China PIPL vs Malaysia PDPA: What Changes for Exporters

China's Personal Information Protection Law took effect in 2021 and reaches Malaysian businesses that handle the personal information of people in China. Malaysia's PDPA is territorial. The difference that costs money is cross-border transfer: PIPL controls data leaving China through three defined routes, and Malaysia has nothing comparable.

If you export to China, sell online to Chinese consumers, host Chinese tourists, or sit inside a group with China operations, PIPL is a live obligation rather than a theoretical one. This page covers what actually differs and what it forces you to build.

By Mac Jake, Founder & CEO, Orbix Tech Sdn Bhd · Last updated

China PIPL vs PDPA at a glance

 China PIPLMalaysia PDPA
The law Personal Information Protection Law of the People's Republic of China, effective 1 November 2021 Personal Data Protection Act 2010 (Act 709), as amended by the Amendment Act 2024
Regulator Cyberspace Administration of China (CAC) and related authorities JPDP, under the Ministry of Digital
Sits alongside The Cybersecurity Law and the Data Security Law, which apply in parallel Sector regulation such as BNM and Securities Commission requirements
Reaches beyond its borders Yes. It applies to processing outside China aimed at providing products or services to people in China, or analysing their behaviour Territorial in practice
Consent model Consent, plus a distinct requirement for separate consent in defined situations Consent-centred, with limited statutory exceptions
Separate consent required for Sensitive personal information, cross-border transfers, disclosure to third parties, and public disclosure No equivalent concept
Cross-border transfer One of three routes: a CAC security assessment, the CAC Standard Contract, or personal information protection certification The 2024 amendment removed the whitelist approach the original Act used
Impact assessment A personal information protection impact assessment (PIPIA) is required before defined high-risk processing DPIA is addressed through JPDP guidelines issued on 30 April 2026
Local presence Overseas handlers must establish an entity or appoint a representative in China and report the details No equivalent requirement
Data localisation Applies to critical information infrastructure operators and large-scale processors No general localisation requirement
Accountability role A person in charge of personal information protection, where thresholds are met A Data Protection Officer above the thresholds set by the 2024 amendment
Maximum penalty Up to RMB 50 million or 5% of the previous year's annual revenue, with business suspension and personal liability available RM 1 million per offence, with up to 3 years imprisonment

Does PIPL apply to a Malaysian business?

It can, with no Chinese entity and no servers in China. PIPL applies to processing carried out outside China where the purpose is to provide products or services to people in China, or to analyse their behaviour.

  • Exporting and holding Chinese customer or distributor contact data
  • Selling through a cross-border e-commerce channel to Chinese consumers
  • Hospitality and tourism operators holding Chinese guest records
  • A manufacturing partnership where staff or supplier data moves both ways
  • Any group entity that shares a CRM or HR platform with a China operation

What is separate consent?

The requirement that trips up most first-time PIPL programmes. For defined situations, general consent buried in a privacy notice is not enough. You need a distinct, specific consent for that particular activity.

  • Processing sensitive personal information
  • Transferring personal information outside China
  • Providing personal information to another handler
  • Disclosing personal information publicly

In practice this means separate, clearly-worded consent steps in the user journey rather than one bundled acceptance, and records showing which consent was given when.

How do you move data out of China legally?

Through one of three routes, chosen by what you transfer and how much. Getting this wrong is the most expensive PIPL mistake because it stops a data flow the business already depends on.

  • A CAC security assessment, required above defined thresholds and for critical information infrastructure operators
  • The CAC Standard Contract, signed with the overseas recipient and filed with the authorities
  • Personal information protection certification from a recognised body
  • In all cases, a PIPIA before the transfer, plus separate consent from the individuals concerned

Malaysia's PDPA imposes nothing equivalent, so a Malaysian team meeting PIPL transfer rules for the first time is building a capability from scratch rather than adapting one.

How do the penalties compare?

PIPL is an order of magnitude larger and is not capped at a fixed sum. It is turnover-linked and reaches individuals.

  • PIPL: up to RMB 50 million or 5% of the previous year's annual revenue
  • PIPL also allows suspension of business, and penalties against the individuals directly responsible
  • Malaysia: RM 1 million per offence, with up to 3 years imprisonment and personal liability for directors and senior officers
  • PIPL enforcement can also affect the ability to keep operating a data flow, which is often the greater commercial risk

Where to take this next

Frequently asked questions

It can, without any Chinese entity. PIPL applies to processing carried out outside China where the purpose is to provide products or services to people in China, or to analyse their behaviour. Exporters, cross-border e-commerce sellers, hospitality operators and groups with China operations are the common cases.

A distinct consent required for specific activities, on top of any general consent. It applies to sensitive personal information, cross-border transfers, providing data to another handler, and public disclosure. General consent buried in a privacy notice does not satisfy it.

Through one of three routes: a CAC security assessment, the CAC Standard Contract filed with the authorities, or personal information protection certification. Which applies depends on volume and on whether you are a critical information infrastructure operator. A personal information protection impact assessment is required first.

PIPL reaches up to RMB 50 million or 5% of the previous year's annual revenue, and allows business suspension and penalties against responsible individuals. Malaysia's PDPA caps at RM 1 million per offence with up to 3 years imprisonment and personal liability for directors and senior officers.

No. The PDPA gives you a base of data governance that helps, but PIPL adds separate consent, a defined cross-border transfer mechanism, a PIPIA, a local representative requirement for overseas handlers, and in some cases data localisation. None of those have PDPA equivalents.

This comparison is general information, current as at 21 August 2026, and is not legal advice. Frameworks change, and the position for your organisation depends on what you process and where. Take specific matters to a qualified adviser.