Law note · Malaysia
Personal Data Protection Act, cross-border transfer
cite Act 709 (Malaysia) s.129, as amended by Act A1727 s.12, in force 2025-04-01
stage IN FORCE in force since 2025-04-01
kind Cross border transfer
binds private bodies
reviewed 2026-08-29
What it requires
- An app transferring the personal data of an individual in Malaysia, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Malaysia must self-assess that the recipient's jurisdiction has a substantially similar law or an adequate level of protection before the transfer.
When LexLint raises it
crawls_webtrains_modelsprocesses_voiceprocesses_biometrics
What we found
The original s.129 barred transferring personal data outside Malaysia except to a place the Minister specified by gazette notification as having a substantially similar law or an adequate level of protection; in practice this whitelist mechanism was never gazetted, making the provision largely inoperative.
Act A1727 s.12 restructures s.129, replacing the Minister's gazetting power with the data controller's own self-assessment against the substantially similar law or adequate level of protection standard, and drops the alternative or that serves the same purposes as this Act language, narrowing the standard. There is no data-localization mandate.