Personal Data Protection Act, cross-border transfer
Act 709 (Malaysia) s.129, as amended by Act A1727 s.12, in force 2025-04-01
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 April 2025.
A cross border transfer rule binding private bodies.
As of 29 August 2026.
What it requires
- An app transferring the personal data of an individual in Malaysia, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Malaysia must self-assess that the recipient's jurisdiction has a substantially similar law or an adequate level of protection before the transfer.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The original s.129 barred transferring personal data outside Malaysia except to a place the Minister specified by gazette notification as having a substantially similar law or an adequate level of protection; in practice this whitelist mechanism was never gazetted, making the provision largely inoperative.
Act A1727 s.12 restructures s.129, replacing the Minister's gazetting power with the data controller's own self-assessment against the substantially similar law or adequate level of protection standard, and drops the alternative or that serves the same purposes as this Act language, narrowing the standard. There is no data-localization mandate.
When LexLint raises it
crawls_webtrains_modelsprocesses_voiceprocesses_biometrics
Read the law
official statute and Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.