Cloud and Data Centres
Malaysia is positioning itself as a leading Southeast Asian hub for cloud services and data centre. This ambition is supported by strong digital‑economy policies, a rapidly growing pipeline of hyperscale and colocation projects, and increasingly coordinated regulation around planning, sustainability and data protection.
Recent measures such as the Regional Framework on Cross‑Border Cloud Computing led by Malaysia at ASEAN level, the National Cloud Computing Policy, new data‑centre planning guidelines, sustainable development guidance and a forthcoming Data Centre Framework demonstrate a shift from ad‑hoc approvals to a more strategic, centralised and sustainability‑aligned regime.
Malaysia has emerged as one of Southeast Asia’s fastest‑growing data‑centre markets, with the sector’s valuation projected to reach USD 13.57 billion by 2030, reflecting strong demand for digital infrastructure.
Driven by a pro-investment climate and government-led digital initiatives, Malaysia offers a stable and transparent landscape for global investors seeking to establish or expand regional cloud and data-centre operations.
Definition of Personal Data
Personal Data is defined under the PDPA as any information in respect of commercial transactions that relates directly or indirectly to a data subject/individual, who is identified or identifiable from the information or from that and other information in the possession of a data controller (previously referred to as “data user”, including any sensitive personal data and expression of opinion about the data subject/individual.
Market Overview
Malaysia’s digital landscape is defined by high-velocity growth and institutional support. Between 2021 and mid‑2025, the Malaysian Investment Development Authority (“MIDA”) approved RM144.4 billion in data centre and cloud computing investments. This momentum is part of a broader surge that saw Malaysia record a total of RM 163.6 billion in digital investments in 2024 alone, accounting for more than 75% of the country’s total digital capital inflows for that year.
The vast majority of this capital originates from global hyperscale cloud providers establishing regional infrastructure in Malaysia. These investments are supported by the Digital Ecosystem Acceleration (“DESAC”) programme, administered by MIDA.Under DESAC, qualifying projects may benefit from a range of fiscal incentives, including investment tax allowances of up to 100% on qualifying capital expenditure for certain projects.
Malaysia’s strong investor appeal is further reflected in its top ranking in Knight Frank’s SEA-5 Data Centre Opportunity Index for both 2023 and 2024, supported by approximately USD23.3 billion in announced hyperscale investments.
These developments underscore Malaysia’s growing position as a leading regional hub for hyperscale data centre and cloud infrastructure investment.
Government policies relevant to cloud and data centres
Malaysia Digital Economy Blueprint (MyDIGITAL)
MyDIGITAL serves as the primary roadmap for Malaysia’s digital transformation. It is implemented through the Malaysia Digital initiative, which replaced the Multimedia Super Corridor programme. Under this framework, companies undertaking qualifying digital activities, including cloud services and data centre operations, may obtain Malaysia Digital (“MD”) status and benefit from a range of facilitation measures and incentives.
As Malaysia enters Phase 3 (2026-2030), policy priorities have shifted from basic digital connectivity towards “Industrial Empowerment” and the development of high-value digital industries. Key targets include the development of high quality and affordable nationwide digital infrastructure, migration of 80% of public data to hybrid or public cloud solutions, and positioning Malaysia as the “Heart of Digital ASEAN” through initiatives that include data centre and cloud investments.
Malaysia Digital is supported by an updated set of Bills of Guarantee which provide investors with assurances such relating to matters such as world class infrastructure, protection of intellectual property, and facilitation for foreign knowledge workers. These guarantees are intended to strengthen investor confidence and make Malaysia an attractive platform for inbound digital infrastructure investment.
National Cloud Computing Policy (“NCCP”)
The NCCP, released by the Ministry of Digital, is a dedicated policy framework aimed at accelerating cloud adoption and anchor Malaysia as a world class cloud hub by 2030. The policy promotes a cloud first approach in the public sector, while also encouraging wider adoption of cloud services across strategic industries such as financial services, healthcare and manufacturing.
The NCCP emphasises the importance of secure, resilient and sustainable cloud infrastructure, and is aligned with broader national strategies including the Malaysia Cyber Security Strategy and MyDIGITAL.
The NCCP identifies several categories of cloud stacks including government cloud, industry cloud and innovation cloud, and emphasises interoperability, cross border data connectivity, and alignment with international standards as preconditions for investor confidence and regional integration.
