Malaysia PDPA vs GDPR: Government Exemption, Scope & 2025 Amendments

Malaysia's Personal Data Protection Act 2010 exempts the Federal Government and State Governments outright (s.3(1)), uses an older establishment-or-equipment territorial test instead of the GDPR's targeting test, and has no legitimate-interests legal basis, no erasure right, and no revenue-percentage fine, even after the 2024 Amendment Act's phased overhaul.
The EU's General Data Protection Regulation and Malaysia's Personal Data Protection Act 2010 (Act 709) look superficially similar: both regulate personal data, require a legal basis for processing, and now require breach notification and a designated privacy officer. The similarity ends once the statutory text is read side by side. Malaysia's Act was drafted around the older "commercial transactions" framing of the EU's 1995 Data Protection Directive, carries a blanket government exemption the GDPR does not have, and only picked up mandatory DPO appointment, breach notification, and data portability in mid-2025, through the Personal Data Protection (Amendment) Act 2024.
This article compares both frameworks section by section, reading the operative language of Act 709, Act A1727, and the Commissioner's 2025 guidelines directly rather than summarizing secondary commentary. For the complete standalone picture, see our guide to Malaysia's data privacy laws.
Information last verified 23 July 2026. This article has not yet been reviewed by a licensed lawyer.
Jurisdictional scope: This article compares Malaysia's Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727, phased into force 1 January 2025 through 1 June 2025), against the EU's General Data Protection Regulation (Regulation (EU) 2016/679). It does not address Malaysian sector-specific data rules outside Act 709, the personal data laws of other Malaysian states (Sabah and Sarawak have separate constitutional arrangements not covered here), or the data privacy laws of other APAC jurisdictions.
Malaysia PDPA vs GDPR: At a Glance
| Feature | Malaysia PDPA (Act 709, as amended) | EU GDPR |
|---|---|---|
| Applies to government? | No, Federal and State Governments are exempt (s.3(1)) | Yes, public authorities are covered controllers; many must appoint a DPO (Art. 37(1)(a)) |
| Territorial test | Establishment in Malaysia, or equipment used in Malaysia (s.2) | "Targeting" test: offering goods/services to, or monitoring, EU data subjects, with no EU presence required (Art. 3(2)) |
| Legal bases | 6: consent + 5 non-consent grounds (s.6) | 6: consent + 5 non-consent grounds, including legitimate interests (Art. 6) |
| Legitimate-interests basis | Not available | Available (Art. 6(1)(f)) |
| Sensitive-data categories | 5: health, political opinions, religious beliefs, criminal-offence data, biometric data (s.4, as amended) | 8 (Art. 9): adds race/ethnicity, trade union membership, genetic data, sex life/orientation |
| Right to erasure | No standalone right; only a retention-duty on the controller (s.10) | Yes (Art. 17) |
| General right to object | No; only a damage/distress-gated right (s.42) and a direct-marketing opt-out (s.43) | Yes (Art. 21) |
| Automated-decision-making right | Not in the statute | Yes (Art. 22) |
| Data portability | Yes, new s.43A, effective 1 June 2025; conditioned on technical feasibility; completion deadline deferred to unpublished regulation | Yes (Art. 20) |
| Mandatory DPO | Yes, effective 1 June 2025, threshold-based | Required for public authorities and certain processing; threshold-based otherwise (Art. 37) |
| Mandatory breach notification | Yes, effective 1 June 2025; 72 hours to the Commissioner | Yes; 72 hours to the supervisory authority (Art. 33) |
| Cross-border transfer mechanism | Controller self-assessment against a "substantially similar law" or "adequate protection" test; no published list (post-1 April 2025) | EU Commission adequacy decisions, SCCs, BCRs; centrally administered (Art. 44-49) |
| Maximum general penalty | RM1,000,000 and/or 3 years' imprisonment (s.5(2), from 1 April 2025) | EUR 20,000,000 or 4% of global annual turnover, whichever is higher (Art. 83(5)) |
| Revenue-percentage fine | None | Yes, up to 4% of global turnover |
| Regulator | Personal Data Protection Commissioner (JPDP), Ministry of Digital | National data protection authorities, coordinated by the European Data Protection Board |

Background and the 2024 Amendment Act Timeline
Act 709 regulates personal data processed "in respect of commercial transactions," administered by the Personal Data Protection Commissioner under the Ministry of Digital. Act A1727 received royal assent on 9 October 2024 and phased into force across three commencement dates rather than one.
