EnglishEspañol

Malaysia PDPA vs GDPR: Government Exemption, Scope & 2025 Amendments

By Recording Law Editorial Team21 min read
Malaysia PDPA vs GDPR: Government Exemption, Scope & 2025 Amendments

Frequently Asked Questions

Does Malaysia's PDPA apply to the Malaysian government?

No. Section 3(1) of Act 709 states the Act does not apply to the Federal Government or State Governments, an exemption the 2024 Amendment Act left untouched. The GDPR takes the opposite approach: public authorities are covered controllers, and Art. 37(1)(a) makes DPO appointment mandatory for most of them.

Does the PDPA apply to a foreign company with no office in Malaysia?

Not necessarily. Section 2 applies the Act to a person established in Malaysia or using equipment in Malaysia. A foreign business with neither may fall outside the Act's reach even while marketing to Malaysian consumers online, unlike the GDPR's Art. 3(2) targeting test, which reaches a controller with no EU presence at all.

What did Malaysia's 2024 Amendment Act change?

Act A1727 phased in over three dates. From 1 April 2025: 'data user' renamed 'data controller,' biometric data added to sensitive data, processors directly regulated, the general penalty raised to RM1,000,000/3 years, and the cross-border transfer whitelist repealed. From 1 June 2025: mandatory DPO appointment, mandatory breach notification, and a new data-portability right.

How much can a company be fined under Malaysia's PDPA?

The general penalty under s.5(2) is up to RM1,000,000 and/or 3 years' imprisonment, effective 1 April 2025. Two others did not rise with it: failure to notify the Commissioner stays at RM250,000/2 years (s.12B(3)), and unlawful cross-border transfer stays at RM300,000/2 years (s.129(5)). Every figure is a flat ringgit amount; Malaysia has no revenue-percentage fine, unlike the GDPR's up to 4% of global turnover.

Does Malaysia's PDPA have a right to erasure like the GDPR?

No. Act 709 has no standalone erasure right a data subject can invoke. Deletion appears only as a retention duty on the controller under s.10, requiring data to be destroyed once no longer needed. The GDPR's Art. 17 gives data subjects an affirmative right to request deletion; the PDPA does not.

How does Malaysia's cross-border data transfer rule work now?

Since 1 April 2025, Malaysia no longer uses a Minister-approved whitelist. Act A1727 repealed it. A controller now self-assesses each transfer against amended s.129(2): whether the destination has a substantially similar law, or an equivalent level of protection, per the Commissioner's Cross-Border Personal Data Transfer Guideline (No. 3/2025). This is less centralized than the GDPR's adequacy model, not more.

How quickly must a data breach be reported under Malaysia's PDPA?

Within 72 hours of the breach, to the Commissioner, under s.4(4) of the breach-notification circular (titled No. 2/2025 on the document itself). Notification is triggered by any one of five risk factors, including more than 1,000 affected individuals, which is one alternative trigger, not a minimum floor. Affected individuals must be notified 7 days after the Commissioner is notified, not 7 days from the breach itself.

Is Malaysia's PDPA stricter or more lenient than the GDPR?

Neither, uniformly. The PDPA is narrower in scope, legal bases, rights, and sensitive-data coverage, and has no revenue-percentage fine. It is comparable to the GDPR only since mid-2025, when DPO appointment and breach notification became mandatory. Its flat statutory penalties can still impose a heavier relative burden on a small or purely domestic Malaysian business than a GDPR percentage fine, calibrated to revenue, would impose on a multinational.

Updates

Page published. Covers the Personal Data Protection Act 2010 (Act 709) as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), phased into force between 1 January 2025 and 1 June 2025, compared against the EU General Data Protection Regulation.

Sources and References

  1. Personal Data Protection Act 2010 (Act 709), full text(mohre.um.edu.my)
  2. Personal Data Protection (Amendment) Act 2024 (Act A1727), full text(pdp.gov.my).gov
  3. Personal Data Protection Department: Personal Data Protection (Amendment) Act 2024 overview(pdp.gov.my).gov
  4. Personal Data Protection (Amendment) Act 2024 commencement date determination(pdp.gov.my).gov
  5. Personal Data Protection Department: Application and Non-Application of the Act(pdp.gov.my).gov
  6. Cross-Border Personal Data Transfer Guideline (No. 3/2025), issued 29 April 2025(pdp.gov.my).gov
  7. Circular of the Personal Data Protection Commissioner No. 2 of 2025 (Data Breach Notification)(pdp.gov.my).gov
  8. Data Protection Impact Assessment (DPIA) Guideline(pdp.gov.my).gov
  9. Personal Data Protection Department: Data Protection Impact Assessment Guideline (DPIA) overview(pdp.gov.my).gov
  10. Regulation (EU) 2016/679 (General Data Protection Regulation), consolidated text(eur-lex.europa.eu).gov
  11. GDPR Articles 3, 6, 9 and 83, verbatim mirror(gdpr-info.eu)
Share: