Law note · Malaysia

Personal Data Protection Act, cross-border transfer

cite Act 709 (Malaysia) s.129, as amended by Act A1727 s.12, in force 2025-04-01 stage IN FORCE in force since 2025-04-01 kind Cross border transfer binds private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of an individual in Malaysia, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Malaysia must self-assess that the recipient's jurisdiction has a substantially similar law or an adequate level of protection before the transfer.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_voice
  • processes_biometrics

What we found

The original s.129 barred transferring personal data outside Malaysia except to a place the Minister specified by gazette notification as having a substantially similar law or an adequate level of protection; in practice this whitelist mechanism was never gazetted, making the provision largely inoperative.

Act A1727 s.12 restructures s.129, replacing the Minister's gazetting power with the data controller's own self-assessment against the substantially similar law or adequate level of protection standard, and drops the alternative or that serves the same purposes as this Act language, narrowing the standard. There is no data-localization mandate.

← Back to the example  ·  Lint your app →