Cross-Border Personal Data Transfer (JPDP CBPDT Guideline)
The 2024 amendments ended Malaysia's never-used whitelist of approved countries. Since 1 April 2025, section 129 of the PDPA lets a data controller transfer personal data abroad if the destination has a law substantially similar to the PDPA, or ensures an adequate level of protection at least equivalent to it, or if one of the listed exceptions applies, such as consent, contract necessity, legal proceedings or all reasonable precautions and due diligence. The Commissioner's Guideline on Cross Border Personal Data Transfer, issued on 29 April 2025, explains each condition. It introduces the Transfer Impact Assessment, whose findings stay valid for no more than three years, and recognises binding corporate rules, contractual clauses such as the ASEAN Model Contractual Clauses and the EU standard contractual clauses, and certification schemes such as APEC CBPR as ways to show due diligence. Individuals must be told about transfers through a notice.
Almost every Malaysian organisation transfers data abroad, often without realising it: cloud hosting, SaaS tools, regional shared service centres, overseas parents and outsourced support. This two-day course is for DPOs, legal, procurement, IT and cloud teams, and HR in multinational groups. Day one covers the conditions and how to choose between them. Day two is practical, running a Transfer Impact Assessment and fitting the contractual and group mechanisms to real transfer scenarios. It pairs with our courses on Singapore PDPA, China PIPL and GDPR for the other end of the transfer.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
Day 1, 9:15 AM - 10:15 AM
What Changed in Section 129
The old whitelist regime, the amended section 129 from 1 April 2025, and the guideline issued on 29 April 2025. The difference between the two main conditions, a substantially similar law and an adequate level of protection, and the exceptions that stand alongside them.
Day 1, 10:15 AM - 10:30 AM
Break
Day 1, 10:30 AM - 11:30 AM
Mapping Your Transfers
Finding the transfers you actually make: cloud regions, SaaS vendors, remote access by overseas staff, group systems, support desks and backups. Recording destination, recipient, data types and purpose for each flow. Exercise: build a transfer register for a sample organisation.
Day 1, 11:30 AM - 12:30 PM
Condition One: A Substantially Similar Law
The guideline's factors for comparing a foreign law with the PDPA, including rights, principles, DPO and breach notification requirements, processor obligations and a regulator with real powers, and the sources you can rely on to assess them.
Day 1, 12:30 PM - 1:30 PM
Lunch
Day 1, 1:30 PM - 3:15 PM
Condition Two: An Adequate Level of Protection
Assessing the recipient rather than the country: security measures aligned with the Security Principle and the Personal Data Protection Standard, certifications, and legally enforceable obligations that the controller or individual can rely on.
Day 1, 3:15 PM - 3:30 PM
Break
Day 1, 3:30 PM - 4:45 PM
The Exceptions and When to Use Them
Consent, contract necessity with the individual or with a third party in the individual's interest, legal proceedings, reasonable grounds, all reasonable precautions and due diligence, and vital interests. Why consent is a weak basis for routine transfers, and recording the basis chosen.
Day 1, 4:45 PM - 5:00 PM
Day 1 Close
Recap and what to review before day two.
Day 2, 9:00 AM - 9:15 AM
Day 1 Review
Recap of day one and the questions it left open.
Day 2, 9:15 AM - 10:15 AM
Running a Transfer Impact Assessment
The guideline's steps: identify destinations, assess the law or the recipient's protections against the listed factors, decide, and record. The three-year validity limit and the duty to review when the foreign law changes. Workshop: a full TIA for a transfer to a cloud provider in another ASEAN country.
Day 2, 10:15 AM - 10:30 AM
Break
Day 2, 10:30 AM - 11:30 AM
Binding Corporate Rules for Groups
What BCRs must contain under the guideline, how a group adopts, reviews and audits them, and when BCRs are worth the effort compared with contracts.
Day 2, 11:30 AM - 12:30 PM
Contractual Clauses and Certification
Using the ASEAN Model Contractual Clauses or EU standard contractual clauses, reviewing whether extra clauses are needed to match the PDPA, and relying on certifications such as APEC CBPR and PRP, including checking a certificate is valid.
Day 2, 12:30 PM - 1:30 PM
Lunch
Day 2, 1:30 PM - 3:15 PM
Notices, Processors and Records
Telling individuals about transfers, the controller's responsibilities when the recipient is a processor or sub-processor, onward transfers, and the records JPDP can ask to see.
Day 2, 3:15 PM - 3:30 PM
Break
Day 2, 3:30 PM - 4:45 PM
Workshop: Five Transfer Scenarios
Teams choose and document the right basis for five realistic transfers, including a regional HR system, offshore customer support, a US SaaS tool, a Chinese parent company and a cloud backup, and defend their choices.
Day 2, 4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Explain the amended section 129 and the conditions in the CBPDT guideline
- Map the personal data transfers your organisation actually makes
- Run and record a Transfer Impact Assessment and keep it current
- Choose between the main conditions and the exceptions for each transfer
- Use binding corporate rules, contractual clauses and certifications appropriately
- Meet notice, processor and record-keeping obligations for transfers
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate. For DPOs, legal, procurement and vendor management, IT, cloud and infrastructure teams, and HR in multinational organisations. Basic PDPA knowledge assumed.
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A completed Transfer Impact Assessment and five documented transfer decisions, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance