[{"data":1,"prerenderedAt":577},["ShallowReactive",2],{"guide-pdpa-cross-border-data-transfer-meta-ads-malaysia":3},{"id":4,"title":5,"answer":6,"authorId":7,"body":8,"category":479,"ctaVariant":480,"dataset":479,"description":481,"examples":482,"extension":483,"faqs":484,"heroImage":509,"intro":510,"meta":511,"navigation":512,"path":513,"publishedAt":514,"seo":515,"sources":516,"stats":543,"stem":575,"updatedAt":514,"__hash__":576},"blog\u002Fblog\u002Fpdpa-cross-border-data-transfer-meta-ads-malaysia.md","Meta Ads and PDPA Cross-Border Transfers","Since 1 April 2025 Malaysia no longer bans data exports by default. Act A1727 deleted section 129(1) of the PDPA, the provision that barred transfers except to a place gazetted by the Minister, and section 129(2) now permits a transfer where the destination has in force a law substantially similar to Act 709 or ensures an adequate level of protection at least equivalent to it. No list of approved destinations was ever gazetted, and the Commissioner has published no view on whether the United States or Ireland qualifies, so the assessment is the advertiser's own to make and document. A standard processing addendum is not automatically sufficient: Guidelines No.: 3\u002F2025 require contractual clauses to cover security at least equivalent to Act 709 and to state and guarantee that processing complies with Act 709, and whatever route you rely on, the same guidelines require you to inform data subjects about the transfer through your personal data protection notice.","likit-sae-lee",{"type":9,"value":10,"toc":462},"minimark",[11,16,20,23,26,30,33,36,39,113,116,119,123,126,129,132,136,139,142,145,148,152,155,158,161,164,167,171,174,266,269,283,287,290,293,316,319,322,325,329,332,335,338,344,350,356,360,363,366,369,373,376,384,387,390,394,397,400,403,407,410,423,426,429,432,435,443,447,450,453,456,459],[12,13,15],"h2",{"id":14},"the-short-version","The short version",[17,18,19],"p",{},"Malaysia inverted its export rule on 1 April 2025. The old section 129(1) of the Personal Data Protection Act 2010 said a data user shall not transfer personal data to a place outside Malaysia unless to a place specified by the Minister by notification published in the Gazette. That was a default prohibition with a permission list attached. The Personal Data Protection (Amendment) Act 2024 deleted the subsection outright, and the commencement notification P.U. (B) 522 brought that deletion into force on 1 April 2025 alongside the raised penalties and the new processor duties.",[17,21,22],{},"What replaced it is a default permission with conditions attached. Section 129(2) allows a transfer where the destination has in force a law substantially similar to Act 709, or ensures an adequate level of protection at least equivalent to Act 709. If neither limb holds, section 129(3) offers seven separate conditions, one of which is consent and one of which is the reasonable-precautions-and-due-diligence route that most advertisers will end up in.",[17,24,25],{},"The catch is that nobody in government has told you which countries pass the section 129(2) test. There is no adequacy list. There never was a whitelist either, despite what you may have read. The judgment now sits with you, it has to be documented, and the documentation has a shelf life.",[12,27,29],{"id":28},"what-actually-happened-to-section-129","What actually happened to section 129",[17,31,32],{},"It is worth being precise about the mechanics, because a lot of secondary commentary compresses them into something misleading.",[17,34,35],{},"Act A1727 received Royal Assent on 9 October 2024 and was gazetted on 17 October 2024. Commencement came separately, through P.U. (B) 522, dated 19 December 2024 and published on 24 December 2024, which staged the amending Act across three dates: 1 January 2025, 1 April 2025 and 1 June 2025. The numbers in that notification are sections of the amending Act, not of Act 709, which is the single most-often-botched fact in this area. The cross-border changes sit in section 12 of the amending Act, which fell in the 1 April 2025 tranche.",[17,37,38],{},"Section 12 of A1727 did five things to section 129:",[40,41,42,58],"table",{},[43,44,45],"thead",{},[46,47,48,52,55],"tr",{},[49,50,51],"th",{},"Change",[49,53,54],{},"Effect",[49,56,57],{},"In force",[59,60,61,73,83,93,103],"tbody",{},[46,62,63,67,70],{},[64,65,66],"td",{},"Deleted subsection 129(1)",[64,68,69],{},"Removed the prohibition on transfer except to a gazetted place, abolishing the whitelist mechanism",[64,71,72],{},"1 April 2025",[46,74,75,78,81],{},[64,76,77],{},"Amended subsection 129(2)",[64,79,80],{},"Deleted the words \"or that serves the same purposes as this Act\" from paragraph (a), leaving \"substantially similar\" as the test",[64,82,72],{},[46,84,85,88,91],{},[64,86,87],{},"Deleted paragraph 129(3)(h)",[64,89,90],{},"Removed the public-interest ground that had operated in circumstances determined by the Minister",[64,92,72],{},[46,94,95,98,101],{},[64,96,97],{},"Deleted subsection 129(4)",[64,99,100],{},"Removed the Commissioner's duty to recommend cancelling or amending a gazetted destination whose law lapsed",[64,102,72],{},[46,104,105,108,111],{},[64,106,107],{},"Amended subsection 129(5)",[64,109,110],{},"The offence is now contravening \"this section\" rather than only subsection (1); the penalty wording was untouched",[64,112,72],{},[17,114,115],{},"Two of those are easy to miss and both narrow your options. The old paragraph (h) is gone, so there is no longer a public-interest ground to fall back on. And the deletion of the phrase \"or that serves the same purposes as