Malaysia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Data can leave Malaysia, but you have to justify it yourself. Until 2024 the country ran an approved-destinations list; that list was scrapped and nothing replaced it. You now decide whether the destination protects data well enough, and you carry the risk if the regulator disagrees. Breaking the core duties is a crime, not a fine, and it can mean prison.
Data governance in Malaysia
The eight things that decide how you handle data about people in Malaysia. Same eight on every country page, so you can compare.
Who has to follow these rules
It reaches you only if you are set up in Malaysia, or if you use equipment inside Malaysia to process the data. Simply selling to Malaysians from abroad, with all your servers elsewhere, is not obviously enough. We found no size or revenue threshold in the law, checked on 18 August 2026. If the equipment test is what catches you, you must appoint a representative who is established in Malaysia.
Section 2 of the Personal Data Protection Act 2010 applies the Act to a person established in Malaysia who processes personal data, and to a person not established in Malaysia who uses equipment in Malaysia for processing otherwise than for the purpose of transit through Malaysia. Section 2(3) requires the second category to nominate a representative established in Malaysia. This is the old European 'use of equipment' test, not the modern 'targeting' test used by the EU General Data Protection Regulation, so the extraterritorial reach is materially narrower than most trackers assume. Two further limits matter more than the reach itself: section 3 excludes the Federal Government and the State Governments entirely, and section 4 confines the Act to processing 'in respect of commercial transactions', defined to cover supply or exchange of goods or services, agency, investment, financing, banking and insurance.
Sources
- Official sourceDepartment of Personal Data Protection, Ministry of DigitalPersonal Data Protection Act 2010 (Act 709), sections 2, 3 and 4
pdp.gov.my
“tidak ditubuhkan di Malaysia, tetapi menggunakan kelengkapan di Malaysia bagi memproses data peribadi itu selain bagi maksud transit melalui Malaysia”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionAkta Perlindungan Data Peribadi 2010 (Akta 709) — legislation index
pdp.gov.my
Link checked 18 August 2026
Where the data is allowed to live
Yes, but you must do the homework yourself. Malaysia used to publish a list of countries you were allowed to send data to. That list was abolished by the 2024 amendment and no replacement list has appeared. You may now send data abroad if the destination's law is substantially similar to Malaysia's, or protects the data at least as well. If it does not, you fall back on a short set of narrow exceptions.
The amended section 129 is a two-limb test. Limb one: the destination country has a law that is substantially similar to the Personal Data Protection Act 2010, or ensures an adequate level of protection at least equivalent to it. Limb two, where that fails: a set of alternative grounds including the data subject's consent, necessity for a contract, legal proceedings, vital interests, and the exporter having taken all reasonable precautions and exercised all due diligence. Sector overrides we could verify: (a) FINANCE (banks, insurers, takaful operators) — Bank Negara Malaysia's Risk Management in Technology policy document of 28 November 2025 requires a financial institution to consult the Bank before first-time adoption of public cloud for critical systems, requires regulator access rights over any record, file or data held at a third party, and requires data at third-party providers to be recoverable in a timely manner; no localisation, but a real approval gate — rating data can leave with paperwork. (b) GOVERNMENT — the privacy law does not apply to the Federal or State Governments at all; public sector hosting runs off the National Cloud Computing Policy approved by Cabinet on 18 June 2025 and the MyGovCloud public sector data centre arrangements; we could not verify the residency terms of those instruments, so we rate this not yet established rather than guess. (c) DESIGNATED CRITICAL INFRASTRUCTURE — the Cyber Security Act 2024 imposes duties on entities designated as National Critical Information Infrastructure; we found no localisation duty in it, but the designation power is broad. We searched specifically for storage or localisation rules in payments, insurance, securities, health, telecoms, education, gambling and mapping and could not confirm any hard localisation mandate from an official Malaysian source as at 18 August 2026. Several of those regulators' websites blocked automated access, so this is an unproven negative, not a proven absence.
