China PIPL vs Malaysia PDPA: What Changes for Exporters
China's Personal Information Protection Law took effect in 2021 and reaches Malaysian businesses that handle the personal information of people in China. Malaysia's PDPA is territorial. The difference that costs money is cross-border transfer: PIPL controls data leaving China through three defined routes, and Malaysia has nothing comparable.
If you export to China, sell online to Chinese consumers, host Chinese tourists, or sit inside a group with China operations, PIPL is a live obligation rather than a theoretical one. This page covers what actually differs and what it forces you to build.
China PIPL vs PDPA at a glance
| China PIPL | Malaysia PDPA | |
|---|---|---|
| The law | Personal Information Protection Law of the People's Republic of China, effective 1 November 2021 | Personal Data Protection Act 2010 (Act 709), as amended by the Amendment Act 2024 |
| Regulator | Cyberspace Administration of China (CAC) and related authorities | JPDP, under the Ministry of Digital |
| Sits alongside | The Cybersecurity Law and the Data Security Law, which apply in parallel | Sector regulation such as BNM and Securities Commission requirements |
| Reaches beyond its borders | Yes. It applies to processing outside China aimed at providing products or services to people in China, or analysing their behaviour | Territorial in practice |
| Consent model | Consent, plus a distinct requirement for separate consent in defined situations | Consent-centred, with limited statutory exceptions |
| Separate consent required for | Sensitive personal information, cross-border transfers, disclosure to third parties, and public disclosure | No equivalent concept |
| Cross-border transfer | One of three routes: a CAC security assessment, the CAC Standard Contract, or personal information protection certification | The 2024 amendment removed the whitelist approach the original Act used |
| Impact assessment | A personal information protection impact assessment (PIPIA) is required before defined high-risk processing | DPIA is addressed through JPDP guidelines issued on 30 April 2026 |
| Local presence | Overseas handlers must establish an entity or appoint a representative in China and report the details | No equivalent requirement |
| Data localisation | Applies to critical information infrastructure operators and large-scale processors | No general localisation requirement |
| Accountability role | A person in charge of personal information protection, where thresholds are met | A Data Protection Officer above the thresholds set by the 2024 amendment |
| Maximum penalty | Up to RMB 50 million or 5% of the previous year's annual revenue, with business suspension and personal liability available | RM 1 million per offence, with up to 3 years imprisonment |
Does PIPL apply to a Malaysian business?
It can, with no Chinese entity and no servers in China. PIPL applies to processing carried out outside China where the purpose is to provide products or services to people in China, or to analyse their behaviour.
- Exporting and holding Chinese customer or distributor contact data
- Selling through a cross-border e-commerce channel to Chinese consumers
- Hospitality and tourism operators holding Chinese guest records
- A manufacturing partnership where staff or supplier data moves both ways
- Any group entity that shares a CRM or HR platform with a China operation
What is separate consent?
The requirement that trips up most first-time PIPL programmes. For defined situations, general consent buried in a privacy notice is not enough. You need a distinct, specific consent for that particular activity.
- Processing sensitive personal information
- Transferring personal information outside China
- Providing personal information to another handler
- Disclosing personal information publicly
In practice this means separate, clearly-worded consent steps in the user journey rather than one bundled acceptance, and records showing which consent was given when.
How do you move data out of China legally?
Through one of three routes, chosen by what you transfer and how much. Getting this wrong is the most expensive PIPL mistake because it stops a data flow the business already depends on.
- A CAC security assessment, required above defined thresholds and for critical information infrastructure operators
- The CAC Standard Contract, signed with the overseas recipient and filed with the authorities
- Personal information protection certification from a recognised body
- In all cases, a PIPIA before the transfer, plus separate consent from the individuals concerned
Malaysia's PDPA imposes nothing equivalent, so a Malaysian team meeting PIPL transfer rules for the first time is building a capability from scratch rather than adapting one.
How do the penalties compare?
PIPL is an order of magnitude larger and is not capped at a fixed sum. It is turnover-linked and reaches individuals.
- PIPL: up to RMB 50 million or 5% of the previous year's annual revenue
- PIPL also allows suspension of business, and penalties against the individuals directly responsible
- Malaysia: RM 1 million per offence, with up to 3 years imprisonment and personal liability for directors and senior officers
- PIPL enforcement can also affect the ability to keep operating a data flow, which is often the greater commercial risk
Where to take this next
- China PIPL Training, one day on separate consent, transfer mechanisms and localisation
- PDPA Awareness Training, the Malaysian baseline this all sits on top of
- Cross-border transfer and TIA advisory, for the assessment work behind a transfer route
- DPO Advanced, cross-border transfers and privacy by design at practitioner level
Frequently asked questions
This comparison is general information, current as at 21 August 2026, and is not legal advice. Frameworks change, and the position for your organisation depends on what you process and where. Take specific matters to a qualified adviser.