Analyzing the Scope of Application and Fundamental Concepts of Personal Data Protection in the Digital Era: From Malaysia’s Perspective and Experience for Vietnam
Abstract
Over the past decades, the Malaysian government has acknowledged the pressing need to regulate personal data protection, becoming the first country in Southeast Asia to recognize this urgent requirement, and as a result, the 2010 Malaysian Personal Data Protection Act was enacted and later entered into force in 2013 in response to the increasing importance of personal data protection in this digital age. On 24 December 2024, the 2024 Malaysian Personal Data Protection (Amendment) Act was enacted and came into force in 2025. The most fundamental step in evaluating a piece of legislation is understanding its scope and application. For this reason, this article covers key aspects of the Malaysian 2024 Personal Data Protection Act, including its scope of application in Malaysia and several fundamental concepts, namely personal data, sensitive personal data, and the roles of data controller and data processor. Furthermore, this article compares Malaysia’s approach with the current situation in Vietnam to offer insights for the development of Vietnam’s data protection policies, with the hope of highlighting the importance of regulatory clarity and cross-border data handling, to contribute to Vietnam’s legal improvements in personal data protection amidst a rapid digital revolution.
© 2026 Nguyen Hoang Phuoc Hanh, Pham Phuong Thao, published by Hochiminh City University of Law
This work is licensed under the Creative Commons Attribution 4.0 License.