Sources
- Official sourceDepartment of Personal Data ProtectionPublic Consultation Paper No. 05/2024 — Cross-Border Personal Data Transfer Guideline
pdp.gov.my
“Klausa 12 Rang Undang-Undang Pindaan memperkenalkan beberapa pindaan kepada Seksyen 129 APDP, iaitu: (a) pemansuhan senarai putih dengan memotong Seksyen 129(1)”
Link checked 18 August 2026
- Official sourceBank Negara MalaysiaRisk Management in Technology (RMiT) policy document, 28 November 2025
bnm.gov.my
“A financial institution is required to consult the Bank prior to the first-time adoption of a public cloud ... for critical systems.”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection (Amendment) Act 2024 (Act A1727)
pdp.gov.my
Link checked 18 August 2026
Sending data out of the country
There is no list to check and no permission to ask for. You assess the destination yourself, write down why you think it is safe enough, and keep that record. If you cannot show the destination is good enough, you need one of the narrow exceptions, such as the person's consent or genuine need to perform a contract. Standard contract templates and group-wide rules were proposed in 2024 but the final guideline still had not been published on 18 August 2026.
Model: no government list, no government approval, self-assessment by the exporter. The old whitelist mechanism in section 129(1) was cut by the 2024 amendment and the Minister has published no successor list that we could find. The regulator's consultation paper 05/2024 (consultation ran 1 to 18 October 2024) proposed the supporting machinery: transfer impact assessments where you rely on the adequacy limb, recognition of binding corporate rules without pre-approval where they contain prescribed minimum content, two families of standard contractual clauses (a Malaysian minimum-clause set and international model clauses such as the ASEAN and EU templates), recognition of certifications such as APEC Cross-Border Privacy Rules alongside a binding agreement, and record-keeping to evidence compliance. Treat all of that as proposal, not law: the consultation closed in October 2024 and we found no final guideline on the regulator's own site as at 18 August 2026. A separate consultation, paper 4/2025 opened on 25 August 2025, proposes amendments to the Personal Data Protection Regulations 2013, which is where the binding detail is expected to land.
Sources
- Official sourceDepartment of Personal Data ProtectionPublic Consultation Paper No. 05/2024 — Cross-Border Personal Data Transfer, proposed mechanisms
pdp.gov.my
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPublic Consultation Paper No. 4/2025 — proposed amendments to the Personal Data Protection Regulations 2013
pdp.gov.my
Link checked 18 August 2026
The regulator, and whether it actually acts
The Department of Personal Data Protection, which sits under the Ministry of Digital, is the privacy regulator. It is genuinely staffed: a new Commissioner took office on 3 September 2025, and the department published binding guidance and ran two public consultations during 2024 and 2025. What it has not done is punish much. The newest case on its own published penalty list dates from 2018.
Rating: the regulator is waking up, not dormant and not active. Evidence for staffed and functioning: gazette notice P.U. (B) 341 appointed Shariffah Rashidah binti Syed Othman as Personal Data Protection Commissioner with effect from 3 September 2025; the department issued the Data Breach Notification guideline and circular and the Data Protection Officer appointment guideline, both dated 25 February 2025; it operates a live breach reporting portal and a data controller registration system; it opened public consultation 4/2025 on 25 August 2025. Evidence against an active enforcement record: the department's own 'Senarai Kes Kompaun' page, refreshed on 18 February 2025, lists compounds of RM10,000 each against two companies, both from 2018, both for failing to hold a registration certificate. We found no published fine or prosecution under the new 2024 duties. Other regulators that matter in this space and are unambiguously operational: Bank Negara Malaysia for banks, insurers and takaful operators; the National Cyber Security Agency for designated critical infrastructure and for licensing cyber security service providers; the Malaysian Communications and Multimedia Commission for communications services; and the National Digital Department for public sector digital policy.
Sources
- Official sourceDepartment of Personal Data ProtectionP.U. (B) 341 — Appointment of the Personal Data Protection Commissioner
pdp.gov.my
“Menteri telah melantik Shariffah Rashidah binti Syed Othman sebagai Pesuruhjaya Perlindungan Data Peribadi berkuat kuasa mulai 3 September 2025.”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionTindakan Penguatkuasaan — list of compound cases under Act 709
pdp.gov.my
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencyCyber Security Act 2024 — National Cyber Security Agency
nacsa.gov.my
Link checked 18 August 2026
How long you must keep it — and when to delete it
The ceiling is a general one: do not keep personal data longer than you need it for the reason you collected it. Two very specific deadlines sit under that. Paper forms used to collect personal data in a commercial deal must be destroyed within fourteen days. And you must run a disposal schedule that clears out data that has been inactive for twenty-four months. Other laws that force you to keep records for longer win over all of this.