this Act\" tightens the first limb of the destination test: the guideline's restatement now reads simply \"substantially similar\".",[17,117,118],{},"One more piece of housekeeping matters when you go reading the Act yourself. From 1 April 2025 the amending Act substituted \"data controller\" for \"data user\" throughout Act 709, with narrow exceptions, and the Attorney General's Chambers has published no consolidated reprint incorporating the amendments. The reprints on the register predate them. So the version of Act 709 you download will show you the 2010 language. Read it for structure, not for current wording, and cross-check anything load-bearing against the Commissioner's own publications, which reproduce the amended text.",[12,120,122],{"id":121},"the-whitelist-that-was-never-there","The whitelist that was never there",[17,124,125],{},"This is the point where most write-ups go wrong, so here it is plainly. The statutory mechanism for a whitelist existed in section 129(1) from 2010 until 1 April 2025. No notification specifying places outside Malaysia was ever published in the Gazette under it. A draft Order was circulated for public comment years ago and never gazetted.",[17,127,128],{},"The evidence for that is the register itself rather than anybody's recollection. The Attorney General's Chambers list of subsidiary legislation made under Act 709 contains sixteen records: the Regulations, the Class of Data Users Order and its 2016 amendment, the Registration of Data User Regulations, the Fees Regulations, the Compounding of Offences Regulations, the Appeal Tribunal Regulations, and a series of commencement, Commissioner and Tribunal appointment notifications. There is no transfer-destination Order of any year in it.",[17,130,131],{},"So the common formulation, that Malaysia had an approved-country list which was later revoked, conflates two separate things. The empty mechanism was repealed. The list never existed to be repealed. The practical consequence is the same either way, and it is the one that matters: there is no government-published answer to the question of which destinations are safe, and there is no adequacy determination for any jurisdiction, including the ones the large advertising platforms operate from.",[12,133,135],{"id":134},"route-one-the-destination-test-in-section-1292","Route one: the destination test in section 129(2)",[17,137,138],{},"Section 129(2) gives you two independent limbs. Either the place where the data is received has in force a law that is substantially similar to Act 709, or that place ensures an adequate level of protection in relation to the processing of personal data which is at least equivalent to the level of protection afforded by Act 709.",[17,140,141],{},"Note what that is asking. The first limb is a question about a legal system. The second is a question about the level of protection actually ensured, which can take into account more than the statute book. Neither is a question the Commissioner has answered for you.",[17,143,144],{},"The honest position for an advertiser is this. Guidelines No.: 3\u002F2025, issued on 29 April 2025, walk through how a controller may establish that either limb is satisfied, and they offer no view whatsoever on whether the United States, Ireland, or anywhere else clears the bar. The regulator publishes no adequacy list. If somebody tells you that transferring to a particular platform's home jurisdiction is fine because that jurisdiction is adequate under Malaysian law, ask them for the instrument. There isn't one. Equally, nobody can tell you it fails. The assessment is yours, and its outcome is not pre-decided.",[17,146,147],{},"That is uncomfortable, but it is workable. What it means in practice is that if you want to stand on section 129(2), you need a reasoned, written, dated view, and you need to be able to produce it.",[12,149,151],{"id":150},"the-transfer-impact-assessment-and-its-three-year-clock","The Transfer Impact Assessment and its three-year clock",[17,153,154],{},"The instrument the guideline offers for that job is the Transfer Impact Assessment.",[17,156,157],{},"Read the verb carefully. The guideline says a data controller may conduct a Transfer Impact Assessment in order to establish that paragraph 129(2)(a) or 129(2)(b) is satisfied. It is offered, not commanded. This distinction gets flattened constantly, including in professional commentary, into a claim that anyone relying on section 129(2) must complete a TIA. The guideline does not say that.",[17,159,160],{},"What is mandatory is what happens once you rely on one. The findings of the TIA shall be valid for no longer than three years, and a follow-up assessment is required after that period. It must also be reviewed earlier in two situations: where the data protection law of the receiving jurisdiction changes, and where there is a significant change to the receiver's security systems or policies. Both of those triggers are live for anyone sending advertising data to a large platform, because platform security posture and foreign privacy law both move faster than a three-year cycle.",[17,162,163],{},"There is also a quieter argument for doing one anyway. The records part of the guideline lists the record of the TIA and the findings of the TIA among the material that evidences a section 129(2) transfer. That is an inference about what good evidence looks like rather than a stated duty, and it should be read that way. But if you are ever asked to justify a transfer under the destination test and your file is empty, the absence is the answer.",[17,165,166],{},"One thing to keep straight: a