Skip to the content
Global Data RulesData governance rules, country by country

Malaysia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Malaysia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

Data can leave Malaysia, but you have to justify it yourself. Until 2024 the country ran an approved-destinations list; that list was scrapped and nothing replaced it. You now decide whether the destination protects data well enough, and you carry the risk if the regulator disagrees. Breaking the core duties is a crime, not a fine, and it can mean prison.

Data governance in Malaysia

The eight things that decide how you handle data about people in Malaysia. Same eight on every country page, so you can compare.

Who has to follow these rules

It reaches you only if you are set up in Malaysia, or if you use equipment inside Malaysia to process the data. Simply selling to Malaysians from abroad, with all your servers elsewhere, is not obviously enough. We found no size or revenue threshold in the law, checked on 18 August 2026. If the equipment test is what catches you, you must appoint a representative who is established in Malaysia.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, but you must do the homework yourself. Malaysia used to publish a list of countries you were allowed to send data to. That list was abolished by the 2024 amendment and no replacement list has appeared. You may now send data abroad if the destination's law is substantially similar to Malaysia's, or protects the data at least as well. If it does not, you fall back on a short set of narrow exceptions.

Ways to send data out:
Official 'this country is safe' decision · Explicit consent · Needed for a contract

What to do: Get the paperwork for one of the routes below signed before any data leaves Malaysia.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

There is no list to check and no permission to ask for. You assess the destination yourself, write down why you think it is safe enough, and keep that record. If you cannot show the destination is good enough, you need one of the narrow exceptions, such as the person's consent or genuine need to perform a contract. Standard contract templates and group-wide rules were proposed in 2024 but the final guideline still had not been published on 18 August 2026.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Explicit consent · Needed for a contract · Legal claims · To save someone’s life
Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

The Department of Personal Data Protection, which sits under the Ministry of Digital, is the privacy regulator. It is properly staffed. A new Commissioner took office on 3 September 2025. The department published binding guidance and ran two public consultations during 2024 and 2025. What it has not done is punish much. The newest case on its own published penalty list dates from 2018.

How long you must keep it — and when to delete it

The ceiling is a general one: do not keep personal data longer than you need it for the reason you collected it. Two very specific deadlines sit under that. Paper forms used to collect personal data in a commercial deal must be destroyed within fourteen days. And you must run a disposal schedule that clears out data that has been inactive for twenty-four months. Other laws that force you to keep records for longer win over all of this.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

You have seventy-two hours from the breach to tell the privacy regulator. If the breach is likely to cause serious harm, you have a further seven days to tell the people affected. If you cannot gather everything in time you may report in stages, but you must finish within thirty days. Missing the report is a crime carrying a fine of up to 250,000 Malaysian ringgit, roughly 59,000 US dollars, or up to two years in prison.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents
What it costs if you get it wrong:
Criminal liability

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

First, the law does not apply to the Federal or State Governments at all, so a leak by a public body gives you no privacy remedy. Second, penalties here are criminal: breaking the core duties can mean up to one million Malaysian ringgit, roughly 235,000 US dollars, or three years in prison. Third, your data protection officer must speak both Malay and English. Fourth, you must shred paper collection forms within fourteen days.

What you have to do here:
Appoint a data protection officer · Delete data after a period · Register or notify
What it costs if you get it wrong:
Criminal liability

What's changing next

The detail that makes sending data abroad workable is still missing. A consultation on rewriting the 2013 regulations opened on 25 August 2025 and those regulations are where the real rules are expected. A final cross-border transfer guideline was consulted on in October 2024 and still had not appeared by 18 August 2026. A national cloud policy was approved by Cabinet on 18 June 2025 but its terms are not public.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries1 rule

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Cloud and outsourcing rules

Official name: Risk Management in Technology (RMiT) · Bank Negara Malaysia policy document on Risk Management in Technology, issued 28 November 2025 · Regulator directive

In forceYes, with paperwork

Banks, insurers and takaful operators may host data abroad, but they must consult the central bank before first putting critical systems on a public cloud, must give the regulator contractual access to the data wherever it sits, and must show they can get it back quickly.

In force since 28 November 2025

Enforced by Bank Negara Malaysia

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company6 rules

These bind you whatever business you are in, once the country's rules reach you.

Government data rules

Official name: Akta Perlindungan Data Peribadi 2010 (Akta 709), sebagaimana dipinda oleh Akta A1727 · Act 709, as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727) · Act of parliament

Partly in forceYes, with paperwork

Malaysia's general privacy law. It covers organisations set up in Malaysia and foreign organisations that use equipment inside Malaysia, but only for commercial dealings, and it does not apply to the Federal or State Governments at all. Penalties are criminal.

In force since 15 November 2013

Enforced by Department of Personal Data Protection

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, To save someone’s life

Telecoms rules

Official name: Seksyen 129, Akta Perlindungan Data Peribadi 2010, sebagaimana dipinda · Act 709 section 129, as amended by Act A1727 clause 12 · Act of parliament

In forceYes, with paperwork

The old list of approved destinations was scrapped. Data may now leave Malaysia if the destination country's law is substantially similar to Malaysia's, or protects the data at least as well; otherwise you need one of a short list of exceptions such as the person's consent.