For foreign investors and multinational cloud customers, the NCCP signals policy continuity and a preference for providers that demonstrate robust security, compliance with data protection standards and strong ESG credentials.
ASEAN Regional Framework on Cross Border Cloud Computing
At the regional level, Malaysia has taken a leadership role in shaping cross-border cloud governance within ASEAN. In early 2026, ASEAN endorsed the Regional Framework on Cross Border Cloud Computing, a Malaysian-led initiative adopted at the 6th ASEAN Digital Ministers’ Meeting.
The framework establishes common principles for cloud data governance across ASEAN, including safeguards for data at rest and in transit, clearer rules on regulatory access, and the concept of “Trusted Data Corridors”. This initiative allows for seamless, secure data transfers between ASEAN countries. It reduces the legal “red tape” usually required for cross-border data flows, lowering compliance costs significantly.
According to the Ministry of Digital and Malaysia Digital Economy Corporation (“MDEC”), the framework is intended to reduce regulatory fragmentation across ASEAN, harmonise rules for cloud adoption (including in regulated sectors such as financial services and healthcare), and reinforce Malaysia’s role as a regional hub for cloud and AI.
For multinational groups operating across the region, this initiative should progressively ease compliance frictions when architecting multi jurisdictional cloud solutions that include Malaysian data centres or regions.
Investment Incentives
Malaysia Digital status and related incentives
Malaysia Digital status is the main investment-promotion vehicle for digital‑economy projects, including data centres and cloud services.
Companies granted MD status may be eligible for a range of incentives and facilitation measures, including:
- tax holidays, investment tax allowances;
- import‑duty exemptions on qualifying ICT equipment;
- facilitation of foreign knowledge workers;
- expedited regulatory approvals; and
- other non‑fiscal support such as fast‑track approvals and infrastructure facilitation, subject to meeting activity and performance criteria.
Many large-scale data-centre investments approved since 2021 have been granted MD status under DESAC, with commitments in the tens of billions of ringgit and a strong skew towards foreign direct investment.
For investors, MD status also functions as a signal of government backing, which can be helpful when negotiating land, utilities and local‑authority approvals that are critical for large‑scale facilities.
Digital Ecosystem Acceleration Scheme (DESAC)
The Digital Ecosystem Acceleration Scheme (DESAC) is a targeted incentive scheme designed to catalyse investments in digital infrastructure, including data centres.
As of early 2025, 21 data-centre projects had been approved under DESAC attracting around RM113.8 billion in investment, of which about 90% came from foreign investors.
In Parliament, the Deputy Investment, Trade and Industry Minister reported that 25 data‑centre projects with Malaysia Digital status and incentives under DESAC involved RM144.4 billion of investments and were expected to create over 1,400 jobs between 2021 and mid‑2025.
Future DESAC‑type incentives are increasingly being tied to sustainability conditions, with the forthcoming sustainable data‑centre framework and MITI guidelines expected to make metrics such as Power Usage Effectiveness (PUE), Water Usage Effectiveness (WUE) and Carbon Usage Effectiveness (CUE) part of eligibility criteria for new incentives.
Overview of key government agencies and coordination mechanisms
Principal agencies for investors
Navigating Malaysia’s data centre and cloud sector requires engagement with a range of federal agencies, each with a distinct but overlapping remit. Understanding who does what – and who to approach first – is essential for investors planning market entry or expansion:
- Malaysian Investment Development Authority (MIDA) is the natural starting point. As the government’s principal investment promotion and approval agency, it has been designated the single focal point for all new and expansion data centre investment applications. Investors should expect MIDA to coordinate engagement with other agencies, significantly reducing (but not completely eliminating) the need to manage all those relationships independently.
- Ministry of Investment, Trade and Industry (MITI) sets the overarching economic and industrial policy framework, including the sustainable data centre development guidelines that will govern eligibility for future incentives. Its role has become more prominent as sustainability conditions are embedded into the investment approval process.
- Ministry of Digital and Malaysia Digital Economy Corporation (MDEC) are responsible for digital economy policy, Malaysia Digital status and the DESAC incentive scheme, as well as Malaysia’s engagement at ASEAN level on cross-border cloud governance. For investors seeking MD status or DESAC benefits, MDEC is the key operational counterpart.