Transfer Impact Assessment is not a Data Protection Impact Assessment. They are different instruments on different clocks. The TIA's three-year validity comes from the 2025 cross-border guidelines. The DPIA, which is the assessment the Commissioner's April 2026 guideline attaches to high-risk processing including behavioural tracking, is valid for two years from its date of completion. An advertiser running a pixel across a Malaysian storefront can easily need both, for different reasons, and confusing their expiry dates is an easy way to let one lapse.",[12,168,170],{"id":169},"route-two-the-seven-conditions-in-section-1293","Route two: the seven conditions in section 129(3)",[17,172,173],{},"If the destination test does not get you there, section 129(3) is the alternative, and after the deletion of the old paragraph (h) it holds seven conditions. Any one of them is sufficient on its own.",[40,175,176,189],{},[43,177,178],{},[46,179,180,183,186],{},[49,181,182],{},"Paragraph",[49,184,185],{},"Condition",[49,187,188],{},"Realistic for advertising data?",[59,190,191,202,213,224,235,245,256],{},[46,192,193,196,199],{},[64,194,195],{},"129(3)(a)",[64,197,198],{},"The data subject has given his consent to the transfer",[64,200,201],{},"Yes, if the consent is properly built and recorded",[46,203,204,207,210],{},[64,205,206],{},"129(3)(b)",[64,208,209],{},"Necessary for the performance of a contract between the data subject and the data controller",[64,211,212],{},"Sometimes, for order fulfilment, rarely for ad targeting",[46,214,215,218,221],{},[64,216,217],{},"129(3)(c)",[64,219,220],{},"Necessary for a contract with a third party entered into at the data subject's request or in his interests",[64,222,223],{},"Narrow",[46,225,226,229,232],{},[64,227,228],{},"129(3)(d)",[64,230,231],{},"Necessary for or in connection with legal proceedings, obtaining legal advice, or establishing, exercising or defending legal rights",[64,233,234],{},"No",[46,236,237,240,243],{},[64,238,239],{},"129(3)(e)",[64,241,242],{},"Reasonable grounds to believe the transfer avoids or mitigates adverse action against the data subject, consent in writing is not practicable, and the subject would have consented if it were",[64,244,234],{},[46,246,247,250,253],{},[64,248,249],{},"129(3)(f)",[64,251,252],{},"The controller has taken all reasonable precautions and exercised all due diligence to ensure the data will not be processed in the destination in any manner contravening Act 709",[64,254,255],{},"Yes, and this is where most advertisers land",[46,257,258,261,264],{},[64,259,260],{},"129(3)(g)",[64,262,263],{},"Necessary to protect the data subject's vital interests",[64,265,234],{},[17,267,268],{},"Paragraph (e) deserves a warning because it is regularly summarised as a general escape hatch for when consent is impractical. It is not. All three of its elements have to hold, and the first of them is the adverse-action gate: the transfer must be for the avoidance or mitigation of adverse action against the data subject. The guideline closes the loose reading explicitly, saying the paragraph only applies if it is not possible for the data subject to give their consent, and instancing unconsciousness, being uncontactable after reasonable steps, or insufficient time. That is an emergency provision. It has nothing to do with an inconvenient consent banner.",[17,270,271,272,277,278,282],{},"Paragraph (a), consent, is the route many small advertisers will reach for, and the guideline puts a sequence around it. You must first provide the data subject with a personal data protection notice containing the class of third parties to whom the data is transferred and the purpose of the transfer. Then you obtain the consent, and the consent must be recorded and maintained in accordance with the requirements of the Personal Data Protection Regulations. Regulation 3 of those Regulations sets three requirements that decide whether your consent survives challenge: it must be in a form that can be recorded and maintained properly, it must be presented distinguishably in its appearance where the same form also concerns another matter, and the burden of proof for consent lies on you. If your consent lives inside a general terms acceptance with no separate record, you will not discharge that burden. The mechanics of building consent capture around a tracking setup sit alongside your ",[273,274,276],"a",{"href":275},"\u002Fblog\u002Fmeta-pixel-setup","Meta pixel setup"," work rather than after it, and the underlying consent and notice duties in sections 6 and 7, which apply whether or not the data ever crosses a border, are worked through in the companion piece on ",[273,279,281],{"href":280},"\u002Fblog\u002Fpdpa-meta-pixel-consent-malaysia","Meta Pixel consent under the PDPA",".",[12,284,286],{"id":285},"the-due-diligence-route-what-all-reasonable-precautions-is-made-of","The due diligence route: what \"all reasonable precautions\" is made of",[17,288,289],{},"Paragraph 129(3)(f) is the workhorse, and it is the one the guideline develops in most detail. It asks whether the data controller has taken all reasonable precautions and exercised all due diligence to ensure the data will not be processed in the destination in any manner that would contravene Act 709.",[17,291,292],{},"The guideline names three mechanisms by which that may be deciphered:",[294,295,296,304,310],"ol",{},[297,298,299,303],"li",{},[300,301,302],"strong",{},"Binding Corporate Rules."," Suitable where the transfer is intra-group, between entities of the same corporate family. Most Malaysian SMEs sending data to an advertising platform are not