Ceiling: the Retention Principle in section 10 of the Personal Data Protection Act 2010 states that personal data processed for any purpose shall not be kept longer than is necessary for the fulfilment of that purpose. The Personal Data Protection Standard 2015, issued by the Commissioner on 23 December 2015 under regulations 6, 7 and 8 of the Personal Data Protection Regulations 2013, adds hard numbers: dispose of personal data collection forms used in commercial transactions within a period not exceeding fourteen days; prepare a personal data disposal schedule for inactive data with a twenty-four month period; and keep a proper record of disposals, produced to the Commissioner on demand. Floor: the Standard itself resolves the conflict in favour of the floor — data users are to keep personal data no longer than necessary 'unless there are requirements by other legal provisions'. So a tax, company law, anti-money-laundering or sectoral record-keeping duty overrides the deletion duty. We were not able to verify the specific Malaysian statutory retention periods (commonly cited as seven years for tax and company records and six years for anti-money-laundering records) against a government source during this run; see the unconfirmed list.
Sources
- Official sourcePersonal Data Protection CommissionerPersonal Data Protection Standard 2015 — retention and disposal standard
pdp.gov.my
“Dispose personal data collection forms used in commercial transactions within the period not exceeding fourteen (14) days”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection Act 2010 (Act 709), section 10 — Retention Principle
pdp.gov.my
“Data peribadi yang diproses bagi apa-apa maksud tidak boleh disimpan lebih lama daripada yang diperlukan bagi memenuhi maksud itu”
Link checked 18 August 2026
If something goes wrong
You have seventy-two hours from the breach to tell the privacy regulator. If the breach is likely to cause serious harm, you have a further seven days to tell the people affected. If you cannot gather everything in time you may report in stages, but you must finish within thirty days. Missing the report is a crime carrying a fine of up to 250,000 Malaysian ringgit, roughly 59,000 US dollars, or up to two years in prison.
Clock one, privacy: the Data Breach Notification circular and guideline issued by the Personal Data Protection Commissioner on 25 February 2025 under section 12B of Act 709 require notification to the Commissioner as soon as practicable and no later than seventy-two hours from the occurrence of the breach, with staged submission permitted but completed no later than thirty days after the first notification. Where the breach causes or is likely to cause significant harm, affected data subjects must be told without unnecessary delay and not later than seven days after the notification to the Commissioner. 'Significant harm' is framed to include physical harm, financial loss, exposure of sensitive personal data, risk of identity fraud, or a breach affecting more than one thousand data subjects. Clock two, cyber security: an entity designated as National Critical Information Infrastructure under the Cyber Security Act 2024 must notify cyber security incidents under the Cyber Security (Notification of Cyber Security Incident) Regulations 2024; we could not retrieve the regulation text from a government source during this run and therefore do not state the hour count — see the unconfirmed list. Clock three, financial: banks, insurers and takaful operators additionally report technology and operational incidents to Bank Negara Malaysia under the Risk Management in Technology and Operational Risk Reporting policy documents. The overlap is the operational trap: one incident, three regulators, three different formats.
Sources
- Official sourcePersonal Data Protection CommissionerPersonal Data Protection Guideline — Data Breach Notification, version 1.0, 25 February 2025
pdp.gov.my
“as soon as practicable and no later than seventy-two (72) hours from the occurrence”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionerData Breach Notification Circular (Pekeliling DBN)
pdp.gov.my
“masa tujuh (7) hari selepas pemberitahuan pelanggaran data dibuat”
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencyCyber Security Act 2024 subsidiary legislation, including the Notification of Cyber Security Incident Regulations 2024
nacsa.gov.my
Link checked 18 August 2026
What catches people out
First, the law does not apply to the Federal or State Governments at all, so a leak by a public body gives you no privacy remedy. Second, penalties here are criminal: breaking the core duties can mean up to one million Malaysian ringgit, roughly 235,000 US dollars, or three years in prison. Third, your data protection officer must speak both Malay and English. Fourth, you must shred paper collection forms within fourteen days.
