Law / Malaysia

Malaysia

11 of 15 named instruments researched to a stage, across four of the six areas of law we track: 11 in force. As of 16 September 2026.

When they take effect11 of 11 carry a date. Earlier is before 2014.
Before 2014: 4 instruments (4 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 5 instruments (5 in force) 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law 2
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (172 words)

Malaysia's comprehensive private-sector data-protection law is the Personal Data Protection Act 2010 (Act 709), substantially amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727), in force on a staged commencement schedule set by Ministerial gazette notification.

Act A1727 s.3, in force since 1 April 2025, added a dedicated biometric data definition (technical processing relating to physical, physiological, or behavioural characteristics) directly to the sensitive personal data list, reaching both a faceprint and a voiceprint since either is produced by exactly that kind of technical processing.

Act A1727 also relabels data user as data controller, imposes direct statutory duties on data processors for the first time, replaces the never-exercised Ministerial cross-border whitelist with controller self-assessed adequacy (s.129, in force since 1 April 2025), and adds a mandatory Data Protection Officer duty and data breach notification duty (ss.12A-12B, in force since 1 June 2025) and a data portability right (s.43A, in force since 1 June 2025). The Act's text is cited from the Department of Personal Data Protection's own PDFs at pdp.gov.my.

Biometric privacy

Personal Data Protection Act, biometric data definition and sensitive category

Act 709 (Malaysia) s.4, as amended by Act A1727 s.3, in force 2025-04-01official Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)

In force since 1 April 2025. Binds private bodies.

What this law does

Act A1727 s.3 inserted a dedicated biometric data definition into s.4 (any personal data resulting from technical processing relating to a person's physical, physiological, or behavioural characteristics) and added biometric data to the sensitive personal data list immediately after the offence-related category.

Both a faceprint and a voiceprint fall squarely within physical, physiological, or behavioural characteristics resulting from technical processing, which is exactly how a voice or face embedding is produced. Both are now, in force, sensitive personal data under s.4, requiring explicit consent under s.40's stricter processing conditions. No biometric-specific retention or destruction duty distinct from the Act's general data-minimisation and accuracy principles was found.

What it requires

Breach notification

Personal Data Protection Act, data protection officer and breach notification

Act 709 (Malaysia) ss.12A-12B, as inserted by Act A1727 s.6, in force 2025-06-01official Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)

In force since 1 June 2025. Binds private bodies.

What this law does

Act A1727 s.6 inserts new Division 1A into Part II, requiring both the data controller and data processor to appoint a Data Protection Officer (s.12A) and, at s.12B, requiring the data controller to notify the Commissioner as soon as practicable on reasonable belief that a personal data breach occurred; where the breach causes or is likely to cause significant harm to the data subject, the controller must also notify the data subject without unnecessary delay.

No fixed numeric deadline is set in the statute itself; timing and form are left to the Commissioner's own prescribed manner. Non-compliance with the Commissioner-notification duty is itself an offence, carrying a fine up to RM250,000, imprisonment up to 2 years, or both. Before this amendment, Act 709 had no statutory breach-notification duty at all.

What it requires

Comprehensive regime

Personal Data Protection Act, comprehensive regime and lawful bases

Act 709 (Malaysia), as amended by the Personal Data Protection (Amendment) Act 2024, Act A1727official statute text, Department of Personal Data Protection (pdp.gov.my)

In force since 15 November 2013. Binds private bodies.

What this law does

Act 709's lawful basis is a bifurcated consent model: ordinary personal data needs the data subject's consent, subject to contract, legal-obligation, and vital-interest exceptions (s.6), while sensitive personal data needs explicit consent under s.40's stricter conditions. Contravening any of the seven Data Protection Principles is itself an offence, carrying a fine up to RM300,000, imprisonment up to 2 years, or both (s.5(2)).

Act A1727 relabels data user as data controller throughout and, for the first time, imposes direct statutory duties on data processors, who were previously reached only through contract with the data user.

Section 1(2) leaves the base Act's own commencement to a Ministerial gazette notification rather than stating a date in the Act's own text; the Department of Personal Data Protection's own published determination fixes that date at 15 November 2013, and that is recorded here as the general commencement date, distinct from the 2024 amendment's own staged commencement dates, recorded separately.

What it requires

Cross border transfer

Personal Data Protection Act, cross-border transfer

Act 709 (Malaysia) s.129, as amended by Act A1727 s.12, in force 2025-04-01official statute and Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)

In force since 1 April 2025. Binds private bodies.

