Skip to content

Cold Email Laws in Malaysia: PDPA Consent and the Coming Spam Rule

October 11, 2026. As far as we could find, Malaysia has no anti-spam rule for email in operation yet, but cold email to a named person is still regulated. The Personal Data Protection Act 2010 requires consent to process personal data in commercial transactions, requires a written notice explaining what you do with it, and gives everyone the right to stop direct marketing at any time. Since April 1, 2025, breaching those principles can cost up to RM1,000,000, up to three years in prison, or both. A new section 233A of the Communications and Multimedia Act, which bans unsolicited commercial electronic messages, has been enacted but was not yet in operation when the regulator consulted on the rules that would implement it.

Cold email laws in Malaysia: PDPA consent, section 43 direct marketing opt-out, 2025 penalties and the coming section 233A anti-spam rule

This guide reads the Act from the government's published text alongside law-firm summaries of the 2024 amendments and of the regulator's consultation, all read 11 October 2026, for B2B teams emailing Malaysian prospects. Whatever the law says, authenticated sending domains and a working unsubscribe are what keep you out of spam folders; that is the starting point of our email infrastructure builds. This is a map of the rules, not legal advice.

Key numbers

ItemNumber
Lawful basis for processing a named contact's data (PDPA s.6; no legitimate interests basis)Consent
Right to stop direct marketing (PDPA s.43(1))At any time, by written notice
Fine for ignoring the Commissioner's s.43 order (or up to 2 years, or both)up to RM200,000
Fine for breaching the principles, from April 1, 2025 (or up to 3 years, or both)up to RM1,000,000
Fine for breaching the principles, before April 1, 2025 (or up to 2 years)up to RM300,000
Mandatory DPO and breach notification fromJune 1, 2025
MCMC spam consultation published (deadline extended to September 8, 2025)August 13, 2025
Section 233A anti-spam ban (no commencement notice found, October 2026)Enacted, not yet in operation

Personal Data Protection Act 2010 (Act 709, 2023 reprint), Skrine's alert on the 2024 amendment's commencement dates, DLA Piper Data Protection Laws of the World and legal updates on the MCMC consultation, all read 11 October 2026.

Who the PDPA covers

Section 2 applies the Act to anyone who processes, or controls or authorizes the processing of, personal data "in respect of commercial transactions". Selling to a business is a commercial transaction, and a named work email identifies an individual, so B2B prospect data is inside the Act. The Federal and State Governments are outside it.

The territorial test is narrower than most people assume. The Act applies to a person established in Malaysia, which includes a Malaysian company, a partnership and anyone who maintains an office, branch, agency or regular practice there, and to a person not established in Malaysia who "uses equipment in Malaysia for processing the personal data otherwise than for the purposes of transit". Such a person must also nominate a representative in Malaysia. A sender with no Malaysian presence and no Malaysian servers may sit outside the PDPA's reach, but that is not a gap to build a business on: the coming anti-spam rule may reach senders the PDPA does not, and its scope will be set by the rules that implement it.

Three provisions shape a cold email program:

  1. Consent, section 6. A data user, now called a data controller, may not process personal data "unless the data subject has given his consent", subject to exceptions such as performing a contract or taking steps the data subject asked for before a contract. Unlike the EU's GDPR, the Act has no general legitimate interests basis, so the strict reading is that emailing a named stranger needs consent.
  2. Notice and choice, section 7. You must tell the person in writing that their data is being processed, for what purposes, where it came from, and how they can access, correct or limit its use. The notice is due as soon as practicable: when you first ask for or first collect the data, or otherwise before you use it for a new purpose or disclose it to a third party.
  3. Stop direct marketing, section 43. Anyone may, "at any time by notice in writing", require you to stop or not begin processing their data for direct marketing, defined as "the communication by whatever means of any advertising or marketing material which is directed to particular individuals." If you ignore the request and the Commissioner orders you to comply, failing to do so is an offence carrying a fine of up to RM200,000, up to two years in prison, or both.

A practical approach is to keep data to the minimum, putting a short PDPA notice and an instant opt-out in the first email, honour every stop request across all lists and tools, and ask for consent before any sustained sequence. Data protection specialists at DLA Piper note that the Act has no specific provisions on electronic marketing, which is why the general principles do the work.

Bar chart of Malaysia's maximum PDPA fines: RM1,000,000 for breaching the principles since 2025, RM300,000 before, and RM200,000 for ignoring a direct marketing order
Section 5(2) as amended from April 1, 2025, and section 43(4). Source: Act 709 and Skrine, October 2026

What changed in 2025

The Personal Data Protection (Amendment) Act 2024 came into force in three stages, as Skrine set out from the Minister's gazette notice:

  • January 1, 2025. Provisions that added no new obligations for data controllers.
  • April 1, 2025. "Data user" became "data controller", biometric data became sensitive data, the security principle and its penalties were extended to data processors, the maximum penalty for breaching the data protection principles rose to RM1,000,000 and three years from RM300,000 and two years, and the whitelist regime for cross-border transfers was removed.
  • June 1, 2025. Mandatory data protection officers, breach notification to the Commissioner and to affected individuals, and a new right to data portability.

