This article first appeared in Digital Edge, The Edge Malaysia Weekly on June 9, 2025 - June 15, 2025
Much of the data processed by government agencies remain trapped in silos, limiting its value for shared policymaking, service delivery and crisis response. The Data Sharing Act 2025 (DSA), which came into force on April 28, seeks to introduce a formal legal framework for public sector agencies to share data with each other, through a data sharing process that aims to be structured, transparent and safe.
Prior to the DSA, there was a lack of unified legal and procedural framework governing how public sector agencies in Malaysia shared data. Ministries and agencies often operated in silos, relying on ad hoc arrangements. Compounding the issue, the Personal Data Protection Act 2010 — which seeks to ensure that personal data of individuals are adequately protected — expressly excluded the federal and state governments from its scope. As a result, public sector data practices, including those relating to personal data, were largely unregulated.
It is worth noting that the new framework under the DSA applies to data sharing among federal public sector agencies and statutory bodies established under federal law only. It does not extend to state governments or local authorities. In practice, this means that only data in the hands of federal public sector agencies or federal statutory bodies will benefit from the DSA.
The DSA adopts a broad definition of “data”, covering any facts, statistics, instructions or information that can be communicated or processed, whether by humans or machines. Open data is excluded, however, under the DSA. Such publicly available datasets from public sector agencies may continue to be accessed and used without a formal request under the DSA. This exclusion supports innovation, research and civic initiatives by ensuring continued access to non-sensitive public datasets.
The DSA enables data sharing for five core purposes:
● Improving public service delivery and policy outcomes;
● Responding to emergencies or threats to public safety;
● Protecting life, health or welfare;
● Acting in the public interest; and
● Other purposes as determined by the National Data Sharing Committee.
Having said that, data sharing between public sector agencies is not automatic. Requests must first be issued by one public sector agency to another; such requests must also be specific to a purpose of use and be transparent on the data recipients, including any third parties hired to assist with data migration, data integration or data analytics (third parties) and the manner in which data to be shared is handled.
Upon an evaluation — taking into account whether the data sharing is warranted, whether it goes against public interest and whether the data requester has in place appropriate security and technical safeguards to ensure unauthorised access or use — public sector agencies receiving data sharing requests may refuse these requests on grounds such as national security, breach of legal privilege, breach of contract or inadequate safeguards to protect from unauthorised use or access.
Importantly, however, a public sector agency recipient of shared data is obligated to take necessary measures to ensure the security and privacy of the data (including protecting data from any loss, misuse and unauthorised or accidental disclosure and preserving the rights of individuals relating to personal data protection).
Save in limited circumstances, any subsequent disclosure of the shared data by any officer or servant of the data recipient — other than for the original purpose for which it was shared — is also prohibited, at risk of fines up to RM1 million and/or an imprisonment for up to five years.
In keeping with the theme that the shared data should be kept confidential and secure, the DSA also extends such an obligation to third parties — whose engagement must also be consented to by the federal public agency disclosing the data — receiving the shared data.
The implementation of the DSA will be spearheaded by the National Data Sharing Committee, which is answerable to the cabinet and has been tasked with driving policies and strategies to ensure that data sharing under the DSA complies with, among others, procedures that preserve privacy and confidentiality of data and is undertaken with safeguards on data handling and storage in place.
Operationalisation of these policies and strategies are, in turn, in the hands of the director-general of the National Digital Department, who is expected to issue guidelines on, among others, how data requests can be made by public sector agencies and how responses to such data requests should be conveyed.
At the inaugural meeting of the National Data Sharing Committee on June 3, Digital Minister Gobind Singh Deo outlined a bold vision for embedding data-driven governance in Malaysia’s public sector transformation.
He emphasised that real-time data access (facilitated by the DSA framework) is essential for accelerating public service delivery, improving decision-making and fostering a more responsive and inclusive government.
To support this, Gobind announced the forthcoming Data Digitalisation Policy, which will establish comprehensive standards for data quality governance, data security ethics, the use of storage and processing technologies, and the cultivation of a digital-first culture in public administration. The minister also introduced the Digital Twin initiative, a virtual city simulation model that leverages real-time, multi-sectoral data to enable smarter urban planning, predictive analytics and faster emergency response.
As the World Bank notes in its white paper, “Digital Public Infrastructure and Development: A World Bank Group Approach”, fragmented data systems can lead to inefficiencies, duplication of effort and missed opportunities.
The DSA addresses these challenges by replacing the existing practices with a risk-based framework that reflects the realities of a government seeking to digitalise its functions in its delivery of public service. It empowers federal agencies to collaborate more efficiently, while holding them accountable for how data is used, protected and governed.
For the rakyat and businesses, it is hoped that this will translate into improved public sector productivity, coordination and efficiency and, in turn, an increased level of trust and certainty for doing business in Malaysia.
Ultimately, its success will depend on how well the DSA’s promises are turned into practice.
Serene Kan is a partner and Nicole Shieh is a legal assistant at Wong & Partners, a member firm of Baker McKenzie International
Save by subscribing to us for your print and/or digital copy.
P/S: The Edge is also available on Apple's App Store and Android's Google Play.