- Malaysian Communications and Multimedia Commission (MCMC) is the communications and multimedia regulator. Its licensing role is directly relevant to cloud service providers. Since 2022, public cloud providers (particularly IaaS and PaaS) have been required to register under the Application Service Provider Class licence. MCMC also oversees technical standards for data security and green data centre specifications through the Malaysian Technical Standards Forum (MTSFB).
- Department of Personal Data Protection (PDPD) administers the Personal Data Protection Act 2010 and its 2024 amendments, which now impose direct obligations on data processors including cloud providers and data centre operators.
- Bank Negara Malaysia (BNM) and Securities Commission (SC) are relevant where cloud or data centre services are provided to regulated financial institutions. BNM’s Risk Management in Technology (RMiT) policy and the SC’s outsourcing guidance impose detailed requirements on how financial institutions govern their cloud arrangements, which flow contractually to service providers. These are addressed in more detail below.
- PLANMalaysia and local authorities, operating under the Ministry of Housing and Local Government (KPKT), administer the Data Centre Planning Guidelines (GPP) approved in October 2024. These guidelines govern zoning, capacity thresholds and environmental mitigation requirements, and are increasingly applied by local authorities when evaluating planning applications.
- The Energy Commission (ST) and the National Water Services Commission (SPAN) have taken on a more active role in data centre approvals given the sector’s intensive power and water demands. Grid capacity constraints — particularly in Johor – and water resource concerns mean that early engagement with both regulators on utility availability and efficiency commitments is now a practical necessity for large-scale projects.
Data Centre Task Force (DCTF) and Data Centre Framework
The multiplicity of agencies involved in data centre approvals has historically created complexity for investors. To address this, the government established the Data Centre Task Force (DCTF) in February 2025 as a dedicated multi-agency coordination platform.
The DCTF is co-chaired at ministerial level by MITI and the Ministry of Digital, and brings together MIDA, MDEC, the Energy Commission, SPAN, MCMC and relevant state authorities. Its mandate covers policy formulation, inter-agency coordination, and monitoring of the sector’s development – with a particular focus on aligning investment approvals with infrastructure planning and sustainability objectives.
Under the structure that the DCTF has put in place, MIDA acts as the central agency for approving new projects and expansions, providing investors with a more structured single-window experience, while the DCTF provides the cross-governmental endorsement and coordination behind that process.
A key deliverable of the DCTF is the Sustainable Data Centre Framework, led by the Ministry of Digital. The framework was originally targeted for launch in October 2025, but as of early 2026 has not yet been formally released, with the DCTF reported to be continuing to refine the guidelines in light of ongoing sector growth. When finalised, the framework is expected to set out policies on new projects and expansions, investment eligibility criteria, certification standards, and sustainability requirements – including metrics such as PUE, WUE and renewable energy targets. Critically, these sustainability benchmarks are expected to be integrated with DESAC, making ESG performance a gatekeeper for incentive eligibility going forward.
For foreign investors, the practical implication is twofold:
- The DCTF structure offers a more predictable approval pathway than the fragmented agency landscape that preceded it.
- At the same time, investors should anticipate increasingly coordinated and substantive scrutiny – across energy, water, planning and sustainability dimensions – as the framework matures. Projects that can demonstrate strong environmental credentials and alignment with national digital economy goals from the outset will be better positioned both to secure approvals and to access the incentive stack.
Legal and regulatory framework for cloud and data centres
Cloud Service Provider Licensing Framework under the Communications and Multimedia Act 1998 (CMA)
Cloud and data centre activities intersect with the CMA where they involve the provision of “cloud services” to end-users in Malaysia.
Since 2022, MCMC has extended the Applications Service Provider Class (ASP(C)) licence, issued under the CMA and the Communications and Multimedia (Licensing) Regulations 2000, to cloud service providers — defined broadly as providers of any service made available to end-users on demand via the internet from a cloud computing provider’s server. The regime is deliberately light-touch, designed to maintain easy market access while establishing baseline obligations around security, reliability and consumer protection. Notably, the ASP(C) carries no foreign shareholding restrictions.
The licensing requirement applies primarily to IaaS and PaaS providers. The following activities are licensable:
- A locally incorporated company providing PaaS or IaaS directly to users in Malaysia.
- A locally incorporated company providing PaaS or IaaS for resale by an agent to users in Malaysia.
- A local data centre assisting a foreign CSP in delivering PaaS or IaaS to users in Malaysia – in this case, the local data centre entity is treated as the licensee, not the foreign CSP.