For an outbound team, the April change is the one that matters: a list built and mailed without a lawful basis or notice now carries more than three times the old maximum fine.

The coming anti-spam rule: section 233A

The Communications and Multimedia (Amendment) Act 2025 inserted a new section 233A into the Communications and Multimedia Act 1998 prohibiting unsolicited commercial electronic messages. Most of that amending Act took effect in February 2025, but section 233A was not yet in operation, and legal updates describe the planned subsidiary legislation as what will make it workable. On August 13, 2025 the Malaysian Communications and Multimedia Commission published a consultation paper on those rules, with a deadline later extended to September 8, 2025. According to DLA Piper's summary and a July 2026 legal update, the proposals would require the recipient's express or implied consent, with implied consent only where there is an established relationship, recorded consent, and a clear, free unsubscribe in every message; they would cover email, SMS, WhatsApp, Telegram and social media messages; and they would restrict address-harvesting and scraping tools. We found no commencement notice when we checked. If the rules are made as proposed, Malaysia would add a consent rule for marketing messages, express or implied within an existing relationship, to its data protection regime, and scraped lists would lose whatever grey area they have today.

What a compliant first email to Malaysia contains

  1. Your company's name, address and a way to contact you.
  2. Why you are writing to this person and where you found the address, which covers the source element of the section 7 notice.
  3. What you will use their data for, and that they can ask to access, correct or stop its use.
  4. A one-click opt-out that you honour immediately, and treat any written reply asking you to stop as a section 43 notice.
  5. A question rather than a sequence: ask whether they want more information, and only continue on a yes.

Record what you sent and any reply: under the 2013 regulations the Commissioner's inspectors can ask to see the consent records a data controller keeps. If you buy a list, ask the seller how each contact consented to being shared; our guide to buying email lists explains why most cannot answer.

How Malaysia compares with its neighbours

Singapore pairs its own PDPA with a Spam Control Act for bulk email, and Indonesia, Thailand and the Philippines each have comprehensive data protection laws with different consent rules; compare them in our guides to Singapore, Indonesia, Thailand and the Philippines, or in the cold email laws by country table.

Checklist for emailing Malaysia

  • Treat named work emails as personal data in a commercial transaction.
  • Have a lawful basis: consent, or one of the section 6 exceptions; there is no legitimate interests fallback.
  • Give a written notice covering purpose, source and rights in the first contact.
  • Honour every request to stop direct marketing at once, across every tool.
  • Do not scrape or buy lists you cannot trace to consent, and expect section 233A to make that explicit.
  • Appoint a data protection officer and document breach handling if you are established in Malaysia.
  • Send from authenticated domains with a visible unsubscribe, through sending infrastructure kept separate from your main domain.

Emailing prospects in Malaysia and Southeast Asia?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

As far as we could find, no anti-spam rule for email is in operation yet, but the Personal Data Protection Act 2010 applies to named B2B contacts. It requires consent to process personal data in commercial transactions, a written notice of purpose, source and rights, and it lets anyone stop direct marketing at any time under section 43.

On a strict reading, yes. Section 6 bars processing personal data without consent unless an exception such as performing a contract applies, and the Act has no general legitimate interests basis. A practical approach is to keep data minimal, include a notice and an instant opt-out in the first email, and ask for consent before any sequence.

Since April 1, 2025, breaching the data protection principles carries a fine of up to RM1,000,000, up to three years in prison, or both, up from RM300,000 and two years. Failing to comply with the Commissioner's order to stop direct marketing carries up to RM200,000, up to two years, or both.

Section 233A of the Communications and Multimedia Act 1998, inserted in 2025, prohibits unsolicited commercial electronic messages, but it needs subsidiary rules to operate. The MCMC consulted on those rules from August 13, 2025, proposing recorded express or implied consent and a free unsubscribe, and we found no commencement notice as of October 2026.

It applies to persons established in Malaysia and to persons not established there who use equipment in Malaysia to process the data other than for transit, who must also nominate a local representative. A sender with no Malaysian presence or equipment may sit outside it, but the coming anti-spam rule may reach further, depending on the rules that implement it.

In stages through 2025: data users became data controllers, biometric data became sensitive, processors gained security duties, penalties rose to RM1 million and three years, the cross-border whitelist was removed, and from June 1, 2025 data protection officers, breach notification and data portability became mandatory.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us