Cross-Border Personal Data Transfer (JPDP CBPDT Guideline)

The 2024 amendments ended Malaysia's never-used whitelist of approved countries. Since 1 April 2025, section 129 of the PDPA lets a data controller transfer personal data abroad if the destination has a law substantially similar to the PDPA, or ensures an adequate level of protection at least equivalent to it, or if one of the listed exceptions applies, such as consent, contract necessity, legal proceedings or all reasonable precautions and due diligence. The Commissioner's Guideline on Cross Border Personal Data Transfer, issued on 29 April 2025, explains each condition. It introduces the Transfer Impact Assessment, whose findings stay valid for no more than three years, and recognises binding corporate rules, contractual clauses such as the ASEAN Model Contractual Clauses and the EU standard contractual clauses, and certification schemes such as APEC CBPR as ways to show due diligence. Individuals must be told about transfers through a notice.

Almost every Malaysian organisation transfers data abroad, often without realising it: cloud hosting, SaaS tools, regional shared service centres, overseas parents and outsourced support. This two-day course is for DPOs, legal, procurement, IT and cloud teams, and HR in multinational groups. Day one covers the conditions and how to choose between them. Day two is practical, running a Transfer Impact Assessment and fitting the contractual and group mechanisms to real transfer scenarios. It pairs with our courses on Singapore PDPA, China PIPL and GDPR for the other end of the transfer.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

Day 1, 9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

Day 1, 9:15 AM - 10:15 AM

What Changed in Section 129

The old whitelist regime, the amended section 129 from 1 April 2025, and the guideline issued on 29 April 2025. The difference between the two main conditions, a substantially similar law and an adequate level of protection, and the exceptions that stand alongside them.

03

Day 1, 10:15 AM - 10:30 AM

Break

04

Day 1, 10:30 AM - 11:30 AM

Mapping Your Transfers

Finding the transfers you actually make: cloud regions, SaaS vendors, remote access by overseas staff, group systems, support desks and backups. Recording destination, recipient, data types and purpose for each flow. Exercise: build a transfer register for a sample organisation.

05

Day 1, 11:30 AM - 12:30 PM

Condition One: A Substantially Similar Law

The guideline's factors for comparing a foreign law with the PDPA, including rights, principles, DPO and breach notification requirements, processor obligations and a regulator with real powers, and the sources you can rely on to assess them.

06

Day 1, 12:30 PM - 1:30 PM

Lunch

07

Day 1, 1:30 PM - 3:15 PM

Condition Two: An Adequate Level of Protection

Assessing the recipient rather than the country: security measures aligned with the Security Principle and the Personal Data Protection Standard, certifications, and legally enforceable obligations that the controller or individual can rely on.

08

Day 1, 3:15 PM - 3:30 PM

Break

09

Day 1, 3:30 PM - 4:45 PM

The Exceptions and When to Use Them

Consent, contract necessity with the individual or with a third party in the individual's interest, legal proceedings, reasonable grounds, all reasonable precautions and due diligence, and vital interests. Why consent is a weak basis for routine transfers, and recording the basis chosen.

10

Day 1, 4:45 PM - 5:00 PM

Day 1 Close

Recap and what to review before day two.

11

Day 2, 9:00 AM - 9:15 AM

Day 1 Review

Recap of day one and the questions it left open.

12

Day 2, 9:15 AM - 10:15 AM

Running a Transfer Impact Assessment

The guideline's steps: identify destinations, assess the law or the recipient's protections against the listed factors, decide, and record. The three-year validity limit and the duty to review when the foreign law changes. Workshop: a full TIA for a transfer to a cloud provider in another ASEAN country.

13

Day 2, 10:15 AM - 10:30 AM

Break

14

Day 2, 10:30 AM - 11:30 AM

Binding Corporate Rules for Groups

What BCRs must contain under the guideline, how a group adopts, reviews and audits them, and when BCRs are worth the effort compared with contracts.

15

Day 2, 11:30 AM - 12:30 PM

Contractual Clauses and Certification

Using the ASEAN Model Contractual Clauses or EU standard contractual clauses, reviewing whether extra clauses are needed to match the PDPA, and relying on certifications such as APEC CBPR and PRP, including checking a certificate is valid.

16

Day 2, 12:30 PM - 1:30 PM

Lunch

17

Day 2, 1:30 PM - 3:15 PM

Notices, Processors and Records

Telling individuals about transfers, the controller's responsibilities when the recipient is a processor or sub-processor, onward transfers, and the records JPDP can ask to see.

18

Day 2, 3:15 PM - 3:30 PM

Break

19

Day 2, 3:30 PM - 4:45 PM

Workshop: Five Transfer Scenarios

Teams choose and document the right basis for five realistic transfers, including a regional HR system, offshore customer support, a US SaaS tool, a Chinese parent company and a cloud backup, and defend their choices.

20

Day 2, 4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Explain the amended section 129 and the conditions in the CBPDT guideline
  • Map the personal data transfers your organisation actually makes
  • Run and record a Transfer Impact Assessment and keep it current
  • Choose between the main conditions and the exceptions for each transfer
  • Use binding corporate rules, contractual clauses and certifications appropriately
  • Meet notice, processor and record-keeping obligations for transfers

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate. For DPOs, legal, procurement and vendor management, IT, cloud and infrastructure teams, and HR in multinational organisations. Basic PDPA knowledge assumed.

Duration   2 Days (16 Hours)  |  9:00 AM to 5:00 PM daily

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A completed Transfer Impact Assessment and five documented transfer decisions, plus a written knowledge check

Certificate   Certificate of Completion issued to all participants upon full attendance

Enquiries   Contact us to register or discuss scheduling

Frequently Asked Questions

Yes. Cross-Border Personal Data Transfer (JPDP CBPDT Guideline) is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

Cross-Border Personal Data Transfer (JPDP CBPDT Guideline) runs for 2 days (16 hours) | 9:00 AM to 5:00 PM daily. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Intermediate. For DPOs, legal, procurement and vendor management, IT, cloud and infrastructure teams, and HR in multinational organisations. Basic PDPA knowledge assumed. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.