- Existing ASP(C) licensees that begin offering cloud services must update their registered activities to include cloud services at annual re-registration.
The following are explicitly outside the licensing requirement:
- Pure SaaS providers that do not control the underlying cloud infrastructure or platform.
- Resellers or agents of a licensed PaaS/IaaS provider that do not take control of the cloud service product.
- Foreign CSPs with no local presence and no use of local data centres, serving Malaysian users purely from overseas.
- Local branches (as opposed to locally incorporated entities) of foreign CSPs.
Once registered, licensees must comply with standard CMA duties, including:
- taking all reasonable steps to ensure the security, integrity, reliability and quality of their facilities and services.
- compliance with MCMC directions issued under section 51 CMA and general licensee duties under section 263 CMA.
- compliance with applicable codes of practice, information submission requirements, and any additional conditions the Communications Minister may impose.
Operating without the requisite licence is an offence under section 126 of the CMA, carrying a maximum penalty of RM 1 million and/or 10 years’ imprisonment. A continuing offence attracts a further daily penalty, increased from RM 1,000 to RM 100,000 for each day or part of a day the offence continues after conviction.
Investors planning to establish Malaysian regions, availability zones or local data centre facilities that will underpin foreign CSPs’ service delivery should treat ASP(C) registration as an early operational priority, and monitor any future MCMC technical standards on data security, privacy and cross-border flows as these develop.
Beyond the ASP(C) licence, data centre operators should be aware that other CMA licences may be triggered depending on the scope of their activities.
A Network Facilities Provider (“NFP”) licence is required for entities that own or provide network facilities such as cables, towers, satellite earth stations, broadband fibre optic cables and radiocommunications transmission equipment.
A Network Services Provider (“NSP”) licence is required for entities providing connectivity and bandwidth services that enable connectivity or transport between different networks.
Foreign equity restrictions apply to individual licences: for NSP(I) and NFP(I) licences, foreign entities may hold up to 49% of equity, with at least 51% required to be held by Malaysians (of which at least 30% must be held by Bumiputeras). No foreign shareholding restrictions apply to class licences, including the ASP(C).
Separately, operators should note that under the CMA and the Communications and Multimedia (Technical Standards) Regulations 2000, all communications equipment must be certified by the Standards and Industrial Research Institute of Malaysia (“SIRIM”) before use or sale.
Where spectrum or frequency bands are utilised, spectrum assessment and appropriate apparatus or class assignment under the CMA and the Communications and Multimedia (Spectrum) Regulations 2000 will be required. It is also relevant to note that certain activities may qualify for exemption from CMA licensing – for example, the Communications and Multimedia (Licensing) (Exemption) Order 2000 exempts web hosting and client-server maintenance activities, which may be relevant for operators whose activities do not extend beyond hosting customer equipment.
Personal Data Protection Act 2010 (“PDPA”)
The PDPA, with amendments introduced in 2024, is the principal legislation that governs the processing of personal data in commercial transactions in Malaysia.
For cloud and data centre operators, the key structural point is that the PDPA, like many modern data protection regime, distinguishes between:
- data controllers – entities that determine the purposes and means of processing, and
- data processors – entities that process data on behalf of controllers.
Cloud service providers and data centre operators will in most cases be characterised as data processors, which carries a more limited set of direct statutory obligations than those imposed on data controllers.
The principal duties on data processors are to:
- implement appropriate security measures in compliance with the Security Principle under the PDPA and the minimum security standards as may be imposed by the Personal Data Protection Commissoiner from time to time, as well as process personal data only on documented instructions from the controller; and
- appoint a Data Protection Officer (DPO) and register with the PDPD where they process more than 20,000 personal datasets, 10,000 sensitive personal datasets, or conduct regular and systematic monitoring of personal data.
For cloud and data centre operators, these obligations have direct operational implications. Security measures must be built into service design, processing activities must be governed by documented instructions (typically reflected in data processing agreements), and larger operators will need to assess whether the DPO threshold is met across their Malaysian operations.
The PDPA does not impose blanket data localisation or data sovereignty requirements on the private sector. However, data controllers transferring personal data out of Malaysia must comply with the cross-border transfer conditions under section 129 of the PDPA and the Cross-Border Personal Data Transfers Guideline issued by the Personal Data Protection Commissioner. This includes ensuring that adequate contractual safeguards are in place so that personal data transferred out of Malaysia receives a level of protection equivalent to that afforded under the PDPA.
