Skip to Content

Malaysia's Cybersecurity Overhaul: Cyber Security Act, PDPA Amendments & ASEAN Cloud Framework Explained

With the Cyber Security Act 2024 now in effect, landmark PDPA amendments, and a new ASEAN cloud computing framework, Malaysia's digital infrastructure is undergoing its biggest transformation yet.

Malaysia's Cybersecurity Overhaul: Cyber Security Act, PDPA Amendments & ASEAN Cloud Framework Explained

With the Cyber Security Act 2024 now in effect, landmark PDPA amendments, and a new ASEAN cloud computing framework, Malaysia's digital infrastructure is undergoing its biggest transformation yet.

Cybersecurity concept - digital lock and network protection

Data security dashboard analytics

Malaysia is rapidly overhauling its digital infrastructure with three major regulatory developments that every SME owner needs to understand. The Cyber Security Act 2024 (Act 854) is now fully in effect, the Personal Data Protection Act (PDPA) amendments constitute the most significant overhaul since 2010, and the newly endorsed ASEAN Cloud Computing Framework positions Malaysia as a regional digital infrastructure leader.

Together, these changes create both compliance obligations and business opportunities for Malaysian SMEs.

RM1M
Maximum PDPA Fine
Up from RM300K — plus up to 3 years imprisonment
AUG 2024
Cyber Security Act Effective
Act 854 — National Critical Information Infrastructure
US$43B
ASEAN Cloud Market by 2030
Trusted Data Corridor enables cross-border data flows

The Cyber Security Act 2024: What's Changed

Gazetted on June 26, 2024 and effective from August 26, 2024, the Cyber Security Act 2024 (Act 854) represents Malaysia's most comprehensive cybersecurity legislation. Administered by the National Cyber Security Agency (NACSA), the Act:

  • Establishes the National Cyber Security Committee to oversee national cyber strategy
  • Outlines duties and powers of the NACSA Chief Executive
  • Defines roles of National Critical Information Infrastructure (NCII) sector leads and entities
  • Mandates management of cyber threats and incidents relating to NCII
  • Regulates cyber security service providers through licencing

Important for SMEs: If your business provides cybersecurity services — or even if you use cybersecurity tools as part of your operations — you may need to understand the new licencing framework. SMEs that serve NCII sectors (banking, energy, transport, healthcare, government) will need to ensure their own security practices meet the new standards.

PDPA Amendments: The Biggest Overhaul in 14 Years

The Personal Data Protection (Amendment) Act 2024, passed by Parliament in Q4 2024 and enforced in stages through early 2025, brings Malaysia's data protection framework substantially closer to EU GDPR standards. Key changes include:

1. Terminology modernisation: "Data user" becomes "data controller" — aligning with international data protection language. This matters because it makes cross-border compliance easier for SMEs serving international clients.

2. Biometric data protected: Fingerprints, facial recognition data, iris scans, and keystroke dynamics are now classified as sensitive personal data. If your SME uses biometric attendance systems, facial recognition for security, or any biometric authentication, you must now treat this data with the highest protection standards.

3. Data processors face direct liability: Previously, only data controllers were responsible for security compliance. Now, data processors are directly liable — meaning if your SME processes personal data on behalf of another business, you carry your own legal obligations.

4. Mandatory Data Protection Officer (DPO): Organisations that meet certain thresholds (regular and systematic monitoring of data subjects, or large-scale processing) must appoint a DPO. For growing SMEs that handle customer data at scale, this is now a compliance requirement.

5. Dramatically increased penalties: The maximum fine has jumped from RM300,000 to RM1,000,000 plus up to 3 years' imprisonment — a more than threefold increase that makes compliance non-negotiable.

ASEAN Cloud Computing Framework: A Regional Game-Changer

Proposed by Malaysia and endorsed at the 6th ASEAN Digital Ministers Meeting in January 2026, this framework — developed by MDEC (under the Ministry of Digital) with the Asian Business Law Institute (ABLI) — addresses one of the biggest challenges for digital businesses in the region: cross-border data flows.

The framework's centrepiece is the Trusted Data Corridor (TDC) concept, where participating ASEAN states adopt special rules within designated areas. Under the TDC:

  • Data flows freely between approved data centres in participating states
  • Data protection standards must be comparable and aligned with international norms
  • Public authority data access powers must align with international standards

The framework also includes a special addendum for the finance and health sectors — two industries with the most sensitive data and strictest regulatory requirements.

What This Means for Malaysian SMEs

Compliance is now mandatory, not optional: With RM1 million fines and potential imprisonment, the PDPA amendments represent real teeth. SMEs should immediately: (1) audit what personal and biometric data they collect, (2) appoint a DPO if processing at scale, (3) review data processor agreements, and (4) implement biometric data handling policies.

Opportunity for cybersecurity SMEs: The Cyber Security Act's licencing requirements for service providers create a formalised market. SMEs offering cybersecurity consulting, penetration testing, or security auditing can now differentiate themselves through NACSA licencing — a competitive advantage.

Regional expansion simplified: The ASEAN Cloud Computing Framework's Trusted Data Corridor reduces cross-border compliance barriers for Malaysian SMEs expanding into neighbouring markets. Instead of navigating 10 different data localisation laws, TDC participants can operate under harmonised rules.

Action steps: Start with a data audit — map what data you collect, where it's stored, who processes it, and whether biometric data is involved. Review your service agreements with data processors. If you haven't appointed a DPO yet and you process customer data regularly, now is the time. For sector-specific guidance, consult the Personal Data Protection Department (JPDP) or a qualified data protection lawyer.

Frequently Asked Questions

Q: Does the Cyber Security Act 2024 apply to all Malaysian businesses?

A: The Act primarily targets National Critical Information Infrastructure (NCII) sectors and cybersecurity service providers. However, if your SME operates in banking, energy, transport, healthcare, government services, or defence — or serves clients in these sectors — you may be affected.

Q: What biometric data is now protected under the PDPA?

A: Fingerprints, facial recognition data, iris scans, and keystroke dynamics are now classified as sensitive personal data. This affects most SMEs using biometric attendance systems, CCTV with facial recognition, or fingerprint/face-scanned access control.

Q: Does my SME need to appoint a Data Protection Officer?

A: If your business regularly and systematically monitors data subjects, or processes large volumes of personal data, you must appoint a DPO. When in doubt, appoint one — the cost of a part-time DPO is far lower than the RM1 million fine for non-compliance.

Q: How does the ASEAN Cloud Computing Framework affect my business?

A: The Trusted Data Corridor makes it easier and cheaper for SMEs to transfer data across ASEAN borders, use regional cloud services, and expand into neighbouring markets without navigating 10 different data localisation laws.

Q: What are the penalties for non-compliance?

A: Under the revised PDPA, fines have increased from RM300,000 to RM1,000,000, plus up to 3 years imprisonment. The Cyber Security Act carries separate penalties for NCII non-compliance. The era of light-touch enforcement is over.

Sum Technology IPO: How This Malaysian Engineering Firm Is Capitalising on AI, EVs & Data Centres
Sum Technology Bhd's ACE Market debut on June 18 aims to raise RM32.76 million — riding the AI semiconductor boom and Chinese EV investments in Malaysia.