Skip to the content
Global Data RulesData governance rules, country by country

Malaysia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Data can leave Malaysia, but you have to justify it yourself. Until 2024 the country ran an approved-destinations list; that list was scrapped and nothing replaced it. You now decide whether the destination protects data well enough, and you carry the risk if the regulator disagrees. Breaking the core duties is a crime, not a fine, and it can mean prison.

Data governance in Malaysia

The eight things that decide how you handle data about people in Malaysia. Same eight on every country page, so you can compare.

Who has to follow these rules

It reaches you only if you are set up in Malaysia, or if you use equipment inside Malaysia to process the data. Simply selling to Malaysians from abroad, with all your servers elsewhere, is not obviously enough. We found no size or revenue threshold in the law, checked on 18 August 2026. If the equipment test is what catches you, you must appoint a representative who is established in Malaysia.

High confidenceNational rulesAppoint a local representative

Where the data is allowed to live

Yes, but you must do the homework yourself. Malaysia used to publish a list of countries you were allowed to send data to. That list was abolished by the 2024 amendment and no replacement list has appeared. You may now send data abroad if the destination's law is substantially similar to Malaysia's, or protects the data at least as well. If it does not, you fall back on a short set of narrow exceptions.

Medium confidenceYes, with paperworkOfficial 'this country is safe' decisionExplicit consentNeeded for a contract

Sending data out of the country

There is no list to check and no permission to ask for. You assess the destination yourself, write down why you think it is safe enough, and keep that record. If you cannot show the destination is good enough, you need one of the narrow exceptions, such as the person's consent or genuine need to perform a contract. Standard contract templates and group-wide rules were proposed in 2024 but the final guideline still had not been published on 18 August 2026.

Medium confidenceApproval each timeOfficial 'this country is safe' decisionExplicit consentNeeded for a contractLegal claimsSomeone's life is at riskPut a transfer safeguard in place

The regulator, and whether it actually acts

The Department of Personal Data Protection, which sits under the Ministry of Digital, is the privacy regulator. It is genuinely staffed: a new Commissioner took office on 3 September 2025, and the department published binding guidance and ran two public consultations during 2024 and 2025. What it has not done is punish much. The newest case on its own published penalty list dates from 2018.

High confidenceWaking upRegulator

How long you must keep it — and when to delete it

The ceiling is a general one: do not keep personal data longer than you need it for the reason you collected it. Two very specific deadlines sit under that. Paper forms used to collect personal data in a commercial deal must be destroyed within fourteen days. And you must run a disposal schedule that clears out data that has been inactive for twenty-four months. Other laws that force you to keep records for longer win over all of this.

Medium confidenceDelete data after a periodKeep data for a minimum periodKeep records of processing

If something goes wrong

You have seventy-two hours from the breach to tell the privacy regulator. If the breach is likely to cause serious harm, you have a further seven days to tell the people affected. If you cannot gather everything in time you may report in stages, but you must finish within thirty days. Missing the report is a crime carrying a fine of up to 250,000 Malaysian ringgit, roughly 59,000 US dollars, or up to two years in prison.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidentsCriminal liability

What catches people out

First, the law does not apply to the Federal or State Governments at all, so a leak by a public body gives you no privacy remedy. Second, penalties here are criminal: breaking the core duties can mean up to one million Malaysian ringgit, roughly 235,000 US dollars, or three years in prison. Third, your data protection officer must speak both Malay and English. Fourth, you must shred paper collection forms within fourteen days.

High confidenceCriminal liabilityAppoint a data protection officerDelete data after a periodRegister or notify

What's changing next

The detail that makes sending data abroad workable is still missing. A consultation on rewriting the 2013 regulations opened on 25 August 2025 and those regulations are where the real rules are expected. A final cross-border transfer guideline was consulted on in October 2024 and still had not appeared by 18 August 2026. A national cloud policy was approved by Cabinet on 18 June 2025 but its terms are not public.

Medium confidenceProposedGovernment policy document

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries1 rule

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Risk Management in Technology (RMiT)

Regulator directive · Bank Negara Malaysia policy document on Risk Management in Technology, issued 28 November 2025

In forceYes, with paperwork

Banks, insurers and takaful operators may host data abroad, but they must consult the central bank before first putting critical systems on a public cloud, must give the regulator contractual access to the data wherever it sits, and must show they can get it back quickly.

In force since 28 November 2025

Enforced by Bank Negara Malaysia

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company6 rules

These bind you whatever business you are in, once the country's rules reach you.

Akta Perlindungan Data Peribadi 2010 (Akta 709), sebagaimana dipinda oleh Akta A1727

Act of parliament · Act 709, as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727)

Partly in forceYes, with paperwork

Malaysia's general privacy law. It covers organisations set up in Malaysia and foreign organisations that use equipment inside Malaysia, but only for commercial dealings, and it does not apply to the Federal or State Governments at all. Penalties are criminal.

In force since 15 November 2013

Enforced by Department of Personal Data Protection

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk

High confidence

Seksyen 129, Akta Perlindungan Data Peribadi 2010, sebagaimana dipinda

Act of parliament · Act 709 section 129, as amended by Act A1727 clause 12

In forceYes, with paperwork

The old list of approved destinations was scrapped. Data may now leave Malaysia if the destination country's law is substantially similar to Malaysia's, or protects the data at least as well; otherwise you need one of a short list of exceptions such as the person's consent.

