• Malaysia is in the middle of accelerating digital technology and boosting the digital economy. The “Cloud First” strategy has been raised in Malaysia to promote adopting clouds in both the private and public sectors to enable rapid digital transformation in Malaysia. Malaysia's Digital Economy Corporation (MDEC) and regulators in sectors, such as banking and financial services, healthcare, and telecommunications, are reshaping the regulation and supervisory framework to keep up with the innovations and enable businesses to benefit from the use and adoption of cloud services.

  • Regulators:
    The Personal Data Protection Department (JPDP) , an agency under the Ministry of Digital, assists the Personal Data Protection Commissioner in regulating and enforcing the Personal Data Protection Act (PDPA) across Malaysia.


    General Privacy Laws:
    The Personal Data Protection Act 2010 (Act 709) , in force since 15 November 2013, regulates the processing of personal data in commercial transactions. To align Malaysia's data protection standards with global benchmarks, the Personal Data Protection (Amendment) Act 2024 (Act A1727) is further enacted. Key enhancements include direct statutory duties for Data Processors, mandatory 72-hour Personal Data Breach Notifications (DBN), requirements for appointing Data Protection Officers (DPOs) etc.


    Data Cross-Border Transfer Requirements:
    Data Controllers may transfer personal data outside Malaysia if at least one of the statutory grounds under the Act and the Cross-Border Personal Data Transfer (CBPDT) Guidelines is satisfied:
    1.The receiving jurisdiction has substantially similar data protection laws or provides an equivalent level of protection.
    2.The Data Subject has been duly notified and has granted explicit consent for the cross-border transfer.
    3.The transfer is necessary for the performance or conclusion of a contract involving the Data Subject.
    4.The transfer is necessary for legal proceedings, obtaining legal advice, defending legal rights, or protecting the vital interests of the Data Subject.
    5.The Data Controller has taken all reasonable precautions and exercised due diligence (including binding contractual safeguards like Data Processing Agreements) to ensure the data is not processed in contravention of the PDPA.

  • Overview:
    Alibaba Cloud provides a resilient, highly available cloud infrastructure in Malaysia with three Availability Zones (AZs) in Kuala Lumpur and Two AZs in Johor. With proper solution design, it can meet the requirements of security, resilience, recoverability, and performance for regulated entities in the Financial Services industry. Alibaba Cloud has helped several customers minimize the risks of losses in confidentiality, integrity, and availability when moving to a public cloud.

    Alibaba Cloud is committed to facilitating the customers in compliance with the financial industry-specific regulatory requirements, including the initial high-level due diligence and risk assessment, solution selection, implementation and transition, and post-implementation assurance. Alibaba Cloud provides a full suite of offerings that can help, including responses in every due diligence evaluation aspect, best practices in services and product configuration, automated and continuous security check tools, as well as assurance over the design and operational effectiveness of internal controls evidenced in our independent audit reports.


    Regulator:
    Bank Negara Malaysia (BNM): The central bank of Malaysia, responsible for monetary and financial stability, as well as the prudential regulation and supervision of banks, insurers, takaful operators, payment system operators, and payment service providers.
    Securities Commission Malaysia (SC): The statutory body entrusted with the regulation and systematic development of Malaysia’s capital markets, overseeing exchanges, intermediaries, fund managers, and digital asset entities.


    Regulations/Guidelines to look at when using cloud computing services:
    1.BNM Risk Management in Technology (RMiT) Policy Document

    (Last revised: November 2025)
    BNM’s RMiT framework sets out mandatory standards on technology governance, operational resilience, risk management, and cybersecurity for financial institutions. Financial institutions adopting public cloud must comply with Appendix 10 (Key Risks and Control Measures for Cloud Services). This appendix provides additional guidance to financial institutions for the assessment of common key risks and considerations of control measures when financial institutions adopt public cloud for critical systems. The guidance is broadly applicable across various cloud service models and financial institutions should apply a risk-based approach in implementing the guidance.

    2.BNM Technology Requirements for Payment Services Regulatees (TR PD)

    (Issued: 12 March 2026)
    The TR PD establishes technology risk management, cybersecurity, and operational resilience standards tailored for non-bank payment services regulatees (PSRs), including e-money issuers, merchant acquirers, money services businesses, and designated payment system operators. It introduces a tiered framework with explicit requirements around third-party provider management, cloud service risk assessments, access controls, and cybersecurity reporting.

    3.BNM Policy Document on Outsourcing

    (Issued: 23 October 2019)
    The BNM updated the Guidelines on Outsourcing arrangements for financial institutions in October 2019. The Guidelines on Outsourcing set out the requirements on management over outsourcing processes and risks for financial institutions. A comprehensive and robust due diligence process should be conducted by FIs over its outsourced service providers, including cloud service providers.

    4. SC Guidelines on Technology Risk Management (GTRM)

    (Revised: 19 August 2024)
    The GTRM outlines technology risk governance, operational reliability, and cyber resilience expectations for capital market entities. For cloud adoption, it emphasizes robust third-party governance, operational resilience and data security in cloud environments, and proactive incident reporting.


    Is cloud permitted?
    Yes.


    Is there any additional approval needed?
    BNM’s prior written approval needs to be obtained before entering into a new material outsourcing arrangement or making a significant change to an existing material outsourcing arrangement. For non-material outsourcing arrangements, financial institutions are required to maintain a complete, accurate and up-to-date register and make it available to BNM upon request.


    Are offshore outsourcing arrangements allowed?
    The BNM permits outsourcing outside of Malaysia on the conditions that the financial institutions address the additional risks (such as country risks) associated with overseas outsourcing arrangements, ensure the same level of abilities of monitoring service providers and business recovery in case of service providers’ failure, maintain BNM’s abilities of timely and unrestricted access to the systems, information or documents. Alibaba Cloud has two availability zones available in Malaysia, which is convenient for local financial institutions to utilize and manage to mitigate the risks associated with overseas outsourcing.

Informational Resources
In this user guide, Alibaba Cloud elaborates on how we facilitate the financial institutions in Malaysia to meet the requirements in the BNM’s guidelines.
Alibaba Cloud has engaged with an independent auditor to assess Alibaba Cloud's internal controls in accordance with applicable regulatory requirements issued by the Bank Negara Malaysia ("BNM") and Securities Commission ("SC") throughout the audit period.
Alibaba Cloud strives to provide customers with consistent, reliable, secure, and compliant cloud computing services, helping customers ensure the confidentiality, integrity, and availability of their systems and data.
This white paper introduces the public cloud security system of Alibaba Cloud, specifically for Alibaba Cloud’s security capabilities and offerings for regions outside of Mainland China.
A whitepaper designed to simplify your compliance journey in Malaysia. Understand the core requirements of the Act, explore Alibaba Cloud’s global security posture, and how we support customers in achieving compliance.
This detailed guide to COP requirements is the Appendix A referenced in "Malaysia Cyber Security Act Compliance Whitepaper". It maps Alibaba Cloud’s security commitments against customer obligations. Includes technical recommendations to help you achieve and maintain compliance with the Act.
A comprehensive guide for customers navigating Malaysia’s Personal Data Protection Act 2010 (Act 709) and the 2024 Amendment Act, illustrating how Alibaba Cloud’s security and privacy capabilities empower organizations to build, process, and protect workloads compliantly in the cloud.

Start with Alibaba Cloud Solutions

Learn and experience the power of Alibaba Cloud with a free trial.

Contact Sales
phone Contact Us
Hi, I'm Alibaba Cloud AI Assistant!
I can help with questions and solutions.