Enforced by Department of Personal Data Protection

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Not fully verified — see “What we're not sure about” below.

Breach reporting rules

Official name: Pekeliling dan Garis Panduan Perlindungan Data Peribadi: Pemberitahuan Pelanggaran Data · Data Breach Notification circular and guideline, version 1.0, issued under section 12B of Act 709 · Regulator directive

In forceYes, with paperwork

Tell the privacy regulator within seventy-two hours of a data breach. Where the breach is likely to cause serious harm, tell the people affected within a further seven days. Failing to report is a criminal offence.

In force since 25 February 2025

Enforced by Department of Personal Data Protection

Who you would hear from

  • Jabatan Perlindungan Data Peribadi (JPDP)

    General privacy law: registration of data controllers, guidelines, breach notification, complaints and prosecution under the Personal Data Protection Act 2010

    Staffed and issuing guidance. Commissioner Shariffah Rashidah binti Syed Othman took office on 3 September 2025 under gazette notice P.U. (B) 341. Issued binding breach-notification and data protection officer guidance on 25 February 2025 and opened a consultation on new regulations on 25 August 2025. However, its own published penalty list contains only two compound cases, both from 2018, both for operating without a registration certificate. Guidance output is high; punishment output is close to zero.

  • Bank Negara Malaysia

    Banks, insurers, takaful operators and payment system operators: technology risk, cloud adoption, outsourcing and operational incident reporting

    Fully operational. Reissued the Risk Management in Technology policy document on 28 November 2025 and an updated frequently-asked-questions document on 1 July 2026, and publishes enforcement actions.

  • Agensi Keselamatan Siber Negara (NACSA)

    Cyber Security Act 2024: designation and supervision of National Critical Information Infrastructure, incident reporting, licensing of cyber security service providers

    Operational. Runs the licensing application process and an incident reporting channel, and has published four sets of regulations plus an exemption order made in 2025 under the Act.

  • Jabatan Digital Negara (JDN)

    Public sector digital policy, public sector cloud (MyGovCloud) and public sector data sharing

    Operational. Maintains the public sector policy repository and the approved cloud service provider list, most recently updated on 18 August 2025.

  • Suruhanjaya Komunikasi dan Multimedia Malaysia (SKMM)

    Communications and multimedia licensing, network and applications service providers, online content and safety

    Operational. Treat the telecoms part of this record as unresearched rather than clear.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact commencement dates for each part of the Personal Data Protection (Amendment) Act 2024

    We could not confirm when the new cross-border transfer test started. The amendment act says the Minister sets dates by gazette notice, and may set different dates for different parts. We confirmed royal assent on 9 October 2024 and gazette publication on 17 October 2024 from the official text, but could not find the commencement notice itself on the regulator's site. The breach notification and data protection officer duties are clearly live, because binding guidance under them was issued on 25 February 2025.

  • The incident notification deadline for critical infrastructure entities under the Cyber Security Act 2024

    We could not confirm the reporting deadline for cyber security incidents. The National Cyber Security Agency lists the Notification of Cyber Security Incident Regulations 2024 but does not publish the deadlines. The Attorney General's Chambers legislation portal blocked our access. We state no hour figure rather than repeat a secondhand source. If you are designated critical infrastructure, ask the Agency.

  • Whether any sector in Malaysia imposes a hard keeping data in the country requirement

    We found no rule requiring data to stay in Malaysia in banking, payments, insurance, securities, health, telecoms, government cloud, education, gambling or mapping. We could not confirm this against every official source. The Malaysian Communications and Multimedia Commission site blocked us, the Securities Commission site gave no usable guideline content, and the Ministry of Health site had no legislation section. If you work in one of these industries, check with your regulator before you rely on it.

  • Whether Malaysian public sector data must be hosted in data centres inside Malaysia

    We could not confirm whether government data must stay in Malaysia. The National Cloud Computing Policy was approved by Cabinet on 18 June 2025, but its text is not published on the Ministry of Digital or National Digital Department sites, and the MyGovCloud portal says nothing about it. The privacy law does not apply to government at all, so this policy is what would decide the question. Ask the agency you are selling to.

  • Malaysian statutory minimum retention periods for tax, company and anti-money-laundering records

    We could not confirm the Malaysian retention periods for tax and company records. The Personal Data Protection Standard 2015 defers to other laws, so such duties exist and override the duty to delete. We could not reach the Inland Revenue Board or Companies Commission legislation pages, so we do not state the year counts. Check with your accountant before you set a schedule.

  • The act number and commencement date of the Data Sharing Act

    We could not confirm the act number or start date of the Data Sharing Act. The National Digital Department lists a 'Data Sharing Act 2025' among its laws, and the Ministry of Digital records that the Data Sharing Bill 2024 passed the Dewan Rakyat on 12 December 2024. Neither source gives an act number or a start date.

  • Whether a final cross-border data transfer guideline has been published since August 2025

    We could not confirm that no final cross-border transfer guideline exists. Consultation paper 05/2024 was still the most recent cross-border document on the regulator's site when we checked on 18 August 2026, and a site search for 2026 material returned nothing. Check the regulator's site before you rely on this.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.