risk assessment must weigh the location of the cloud infrastructure, including geopolitical and legal risks that could impede compliance.
- Assess high-risk projectsDisaster recovery and backup arrangements must make data held at third parties recoverable in a timely manner.
Sources
- Official sourceBank Negara MalaysiaRisk Management in Technology (RMiT) policy document, 28 November 2025
bnm.gov.my
“access rights for the regulator and any party appointed by the financial institution to examine any activity or entity of the financial institution. This shall include access to any record, file or data of the financial institution”
Link checked 18 August 2026
- Official sourceBank Negara MalaysiaStandards and guidelines index — RMiT and Operational Risk Reporting policy documents
bnm.gov.my
Link checked 18 August 2026
Applies to every company6 rules
These bind you whatever business you are in, once the country's rules reach you.
Government data rules
Official name: Akta Perlindungan Data Peribadi 2010 (Akta 709), sebagaimana dipinda oleh Akta A1727 · Act 709, as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727) · Act of parliament
Malaysia's general privacy law. It covers organisations set up in Malaysia and foreign organisations that use equipment inside Malaysia, but only for commercial dealings, and it does not apply to the Federal or State Governments at all. Penalties are criminal.
Enforced by Department of Personal Data Protection
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, To save someone’s life
What you have to do
- Get consent
- Tell people what you do
- Secure the data
- Delete data after a period
- Let people see their data
- Let people correct their data
- Let people take their data elsewhereNew right added by the 2024 amendment: a person can ask for their data to be sent directly to another organisation, subject to technical feasibility and format compatibility.
- Register or notifyIf the Minister has listed your class of organisation, you must hold a registration certificate. Both published compound cases were for operating without one.
- Appoint a representativeRequired where the organisation is not established in Malaysia but uses equipment in Malaysia to process the data.
What it costs if you get it wrong
- Criminal liability: RM1,000,000 or 3 years imprisonment, or both — about $235 thousandContravening the personal data protection principles. Raised from RM300,000 and 2 years by the 2024 amendment.
Sources
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection Act 2010 (Act 709), consolidated text
pdp.gov.my
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection (Amendment) Act 2024 (Act A1727), royal assent 9 October 2024, published 17 October 2024
pdp.gov.my
Link checked 18 August 2026
Telecoms rules
Official name: Seksyen 129, Akta Perlindungan Data Peribadi 2010, sebagaimana dipinda · Act 709 section 129, as amended by Act A1727 clause 12 · Act of parliament
The old list of approved destinations was scrapped. Data may now leave Malaysia if the destination country's law is substantially similar to Malaysia's, or protects the data at least as well; otherwise you need one of a short list of exceptions such as the person's consent.
Enforced by Department of Personal Data Protection
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Put a transfer safeguard in placeThe exporter assesses the destination itself. There is no government list and no government approval step.
- Keep records of how you use dataKeep documentation showing which limb of the test you relied on.
Sources
- Official sourceDepartment of Personal Data ProtectionPublic Consultation Paper No. 05/2024 — Cross-Border Personal Data Transfer
pdp.gov.my
“pemansuhan senarai putih dengan memotong Seksyen 129(1)”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection (Amendment) Act 2024 (Act A1727)
pdp.gov.my
Link checked 18 August 2026
Breach reporting rules
Official name: Pekeliling dan Garis Panduan Perlindungan Data Peribadi: Pemberitahuan Pelanggaran Data · Data Breach Notification circular and guideline, version 1.0, issued under section 12B of Act 709 · Regulator directive
Tell the privacy regulator within seventy-two hours of a data breach. Where the breach is likely to cause serious harm, tell the people affected within a further seven days. Failing to report is a criminal offence.
Enforced by Department of Personal Data Protection
What you have to do
- Report breaches to the regulator — applies at: Any personal data breach; a fuller report is required where the breach causes or is likely to cause significant harm, including where more than 1,000 data subjects are affected., within 72 hoursStaged reporting is allowed but must be completed within 30 days of the first notification.
- Tell affected people — applies at: Breaches causing or likely to cause significant harm., within 168 hoursSeven days, counted from the notification to the Commissioner, not from the breach.
What it costs if you get it wrong
- Criminal liability: RM250,000 or 2 years imprisonment, or both — about $59 thousandFailure to notify a personal data breach.
Sources
- Official sourcePersonal Data Protection CommissionerPersonal Data Protection Guideline — Data Breach Notification
pdp.gov.my
“as soon as practicable and no later than seventy-two (72) hours from the occurrence”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionGaris Panduan dan Pekeliling Pemberitahuan Pelanggaran Data (DBN)
pdp.gov.my
Link checked 18 August 2026
General data protection law
Official name: Garis Panduan Perlindungan Data Peribadi: Pelantikan Pegawai Perlindungan Data (DPO) · Guideline on the appointment of a Data Protection Officer, version 1.0, issued under section 12A of Act 709 · Regulator guideline
Above set volumes you must appoint a data protection officer and register them with the regulator within twenty-one days. The officer has to be contactable in Malaysia and able to work in both Malay and English.
Enforced by Department of Personal Data Protection
What you have to do
- Appoint a data protection officer — applies at: More than 20,000 data subjects' personal data; or sensitive personal data including financial data of more than 10,000 data subjects; or regular and systematic monitoring such as behavioural profiling, closed-circuit television or wearable health devices.The officer must be resident in Malaysia, meaning physically present at least 180 days in a calendar year, or easily contactable by any means, and must be proficient in the national language and English.