Phase 1 (1 January 2025) brought in administrative provisions only: sections 7, 11, 13, and 14.
Phase 2 (1 April 2025) carried the substantive core of the amendment. "Data user" was renamed "data controller" throughout the Act; biometric data was added to the sensitive-data category; "personal data breach" received a statutory definition for the first time; data processors came under direct regulation rather than only through their controllers; the general penalty under s.5(2) rose from RM300,000/2 years to RM1,000,000/3 years; and the Minister's cross-border transfer whitelist was repealed and replaced with a controller-assessed adequacy test. The Commissioner published the Cross-Border Personal Data Transfer Guideline (No. 3/2025) on 29 April 2025 to accompany the new test.
Phase 3 (1 June 2025) brought the three provisions with the widest operational impact into force: mandatory DPO appointment, mandatory breach notification, and the new data-portability right (s.43A). Two Commissioner circulars dated 25 February 2025 implement these duties. The breach-notification circular is titled, on the document itself, "Circular of the Personal Data Protection Commissioner No. 2 of 2025," though the Commissioner's own website navigation and page URL label it "1/2025", cite the number printed on the PDF, not the site's menu label, if pulling the primary source directly. The DPO circular is Circular No. 1/2025.
The GDPR, by contrast, has a single effective date (25 May 2018) across all 30 EEA member states, with no comparable phased overhaul since.

Who the Law Does and Does Not Bind: The Government Exemption
Section 3(1) of Act 709 states plainly: "This Act shall not apply to the Federal Government and State Governments." Section 3(2) adds a second non-application rule: the Act does not apply to personal data processed outside Malaysia unless that data is intended for further processing inside Malaysia. Neither provision was touched by the 2024 Amendment Act.
This is not a narrow carve-out bolted onto an otherwise general-purpose law. It sits alongside s.2(1), which frames the whole Act around personal data processed "in respect of commercial transactions," and s.4's definition of "personal data" itself, likewise scoped to commercial transactions. Malaysia's federal and state agencies, including tax authorities, police, Ministry of Health hospitals, and immigration, sit entirely outside the PDPA's reach. There is no Malaysian public-sector equivalent of the GDPR at all.
The GDPR takes the opposite position. It does not exclude public authorities from the definition of "controller" (Art. 4(7)), and Art. 37(1)(a) makes DPO appointment mandatory specifically for public authorities and bodies.
Two edges are worth flagging rather than resolving. Act 709 does not itself define "Federal Government" or "State Government," relying on the general Interpretation Acts 1948/1967. And whether a government-linked company operating as a separately incorporated commercial entity falls inside or outside the exemption is contested in Malaysian legal commentary, untested by any court. Treat s.3(1)'s plain-text exemption as settled and the GLC edge as open.

Scope and Extraterritorial Reach
Section 2 of Act 709 sets Malaysia's territorial test, and it is structurally older than the GDPR's. The Act applies to a person who is "established in Malaysia," regardless of where the processing actually occurs, or to a person not established in Malaysia who "uses equipment in Malaysia for processing the personal data otherwise than for the purposes of transit through Malaysia" (s.2(2)). A person caught only through the equipment limb must nominate a Malaysian-established representative (s.2(3)). Section 2(4) defines "established in Malaysia" as: an individual with 180 or more days of physical presence; incorporation under the Companies Act 1965; a partnership formed under Malaysian law; or maintaining an office, branch, or agency, or otherwise carrying on "a regular practice," in Malaysia.