Trap 1 — the government carve-out. Section 3 of Act 709 states plainly that the Act does not apply to the Federal Government and the State Governments. Public sector data handling is governed by policy, not by this statute, and individuals have no route to the privacy regulator against a ministry. Trap 2 — 'commercial transactions' only. Section 4 confines the Act to processing in respect of commercial transactions. Processing outside a commercial context sits outside the Act, which is a very different design from the European model and catches people who assume equivalence. Trap 3 — criminal, not administrative. The 2024 amendment raised the penalty for contravening the personal data protection principles from 300,000 ringgit or two years to one million ringgit (about 235,000 US dollars) or three years imprisonment, or both. Failure to notify a data breach carries 250,000 ringgit (about 59,000 US dollars) or two years. These are prosecutions, and they can attach to individuals. Trap 4 — the data protection officer has personal qualifying conditions. The February 2025 guideline requires appointment where you process the personal data of more than twenty thousand data subjects, or sensitive personal data including financial data of more than ten thousand data subjects, or you carry out regular and systematic monitoring. The officer must either be resident in Malaysia, meaning physically present at least one hundred and eighty days in a calendar year, or be easily contactable by any means, and must be proficient in both the national language and English. You must register the appointment through the Personal Data Protection System within twenty-one days. Trap 5 — the micro-deadlines in the 2015 Standard. Personal data collection forms used in commercial transactions must be disposed of within fourteen days; you need a documented disposal schedule for data inactive for twenty-four months; and removable media may not be used to store personal data without written approval from the organisation's top management. These are the kind of rules an audit finds instantly and a compliance programme built to a European template never mentions.
Sources
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection (Amendment) Act 2024 (Act A1727) — increased penalties, data protection officer, breach notification, data portability, biometric data
pdp.gov.my
“satu juta ringgit atau dipenjarakan selama tempoh tidak melebihi tiga tahun”
Link checked 18 August 2026
- Official sourcePersonal Data Protection CommissionerGuideline on the Appointment of a Data Protection Officer, version 1.0, 25 February 2025
pdp.gov.my
“bermastautin di Malaysia (iaitu berada secara fizikal di Malaysia untuk sekurang-kurangnya 180 hari dalam satu tahun kalendar); atau mudah dihubungi melalui apa-apa cara; dan mahir dalam Bahasa Kebangsaan dan Bahasa Inggeris.”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection Act 2010 (Act 709), section 3 — non-application to the Federal and State Governments
pdp.gov.my
“Akta ini tidaklah terpakai bagi Kerajaan Persekutuan dan Kerajaan Negeri”
Link checked 18 August 2026
What's changing next
The detail that makes sending data abroad workable is still missing. A consultation on rewriting the 2013 regulations opened on 25 August 2025 and those regulations are where the real rules are expected. A final cross-border transfer guideline was consulted on in October 2024 and still had not appeared by 18 August 2026. A national cloud policy was approved by Cabinet on 18 June 2025 but its terms are not public.
Landing in the next twelve months, on current evidence: (1) amended Personal Data Protection Regulations 2013, following public consultation paper 4/2025 opened 25 August 2025 — expected to carry the operative detail on transfers, data protection officers and breach handling; no commencement date announced. (2) A final cross-border personal data transfer guideline, following consultation paper 05/2024 which ran from 1 to 18 October 2024; twenty-two months later nothing final has been published on the regulator's site, so treat any standard clauses, binding corporate rules or certification route as unavailable today. (3) Implementation of the National Cloud Computing Policy approved by Cabinet on 18 June 2025. (4) The Data Sharing Act, passed by the Dewan Rakyat on 12 December 2024 and listed among the National Digital Department's instruments, covering data sharing between public sector agencies; we could not verify its act number or commencement date. DORMANT SWITCHES — powers already held that can change the picture without consultation: (a) The Minister sets the commencement dates for the 2024 amendment by gazette notice and may appoint different dates for different provisions, so any not-yet-commenced provision can be switched on overnight. (b) The Commissioner can issue binding standards directly under the 2013 regulations — that is exactly how the detailed 2015 Standard, with its fourteen-day and twenty-four-month rules, came into being. (c) The Minister can prescribe which classes of data controller must register, converting a registration duty into a licensing gate for a whole industry. (d) Under the Cyber Security Act 2024, in force since 26 August 2024, the government can designate further sectors and entities as National Critical Information Infrastructure, pulling private companies into audit, risk assessment and incident reporting duties.