in this situation.",[297,305,306,309],{},[300,307,308],{},"Contractual Clauses."," The mechanism nearly every advertiser is actually using, whether or not they have thought about it that way, because the platform terms you accepted are a contract.",[297,311,312,315],{},[300,313,314],{},"Certification"," under an approved certification scheme, with the guideline referring to a recognised certificate held by the receiver.",[17,317,318],{},"For the contractual route, the guideline sets a floor and then adds a recommendation, and it is important not to flatten the two. The floor is mandatory in the guideline's own language: the contractual clauses must at minimum cover the security measures giving protection at least equivalent to the level afforded by Act 709, and contain clauses that state and guarantee that the processing will be carried out in compliance with Act 709. The recommendation is softer: before using an international model, the data controller is recommended to review the clauses to determine whether any additional clauses are necessary to be included.",[17,320,321],{},"On the models themselves, the guideline says a controller may adopt clauses including, but not limited to, the ASEAN Model Contractual Clauses for Cross Border Data Flows, the EU GDPR Standard Contractual Clauses for the Transfer of Personal Data to Third Countries, or such other clauses as the Commissioner determines from time to time. That is a list of acceptable starting points, not a list of things that are automatically sufficient. Both named models were drafted against other regimes, so the clause most likely to be missing from either is the one the guideline specifically requires: the statement and guarantee of Act 709 compliance.",[17,323,324],{},"There is also an ongoing duty attached to this route. Where a controller relying on contractual clauses discovers a breach of the terms provided by those clauses, the controller shall cease the transfer of personal data to the other parties to the contract until that party rectifies the breach. The guideline imposes a parallel duty on the certification route: where a receiver relied on under a recognised certificate breaches its obligations, the controller shall cease the transfer until the breach has been rectified. That converts what many businesses treat as a filing exercise into something with a monitoring obligation behind it.",[12,326,328],{"id":327},"so-is-a-standard-processing-addendum-enough","So is a standard processing addendum enough?",[17,330,331],{},"A standard processing addendum is not, in itself, an answer to section 129. It is potentially a component of the paragraph 129(3)(f) route, sitting under the contractual clauses mechanism. Whether it discharges the route depends on whether the clauses meet the guideline's floor: security at least equivalent to Act 709, and clauses stating and guaranteeing Act 709 compliance. Those are specific requirements pointing at a specific statute.",[17,333,334],{},"The addendum itself is a document you have to read for yourself, and the reason is not squeamishness. We could not verify, from a fresh and dated reading of the exact document served to a Malaysian advertiser, what any particular platform's current terms say about Act 709. The copy retrieved during research was served in Malay and allocated controller and processor roles by reference to other regimes, and in any event a platform's business tools terms are a private contract rather than a Malaysian legal instrument. Nobody should be making a section 129 argument out of a summary of a contract they have not read. Open the terms you accepted, note the date and version, and check them against the two requirements above.",[17,336,337],{},"Then check three things the contract cannot fix for you:",[17,339,340,343],{},[300,341,342],{},"Your own role."," Whether the platform is acting as your data processor or as a separate data controller for its own purposes changes the analysis, and it is settled by the terms you signed plus the facts of what actually happens to the data, not by an assumption. Since 1 April 2025 a data processor is directly bound by the Security Principle in section 9 in its own right, and the cross-border guideline separately requires a data controller to ensure its data processors comply with that section, so getting the role wrong has consequences in both directions.",[17,345,346,349],{},[300,347,348],{},"Your notice."," No contract cures a notice that never mentioned the transfer.",[17,351,352,355],{},[300,353,354],{},"Your records."," A contract in a drawer with no record of who receives what, in which country, for what purpose, does not evidence due diligence.",[12,357,359],{"id":358},"the-notice-obligation-that-applies-whatever-route-you-take","The notice obligation that applies whatever route you take",[17,361,362],{},"This one is short, cheap and skipped constantly. Guidelines No.: 3\u002F2025 provide that where a data controller carries out or intends to carry out the transfer of personal data out of Malaysia, the data controller shall through its personal data protection notice or such other written notice inform the data subject about the transfer. It is not conditional on which of the section 129 conditions you rely on.",[17,364,365],{},"Attribute that correctly when you brief your team: it is an obligation stated in a guideline issued under section 48(g) of Act 709, not a subsection of the Act. That does not make it optional in practice, and it is the regulator's published expectation.",[17,367,368],{},"Underneath it sits the statutory notice duty in section 7(1) of Act 709, which requires