Importantly, the obligation to comply with cross-border transfer requirements rests with the data controller, not the data processor. For cloud and data centre operators, this means that where a customer (as data controller) transfers personal data to or through a Malaysian cloud or data centre facility (whether as part of a regional architecture or for processing by a foreign parent or affiliate) it is the customer’s responsibility to ensure the transfer is properly structured.
In practice, however, cloud providers and data centre operators will frequently be asked to support this compliance through appropriate contractual arrangements, data residency options and transparency around where data is stored and processed.
In addition to the above, operators should note a further registration dimension under the PDPA: where a data centre operator holds a licence under the CMA, it will fall within the classes of data users specified under the Personal Data Protection (Class of Data Users) Order 2013, thereby triggering a separate obligation to obtain a certificate of registration under the PDPA as a data controller. Where an operator acts as a data processor, it is subject to a direct obligation under the Security Principle to implement sufficient technical and organisational security measures, including compliance with the Personal Data Protection Standard 2015, and to take reasonable steps to ensure ongoing compliance with those measures.
Sector‑specific requirements and "trickle‑down" obligations
Certain industries impose additional regulatory requirements that may indirectly affect cloud and data centre providers.
For example, Bank Negara Malaysia’s Risk Management in Technology (RMiT) policy regulates cloud outsourcing by financial institutions and requires detailed governance, risk management and audit rights over service providers.
Similarly, Securities Commission guidance governs outsourcing arrangements by capital markets intermediaries.
In practice, these regulatory requirements are often reflected in contractual obligations imposed on cloud and data centre providers, including audit rights, security controls, incident reporting and exit arrangements.
On operational commencement, data centre operators face a further layer of compliance obligations. All businesses operating from a premise in Malaysia must obtain a business premise licence and a signboard licence from the relevant local municipal council, with requirements varying by location and applicable by-laws. Upon commencement of business, the company must register for an income tax reference number with the Inland Revenue Board of Malaysia (“IRB”), and separately register as an employer with the IRB, the Employees Provident Fund (“EPF”), the Social Security Organisation (“SOCSO”) and the Human Resources Development Corporation (“HRD Corp”).
On occupational safety, employers owe general duties under the Occupational Safety and Health Act 1994 (“OSHA”).
Any owner of a steam boiler, pressure vessel or lifting machinery must hold a valid certificate of fitness under the Occupational Safety and Health (Plant Requiring Certificate of Fitness) Regulations 2024. Diesel and other controlled fuels stored on site require a permit under the Control of Supplies Regulations 1974. DOSH machine registration is a standard operational step required before commissioning.
On environmental and energy matters, operational activities that exceed permitted thresholds under the Environmental Quality Act 1974 (“EQA”) (including clean air emissions, noise, industrial effluents, scheduled wastes and sewage) trigger licensing obligations administered by the Department of Environment (“DOE”). Data centres’ high electricity consumption also engages the Efficient Management of Electrical Energy Regulations 2008: where consumption exceeds 3,000,000 kWh over any consecutive six-month period, the Energy Commission may require the appointment of a registered electrical energy manager and periodic submission of energy management reports. Where on-site generation or high-voltage installations are used, private or public installation licensing or registration with the Energy Commission may apply.
Any solar generation deployed under net energy metering (“NEM”) schemes requires approval from the Sustainable Energy Development Authority (“SEDA”), following which the operator must enter into a NEM contract in the form prescribed by SEDA.
On cybersecurity, the Cyber Security Act 2024 (“CSA”) establishes a designation regime for National Critical Information Infrastructure (“NCII”) entities. A data centre operator will only be subject to the NCII obligations under the CSA – which include binding codes of practice covering cybersecurity audits, risk assessments, incident notification and cyber exercises – if it receives a formal notification of designation as an NCII Entity. Absent such designation, the NCII-specific obligations do not apply. Separately, the CSA establishes a licensing regime for prescribed cybersecurity services: operators providing managed security operation centre monitoring services or penetration testing services must obtain a licence under the CSA, irrespective of whether they have been designated as an NCII Entity.
Data Sovereignty and Government Data
Malaysia currently does not impose general data localisation requirements for private sector data. However, certain sector-specific regulations and government policies favour domestic infrastructure for sensitive workloads, particularly in the financial and public sectors.
