Data Centres and the Law: What Every Director Needs to Know Occupational Safety, Construction Risk and the Real Cost of Getting it Wrong

Introduction

Part One of this three-part advisory series, titled “Data Centres and the Law: What Every Director Needs to Know – Occupational Safety, Construction Risk and the Real Cost of Getting it Wrong”, examines the occupational safety and health risks arising from data centre development and operations. It considers the expanded compliance framework under the Occupational Safety and Health Act 1994 (“OSHA“), the strengthened enforcement landscape following the 2024 amendments, and the growing personal liability of directors and senior management. Building on those issues, the upcoming Part Two will unpack the environmental obligations applicable to data centre development and operations in full, while Part Three will cover civil liability arising from neighbouring landowners.

Malaysia’s Data Centre Boom Is Real. So Is the Legal Exposure.

Malaysia is building data centres faster than almost anywhere else in Asia. Currently, 87 data centres are already running in Malaysia.  Between 2021 and June 2025, the federal government approved 143 data centre projects worth RM144.4 billion. Digital investment hit a record RM163.6 billion in 2024 alone, up 55.5% in a single year, with over three-quarters flowing into data centres and cloud infrastructure. Microsoft, Google, AWS, Nvidia and YTL all have operations in Malaysia, alongside newer entrants like China’s Zdata. Johor now accounts for roughly 80% of Malaysia’s live information technology capacity.

But the same reporting that tracks this boom also tracks its cracks. The Business Times has flagged a US$20 billion funding gap as the sector “enters reset mode”. On the ground, real construction sites are already colliding with real communities, real regulators, and real enforcement powers. 

Key Takeaway

  1. Although 143 data centre projects (RM144.4 billion) have been approved, a US$20 billion funding gap and growing community opposition signal the sector cannot outrun its regulatory obligations.

  2. Directors must treat regulatory compliance as a precondition to project delivery, not an afterthought.

Data Centre Hazards and What They Actually Cost You

Data centre construction and operations carry specific hazards, each with a real financial and legal consequence:

Electrical hazards – high-voltage switchgear, uninterrupted power supply (“UPS“) systems and backup power at industrial scale. A failure means extended downtime and service level agreement penalty payments.

Cooling system risks – ammonia and glycol-based coolants, compounded by liquid/immersion cooling for artificial intelligence-dense racks. A leak means clean-up costs and third-party claims. 

Confined space entry – ductwork, cooling plant rooms, under-floor plenums. An incident brings Department of Occupational Safety and Health (“DOSH“) prosecution and site shutdown. 

Fire suppression hazards – clean-agent gas systems posing asphyxiation and pressure-release risks. A discharge event means lost revenue plus injury claims. 

Noise exposure – from UPS units and industrial-scale cooling plant. Breaches invite compensation claims and enforcement action.

These are not hypothetical. In September 2024, a lithium-ion battery fire at Digital Realty’s SIN11 facility in Singapore took over 36 hours to control, required four water jets and building evacuation. In Hong Kong, an engineer was hospitalised after an explosion during cooling-system maintenance at a SUNeVision facility. These are the exact loss categories Malaysian regulators expect operators to control.

Key Takeaway

  1. Every hazard above is a prosecutable exposure under the amended Occupational Safety and Health 1994 (“OSHA“).

  2. Regional incidents (Singapore, Hong Kong) confirm these are not hypothetical – they are the asset class’s operating reality.

  3. Audit before you break ground. The cheapest compliance step is the one taken before a regulator arrives.

The Law Just Got Much Tougher: OSHA Before and After 1 June 2024

The Occupational Safety and Health (Amendment) Act 2022, in force since 1 June 2024, fundamentally reshaped the enforcement landscape. The Factories and Machinery Act 1967 has been repealed in its entirety, and OSHA’s scope now extends to every workplace in Malaysia, ending three decades of exemptions for industries outside the First Schedule. DOSH’s powers are broader, penalties are harsher, and personal liability for directors is now explicit. Practitioners tracking enforcement since the amendment took effect describe a decisive shift “from a corrective compliance model towards a deterrence-driven enforcement regime”, with investigations escalating more quickly to prosecution and a greater willingness to pursue directors and senior management personally.