Sources
- Official sourceDepartment of Personal Data ProtectionPublic Consultation Paper No. 4/2025 — proposed amendments to the Personal Data Protection Regulations 2013, 25 August 2025
pdp.gov.my
Link checked 18 August 2026
- Official sourceMinistry of Digital MalaysiaMinistry of Digital — Cabinet approval of the National Cloud Computing Policy on 18 June 2025 and passage of the Data Sharing Bill 2024 on 12 December 2024
digital.gov.my
“Memorandum Jemaah Menteri (MJM) Dasar Pengkomputeran Awan Negara telah diluluskan oleh Jemaah Menteri pada 18 Jun 2025”
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencyCyber Security Act 2024 — commencement 26 August 2024 and designation powers
nacsa.gov.my
“26 August 2024 as the date on which the Act comes into operation”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries1 rule
If your product does one of these things, read this group first — industry rules beat the general position.
Risk Management in Technology (RMiT)
Regulator directive · Bank Negara Malaysia policy document on Risk Management in Technology, issued 28 November 2025
Banks, insurers and takaful operators may host data abroad, but they must consult the central bank before first putting critical systems on a public cloud, must give the regulator contractual access to the data wherever it sits, and must show they can get it back quickly.
Enforced by Bank Negara Malaysia
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyConsult Bank Negara Malaysia before adopting a public cloud for critical systems for the first time; later adoptions require notification with updated documentation.
- Written vendor contractThe contract must give the regulator, and anyone the institution appoints, access to any record, file or data held by the provider.
- Secure the dataCloud risk assessment must weigh the location of the cloud infrastructure, including geopolitical and legal risks that could impede compliance.
- Assess high-risk projectsDisaster recovery and backup arrangements must make data held at third parties recoverable in a timely manner.
Sources
- Official sourceBank Negara MalaysiaRisk Management in Technology (RMiT) policy document, 28 November 2025
bnm.gov.my
“access rights for the regulator and any party appointed by the financial institution to examine any activity or entity of the financial institution. This shall include access to any record, file or data of the financial institution”
Link checked 18 August 2026
- Official sourceBank Negara MalaysiaStandards and guidelines index — RMiT and Operational Risk Reporting policy documents
bnm.gov.my
Link checked 18 August 2026
Applies to every company6 rules
These bind you whatever business you are in, once the country's rules reach you.
Akta Perlindungan Data Peribadi 2010 (Akta 709), sebagaimana dipinda oleh Akta A1727
Act of parliament · Act 709, as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727)
Malaysia's general privacy law. It covers organisations set up in Malaysia and foreign organisations that use equipment inside Malaysia, but only for commercial dealings, and it does not apply to the Federal or State Governments at all. Penalties are criminal.
Enforced by Department of Personal Data Protection
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk
What it makes you do
- Get consent
- Tell people what you do
- Secure the data
- Delete data after a period
- Let people see their data
- Let people correct their data
- Let people take their data elsewhereNew right added by the 2024 amendment: a person can ask for their data to be sent directly to another organisation, subject to technical feasibility and format compatibility.
- Register or notifyData controllers in classes prescribed by the Minister must hold a registration certificate. Both published compound cases were for operating without one.
- Appoint a local representativeRequired where the organisation is not established in Malaysia but uses equipment in Malaysia to process the data.
What it costs if you get it wrong
- Criminal liability: RM1,000,000 or 3 years imprisonment, or both — about $235 thousandContravening the personal data protection principles. Raised from RM300,000 and 2 years by the 2024 amendment.
Sources
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection Act 2010 (Act 709), consolidated text
pdp.gov.my
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection (Amendment) Act 2024 (Act A1727), royal assent 9 October 2024, published 17 October 2024
pdp.gov.my
Link checked 18 August 2026
Seksyen 129, Akta Perlindungan Data Peribadi 2010, sebagaimana dipinda
Act of parliament · Act 709 section 129, as amended by Act A1727 clause 12
The old list of approved destinations was scrapped. Data may now leave Malaysia if the destination country's law is substantially similar to Malaysia's, or protects the data at least as well; otherwise you need one of a short list of exceptions such as the person's consent.