The Malaysian government has also indicated plans to establish a dedicated national data centre facility for government data, reflecting increasing policy emphasis on data sovereignty and national digital infrastructure.
For foreign investors, this means that while regional cloud architectures remain permissible, regulators will expect clear transparency regarding data storage locations, cross-border access and security safeguards.
Land, water and energy considerations
For foreign investors establishing data centres in Malaysia, the initial development phase centres on three key considerations: land tenure, planning approvals, and reliable access to utilities.
Land Tenure and Zoning
Land tenure and zoning are primarily governed by the National Land Code 1965. Most data centres are developed on industrial land, typically through long-term leasehold titles or registered lease arrangements. Under Malaysian law, leases exceeding three (3) years must be registered on the land title, which provides indefeasible rights and long-term security – an important consideration for project financing. Leases may run for up to 99 years for an entire land parcel, while leases for part of a property (such as a specific building footprint) are generally limited to thirty (30) years. Where land is not already zoned for industrial or commercial use, a change of land use category must be approved by the State Authority, usually with payment of a conversion premium.
In undertaking pre-acquisition diligence, investors should also have regard to the site selection criteria set out in the Planning Guideline. A suitable site should be accessible and in proximity to main infrastructure and utility services, and must be situated outside zones prone to natural disasters and outside environmentally sensitive areas (“ESA”), such as coastal areas, water catchment areas, underground water sources and hilly terrain.
Peatlands and sites in proximity to high-risk industrial activities, such as chemical and petroleum complexes, are discouraged. The site should maintain appropriate distance from major highways, railway lines and aviation flight paths, and must comply with height control regulations established by the Civil Aviation Authority of Malaysia (“CAAM”).
Additionally, the required distance from important national security targets as determined by the Office of the Chief Government Security Officer (“CGSO”) must be observed. During the acquisition phase, the data centre operator should also confirm that the land category supports data centre use in either the building or industrial category, that the intended use aligns with express land conditions or can be regularised through State Authority consent, and that the parcel sits within light or medium industrial or commercial use zones as shown in the relevant local plan.
Planning Permission and Local Authority Approvals
From a planning and regulatory perspective, all new data centre developments must comply with Malaysia’s Data Centre Planning Guidelines (“GPP”), as discussed above. Investors must first obtain planning permission from the relevant local authority. Projects with electrical capacity exceeding 1 MVA are subject to stricter planning controls, including buffer zones and setback requirements from residential areas to address noise and heat considerations. Following planning approval, developers must also obtain building plan approval and satisfy technical requirements before the Certificate of Completion and Compliance (CCC) can be issued.
Planning applications are submitted through the OSC 3.0 Plus system, under which developers may concurrently submit planning permission, earthworks, road and drain, and building plans to the local authority. Several approval routes are available. The Medium Category Application (KM Medium Category OSC 3.0 Plus) takes between 57 and 99 days for the official KM C1 document to be issued, and applies to developments that comply with the express land use condition, involve a main switching station of 33kV or 11kV with a maximum capacity of 25 MVA, and submit concurrent plan applications. The Industrial Green Lane (“IGL”) Initiative Application is an encouraged route for developments on industrial land, offering a minimum application period of 29 days, subject to the proposed development having been accepted as an IGL project by the local authority prior to OSC lodgement and the site being ready for construction commencement.
Under the IGL route, Environmental Impact Assessment and Traffic Impact Assessment approvals must be in hand before OSC lodgement. Where a precondition notification letter has been obtained through the OSC 3.0 Online Plus system, the Prerequisite Initiative Application allows the KM C1 to be granted within a minimum of 22 days. Separately, developments in existing CCC-ed buildings that do not require amendments to the original planning permission or building plan may proceed under the Temporary Permit Plan and Small Construction Permit route, with a minimum processing period of 33 days subject to eligibility criteria. For developments in existing buildings, only Small (1–5 MVA) and Medium (above 5 MVA to 25 MVA) category data centres are permitted; all categories are permitted for new-area developments.
A buffer zone of 50 metres from the data centre building boundary to any residential lot boundary is required, unless noise levels do not exceed 5dB above the original ambient level. The CCC is issued by the principal submitting person (i.e. the professional architect, engineer or building draftsman responsible for the submission), with utility companies issuing parallel certifications for power, water, telecommunications and gas connections. DOSH registration of relevant machinery is required before operations commence.