This is the same establishment-and-equipment model the EU used under the 1995 Data Protection Directive (Art. 4), not the newer GDPR Art. 3(2) "targeting" test, which extends to a controller with no EU establishment and no EU equipment at all, whenever it offers goods or services to, or monitors, data subjects in the Union. Malaysia's Act has no comparable hook.
The practical consequence: a foreign e-commerce business with no Malaysian office and no equipment physically in Malaysia, but which markets to and processes Malaysian consumers' data online, arguably falls entirely outside the PDPA's territorial reach as written. The Commissioner's own explainer on application and non-application of the Act restates the same establishment-and-equipment language without any targeting-style extension. Businesses should not assume Malaysia-facing operations are covered just because equivalent EU-facing operations are covered under GDPR Art. 3(2); the two tests are not equivalent.

Definitions and Sensitive Data
| Concept | Malaysia PDPA | EU GDPR |
|---|---|---|
| Controlling party | "Data controller" (renamed from "data user" by Act A1727, effective 1 April 2025) | "Controller" |
| Individual | "Data subject" | "Data subject" |
| Protected information | "Personal data," scoped to commercial transactions (s.4) | "Personal data," no commercial-transaction scoping |
| Sensitive category | "Sensitive personal data" (s.4) | "Special categories of personal data" (Art. 9) |
| Privacy lead | Person appointed as Data Protection Officer, mandatory from 1 June 2025 | Data Protection Officer (Art. 37) |
The original s.4 definition of "sensitive personal data" covered health or medical condition, political opinions, religious or similar beliefs, and criminal-offence data, plus anything the Minister added by Gazette. Act A1727 §3 inserted a definition of "biometric data" ("any personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person") and added biometric data to the sensitive-data list.
Even with that addition, Malaysia's list remains structurally shorter than the GDPR's eight Art. 9(1) categories: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, and sex life or sexual orientation. Malaysia still has no equivalent for race/ethnicity, trade union membership, genetic data, or sex-life data; the 2024 amendment added one category to a list that remains narrower, not one that now matches the GDPR's.
Section 40 sets the conditions for processing sensitive personal data: explicit consent, or one of a longer enumerated list covering employment-law necessity, vital interests, medical purposes by a healthcare professional, legal proceedings, administration of justice, or statutory functions. This broadly parallels the GDPR's Art. 9(2) exceptions, though the grounds do not map one to one; treat the two regimes as structurally similar, not equivalent.
Legal Bases for Processing
Section 6 sets Malaysia's baseline: a controller may not process personal data other than sensitive personal data unless the data subject has consented (s.6(1)(a)), unless processing is necessary for one of five non-consent grounds under s.6(2): contract performance; pre-contractual steps; a non-contractual legal obligation; vital interests; the administration of justice; or the exercise of functions conferred by law. That totals six legal bases: consent plus five non-consent grounds. The 2024 Amendment Act did not touch s.6.
The critical omission, confirmed by its absence, is a GDPR-style legitimate-interests basis. The GDPR's Art. 6(1)(f) allows processing "necessary for the purposes of the legitimate interests pursued by the controller," subject to a balancing test. Malaysia has no equivalent ground. Routine processing a GDPR controller would ground on legitimate interests, such as fraud prevention, network security, or direct-mail analytics, has no matching non-consent basis under the PDPA unless it fits one of the six listed grounds, pushing PDPA compliance toward consent far more often than the GDPR requires.
Consent
Both regimes require consent to be freely given and capable of withdrawal, but the PDPA layers additional structure onto the baseline. General consent under s.6(1)(a) governs non-sensitive personal data. Sensitive personal data requires explicit consent under s.40, subject to the enumerated exceptions described above. Section 38 gives data subjects the right to withdraw consent at any time.
The regimes diverge most in what follows withdrawal. The GDPR's Art. 7 requires consent to be as easy to withdraw as to give. Malaysia's s.38 mirrors that for future processing, but gives no general right to demand deletion of data already collected; withdrawal stops further processing, while erasure remains governed only by the retention principle discussed below.