For an industry racing to build capacity against a US$20 billion funding gap and mounting community opposition, that shift matters: the commercial pressure to move fast is now matched by a regulatory apparatus built to catch exactly the shortcuts that speed encourages.

Section 18A: Principal’s Duty to Directed Contractors

Where a company directs not only what work a contractor performs but also how it is performed, the company becomes a “principal” under section 18A of the OSHA and owes a duty, so far as is practicable, to that contractor, its subcontractors, and their employees. Specifying only the outcome of the work – not the method – will not, on its own, trigger section 18A of the OSHA, though sections 17 and 18 of the OSHA may still apply.

For data centre operators, this matters most at the construction and fit-out stage, where main contractors, mechanical and electrical (M&E) subcontractors and specialist cooling or electrical installers are rarely left to work unsupervised. Regulators focus on who had control over the work environment, not on who signed the subcontract – outsourcing the work does not outsource the liability, and the more integrated a contractor is into daily operations, the weaker the argument that responsibility lies elsewhere.

Section 18B(1), OSHA: Mandatory Risk Assessments

Every employer, self-employed person and principal must assess the safety and health risks posed to employees and non-employees alike at the place of work. There is no “so far as is practicable” qualifier – the duty to assess is mandatory, full stop. Each risk assessment must satisfy four requirements:

  1. Documented in writing;

  2. Reviewed when no longer valid, or when significant changes occur at the site;

  3. Conducted by competent persons; and

  4. Covering all operations, activities and work processes at the facility – not a sample.

Section 18B(2), OSHA: Implementing Control Measures

Where a risk assessment shows that risk control is needed, section 18B(2) of the OSHA requires employers, self-employed persons and principals to implement controls. This must be done in the following mandatory hierarchy, not in whatever order is cheapest or fastest:

  1. Elimination: Remove the hazard entirely.

  2. Substitution: Replace with a less hazardous alternative.

  3. Engineering controls: Isolate people from the hazard.

  4. Administrative controls: Change the way people work.

  5. Protective Personal Equipment (“PPE“): Protect the worker with PPE (last resort only).

As with subsection (1), there is no “practicable” qualifier on this duty to implement. A documented risk assessment that identifies a hazard but stops short of implementing the indicated control is not compliance – it is evidence of a known, unaddressed risk.

Provision
Before (pre-1 June 2024)
After (post-1 June 2024)
Director Liability
Scope of OSHALimited to industries listed in the First ScheduleAll workplaces in Malaysia – no exceptions
-
General duty of care (section 15)RM50,000.00Fine up to RM500,000.00; imprisonment up to two yearsYes
Fine up to RM50,000.00; imprisonment up to five yearsFine up to RM500,000.00; imprisonment up to two yearsFine up to RM500,000.00; imprisonment up to two yearsYes
Director/officer personal liabilityLimitedExplicit: jointly and severally liable under section 52-
Mandatory risk assessment (section 18B)No equivalent provisionAbsolute, unqualified statutory duty on every employerYes
Principal's duty to directed contractors (section 18A)No equivalent provisionFine up to RM500,000; imprisonment up to two yearsYes
Safety and Health Coordinator (section 29A)No equivalent provisionFine up to RM50,000; imprisonment up to six monthsYes
Certificate of Fitness for plant/machineryGoverned under Factories and Machinery Act 1967Fine up to RM500,000; imprisonment up to two years (Occupational Safety and Health (Plant Requiring Certificate of Fitness) Regulations 2024)Yes

Key Takeaway

  1. Every data centre workplace is now within OSHA’s scope – no exceptions.

  2. Maximum fines have increased tenfold (RM50,000.00 → RM500,000.00).

  3. Directors face personal criminal liability under section 52 of the OSHA.

The Critical Distinction: Section 15 vs. Section 18B, OSHA

Section 15 of the OSHA – the general duty of care – is qualified by the words “so far as is practicable”. Under section 51 of the OSHA, an accused employer can defend against a prosecution by proving it was not practicable to do more than was in fact done. That defence turns on the severity of the risk, the state of knowledge, the availability of measures, and the cost of implementation.

