-
Overview
Malaysia is in the middle of accelerating digital technology and boosting the digital economy. The “Cloud First” strategy has been raised in Malaysia to promote adopting clouds in both the private and public sectors to enable rapid digital transformation in Malaysia. Malaysia's Digital Economy Corporation (MDEC) and regulators in sectors, such as banking and financial services, healthcare, and telecommunications, are reshaping the regulation and supervisory framework to keep up with the innovations and enable businesses to benefit from the use and adoption of cloud services.
-
General Regulatory Environment
Regulators:
The Personal Data Protection Department (JPDP) , an agency under the Ministry of Digital, assists the Personal Data Protection Commissioner in regulating and enforcing the Personal Data Protection Act (PDPA) across Malaysia.
General Privacy Laws:
The Personal Data Protection Act 2010 (Act 709) , in force since 15 November 2013, regulates the processing of personal data in commercial transactions. To align Malaysia's data protection standards with global benchmarks, the Personal Data Protection (Amendment) Act 2024 (Act A1727) is further enacted. Key enhancements include direct statutory duties for Data Processors, mandatory 72-hour Personal Data Breach Notifications (DBN), requirements for appointing Data Protection Officers (DPOs) etc.
Data Cross-Border Transfer Requirements:
Data Controllers may transfer personal data outside Malaysia if at least one of the statutory grounds under the Act and the Cross-Border Personal Data Transfer (CBPDT) Guidelines is satisfied:
1.The receiving jurisdiction has substantially similar data protection laws or provides an equivalent level of protection.
2.The Data Subject has been duly notified and has granted explicit consent for the cross-border transfer.
3.The transfer is necessary for the performance or conclusion of a contract involving the Data Subject.
4.The transfer is necessary for legal proceedings, obtaining legal advice, defending legal rights, or protecting the vital interests of the Data Subject.
5.The Data Controller has taken all reasonable precautions and exercised due diligence (including binding contractual safeguards like Data Processing Agreements) to ensure the data is not processed in contravention of the PDPA. -
Financial Services Sector
Overview:
Alibaba Cloud provides a resilient, highly available cloud infrastructure in Malaysia with three Availability Zones (AZs) in Kuala Lumpur and Two AZs in Johor. With proper solution design, it can meet the requirements of security, resilience, recoverability, and performance for regulated entities in the Financial Services industry. Alibaba Cloud has helped several customers minimize the risks of losses in confidentiality, integrity, and availability when moving to a public cloud.
Alibaba Cloud is committed to facilitating the customers in compliance with the financial industry-specific regulatory requirements, including the initial high-level due diligence and risk assessment, solution selection, implementation and transition, and post-implementation assurance. Alibaba Cloud provides a full suite of offerings that can help, including responses in every due diligence evaluation aspect, best practices in services and product configuration, automated and continuous security check tools, as well as assurance over the design and operational effectiveness of internal controls evidenced in our independent audit reports.
Regulator:
•Bank Negara Malaysia (BNM): The central bank of Malaysia, responsible for monetary and financial stability, as well as the prudential regulation and supervision of banks, insurers, takaful operators, payment system operators, and payment service providers.
•Securities Commission Malaysia (SC): The statutory body entrusted with the regulation and systematic development of Malaysia’s capital markets, overseeing exchanges, intermediaries, fund managers, and digital asset entities.
Regulations/Guidelines to look at when using cloud computing services:
1.BNM Risk Management in Technology (RMiT) Policy Document(Last revised: November 2025)
BNM’s RMiT framework sets out mandatory standards on technology governance, operational resilience, risk management, and cybersecurity for financial institutions. Financial institutions adopting public cloud must comply with Appendix 10 (Key Risks and Control Measures for Cloud Services). This appendix provides additional guidance to financial institutions for the assessment of common key risks and considerations of control measures when financial institutions adopt public cloud for critical systems. The guidance is broadly applicable across various cloud service models and financial institutions should apply a risk-based approach in implementing the guidance.
2.BNM Technology Requirements for Payment Services Regulatees (TR PD)(Issued: 12 March 2026)
The TR PD establishes technology risk management, cybersecurity, and operational resilience standards tailored for non-bank payment services regulatees (PSRs), including e-money issuers, merchant acquirers, money services businesses, and designated payment system operators. It introduces a tiered framework with explicit requirements around third-party provider management, cloud service risk assessments, access controls, and cybersecurity reporting.
3.BNM Policy Document on Outsourcing(Issued: 23 October 2019)
The BNM updated the Guidelines on Outsourcing arrangements for financial institutions in October 2019. The Guidelines on Outsourcing set out the requirements on management over outsourcing processes and risks for financial institutions. A comprehensive and robust due diligence process should be conducted by FIs over its outsourced service providers, including cloud service providers.
4. SC Guidelines on Technology Risk Management (GTRM)(Revised: 19 August 2024)
The GTRM outlines technology risk governance, operational reliability, and cyber resilience expectations for capital market entities. For cloud adoption, it emphasizes robust third-party governance, operational resilience and data security in cloud environments, and proactive incident reporting.
Is cloud permitted?
Yes.
Is there any additional approval needed?
BNM’s prior written approval needs to be obtained before entering into a new material outsourcing arrangement or making a significant change to an existing material outsourcing arrangement. For non-material outsourcing arrangements, financial institutions are required to maintain a complete, accurate and up-to-date register and make it available to BNM upon request.
Are offshore outsourcing arrangements allowed?
The BNM permits outsourcing outside of Malaysia on the conditions that the financial institutions address the additional risks (such as country risks) associated with overseas outsourcing arrangements, ensure the same level of abilities of monitoring service providers and business recovery in case of service providers’ failure, maintain BNM’s abilities of timely and unrestricted access to the systems, information or documents. Alibaba Cloud has two availability zones available in Malaysia, which is convenient for local financial institutions to utilize and manage to mitigate the risks associated with overseas outsourcing.
This white paper introduces the public cloud security system of Alibaba Cloud, specifically for Alibaba Cloud’s security capabilities and offerings for regions outside of Mainland China.
Customer Stories
-
TNG Digital
Alibaba Cloud brings new cutting-edge technology, global security standards, and operational effectiveness. The combination allows TNG Digital Sdn Bhd to focus on building better products and services.
-
Revenue Monster
Harnessed with the power of Alibaba Cloud, enterprises and financial institutions can now reimagine its future with Revenue Monster's FinTech as a Service (FaaS) and Financial Cloud solutions.
Start with Alibaba Cloud Solutions
Learn and experience the power of Alibaba Cloud with a free trial.
Contact Sales