Data Subject Rights and the Gaps
Part V of Act 709 sets out the rights data subjects can exercise: the right of access (s.30), the right to correct inaccurate data (s.34), the right to withdraw consent (s.38), a right to prevent processing likely to cause damage or distress (s.42), and a right to prevent direct marketing (s.43). Act A1727 §9 added a new s.43A right to data portability, effective 1 June 2025.
Section 43A lets a data subject request that a controller transmit their data to another controller of their choice, by written electronic notice. Two qualifiers matter. First, the right is expressly conditioned on "technical feasibility and compatibility of the data format" (s.43A(2)), a broader carve-out than the GDPR's Art. 20, which limits its own feasibility qualifier to the narrower direct-transmission sub-clause. Second, the completion deadline is left to "the period as may be prescribed" (s.43A(3)) and deferred to a subsidiary regulation not yet published. No specific number of days should be treated as the current deadline.
Three gaps are confirmed by absence from the statutory text, not inferred:
- No standalone right to erasure. Deletion appears only as a retention duty on the controller (s.10: data must be destroyed once no longer required for its purpose), never as a right a data subject can affirmatively invoke the way the GDPR's Art. 17 does.
- No general right to object. Section 42's right applies only where processing is "likely to cause damage or distress," a threshold the GDPR's Art. 21 does not require. Section 43's direct-marketing opt-out matches GDPR Art. 21(2), but there is no general-processing objection equivalent.
- No automated-decision-making right in the statute. The GDPR's Art. 22 gives data subjects a right not to be subject to a solely automated decision with legal or similarly significant effects, plus safeguards. Act 709 and Act A1727 contain no equivalent provision. The Commissioner's separate Automated Decision-Making and Profiling Guideline's binding status is unconfirmed; see Recent Developments below.
For a jurisdiction-by-jurisdiction look at DPO obligations, including how Malaysia's 1 June 2025 threshold compares to other countries, see data protection officer requirements.
Breach Notification
Malaysia's breach-notification duty is implemented through a Commissioner circular, not directly in the Act itself. The circular's own title is "Circular of the Personal Data Protection Commissioner No. 2 of 2025" (despite the Commissioner's website navigation labeling it "1/2025"), dated 25 February 2025, effective 1 June 2025 (s.10 of the circular).
Section 4(1) sets the underlying duty in general terms: notification must occur "as soon as practicable." Section 4(4) then fixes a hard clock: the data controller must submit the required information to the Commissioner within 72 hours of the personal data breach. Section 4(5) requires the controller to provide reasons and supporting evidence if the 72-hour window is missed.
The duty is triggered by any one of five listed risk factors under s.4(3): physical injury, financial loss, or credit damage to affected individuals; misuse for an unlawful purpose; involvement of sensitive personal data; a combination enabling identity fraud; or "significant scale," which s.3(1)(e) defines as more than 1,000 affected data subjects. The 1,000-person threshold is one alternative trigger among five, not a floor; a breach affecting 50 people that risks identity fraud still triggers the duty.
Individual notice runs on a separate, later clock: s.5(2) requires notice to affected data subjects within 7 days after the Commissioner is notified, not 7 days from the breach itself. Section 9 sets the penalty for failing to notify the Commissioner under s.12B(1): a fine up to RM250,000 and/or up to 2 years.
The GDPR's Art. 33 sets a comparable 72-hour clock, running from the controller's awareness, with Art. 34 requiring "without undue delay" individual notice for high-risk breaches. The structural difference is the individual-notice trigger: Malaysia's runs from the regulator-notification date, the GDPR's from the controller's own awareness, independent of the regulator notice. For how Malaysia's clock compares elsewhere, see data breach notification deadlines by country.
Cross-Border Transfers After the Whitelist Repeal
Before 1 April 2025, s.129(1) of Act 709 banned personal data transfers outside Malaysia except to places the Minister had gazetted onto a published whitelist. Act A1727 §12 deleted that subsection entirely, along with subsection (4), the mechanism for the Minister to remove a place from the list.