Power Supply and Renewable Energy Options
Reliable power supply is another critical consideration. Data centres are typically classified as ultra-high voltage (UHV) consumers, and their electrical installations must be registered with the Energy Commission (Suruhanjaya Tenaga) under the Electricity Supply Act 1990. Malaysia has also introduced new renewable energy procurement mechanisms. Since January 2026, investors may participate in the Corporate Renewable Energy Supply Scheme (CRESS), which allows large consumers to procure renewable electricity directly from generation companies to meet sustainability and ESG commitments. At the same time, the government has begun prioritising “AI-ready” and energy-efficient facilities in allocating grid capacity, making energy efficiency and green infrastructure increasingly important for project approvals.
The Planning Guideline prescribes specific Main Intake Substation (“MIS”) requirements by scale: small data centres require an 11kV MIS (approximately 7.6m x 5.7m); medium data centres require a 33kV MIS (approximately 30m x 30m); and large or hyperscale data centres require a 132kV or 275kV MIS (approximately 120m x 110m and 190m x 160m respectively).
Proximity to existing transmission lines or MIS facilities is encouraged. Grid capacity confirmation with Tenaga Nasional Berhad should be sought early in the development process. The use of conventional or green energy standby generators with sufficient capacity, as well as renewable energy technologies and energy-saving methods, is encouraged. Efficient electricity use benchmarked against the Power Usage Effectiveness (“PUE”) standard is an express expectation of the Planning Guideline.
On telecommunications infrastructure, the use of fibre optic or dark fibre for internet supply, with at least two (2) service providers providing a minimum internet access speed of 300 Mbps, is encouraged.
Water Supply Considerations
Finally, water supply has emerged as an important factor, particularly in states with significant data centre development such as Johor and Selangor. It may be worth noting that under the Water Services Industry Act 2006, the National Water Services Commission (SPAN) may require a Water Impact Assessment for large data centre facilities. To secure approvals, operators are increasingly expected to incorporate alternative water sources, such as rainwater harvesting systems or recycled industrial water, to reduce dependence on potable water supply.
The Planning Guideline further requires provision of water storage tanks scaled to the data centre’s requirements. Water-saving and renewable water technologies, such as direct expansion and eco-chiller water systems, are encouraged.
Developers are expected to seek advice from relevant state water authorities and SPAN on all applicable water supply requirements at the pre-acquisition stage. Efficient water use benchmarked against WUE standards is an express expectation of the Planning Guideline.
Planning, sustainability and infrastructure guidelines
Data Centre Planning Guidelines (GPP Pusat Data)
In October 2024, the Malaysian Cabinet officially approved the Data Centre Planning Guidelines (“GPP”). Developed by the Ministry of Housing and Local Government (KPKT) through PLANMalaysia, these guidelines standardise the application process across all 156 local authorities.
Key elements reported in government and industry commentary include:
- Capacity threshold – the GPP applies to all data centre developments with a power capacity exceeding 1 MVA. Projects are further categorised into Small (1-5 MVA), Medium (5-100 MVA), and Large/Hyperscale (above 100 MVA) to determine specific regulatory oversight.
- Zoning restrictions – to protect domestic resources, data centres are strictly permitted only within Commercial and Industrial land-use zones. Conversion of residential land for data centre use is generally prohibited.
- Buffer and mitigation – facilities located near residential areas must implement specific noise mitigation measures and maintain defined buffer zones (typically 50m for larger facilities) to minimise environmental impact on local communities.
MITI Guidelines for Sustainable Development of Data Centres
To complement planning reforms, MITI introduced Guidelines for Sustainable Development of Data Centres in late 2024. These guidelines serve as the primary framework for aligning digital growth with Malaysia’s Net-Zero 2050 goal.
The guidelines’ stated objectives include attracting sustainability‑oriented investments, promoting energy‑efficient design and operations, encouraging renewable and clean‑energy use, and improving water‑consumption efficiency in data centres.
Eligibility criteria and expectations typically cover aspects such as minimum energy‑efficiency performance (often expressed in targeted PUE values), water‑efficiency measures (WUE), carbon‑accounting requirements (CUE), green‑building certifications, and commitments to utilise renewable energy sources where available.
As MITI has indicated in Parliament, these sustainable‑development guidelines are being finalised and will become a prerequisite for certain incentive applications, effectively making ESG performance a gatekeeper for future DC incentives.
