Why Tech Businesses Get Caught Late
We Track the Rules That Keep Moving
Technology businesses in Malaysia have absorbed more regulatory change in the last two years than in the decade before. Data protection obligations were amended and phased in through 2025. A dedicated cyber security regime came into force in 2024. Licensing was extended to large platform operators. Most of the businesses we speak to are not resisting any of it — they simply did not know the obligation had landed, because it landed while they were shipping product. The gap is almost always awareness, not intent.
How We Support Technology and Media
Compliance, contracts and IP together.
We build data protection and cyber governance frameworks, prepare the commercial contracts a technology business runs on — SaaS and master services agreements, service levels, licensing and content agreements — and make sure the intellectual property created by founders, employees and contractors actually sits with the company.
Choose Where You Are Now
Select the service your business needs next.
Compliance, contracts, IP or fundraising. Pick where the pressure is and we will start there.
Three regimes shape a Malaysian technology, media or telecommunications business: the Communications and Multimedia Act 1998, administered by MCMC, for network and applications services; the Personal Data Protection Act 2010 as amended in 2024, administered by the Personal Data Protection Commissioner; and the Cyber Security Act 2024, administered by NACSA, for entities designated as national critical information infrastructure.
What changed in data protection?
The Personal Data Protection (Amendment) Act 2024 was brought into force in stages across 1 January, 1 April and 1 June 2025, and it is the most significant change to Malaysian data protection since the original Act.
Change | What it means operationally |
|---|---|
"Data user" renamed "data controller" | Terminology aligned with international regimes; update your policies |
Mandatory data protection officer | Data controllers and processors must appoint at least one and notify the Commissioner |
Mandatory breach notification | Notify the Commissioner, and affected individuals where the breach is likely to cause significant harm |
Processors directly bound | Data processors now carry direct obligations under the Security Principle |
Biometric data | Now treated as sensitive personal data |
Data portability | New right for individuals to have data transmitted to another controller where technically feasible |
The Commissioner has issued guidelines on breach notification, appointment of data protection officers and cross-border transfers. Because those guidelines are still developing, confirm the current requirements before finalising a compliance programme.
Does the Cyber Security Act apply to us?
Directly, only if you are designated as an NCII entity. The Cyber Security Act 2024 came into force on 26 August 2024 and applies to entities designated as national critical information infrastructure across eleven sectors, including government, banking and finance, transportation, healthcare, energy and information, communication and digital.
Indirectly, it reaches much further. If you supply software or services to an NCII entity, their obligations will flow to you through procurement and vendor risk requirements. That is now a contracting issue for suppliers who are nowhere near being designated themselves.
Do we need an MCMC licence?
Most software businesses and websites do not. Licensing under the Communications and Multimedia Act 1998 attaches to defined activities, and the exemptions matter as much as the licence classes. A regulatory framework introduced for internet messaging and social media services brought large platform operators — those meeting a substantial user threshold in Malaysia — into the licensing regime, and cloud service providers have required a class licence since 2022.
Because the classes and thresholds are set by MCMC and have been revised, confirm the position for your specific service rather than relying on a general summary.
Who owns the code?
Not automatically the company that paid for it. Work produced by employees in the course of employment and work commissioned from contractors are treated differently, and a contractor who was never asked to sign an assignment may retain rights in the work. This is the single most common finding in technology diligence, and it surfaces at exactly the wrong moment — during a fundraise or a sale.
Frequently Asked Questions
Do we need a data protection officer?
The amended PDPA introduces a mandatory appointment obligation for data controllers and data processors, with notification to the Commissioner. Thresholds and scope are addressed in the Commissioner's guidelines, so confirm how they apply to your processing activities.
Can we transfer personal data outside Malaysia?
Cross-border transfer is subject to the PDPA's restrictions and exceptions, and the Commissioner has issued guidelines on the subject. This is a fast-moving area and the current guidance should be checked before you finalise a hosting or vendor arrangement.
Does our contractor own the software they built for us?
Possibly, if there is no written assignment. Commissioned work does not always vest in the paying party by default. Get assignments signed — ideally at engagement, and at the latest before diligence.
Where to start
For compliance, see the PDPA compliance framework and website terms of use and privacy policy. For contracts, see the master services agreement and service level agreement. For brand and content, see trademark registration and content and media licensing agreements.
This page is general information about Malaysian law and does not constitute legal advice. Licensing requirements, thresholds and guidelines change. Confirm the current position with the relevant authority or your adviser before acting on any part of it.