What remains, amended s.129(2), reads: a data controller may transfer personal data to any place outside Malaysia if there is in force in that place a law "substantially similar" to Act 709, or if that place ensures a level of protection "at least equivalent" to the protection Act 709 affords. That substantive test carries over largely unchanged from the old Ministerial criteria; what changed is who applies it. The Minister used to pre-approve countries by Gazette, a closed list businesses could check. Now each controller self-assesses, transfer by transfer, against the Commissioner's Cross-Border Personal Data Transfer Guideline (No. 3/2025, issued 29 April 2025), which sets multi-factor checklists for both routes plus a "Recognised Certificate" option from an accredited body.
Section 129(3)'s alternative exceptions (consent, contract necessity, legal proceedings and rights, vital interests, and a "reasonable grounds" avoidance-of-adverse-action ground) are retained largely as before, with the old public-interest-as-determined-by-the-Minister ground deleted.
The GDPR's Art. 44-49 uses a structurally similar adequacy-plus-safeguards framework, but the European Commission centrally determines adequacy through a closed, published list, with standard contractual clauses and binding corporate rules as the fallback for non-adequate destinations. Malaysia has moved in the opposite direction: from a centrally curated whitelist toward a fully decentralized, controller-self-assessed model with no published list at all. That inversion, less centralized than the GDPR after 1 April 2025 rather than more, is one of the more distinctive features of the 2024 Amendment Act.
Enforcement and Penalties
| Provision | Penalty | Changed by Act A1727? |
|---|---|---|
| s.5(2), breach of a core Principle (general penalty) | RM1,000,000 and/or 3 years' imprisonment | Yes, raised from RM300,000/2 years, effective 1 April 2025 |
| s.12B(3), failure to notify the Commissioner of a breach | RM250,000 and/or 2 years' imprisonment | No, unchanged |
| s.129(5), unlawful cross-border transfer | RM300,000 and/or 2 years' imprisonment | No, only the scope of what triggers it changed (from "subsection (1)" to "this section") |
The general penalty under s.5(2) covers a breach of any of the Act's seven core Principles (General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, and Access), and is the only figure the 2024 Amendment Act actually raised. It is a mistake to assume every PDPA penalty jumped to RM1,000,000; the breach-notification and cross-border penalties did not move.
Every penalty figure in Act 709 is a flat ringgit amount with an alternative or cumulative prison term; none is expressed as a percentage of turnover. The GDPR's Art. 83(4)-(6) sets a lower tier of up to EUR 10,000,000 or 2% of global annual turnover, whichever is higher, and a higher tier of up to EUR 20,000,000 or 4%, whichever is higher, covering processing-principle, special-category, rights, and transfer violations. This is a structural difference, not just a size difference: the GDPR's ceiling scales with the entity's revenue, while Malaysia's is fixed regardless of it. A small Malaysian business facing the RM1,000,000 maximum may feel a heavier relative burden than a multinational facing a GDPR percentage fine calibrated to its own turnover.
Enforcement history under the older regime was modest: 33 compounded settlements between 2017 and 2025, highest RM108,000, all pre-amendment. No enforcement action has been identified under the new RM1,000,000 ceiling as of this research, an absence of confirmed cases, not a prediction that none will occur.
Recent Developments
On 8 May 2026, the Commissioner issued three new guidelines following a 2025 consultation: a Data Protection Impact Assessment (DPIA) Guideline, a Data Protection by Design Guideline, and an Automated Decision-Making and Profiling Guideline. Only the DPIA Guideline has been read directly; the other two, referenced as companion documents in its table of contents, have not been independently reviewed, and their content and status should not be assumed to mirror it.