a written notice covering eight specified matters, including the class of third parties to whom the data controller discloses or may disclose the personal data, and section 7(3), which requires the notice to be in the national and English languages. If your privacy notice does not name advertising and analytics recipients as a class, and does not say that data is transferred outside Malaysia, that is the first thing to fix, before any assessment or contract review. It is also the fix that most improves your position under both the consent route and the due diligence route at the same time.",[12,370,372],{"id":371},"what-your-file-should-contain","What your file should contain",[17,374,375],{},"The guideline sets out a record-keeping expectation for transfers, and it is worth turning into a template because it doubles as your evidence if anyone asks.",[17,377,378,379,383],{},"For each overseas receiver, keep the receiver's name, the company registration number if any, and contact details of the data protection officer or such other person at the receiver's end. That alternative matters: the requirement is a contact point, not proof that the receiver has appointed a DPO. Whether you need one on your own side is a separate question governed by separate instruments, covered in ",[273,380,382],{"href":381},"\u002Fblog\u002Fpdpa-dpo-requirement-meta-advertisers-malaysia","do Malaysian advertisers need a DPO",". Alongside that, record the destination country, the type of personal data transferred, the purposes of the transfer, and any other information you consider necessary.",[17,385,386],{},"The guideline also tabulates the records that evidence a transfer under each specific condition, which is more useful to an advertiser than the general list. For the consent route in paragraph 129(3)(a), that means the personal data protection notice and a record of the data subject's consent. For a transfer under section 129(2), it includes the record and the findings of the Transfer Impact Assessment.",[17,388,389],{},"A workable file for a Malaysian ecommerce advertiser therefore looks like this: the current privacy notice with the transfer language and the recipient class, dated; the consent capture mechanism and its stored records; the platform terms you accepted, with a version and date; the note of your review of those terms against the guideline's minimum clause requirements; the receiver record; and, if you are standing on the destination test, the assessment with its completion date and its three-year expiry marked in a calendar. None of that is exotic. Almost all of it is a document you already half have.",[12,391,393],{"id":392},"penalties-and-the-awkward-gap","Penalties, and the awkward gap",[17,395,396],{},"Section 129(5) is the offence provision. Its ceiling did not move in 2024: a fine not exceeding three hundred thousand ringgit, or imprisonment for a term not exceeding two years, or both. What A1727 changed is the trigger, substituting a contravention of \"this section\" for a contravention of the deleted subsection (1).",[17,398,399],{},"That is where an honest gap opens. With subsection (1) gone, the surviving subsections (2) and (3) are permissive in form. They say a data controller may transfer personal data outside Malaysia if a condition is met. Nobody has ruled on precisely what conduct now contravenes a permissive provision. So state the penalty, and do not assert that it attaches cleanly to any transfer that fails a condition. That is a genuinely unsettled question and pretending otherwise does a reader no favours.",[17,401,402],{},"The larger exposure sits elsewhere, and this is the part worth internalising. Since 1 April 2025 the maximum penalty for contravening the seven Personal Data Protection Principles has been one million ringgit or three years' imprisonment or both, raised from three hundred thousand ringgit and two years. A cross-border problem is almost never only a cross-border problem. A transfer made without a notice that mentions it is a Notice and Choice problem. A transfer to a receiver with inadequate security is a Security Principle problem. Those are Principles, and they carry the higher ceiling.",[12,404,406],{"id":405},"a-working-sequence","A working sequence",[17,408,409],{},"If you run Meta campaigns for a Malaysian business and you want to get this in order without hiring a firm to start from zero, the order of operations is fairly stable.",[17,411,412,413,417,418,422],{},"Start with an inventory rather than a legal question. Write down every flow of personal data out of your business: the pixel and any ",[273,414,416],{"href":415},"\u002Fblog\u002Fserver-side-tracking-facebook-ads","server-side event feed",", customer lists uploaded for ",[273,419,421],{"href":420},"\u002Fblog\u002Ffacebook-custom-audiences","custom audiences",", the CRM or email tool, the analytics platform, the payment processor, the fulfilment partner. For each, note the recipient, the country, the categories of data and the purpose. Most advertisers discover four or five flows they had not thought of, and the exercise is worth doing before anything else because everything downstream depends on it.",[17,424,425],{},"Then fix the notice, because it is the cheapest fix and it supports every route. Name the classes of recipient, say plainly that data is transferred outside Malaysia, state the purposes, and publish it in both the national language and English.",[17,427,428],{},"Then pick a route per flow, not one route for the whole business. Some flows genuinely sit under contract performance. Advertising and analytics flows usually land on either