Enforced by Department of Personal Data Protection

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

Medium confidence

Pekeliling dan Garis Panduan Perlindungan Data Peribadi: Pemberitahuan Pelanggaran Data

Regulator directive · Data Breach Notification circular and guideline, version 1.0, issued under section 12B of Act 709

In forceYes, with paperwork

Tell the privacy regulator within seventy-two hours of a data breach. Where the breach is likely to cause serious harm, tell the people affected within a further seven days. Failing to report is a criminal offence.

In force since 25 February 2025

Enforced by Department of Personal Data Protection

High confidence

Who you would hear from

  • Jabatan Perlindungan Data Peribadi (JPDP)

    General privacy law: registration of data controllers, guidelines, breach notification, complaints and prosecution under the Personal Data Protection Act 2010

    Staffed and issuing guidance. Commissioner Shariffah Rashidah binti Syed Othman took office on 3 September 2025 under gazette notice P.U. (B) 341. Issued binding breach-notification and data protection officer guidance on 25 February 2025 and opened a consultation on new regulations on 25 August 2025. However, its own published penalty list contains only two compound cases, both from 2018, both for operating without a registration certificate. Guidance output is high; punishment output is close to zero.

  • Bank Negara Malaysia

    Banks, insurers, takaful operators and payment system operators: technology risk, cloud adoption, outsourcing and operational incident reporting

    Fully operational. Reissued the Risk Management in Technology policy document on 28 November 2025 and an updated frequently-asked-questions document on 1 July 2026, and publishes enforcement actions.

  • Agensi Keselamatan Siber Negara (NACSA)

    Cyber Security Act 2024: designation and supervision of National Critical Information Infrastructure, incident reporting, licensing of cyber security service providers

    Operational. Runs the licensing application process and an incident reporting channel, and has published four sets of regulations plus an exemption order made in 2025 under the Act.

  • Jabatan Digital Negara (JDN)

    Public sector digital policy, public sector cloud (MyGovCloud) and public sector data sharing

    Operational. Maintains the public sector policy repository and the approved cloud service provider list, most recently updated on 18 August 2025.

  • Suruhanjaya Komunikasi dan Multimedia Malaysia (SKMM)

    Communications and multimedia licensing, network and applications service providers, online content and safety

    Operational, but its website blocked automated access on 18 August 2026, so no telecoms-specific data storage rule could be verified in this run. Treat the telecoms layer of this record as unresearched rather than clear.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact commencement dates for each part of the Personal Data Protection (Amendment) Act 2024

    The amendment act says the Minister sets dates by gazette notice and may set different dates for different provisions. We confirmed royal assent on 9 October 2024 and gazette publication on 17 October 2024 from the official text, but could not locate the commencement notice itself on the regulator's site. The breach notification and data protection officer duties are clearly operative because binding guidance under them was issued on 25 February 2025. The commencement date of the new cross-border transfer test is not evidenced.

  • The incident notification deadline for critical infrastructure entities under the Cyber Security Act 2024

    The National Cyber Security Agency lists the Notification of Cyber Security Incident Regulations 2024 but does not publish the deadlines on its site, and the Attorney General's Chambers legislation portal returned a robots.txt error to automated fetching. We deliberately state no hour figure rather than repeat a secondary source.

  • Whether any sector in Malaysia imposes a hard data localisation requirement

    We searched for storage and localisation rules in banking, payments, insurance, securities, health, telecoms, government cloud, education, gambling and mapping. We found none from an official source, but the Malaysian Communications and Multimedia Commission site returned 403 to automated fetching, the Securities Commission site returned no usable guideline content, and the Ministry of Health site exposed no legislation section. This is an unproven negative, not a proven absence.

  • Whether Malaysian public sector data must be hosted in data centres inside Malaysia

    The National Cloud Computing Policy was approved by Cabinet on 18 June 2025 but the policy text is not published on the Ministry of Digital or National Digital Department sites, and the MyGovCloud portal does not state a residency term. Because the privacy law does not apply to government at all, this is the instrument that would decide the question.

  • Malaysian statutory minimum retention periods for tax, company and anti-money-laundering records

    The Personal Data Protection Standard 2015 expressly defers to 'requirements by other legal provisions', so floors exist and override the deletion duty. We could not reach the Inland Revenue Board or Companies Commission legislation pages during this run, so we do not state the year counts.

  • The act number and commencement date of the Data Sharing Act

    The National Digital Department lists a 'Data Sharing Act 2025' among its instruments and the Ministry of Digital records that the Data Sharing Bill 2024 passed the Dewan Rakyat on 12 December 2024. Neither source gives an act number or a commencement date.

  • Whether a final cross-border data transfer guideline has been published since August 2025

    We can evidence that consultation paper 05/2024 was still the most recent cross-border document on the regulator's site when checked on 18 August 2026, and a site search for 2026 cross-border material returned nothing. We cannot prove a document was not published elsewhere.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Malaysia versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.