The DPIA Guideline frames itself carefully. Its own §1.3 describes it as providing "practical guidance" for carrying out a DPIA, and §1.5 states the Guideline "shall not be considered to override any other personal data protection-related laws and regulations in force." It is issued under the Commissioner's general supervisory function in s.48(g) of Act 709, a monitoring and instrument-issuing power rather than independent rule-making. At the same time, §2.1 ties the DPIA requirement back to "subparagraph 5(1)(d)" of the DPO Circular No. 1/2025, a provision this research did not independently open. Whether that subparagraph independently creates a binding DPIA duty, or is simply a cross-reference, is unresolved on the sources reviewed. No effective-date field appears anywhere in the DPIA Guideline's text, only a 2026 copyright line. This article does not characterize the DPIA, Data Protection by Design, or Automated Decision-Making and Profiling guidelines as either mandatory or advisory; treat the question as open until the underlying Circular is confirmed.
The DPIA Guideline itself is a useful data point on regional comparison: its own §5.2 states that the European Union, the United Kingdom, Indonesia, the Philippines, and South Korea have made DPIAs a mandatory legal obligation in specified circumstances, while Singapore, Japan, Australia, and New Zealand recommend DPIAs as best practice without making them mandatory. The Guideline does not place Malaysia in either list, which is itself a signal that the drafters left the question deliberately open in the document.
Dual-Compliance Guidance
Organizations subject to both regimes, most commonly multinationals with a Malaysian subsidiary, distributor, or outsourced processing operation, face several points where the two pull in different directions.
| Issue | GDPR requirement | PDPA requirement | Compliance approach |
|---|---|---|---|
| Government-adjacent processing | Public authorities are covered controllers, DPO often mandatory | Federal/State Government agencies entirely outside the Act | Don't assume PDPA protection over Malaysian government-held data |
| Extraterritorial trigger | Targeting test (Art. 3(2)); no EU establishment needed | Establishment or equipment required (s.2); no-footprint business may fall outside | Assess each jurisdiction's test separately, not by analogy |
| Basis for marketing/analytics | Legitimate interests available (Art. 6(1)(f)) | No legitimate-interests ground; must fit one of six s.6 grounds | Default to consent for Malaysian data subjects |
| Erasure requests | Right to erasure (Art. 17) | No standalone right; s.10 retention duty only | Honor deletion requests as policy; no statutory right to invoke |
| DPO appointment | Mandatory for public authorities and certain processing (Art. 37) | Mandatory from 1 June 2025, threshold-based | Appoint under each regime's own threshold; duties are separate |
| Breach notification clock | 72 hours to the authority from awareness (Art. 33) | 72 hours to the Commissioner from the breach; individual notice 7 days after Commissioner notice | Track both clocks independently in the incident-response runbook |
| Cross-border transfers | Centralized adequacy decisions, SCCs, BCRs | Controller self-assessment; no published list | Document each transfer's basis separately; neither regime's clearance satisfies the other |
Many organizations manage the gap by treating Malaysian operations as a distinct compliance track rather than extending EU policies by reference. A consent flow built to satisfy the GDPR's legitimate-interests basis will not satisfy the PDPA for the same activity, because that basis does not exist under s.6.
Disclaimer
This article presents general legal information about Malaysia's Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), and the EU's General Data Protection Regulation. It is not legal advice. Information reflects the state of both laws as of 23 July 2026, including the Amendment Act's phased commencement through 1 June 2025 and the Commissioner's 8 May 2026 DPIA Guideline. Both frameworks continue to evolve through subsidiary regulations, circulars, and guidelines, including at least one item (the data-portability completion deadline) still pending a subsidiary regulation as of this writing. Organizations subject to either or both frameworks should consult a lawyer licensed in the relevant jurisdiction for advice specific to their situation.
Frequently Asked Questions
Does Malaysia's PDPA apply to the Malaysian government?
No. Section 3(1) of Act 709 states the Act does not apply to the Federal Government or State Governments, an exemption the 2024 Amendment Act left untouched. The GDPR takes the opposite approach: public authorities are covered controllers, and Art. 37(1)(a) makes DPO appointment mandatory for most of them.
Does the PDPA apply to a foreign company with no office in Malaysia?
Not necessarily. Section 2 applies the Act to a person established in Malaysia or using equipment in Malaysia. A foreign business with neither may fall outside the Act's reach even while marketing to Malaysian consumers online, unlike the GDPR's Art. 3(2) targeting test, which reaches a controller with no EU presence at all.
