Data Sharing Act 2025: A new era of responsible data use

PrintMailRate-it

The Data Sharing Act 2025 (“the Act”) represents a pivotal step in regulating personal and institutional data in Malaysia, striking a balance between the growing demand for data-driven innovation and the protection of individual privacy rights. Together with the establishment of the National AI Office, the Act further accelerates Malaysia’s ambition to become a leading AI-driven nation.
     

Key Objectives

The Act is designed to:
  • Enable secure and efficient data sharing between public sector agencies such as the armed forces, the judicial and legal services, the general public services of the Federation, and others.
  • Establish clear legal boundaries for the collection, use, and transfer of personal data.
      

Notable Provisions

1. Establishment of National Data Sharing Committee

A new regulatory authority - the National Data Sharing Committee - has been established to, amongst others, regulate and oversee the implementation of the Act.
    

2. Request and Approval

A public sector agency is required to request data from another public sector agency that has control over the requested data by providing the necessary information of the data required and purpose of such request. 
     
The public sector agency to whom a request is made to shall evaluate and respond within 14 days from receipt of such request. However, it is to be noted that open data made freely available by any public sector agency can be accessed and shared without the need for a formal request.
     

3. Grounds for Refusal 

The Act provides a list of grounds for refusal of data sharing, amongst others, sharing of data can be refused if the disclosure could reveal the identity of confidential informants or protected witnesses, or such sharing of data would breach legal privilege, contracts, confidentiality obligations, or court orders.
     

4. Enforcement and Penalty 

Any officer or servant of a data recipient is not allowed to disclose the shared data other than for the purpose of this Act or any civil or criminal proceedings under any written law. Any violation would result in a fine up to RM1 million, a prison sentence of up to five years, or both.
      

Implications

By establishing a structured legal framework for data exchange among federal public sector agencies, the Act aims to enhance operational efficiency, promote transparency, and safeguard data privacy. While the Act is only applicable to public sector agencies, ccompanies must comply with new privacy and security requirements, creating opportunities for collaboration with government agencies. The Act also provides clear legal guidelines for data handling.
       
Additionally, individuals may experience faster and more personalized public services, while companies could face increased administrative tasks to ensure compliance and potential penalties for non-compliance.

From The Newsletter

Newsflash Asean 

Newsflash ASEAN​​

Contact

Contact Person Picture

Felix Engelhardt

Manager

+60 3 2276 2755

Send inquiry

Skip Ribbon Commands
Skip to main content
Deutschland Weltweit Search Menu