consent or the due diligence route, and the two are not mutually exclusive: consent that is properly captured and recorded strengthens your position regardless.",[17,430,431],{},"Then do the contract work. Retrieve the actual terms for each recipient, dated, and check them against the guideline's minimum: equivalent security, and clauses that state and guarantee Act 709 compliance. Where the clauses are an international model drafted for another regime, that is precisely where the guideline recommends checking whether additional clauses are needed.",[17,433,434],{},"Then build the file described above, and diarise the review dates. Three years for a transfer assessment. Two years for a DPIA if your processing triggers one. Sooner for either if the receiver changes its security posture or the law at the destination moves.",[17,436,437,438,442],{},"Finally, keep the whole thing proportionate to your actual data. A Malaysian storefront doing conversion tracking on a few thousand customers is not in the same position as a lender processing financial data at scale, and the practical guidance for ",[273,439,441],{"href":440},"\u002Fblog\u002Ffacebook-ads-for-small-business-malaysia","smaller Malaysian advertisers"," applies here too: do the work that matches your exposure, document it, and revisit it on a schedule rather than in a panic.",[12,444,446],{"id":445},"what-is-still-unsettled-stated-plainly","What is still unsettled, stated plainly",[17,448,449],{},"Three things in this area have no published answer, and it is better to know that than to be told a confident one.",[17,451,452],{},"First, whether any given destination satisfies section 129(2). The regulator has expressed no view on the United States, Ireland or anywhere else, and there is no adequacy list. Your assessment, your judgment, your documentation.",[17,454,455],{},"Second, what conduct contravenes section 129 now that the prohibition in subsection (1) is gone and the remaining subsections are permissive. The penalty is on the books. Its precise trigger is not settled.",[17,457,458],{},"Third, the registration regime. A Commissioner's circular on the registration of data controllers takes effect from 1 June 2026 and revokes an earlier 2024 circular, leaving the 2025 circulars on data protection officers and breach notification in force. Which classes of data controller must register under it turns on the Class of Data Users Order, which this guide has not analysed, so treat the question of whether an ordinary Malaysian ecommerce or services advertiser is caught as open and check the current instruments before assuming either way.",[17,460,461],{},"Finally, a note on velocity. The Commissioner issued three further guidelines on 30 April 2026, covering automated decision-making and profiling, data protection impact assessments, and data protection by design. That is a regulator building out an area quickly. Anything you write down about cross-border transfers today should carry the date you wrote it and a reminder to re-read the current instruments before you rely on it a year from now.",{"title":463,"searchDepth":464,"depth":464,"links":465},"",2,[466,467,468,469,470,471,472,473,474,475,476,477,478],{"id":14,"depth":464,"text":15},{"id":28,"depth":464,"text":29},{"id":121,"depth":464,"text":122},{"id":134,"depth":464,"text":135},{"id":150,"depth":464,"text":151},{"id":169,"depth":464,"text":170},{"id":285,"depth":464,"text":286},{"id":327,"depth":464,"text":328},{"id":358,"depth":464,"text":359},{"id":371,"depth":464,"text":372},{"id":392,"depth":464,"text":393},{"id":405,"depth":464,"text":406},{"id":445,"depth":464,"text":446},null,"local","What Malaysia's amended section 129 actually requires when your Meta pixel, customer list or conversion data leaves the country, and why a standard processing addendum is not the end of the analysis.",[],"md",[485,488,491,494,497,500,503,506],{"question":486,"answer":487},"Is Meta's standard data processing addendum enough to send Malaysian personal data abroad?","Signing a processing addendum is not by itself an answer to section 129, and you should not assume it is. Guidelines No.: 3\u002F2025 treat contractual clauses as one of three ways a data controller can show it took all reasonable precautions and exercised all due diligence under paragraph 129(3)(f), and they set a floor for what those clauses have to do: at minimum they must cover security measures giving protection at least equivalent to the level afforded by Act 709, and contain clauses that state and guarantee the processing will be carried out in compliance with Act 709. A contract drafted around another jurisdiction's regime does not, on its face, make those Act 709 statements. The guideline also recommends that a controller review the clauses before use to determine whether any additional clauses need to be included. So the practical step is to read the exact terms you have accepted, dated, and check them against those two requirements rather than treating the addendum as a compliance certificate. We could not verify, from a current and dated reading of Meta's Malaysian-facing terms, what they say about Act 709 specifically, and you should not rely on anyone else's summary of them either.",{"question":489,"answer":490},"Does Malaysia publish a list of approved countries I can transfer data to?","No, and it never did. The old section 129(1) contained a mechanism for the Minister to specify permitted destinations by notification in the Gazette, but no such notification was ever published. The Attorney General's Chambers register of subsidiary legislation made under Act 709 lists sixteen