What this law does

The original s.129 barred transferring personal data outside Malaysia except to a place the Minister specified by gazette notification as having a substantially similar law or an adequate level of protection; in practice this whitelist mechanism was never gazetted, making the provision largely inoperative.

Act A1727 s.12 restructures s.129, replacing the Minister's gazetting power with the data controller's own self-assessment against the substantially similar law or adequate level of protection standard, and drops the alternative or that serves the same purposes as this Act language, narrowing the standard. There is no data-localization mandate.

What it requires

Data subject rights

Personal Data Protection Act, data portability

Act 709 (Malaysia) s.43A, as inserted by Act A1727 s.9, in force 2025-06-01official Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)

In force since 1 June 2025. Binds private bodies.

What this law does

Act A1727 s.9 added s.43A, giving a data subject the right to request the data controller transmit their personal data to another data controller of the subject's choice by written electronic notice, subject to technical feasibility and compatibility of the data format. The controller must complete the transmission within the period as may be prescribed, with no fixed statutory deadline; the specific period is left to subsidiary regulation not read.

What it requires

Enforcement supervision

Personal Data Protection Act, enforcement

Act 709 (Malaysia) ss.5(2), 12B(3)official statute and Act A1727 amendment text, Department of Personal Data Protection (pdp.gov.my)

In force since 15 November 2013, effective 1 June 2025. Binds private bodies.

What this law does

The Personal Data Protection Commissioner is the supervisory authority. Enforcement is criminal and administrative: contravening any Data Protection Principle is an offence under the base Act's s.5(2) (fine up to RM300,000, imprisonment up to 2 years, or both), which came into force with the rest of the base Act on 15 November 2013, and the new s.12B(3) breach-notification offence, in force since 1 June 2025, carries a fine up to RM250,000, imprisonment up to 2 years, or both.

No private right of action provision was located in the sections read; enforcement is Commissioner-driven and criminal, not a statutory civil cause of action for the data subject, though the search was not exhaustive across the full base Act text.

What it requires

Scraping law2 instruments, 2 in force

Research summary (239 words)

Malaysia has no scraping-specific statute, so general law governs each dimension separately. The Computer Crimes Act 1997 criminalises unauthorised access to a computer, but section 3 turns on whether the access itself is unauthorised rather than on the manner of access, so a plain reading does not resolve whether reading a public, unauthenticated page without defeating any access control is unauthorised access, and no reported Malaysian decision on the point was located.

No Malaysian court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located.

The Copyright Act 1987 excuses limited reproduction for research, private study, criticism, review, or reporting news or current events by way of fair dealing, tested against a four-factor purpose, nature, amount, and market-effect standard, but Malaysia has not enacted a text-and-data-mining exception, so training a model on scraped copyright text rests only on the general fair dealing ground if it can be characterised as research; the Act confers no sui generis database right.

The Personal Data Protection Act 2010, as amended, applies to personal data without a general carve-out for information that is publicly accessible, so scraping personal data from a public Malaysian website remains subject to that Act's lawful-basis and cross-border-transfer duties (see the privacy topic for that Act's provisions).

No Malaysian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Computer Crimes Act 1997, unauthorised access to computer material

Computer Crimes Act 1997 (Act 563), s. 3 (Unauthorised Access to Computer Material)official consolidated reprint text, Attorney General's Chambers of Malaysia (Laws of Malaysia portal)

In force since 1 June 2000. Binds public and private bodies.

What this law does

Section 3 makes it an offence to cause a computer to perform a function with intent to secure access to a program or data held in any computer, where that access is unauthorised and the person knows at the time that it is unauthorised; the intent need not be directed at any particular program, data, or computer.

Section 2(5) defines access as unauthorised only where the person is not entitled to control access of that kind and does not have consent from, or exceeds a right or consent given by, a person who is so entitled.

Because the offence turns on whether the access itself is unauthorised rather than on the manner of access, reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision, though no reported Malaysian decision addresses the point either way.

Sections 4 and 5 separately punish, at higher penalties, unauthorised access committed with intent to commit or facilitate a further offence, and unauthorised modification of the contents of a computer.

What it requires

Age gating law2 instruments, 2 in force

Research summary (164 words)

Malaysia's Online Safety Act 2025 (Act 866), in force since 1 January 2026, requires a licensed applications service provider or licensed content applications service provider to protect the online safety of a child user, defined as a person under eighteen.

