Author name: Wong Shen Ming

Shen Ming is a corporate and commercial lawyer who is deeply committed to supporting her clients in achieving their business goals. Specialising in commercial and employment law, she demonstrates her expertise by crafting and reviewing various types of commercial agreements. View her full profile here.

Wong Shen Ming
PDPA vs GDPR For Malaysian Businesses A 2026 Guide

PDPA vs GDPR For Malaysian Businesses: A 2026 Guide

A note on timing: Our earlier comparative analysis between the PDPA and GDPR was published before the 2024 amendments came into full effect. Some of the points it makes, particularly around breach notification, cross-border transfers, and data subject rights, have since been updated by law. The summary below reflects the current position; treat this article as the more up-to-date reference on those specific points. Malaysian businesses operating locally may assume only our Personal Data Protection Act 2010 (PDPA) applies to them, but in practice, the European Union’s General Data Protection Regulation (GDPR) affects them more than expected, and this guide explains:  Let’s begin.  GDPR overview  The General Data Protection Regulation (GDPR) is the European Union’s data protection law. It is widely regarded as one of the strictest data protection regimes in the world, and it applies with extraterritorial reach, meaning it can catch organisations outside the EU under certain circumstances.  3 ways GDPR applies to a Malaysian business  In our experience, Malaysian businesses encounter GDPR through one of three distinct pathways, and it matters which one applies to you, since the practical response is different for each.  1. Direct legal applicability  GDPR applies directly to your Malaysian business if either of the following is true:  If neither applies, GDPR does not reach your business through this pathway.  2. Group policy cascade  This is one of the most common ways we see GDPR show up in practice.   A Malaysian office of a multinational group, whose EU or global headquarters operates under GDPR, is frequently instructed to follow the group’s GDPR-aligned privacy policy and internal data handling standards, regardless of whether the Malaysian entity’s own processing activities independently trigger GDPR.  This is generally an internal group governance decision where the parent company adopts a single, group-wide standard (usually the strictest one, GDPR) to keep its compliance posture consistent across all its offices worldwide, rather than maintaining a different standard in each jurisdiction.   For the Malaysian office, this means GDPR-level practices may be expected as a matter of internal policy, contract, or reporting line, even where PDPA alone would technically be sufficient.  3. Counterparty-driven requirements (cross-border data transfer)  The third pathway is driven by the EU counterparty’s own obligations. GDPR restricts the export of personal data out of the EU to countries that are not considered to offer an adequate level of protection.   Malaysia does not currently hold an EU adequacy decision, meaning it is not on the list of countries the European Commission has formally recognised as offering an adequate level of data protection. If an EU customer, supplier, or your own group’s EU headquarters needs to send personal data to your Malaysian office, that EU party is the one under legal pressure to put safeguards in place before the data can leave the EU.  In practice, this means the EU counterparty will often require your Malaysian business to sign up to Standard Contractual Clauses (SCCs) or an equivalent data processing agreement containing GDPR-standard protections, as a condition of receiving the data at all. This is frequently misread as “GDPR applies to us,” when what is actually happening is that the EU party is protecting itself under its own law, and passing the compliance burden downstream contractually.  The EU party’s caution here is not arbitrary. GDPR fines can reach up to EUR20 million, or 4% of the offending organisation’s global annual turnover, whichever is higher, for the most serious breaches.   How each pathway influences the right response  Direct applicability means a genuine compliance obligation under EU law. Group cascade means an internal policy decision you can discuss and scope with your parent company. Counterparty-driven requirements mean a contractual negotiation, where the terms of the data processing agreement are very much open to discussion.  How close is the current PDPA to GDPR?  Following the Personal Data Protection (Amendment) Act 2024, which came into full effect in stages, the PDPA has moved noticeably closer to GDPR in several respects:  Where gaps still remain  The two regimes are closer than before, but not identical.   No right to erasure equivalent under PDPA  The clearest difference is the right to erasure (the so-called “right to be forgotten”), which exists under GDPR but has no direct equivalent under the PDPA. Under GDPR, a data subject can, in defined circumstances, require an organisation to delete their personal data entirely. Under the PDPA, a data subject’s options centre on withdrawing consent, requesting correction, and, following the 2024 amendments, requesting data portability, a related but distinct mechanism.  Specific scope and interpretation  Beyond this, the two frameworks continue to differ in some of the finer detail, such as how consent is defined, the specific scope of a data subject’s right to object to processing, and how each regime approaches risk assessment for higher-risk processing activities. These differences reflect each law’s own regulatory design.  For the principle-by-principle comparison, covering territorial scope, consent standards, retention, cross-border transfer, and data subject rights, see ELP’s comparative analysis of the PDPA and GDPR, which sets out the side-by-side comparison in full.  Is “GDPR” or “PDPA certification” a thing?  There is no official GDPR certification issued by an EU authority that businesses are legally required to obtain, and there is no equivalent general “PDPA certification” either.  Compliance with both laws is a matter of demonstrating good practices, documentation, and accountability, not passing a single certification exam. Businesses searching for “GDPR certification in Malaysia” are usually looking for help assessing and documenting their compliance posture, often because a group parent company or an EU counterparty (pathway 2 or 3 above) has asked them to demonstrate GDPR alignment.  There is, however, a distinct requirement worth knowing about: under the PDPA, certain classes of data controllers (including communications, banking and financial services, insurance, healthcare, and several professional services), are legally required to register with the PDPC  and are issued an actual certificate of registration upon successful registration.   This certificate is typically valid for a certain duration and must be renewed and displayed at the business premises. This is a genuine statutory obligation, and it only applies to the specified sectors.  What should a Malaysian business do?  If you are unsure which pathway applies to your business or need your PDPA compliance framework reviewed with GDPR exposure in mind, ELP’s DPO outsourcing service and PDPA compliance framework can help assess and manage this on an ongoing basis.  Let ELP support your data protection policies  We advise Malaysian businesses, including Malaysian offices of multinational groups, on PDPA compliance. If you are unsure whether GDPR applies

PDPA vs GDPR For Malaysian Businesses: A 2026 Guide Read More »

Responsibilities of Executor:

  • Apply for and extract the grant of probate.
  • Make arrangements for the funeral of the deceased.
  • Collect and make an accurate inventory of the deceased’s assets.
  • Settling the debts and obligations of the deceased.
  • Distributing the assets.

Note for Digital Executor:
If you wish to leave your digital assets to certain people in your Will, there are important steps that need to be taken to ensure that your wishes can be carried out:

  • Keep a note of specific instructions on how to access your username and password of your digital asset.
  • You are advised to store these private and confidential information in a USB stick, password management tool or write them down.
  • Please inform your executor or a trusted person of the whereabouts of the tools so that they will have access to your digital asset.