It is important to note that until 31 December 2027, tax exemption applications received by MIDA under the DESAC scheme will be subject to the conditions in the MITI Guidelines. Developers who wish to qualify for tax exemptions under DESAC are therefore incentivised to prioritise sustainability from the outset. The MITI Guidelines also account for different baselines depending on the category of the data centre, including hyperscale, colocation variants and enterprise private data centres. Developers may additionally consider applying for tax incentives under the Malaysia Digital (“MD”) scheme, which offers either a reduced tax rate or an investment tax allowance to companies undertaking qualifying activities involving promoted technology enablers such as cloud services.
Green‑data‑centre specifications and industry practice
The Malaysian Technical Standards Forum (MTSFB), under the authority of the MCMC, registered a revised “Specification for Green Data Centres” (MCMC MTSFB TC G004:2024) in November 2024.
This technical code aligns Malaysian facilities with international benchmarks (such as ISO/IEC 30134). It covers hardware efficiency, high-efficiency UPS systems, and advanced thermal management.
These standards are already being used as reference models for new “AI-ready” hubs in Cyberjaya and Johor, ensuring that high‑density workloads do not compromise national energy or water security.
Together with MITI’s guidelines and GPP, these standards contribute to a more coherent framework for green data‑centre development in Malaysia.
Outlook and emerging developments
Malaysia’s regulatory landscape is rapidly maturing as it transitions into Phase 3 of its national digital roadmap.
Policy discussions have increasingly focused on the potential for a Digital Infrastructure Act to consolidate disparate rules governing data centres, subsea cables, and cloud services. This proposed legislation is expected to mirror regional benchmarks (such as Singapore’s “Call-for-Application” (DC-CFA) model) by introducing more prescriptive mechanisms for capacity allocation. Investors should anticipate a shift where the right to develop large-scale facilities is tethered to strict performance standards, particularly regarding grid stability and high-value economic contributions. The establishment of the Data Centre Task Force (DCTF) and MIDA’s role as the central approving body are the foundational building blocks for this new, integrated regime.
Despite the selective approach toward new capacity, Malaysia remains a premier destination for digital investment due to its strategic landmass, robust subsea connectivity, and the January 2026 endorsement of the ASEAN Regional Framework on Cross-Border Cloud Computing. This framework is a pivotal development for multinational investors, as it establishes “Trusted Data Corridors” that reduce the legal friction of multi-jurisdictional cloud architectures. For your market-entry strategy, the key differentiator will no longer be mere availability, but the ability to align with the 2025 National Cloud Computing Policy’s emphasis on “Sovereign Cloud” and ESG metrics.
The emerging environment demands that regulatory engagement and technical design be treated as core strategic elements rather than administrative afterthoughts. As Malaysia integrates its Cyber Security Act 2024 obligations with new cross-border data standards, global providers must ensure their operational frameworks are resilient enough to meet the heightened expectations of both sectoral regulators and multinational customers. For the sophisticated investor, this evolving clarity provides a predictable, stable, and highly competitive pathway to capturing the next wave of Southeast Asia’s digital transformation.
Contribution Note
This chapter of the Guide to Doing Business in Malaysia was authored by the Partners listed, with the assistance of Ashley Khor (Associate, Christopher & Lee Ong).
For more information, click here to read more Doing Business Guide.
Disclaimer
Rajah & Tann Asia is a network of member firms with local legal practices in Cambodia, Indonesia, Lao PDR, Malaysia, Myanmar, the Philippines, Singapore, Thailand and Vietnam. Our Asian network also includes our regional office in China as well as regional desks focused on Brunei, Japan and South Asia. Member firms are independently constituted and regulated in accordance with relevant local requirements.
The contents of this publication are owned by Rajah & Tann Asia together with each of its member firms and are subject to all relevant protection (including but not limited to copyright protection) under the laws of each of the countries where the member firm operates and, through international treaties, other countries. No part of this publication may be reproduced, licensed, sold, published, transmitted, modified, adapted, publicly displayed, broadcast (including storage in any medium by electronic means whether or not transiently for any purpose save as permitted herein) without the prior written permission of Rajah & Tann Asia or its respective member firms.
Please note also that whilst the information in this publication is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as legal advice or a substitute for specific professional advice for any particular course of action as such information may not suit your specific business and operational requirements. You should seek legal advice for your specific situation. In addition, the information in this publication does not create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on the information in this publication.