What did Malaysia's 2024 Amendment Act change?
Act A1727 phased in over three dates. From 1 April 2025: 'data user' renamed 'data controller,' biometric data added to sensitive data, processors directly regulated, the general penalty raised to RM1,000,000/3 years, and the cross-border transfer whitelist repealed. From 1 June 2025: mandatory DPO appointment, mandatory breach notification, and a new data-portability right.
How much can a company be fined under Malaysia's PDPA?
The general penalty under s.5(2) is up to RM1,000,000 and/or 3 years' imprisonment, effective 1 April 2025. Two others did not rise with it: failure to notify the Commissioner stays at RM250,000/2 years (s.12B(3)), and unlawful cross-border transfer stays at RM300,000/2 years (s.129(5)). Every figure is a flat ringgit amount; Malaysia has no revenue-percentage fine, unlike the GDPR's up to 4% of global turnover.
Does Malaysia's PDPA have a right to erasure like the GDPR?
No. Act 709 has no standalone erasure right a data subject can invoke. Deletion appears only as a retention duty on the controller under s.10, requiring data to be destroyed once no longer needed. The GDPR's Art. 17 gives data subjects an affirmative right to request deletion; the PDPA does not.
How does Malaysia's cross-border data transfer rule work now?
Since 1 April 2025, Malaysia no longer uses a Minister-approved whitelist. Act A1727 repealed it. A controller now self-assesses each transfer against amended s.129(2): whether the destination has a substantially similar law, or an equivalent level of protection, per the Commissioner's Cross-Border Personal Data Transfer Guideline (No. 3/2025). This is less centralized than the GDPR's adequacy model, not more.
How quickly must a data breach be reported under Malaysia's PDPA?
Within 72 hours of the breach, to the Commissioner, under s.4(4) of the breach-notification circular (titled No. 2/2025 on the document itself). Notification is triggered by any one of five risk factors, including more than 1,000 affected individuals, which is one alternative trigger, not a minimum floor. Affected individuals must be notified 7 days after the Commissioner is notified, not 7 days from the breach itself.
Is Malaysia's PDPA stricter or more lenient than the GDPR?
Neither, uniformly. The PDPA is narrower in scope, legal bases, rights, and sensitive-data coverage, and has no revenue-percentage fine. It is comparable to the GDPR only since mid-2025, when DPO appointment and breach notification became mandatory. Its flat statutory penalties can still impose a heavier relative burden on a small or purely domestic Malaysian business than a GDPR percentage fine, calibrated to revenue, would impose on a multinational.
Updates
Page published. Covers the Personal Data Protection Act 2010 (Act 709) as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), phased into force between 1 January 2025 and 1 June 2025, compared against the EU General Data Protection Regulation.
Sources and References
- Personal Data Protection Act 2010 (Act 709), full text(mohre.um.edu.my)
- Personal Data Protection (Amendment) Act 2024 (Act A1727), full text(pdp.gov.my).gov
- Personal Data Protection Department: Personal Data Protection (Amendment) Act 2024 overview(pdp.gov.my).gov
- Personal Data Protection (Amendment) Act 2024 commencement date determination(pdp.gov.my).gov
- Personal Data Protection Department: Application and Non-Application of the Act(pdp.gov.my).gov
- Cross-Border Personal Data Transfer Guideline (No. 3/2025), issued 29 April 2025(pdp.gov.my).gov
- Circular of the Personal Data Protection Commissioner No. 2 of 2025 (Data Breach Notification)(pdp.gov.my).gov
- Data Protection Impact Assessment (DPIA) Guideline(pdp.gov.my).gov
- Personal Data Protection Department: Data Protection Impact Assessment Guideline (DPIA) overview(pdp.gov.my).gov
- Regulation (EU) 2016/679 (General Data Protection Regulation), consolidated text(eur-lex.europa.eu).gov
- GDPR Articles 3, 6, 9 and 83, verbatim mirror(gdpr-info.eu)