- Register or notifyRegister the appointed officer through the Personal Data Protection System within 21 days of appointment.
Sources
- Official sourcePersonal Data Protection CommissionerGaris Panduan Pelantikan Pegawai Perlindungan Data (DPO), version 1.0
pdp.gov.my
“dalam tempoh dua puluh satu (21) hari dari tarikh pelantikan”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionData Protection Officer (DPO) Competency Guideline, 1 August 2025
pdp.gov.my
Link checked 18 August 2026
Data rules
Official name: Standard Perlindungan Data Peribadi 2015 · Personal Data Protection Standard 2015, issued under regulations 6, 7 and 8 of the Personal Data Protection Regulations 2013 [P.U.(A) 335/2013] · Statutory code of practice
The regulator's binding minimum security and disposal standard. It contains the numbers that trip audits: destroy paper collection forms within fourteen days, and clear out data that has sat inactive for twenty-four months.
Enforced by Department of Personal Data Protection
What you have to do
- Delete data after a period — 2 yearsMaintain a disposal schedule that clears personal data inactive for 24 months.
- Delete data after a periodDispose of personal data collection forms used in commercial transactions within a period not exceeding 14 days.
- Secure the dataRemovable media may not be used to store personal data without written approval from the organisation's top management.
- Keep records of how you use dataKeep a proper record of disposals and produce it to the Commissioner on request.
Sources
- Official sourcePersonal Data Protection CommissionerPersonal Data Protection Standard 2015
pdp.gov.my
“Prepare a personal data disposal schedule for inactive data with a 24 month period”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionStandard Perlindungan Data Peribadi 2015 — publication page
pdp.gov.my
Link checked 18 August 2026
Cyber security rules
Official name: Akta Keselamatan Siber 2024 (Akta 854) · Cyber Security Act 2024 (Act 854), gazetted 26 June 2024 · Act of parliament
Malaysia's cyber security law started on twenty-six August 2024. It lets the government designate companies as critical national infrastructure, which brings audits, risk assessments and incident reporting. It also makes some security services a licensed activity.
Enforced by National Cyber Security Agency
What you have to do
- Report cyber incidentsEntities designated as National Critical Information Infrastructure must notify cyber security incidents. The exact deadline is set by the Notification of Cyber Security Incident Regulations 2024, which we could not retrieve from a government source on 18 August 2026.
- Independent auditPeriodic cyber security risk assessment and audit, on a cycle set by separate regulations.
- Register or notifyProviders of managed security operations centre monitoring and penetration testing services must be licensed by the Chief Executive.
Sources
- Official sourceNational Cyber Security AgencyCyber Security Act 2024 (Act 854)
nacsa.gov.my
“26 August 2024 as the date on which the Act comes into operation”
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencySubsidiary legislation under the Cyber Security Act 2024
nacsa.gov.my
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact commencement dates for each part of the Personal Data Protection (Amendment) Act 2024
We could not confirm when the new cross-border transfer test started. The amendment act says the Minister sets dates by gazette notice, and may set different dates for different parts. We confirmed royal assent on 9 October 2024 and gazette publication on 17 October 2024 from the official text, but could not find the commencement notice itself on the regulator's site. The breach notification and data protection officer duties are clearly live, because binding guidance under them was issued on 25 February 2025.
The incident notification deadline for critical infrastructure entities under the Cyber Security Act 2024
We could not confirm the reporting deadline for cyber security incidents. The National Cyber Security Agency lists the Notification of Cyber Security Incident Regulations 2024 but does not publish the deadlines. The Attorney General's Chambers legislation portal blocked our access. We state no hour figure rather than repeat a secondhand source. If you are designated critical infrastructure, ask the Agency.
Whether any sector in Malaysia imposes a hard keeping data in the country requirement
We found no rule requiring data to stay in Malaysia in banking, payments, insurance, securities, health, telecoms, government cloud, education, gambling or mapping. We could not confirm this against every official source. The Malaysian Communications and Multimedia Commission site blocked us, the Securities Commission site gave no usable guideline content, and the Ministry of Health site had no legislation section. If you work in one of these industries, check with your regulator before you rely on it.
Whether Malaysian public sector data must be hosted in data centres inside Malaysia
We could not confirm whether government data must stay in Malaysia. The National Cloud Computing Policy was approved by Cabinet on 18 June 2025, but its text is not published on the Ministry of Digital or National Digital Department sites, and the MyGovCloud portal says nothing about it. The privacy law does not apply to government at all, so this policy is what would decide the question. Ask the agency you are selling to.
Malaysian statutory minimum retention periods for tax, company and anti-money-laundering records
We could not confirm the Malaysian retention periods for tax and company records. The Personal Data Protection Standard 2015 defers to other laws, so such duties exist and override the duty to delete. We could not reach the Inland Revenue Board or Companies Commission legislation pages, so we do not state the year counts. Check with your accountant before you set a schedule.
The act number and commencement date of the Data Sharing Act
We could not confirm the act number or start date of the Data Sharing Act. The National Digital Department lists a 'Data Sharing Act 2025' among its laws, and the Ministry of Digital records that the Data Sharing Bill 2024 passed the Dewan Rakyat on 12 December 2024. Neither source gives an act number or a start date.
Whether a final cross-border data transfer guideline has been published since August 2025
We could not confirm that no final cross-border transfer guideline exists. Consultation paper 05/2024 was still the most recent cross-border document on the regulator's site when we checked on 18 August 2026, and a site search for 2026 material returned nothing. Check the regulator's site before you rely on this.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.