records, covering the Regulations, the Class of Data Users Order and its amendment, registration, fees, compounding and appeal tribunal instruments, and a series of commencement and appointment notifications. There is no transfer-destination Order of any year among them. The mechanism itself was then deleted outright by Act A1727 with effect from 1 April 2025. A common misstatement is that Malaysia gazetted a whitelist and later revoked it. Two different things are being run together there: the empty mechanism existed and was repealed, but the list never came into being. There is no whitelist and no adequacy list today.",{"question":492,"answer":493},"Has the regulator said whether the United States or Ireland qualifies under section 129(2)?","It has not, and that silence is the single most important fact for a Meta advertiser. Section 129(2) permits a transfer where the destination has in force a law substantially similar to Act 709, or ensures an adequate level of protection at least equivalent to Act 709. Guidelines No.: 3\u002F2025 explain how a controller may go about establishing that, but they offer no view on any particular country, and the Commissioner publishes no adequacy list. That means the assessment is yours, its outcome is not pre-determined by the regulator, and nobody can honestly tell you that a given Meta entity's jurisdiction passes or fails. Treat any confident claim in either direction as unsourced. What you can do is make the assessment properly, write down how you reached it, keep the evidence, and revisit it when the law at the other end changes.",{"question":495,"answer":496},"Do I have to carry out a Transfer Impact Assessment?","The guideline says a data controller may conduct a Transfer Impact Assessment in order to establish that paragraph 129(2)(a) or 129(2)(b) is satisfied. That word is permissive and it is worth holding on to, because the assessment is widely described elsewhere as a duty. It is not commanded. What is mandatory is the clock that runs once you rely on one: the findings of a TIA shall be valid for no longer than three years, after which a follow-up assessment is required, and it must be reviewed sooner if the receiving jurisdiction's data protection law changes or there is a significant change to the receiver's security systems or policies. There is also a practical pull toward doing one. The guideline's records section lists the record of the TIA and the findings of the TIA among the material evidencing a section 129(2) transfer, which is an inference about what evidence looks like rather than a stated obligation, but it points the same way. If you are relying on the destination test and you have nothing written down, you have nothing to show.",{"question":498,"answer":499},"Can I rely on customer consent instead of assessing the destination?","Consent is the first of the seven conditions in section 129(3), and for many advertisers it is the cleanest route, but the guideline attaches a sequence to it. Before obtaining consent to a cross-border transfer you must first give the data subject a personal data protection notice containing the class of third parties to whom the data is transferred and the purpose of the transfer. Only then do you take the consent, and that consent must be recorded and maintained in accordance with the requirements of the Personal Data Protection Regulations. Regulation 3 of those Regulations is specific: consent has to be in a form that can be recorded and maintained properly, it has to be presented distinguishably in its appearance where the same form covers another matter, and the burden of proof lies on you. A buried line in a terms-of-use checkbox does not survive that. Note too that those paragraphs of the guideline apply to the consent route for transfers, not as general notice-and-consent law; your ordinary notice duty comes from section 7 of the Act.",{"question":501,"answer":502},"What must my privacy notice say about the transfer?","The guideline is direct on this and it does not depend on which condition you rely on. Where a data controller carries out or intends to carry out a transfer of personal data out of Malaysia, it shall through its personal data protection notice or such other written notice inform the data subject about the transfer. That is a guideline obligation issued under section 48(g) of Act 709 rather than a section of the Act itself, and it is worth attributing correctly, but it is the regulator's stated expectation and it costs almost nothing to meet. Separately, section 7(1) of Act 709 already requires the notice to state eight specific matters, one of which is the class of third parties to whom the data controller discloses or may disclose the personal data. Section 7(3) requires the notice to be in the national and English languages. If your notice does not mention that advertising and analytics data leaves Malaysia, and does not name the class of recipient, fix that before you touch anything else.",{"question":504,"answer":505},"Are the EU Standard Contractual Clauses enough on their own?","They are named, which helps, but naming is not endorsement of sufficiency. Guidelines No.: 3\u002F2025 say a controller wishing to use an international model may adopt contractual clauses including, but not limited to, the ASEAN Model Contractual Clauses for Cross Border Data Flows, the EU GDPR Standard Contractual Clauses for the Transfer of Personal Data to Third Countries, or such other clauses as the Commissioner determines from time to time. The same part of the guideline then sets the floor those clauses have to reach: security measures at least equivalent