Enforced by Department of Personal Data Protection
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Put a transfer safeguard in placeThe exporter assesses the destination itself. There is no government list and no government approval step.
- Keep records of processingKeep documentation showing which limb of the test you relied on.
Sources
- Official sourceDepartment of Personal Data ProtectionPublic Consultation Paper No. 05/2024 — Cross-Border Personal Data Transfer
pdp.gov.my
“pemansuhan senarai putih dengan memotong Seksyen 129(1)”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionPersonal Data Protection (Amendment) Act 2024 (Act A1727)
pdp.gov.my
Link checked 18 August 2026
Pekeliling dan Garis Panduan Perlindungan Data Peribadi: Pemberitahuan Pelanggaran Data
Regulator directive · Data Breach Notification circular and guideline, version 1.0, issued under section 12B of Act 709
Tell the privacy regulator within seventy-two hours of a data breach. Where the breach is likely to cause serious harm, tell the people affected within a further seven days. Failing to report is a criminal offence.
Enforced by Department of Personal Data Protection
What it makes you do
- Report breaches to the regulator — applies at: Any personal data breach; a fuller report is required where the breach causes or is likely to cause significant harm, including where more than 1,000 data subjects are affected., within 72 hoursStaged reporting is allowed but must be completed within 30 days of the first notification.
- Tell affected people — applies at: Breaches causing or likely to cause significant harm., within 168 hoursSeven days, counted from the notification to the Commissioner, not from the breach.
What it costs if you get it wrong
- Criminal liability: RM250,000 or 2 years imprisonment, or both — about $59 thousandFailure to notify a personal data breach.
Sources
- Official sourcePersonal Data Protection CommissionerPersonal Data Protection Guideline — Data Breach Notification
pdp.gov.my
“as soon as practicable and no later than seventy-two (72) hours from the occurrence”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionGaris Panduan dan Pekeliling Pemberitahuan Pelanggaran Data (DBN)
pdp.gov.my
Link checked 18 August 2026
Garis Panduan Perlindungan Data Peribadi: Pelantikan Pegawai Perlindungan Data (DPO)
Regulator guideline · Guideline on the appointment of a Data Protection Officer, version 1.0, issued under section 12A of Act 709
Above set volumes you must appoint a data protection officer and register them with the regulator within twenty-one days. The officer has to be contactable in Malaysia and able to work in both Malay and English.
Enforced by Department of Personal Data Protection
What it makes you do
- Appoint a data protection officer — applies at: More than 20,000 data subjects' personal data; or sensitive personal data including financial data of more than 10,000 data subjects; or regular and systematic monitoring such as behavioural profiling, closed-circuit television or wearable health devices.The officer must be resident in Malaysia, meaning physically present at least 180 days in a calendar year, or easily contactable by any means, and must be proficient in the national language and English.
- Register or notifyRegister the appointed officer through the Personal Data Protection System within 21 days of appointment.
Sources
- Official sourcePersonal Data Protection CommissionerGaris Panduan Pelantikan Pegawai Perlindungan Data (DPO), version 1.0
pdp.gov.my
“dalam tempoh dua puluh satu (21) hari dari tarikh pelantikan”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionData Protection Officer (DPO) Competency Guideline, 1 August 2025
pdp.gov.my
Link checked 18 August 2026
Standard Perlindungan Data Peribadi 2015
Statutory code of practice · Personal Data Protection Standard 2015, issued under regulations 6, 7 and 8 of the Personal Data Protection Regulations 2013 [P.U.(A) 335/2013]
The regulator's binding minimum security and disposal standard. It contains the numbers that trip audits: destroy paper collection forms within fourteen days, and clear out data that has sat inactive for twenty-four months.
Enforced by Department of Personal Data Protection
What it makes you do
- Delete data after a period — 2 yearsMaintain a disposal schedule that clears personal data inactive for 24 months.
- Delete data after a periodDispose of personal data collection forms used in commercial transactions within a period not exceeding 14 days.