The Malaysian Communications and Multimedia Commission's Child Protection Code, issued under the Act and effective 1 June 2026, requires effective age verification, based on government-issued identity records, before a social media service likely to be accessed by children may let a user register or access an age-appropriate feature, limited to users identified as sixteen or older; the same Code separately requires any qualifying applications or content applications service to build in broader child-safety measures (content moderation, parental controls, default privacy and safety settings, and controls over search and recommendation algorithms) for a service likely to be accessed by a child under eighteen.

Malaysia has no adult-content age-verification statute distinct from the Online Safety Act's harmful-content regime, and no app-store-level, device-based age-verification requirement was located.

Age-appropriate design code

Online Safety Act 2025, Child Protection Code, safe design and operation duty for services likely accessed by children

Online Safety Act 2025 (Act 866), Child Protection Code ss. 2, 4-7 (Child Safety by Design)Online Safety Act 2025: Child Protection Code, Malaysian Communications and Multimedia Commission, read with the Act's own text

In force 4 months, effective 1 June 2026. Binds private bodies.

What this law does

Section 18 of the Online Safety Act 2025 requires a licensed applications service provider or licensed content applications service provider to implement measures, specified in a code issued by the Commission, to ensure the safe use of its services by a child user, defined as a person under the age of eighteen years; subsection 18(3) requires that, for a service that is, in the provider's opinion, likely to be accessed by child users, those measures include safe design and operation to prevent a child's access to suspected harmful content, limit an identified adult's ability to communicate with an identified child, limit features that increase or sustain a child's use of the service, prevent an identified adult from viewing an identified child's personal information, and control personalised recommendation systems suitable for child users.

The Child Protection Code, issued by the Commission under section 80 read with section 18 and taking effect 1 June 2026, applies these duties to any applications service enabling communication between users and any content applications service, and adds content-moderation duties (detecting and removing harmful content, accessible reporting channels for child users, steps against repeated exposure to reported or removed content), a duty to make available parental control features, a duty to set privacy and safety settings to the highest level by default for child users and limit an unconnected adult's direct communication with a child user, and duties over search and recommendation systems.

Those duties include activating safe search by default. Separately, algorithmic recommendation does not display or promote harmful content to child users.

Note and primary source

Social media and minors

Online Safety Act 2025, Child Protection Code, social-media age verification

Online Safety Act 2025 (Act 866), Child Protection Code s. 3 (Age Verification)Online Safety Act 2025: Child Protection Code, Malaysian Communications and Multimedia Commission

In force 4 months, effective 1 June 2026. Binds private bodies.

What this law does

The Child Protection Code, issued by the Malaysian Communications and Multimedia Commission under section 80 of the Online Safety Act 2025 read with section 18, requires a licensed applications service provider or licensed content applications service provider offering a social media service likely to be accessed by child users to implement effective age verification measures so that only users whose ages have been identified as sixteen years or above may register for the service or access a feature of the service appropriate for their age.

The Code requires verification against records issued by the Government of Malaysia (National Registration Identity Card, passport, birth certificate, or another government-recognised document) or an equivalent record issued or recognised by a competent authority in another jurisdiction, and requires that any personal data collected for age verification be adequate, relevant, and limited to what is necessary, and not kept longer than necessary for that process, consistently with the Personal Data Protection Act 2010. The Code was published on 22 May 2026 and took effect on 1 June 2026.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (194 words)

Malaysia has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognised hot-news or misappropriation doctrine distinct from ordinary copyright and unfair-competition law, and no located statute or reported case addressing hyperlinking or framing liability specifically; each of those dimensions is an absence rather than an unresolved question.

The relevant instrument is the Copyright Act 1987 (Act 332), which excuses, by way of fair dealing, the reproduction, criticism, review, or reporting of another's work for research, private study, or the reporting of news or current events (s. 13(2)(a)), tested against the purpose, nature, amount, and market-effect factors added by the Copyright (Amendment) Act 2012 (s. 13(2A)).

Unlike some other jurisdictions' copyright statutes, the Act carries no separate exclusion of the news of the day or of mere facts from copyright protection; a bare headline or short news item's protection instead turns on whether sufficient effort was expended to make it original in character (s. 7(3)(a)), and no reported Malaysian decision on a systematic aggregator's reproduction of headlines and snippets, as opposed to a traditional press review, was located. Malaysia has no text-and-data-mining exception, so no machine-readable opt-out mechanism of that kind exists either.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.