A minister admits the obvious
Speaking at the CloudTech & DataCentre Conference 2026 on August 13, Malaysia's Digital Minister Gobind Singh Deo confirmed the government is examining two separate Acts to stand up a National Data Commission with enforcement powers over personal data and AI (The Star). His framing was blunt: "We are already looking at incorporating a new body that has the powers and the authority to advise the government on data," and, crucially, that body must do more than write rules — "there is an organisation that has the power to enforce those rules" (The Star, Aug 14). Gobind did not name the two Acts or set a timeline; the proposal is still at the planning stage.
That vagueness is itself informative. A minister does not float "two different Acts" for a brand-new commission unless the current architecture is too tangled to patch with a single amendment.
Three regulators, one dataset
Malaysia currently splits data governance three ways. The Department of Personal Data Protection (JPDP), under the Ministry of Communications and Digital, enforces the Personal Data Protection Act 2010 — substantially overhauled by the Personal Data Protection (Amendment) Act 2024, which passed the Senate on 31 July 2024 and rolled into force in stages through 2025 (JPDP; IAPP). The National AI Office (NAIO), incubated under MyDIGITAL Corporation since its December 2024 launch, is drafting a standalone AI Governance Bill — public consultation on which closed 31 July 2026 — that would create a Central AI Authority with its own investigation and enforcement powers over AI incidents (Rahmat Lim & Partners). And the Malaysian Communications and Multimedia Commission (MCMC) separately regulates the telecom and platform operators who carry most of that data, under a sector-specific Code of Practice negotiated with JPDP itself.
This is precisely the seam that matters for cross-border data flows. The 2024 PDPA amendment replaced Malaysia's old "whitelist" of approved destination countries with a case-by-case adequacy test: a controller may now export personal data if the receiving jurisdiction has a law "substantially similar" to the PDPA or otherwise ensures an equivalent standard of protection (Digital Policy Alert). That is a genuinely more flexible, GDPR-adjacent mechanism than the rigid whitelist it replaced — a real improvement for firms running regional data pipelines through Malaysian data centres. But JPDP administers that test with no formal mandate to weigh in on the AI systems processing the same exported data, and NAIO's forthcoming AI Bill is being drafted with only a general "responsible data governance" principle and no explicit JPDP linkage described in its own consultation material. Two regulators, two rulebooks, one data pipeline.
The case for consolidation — and its limits
The steelman for a single commission is straightforward and correct as far as it goes: fragmented authority creates compliance uncertainty, and uncertainty is a tax on the exact data-centre and cloud investment Malaysia is courting. A firm structuring a cross-border transfer today must separately satisfy JPDP's adequacy test, anticipate NAIO's future incident-reporting duties if the data feeds an AI system, and stay inside MCMC's sector code if it touches a licensed network. A commission with genuine enforcement teeth — audit power, penalty authority, one point of contact — would cut that compliance surface meaningfully, and Gobind is right to say advisory-only bodies don't fix that.
But "two different Acts" for one new commission is also a warning sign. Malaysia does not obviously need a fourth data authority; it needs JPDP and NAIO's overlapping mandates resolved — through merger, a clear statutory division of labour, or an MOU with real teeth — before a new commission is layered on top. NAIO's own AI Bill already proposes a Central AI Authority with enforcement and incident-coordination powers; standing up a separate National Data Commission with parallel powers over the same underlying data risks recreating the JPDP/MCMC overlap that recently required its own negotiated Code of Practice, just one level up. The 2024 PDPA reform already showed Malaysia can modernise cross-border rules without a wholesale institutional rebuild — the adequacy-test switch was legislated inside the existing JPDP framework. The stronger fix is scoping and merging, not adding.
What to watch
Gobind's timeline is empty by design — "still at the planning stage," no Act named. The two things worth tracking: whether the eventual bill folds JPDP's cross-border enforcement into the new commission outright (consolidation) or bolts a fourth layer on top of JPDP, NAIO and MCMC (fragmentation with extra steps); and whether NAIO's AI Governance Bill, expected to be tabled in 2026, gets amended to formally cross-reference whatever data commission emerges, rather than being finalised first and reconciled later. Malaysia has real regulatory infrastructure — a modernised PDPA, a functioning Cyber Security Act 2024 enforced by NACSA — worth protecting from duplicate bureaucracy dressed up as reform.