- Secure the dataRemovable media may not be used to store personal data without written approval from the organisation's top management.
- Keep records of processingKeep a proper record of disposals and produce it to the Commissioner on request.
Sources
- Official sourcePersonal Data Protection CommissionerPersonal Data Protection Standard 2015
pdp.gov.my
“Prepare a personal data disposal schedule for inactive data with a 24 month period”
Link checked 18 August 2026
- Official sourceDepartment of Personal Data ProtectionStandard Perlindungan Data Peribadi 2015 — publication page
pdp.gov.my
Link checked 18 August 2026
Akta Keselamatan Siber 2024 (Akta 854)
Act of parliament · Cyber Security Act 2024 (Act 854), gazetted 26 June 2024
Malaysia's cyber security law started on twenty-six August 2024. It lets the government designate companies as critical national infrastructure, which brings audits, risk assessments and incident reporting. It also makes some security services a licensed activity.
Enforced by National Cyber Security Agency
What it makes you do
- Report cyber incidentsEntities designated as National Critical Information Infrastructure must notify cyber security incidents. The exact deadline is set by the Notification of Cyber Security Incident Regulations 2024, which we could not retrieve from a government source on 18 August 2026.
- Independent auditPeriodic cyber security risk assessment and audit, on a cycle set by separate regulations.
- Register or notifyProviders of managed security operations centre monitoring and penetration testing services must be licensed by the Chief Executive.
Sources
- Official sourceNational Cyber Security AgencyCyber Security Act 2024 (Act 854)
nacsa.gov.my
“26 August 2024 as the date on which the Act comes into operation”
Link checked 18 August 2026
- Official sourceNational Cyber Security AgencySubsidiary legislation under the Cyber Security Act 2024
nacsa.gov.my
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact commencement dates for each part of the Personal Data Protection (Amendment) Act 2024
The amendment act says the Minister sets dates by gazette notice and may set different dates for different provisions. We confirmed royal assent on 9 October 2024 and gazette publication on 17 October 2024 from the official text, but could not locate the commencement notice itself on the regulator's site. The breach notification and data protection officer duties are clearly operative because binding guidance under them was issued on 25 February 2025. The commencement date of the new cross-border transfer test is not evidenced.
The incident notification deadline for critical infrastructure entities under the Cyber Security Act 2024
The National Cyber Security Agency lists the Notification of Cyber Security Incident Regulations 2024 but does not publish the deadlines on its site, and the Attorney General's Chambers legislation portal returned a robots.txt error to automated fetching. We deliberately state no hour figure rather than repeat a secondary source.
Whether any sector in Malaysia imposes a hard data localisation requirement
We searched for storage and localisation rules in banking, payments, insurance, securities, health, telecoms, government cloud, education, gambling and mapping. We found none from an official source, but the Malaysian Communications and Multimedia Commission site returned 403 to automated fetching, the Securities Commission site returned no usable guideline content, and the Ministry of Health site exposed no legislation section. This is an unproven negative, not a proven absence.
Whether Malaysian public sector data must be hosted in data centres inside Malaysia
The National Cloud Computing Policy was approved by Cabinet on 18 June 2025 but the policy text is not published on the Ministry of Digital or National Digital Department sites, and the MyGovCloud portal does not state a residency term. Because the privacy law does not apply to government at all, this is the instrument that would decide the question.
Malaysian statutory minimum retention periods for tax, company and anti-money-laundering records
The Personal Data Protection Standard 2015 expressly defers to 'requirements by other legal provisions', so floors exist and override the deletion duty. We could not reach the Inland Revenue Board or Companies Commission legislation pages during this run, so we do not state the year counts.
The act number and commencement date of the Data Sharing Act
The National Digital Department lists a 'Data Sharing Act 2025' among its instruments and the Ministry of Digital records that the Data Sharing Bill 2024 passed the Dewan Rakyat on 12 December 2024. Neither source gives an act number or a commencement date.
Whether a final cross-border data transfer guideline has been published since August 2025
We can evidence that consultation paper 05/2024 was still the most recent cross-border document on the regulator's site when checked on 18 August 2026, and a site search for 2026 cross-border material returned nothing. We cannot prove a document was not published elsewhere.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Malaysia versus
Compare