to Act 709, and clauses stating and guaranteeing compliance with Act 709. It also recommends reviewing the model before use to see whether additional clauses are needed. Because both named models were drafted against other regimes, the Act 709 guarantee is exactly the clause most likely to be missing. Treat the model as a starting document to be supplemented, not a finished one to be signed.",{"question":507,"answer":508},"What is the penalty if I get a cross-border transfer wrong?","The offence provision is section 129(5), and its ceiling did not move in the 2024 amendments: a fine not exceeding three hundred thousand ringgit, or imprisonment for a term not exceeding two years, or both. Act A1727 changed the trigger rather than the number, so the offence is now committed by a data controller who contravenes this section rather than only the repealed subsection (1). Be careful with the next step, because there is a genuine gap here. With subsection (1) deleted, the surviving subsections (2) and (3) are permissive in form, saying a data controller may transfer if a condition is met, and nobody has ruled on precisely what conduct now contravenes the section. Do not assume the RM300,000 attaches cleanly to any transfer that fails a condition. The larger exposure is elsewhere anyway: contravening the seven Personal Data Protection Principles has carried a maximum of one million ringgit or three years since 1 April 2025, and a sloppy transfer usually involves a notice or security failure that lands there.","\u002Fimages\u002Fblog\u002Fpdpa-cross-border-data-transfer-meta-ads-malaysia-hero.webp","You uploaded a customer list to build a lookalike audience, your pixel fires on every product page, and the Conversions API posts purchase events from your server. All of that personal data leaves Malaysia the moment it reaches Meta's infrastructure. The rules governing that export changed shape completely on 1 April 2025, and the regime that replaced them puts the burden of judgment on you rather than on a government list.",{},true,"\u002Fblog\u002Fpdpa-cross-border-data-transfer-meta-ads-malaysia","2026-07-31",{"title":5,"description":481},[517,521,524,528,532,536,540],{"label":518,"url":519,"year":520},"Personal Data Protection (Amendment) Act 2024 [Act A1727]","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2024\u002F11\u002FAct-A1727.pdf","2024",{"label":522,"url":523,"year":520},"P.U. (B) 522 - Appointment of Date of Coming into Operation, Act A1727","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2024\u002F12\u002FPENETAPAN-TARIKH-PERMULAAN-KUAT-KUASA-1.pdf",{"label":525,"url":526,"year":527},"Personal Data Protection Guidelines No.: 3\u002F2025 - Cross Border Personal Data Transfer, Version 1.0","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2025\u002F08\u002FGP_CBPDT_EN-1.pdf","2025",{"label":529,"url":530,"year":531},"Personal Data Protection Act 2010 [Act 709], text as originally enacted","https:\u002F\u002Flom.agc.gov.my\u002Filims\u002Fupload\u002Fportal\u002Fakta\u002Foutputaktap\u002FAct%20709%20ori.pdf","2010",{"label":533,"url":534,"year":535},"Personal Data Protection Regulations 2013 [P.U. (A) 335\u002F2013]","https:\u002F\u002Flom.agc.gov.my\u002Filims\u002Fupload\u002Fportal\u002Fakta\u002Foutputp\u002Fpua_20131114_P.U.%20(A)%20335%20-%20PERSONAL_DATA_PROTECTION_REGULATIONS_2013.pdf","2013",{"label":537,"url":538,"year":539},"Attorney General's Chambers - subsidiary legislation made under Act 709","https:\u002F\u002Flom.agc.gov.my\u002Fact-detail.php?act=709&lang=BI","2026",{"label":541,"url":542,"year":539},"Personal Data Protection Guideline: Data Protection by Design (DPbD), Version 1.0","https:\u002F\u002Fwww.pdp.gov.my\u002Fppdpv1\u002Fwp-content\u002Fuploads\u002F2026\u002F04\u002FData-Protection-By-Design-Guideline-DpbD.pdf",[544,547,551,555,559,563,567,571],{"label":545,"value":72,"source":546},"Date the section 129(1) export prohibition was deleted","P.U. (B) 522, commencement notification for Act A1727, 2024",{"label":548,"value":549,"source":550},"Conditions in section 129(3) permitting a cross-border transfer after the amendments","7 (paragraphs (a) to (g))","Act 709 s.129(3) as amended by Act A1727, 2024",{"label":552,"value":553,"source":554},"Transfer-destination Orders ever gazetted under Act 709","0 of 16 subsidiary instruments on the register","Attorney General's Chambers federal legislation register, Act 709, 2026",{"label":556,"value":557,"source":558},"Maximum validity of a Transfer Impact Assessment once relied on","3 years","Personal Data Protection Guidelines No.: 3\u002F2025, paras 5.6 and 6.5, 2025",{"label":560,"value":561,"source":562},"Due-diligence mechanisms named for the section 129(3)(f) route","3 (binding corporate rules, contractual clauses, certification)","Personal Data Protection Guidelines No.: 3\u002F2025, para 12.1, 2025",{"label":564,"value":565,"source":566},"Maximum fine under section 129(5) for an unlawful transfer out of Malaysia","RM300,000 (or 2 years' imprisonment, or both)","Act 709 s.129(5) as amended by Act A1727 s.12(e), 2024",{"label":568,"value":569,"source":570},"Maximum fine for contravening the seven Personal Data Protection Principles","RM1,000,000 (or 3 years' imprisonment, or both)","Act A1727 s.4(b)(ii) amending Act 709 s.5(2), in force 1 April 2025",{"label":572,"value":573,"source":574},"Date of issuance of the cross-border transfer guidelines","29 April 2025","Personal Data Protection Guidelines No.: 3\u002F2025, Version 1.0, cover, 2025","blog\u002Fpdpa-cross-border-data-transfer-meta-ads-malaysia","x7vamOjUGBPE1PKgVeqXV0jDQMww2f3atu4_fqlyCqs",1785891721095]