Section 18B of the OSHA contains no such qualifier. The duty is expressed in absolute, unqualified terms. Either a proper risk assessment was conducted – and, where indicated, risk controls were implemented – or it was not. There is no equivalent escape route.

What this Means for Directors

Under section 15 of the OSHA, a company can defend against a prosecution by showing it did everything reasonably practicable. Under section 18B of the OSHA, DOSH need only show that no adequate risk assessment was conducted, or that indicated risk controls were not implemented. The burden is procedurally simpler for the regulator and materially harder for the accused to establish its defence.

As section 18B of the OSHA is easier to prove – a documentary check rather than a fact-intensive practicability assessment. It is increasingly attractive to regulators as a preferred or additional charge alongside section 15 of the OSHA. This sharpens prosecution risk for every board that has not documented a proper risk assessment process.

The Board of Directors’ Obligations

When a body corporate is convicted of an offence under the OSHA, every director, manager, secretary or similar officer is deemed to have committed the same offence – a rebuttable presumption of guilt. The burden shifts to the accused officer to prove, on the balance of probabilities, that the offence was committed without their consent or connivance, and that they exercised all due diligence to prevent it. Both limbs must be satisfied; proving one without the other is not enough.  Regulators pursue this personal route deliberately: a corporate fine alone can be absorbed as a cost of doing business, while personal exposure focuses minds on prevention rather than remediation.

Because section 52 of the OSHA puts the burden of proof on the director, not the regulator, the only workable defence is one built before an incident – not after. A documented, regularly updated risk assessment covering electrical, cooling, confined space, fire suppression and noise hazards is the primary evidence a director needs to discharge the due diligence limb of that defence; without it, section 52 of the OSHA leaves nowhere to stand.

Boards must ensure a documented, regularly updated risk assessment is in place for every data centre site – covering electrical, cooling, confined-space, fire-suppression, and noise hazards –because the absence of such a document is now, on its own, a prosecutable offence.

Preview: Parallel Exposure under Environmental Law

Data centres carry a parallel layer of exposure under Malaysia’s environmental laws, where strict liability and personal officer liability apply in much the same way as under the OSHA. Part Two of this series addresses that regime in full.

This article is for general information only and does not constitute legal advice. For specific guidance on data centre regulatory compliance in Malaysia, please contact our team set out on this page.

For regional data and digital economy matters, please see Rajah & Tann Asia’s Regional Data & Digital Economy Practice for more information.

Contribution Note

Written by Partner Shannon Rajan of Christopher & Lee Ong.


 

Disclaimer

Rajah & Tann Asia is a network of member firms with local legal practices in Cambodia, Indonesia, Lao PDR, Malaysia, Myanmar, the Philippines, Singapore, Thailand and Vietnam. Our Asian network also includes our regional office in China as well as regional desks focused on Brunei, Japan and South Asia. Member firms are independently constituted and regulated in accordance with relevant local requirements.

The contents of this publication are owned by Rajah & Tann Asia together with each of its member firms and are subject to all relevant protection (including but not limited to copyright protection) under the laws of each of the countries where the member firm operates and, through international treaties, other countries. No part of this publication may be reproduced, licensed, sold, published, transmitted, modified, adapted, publicly displayed, broadcast (including storage in any medium by electronic means whether or not transiently for any purpose save as permitted herein) without the prior written permission of Rajah & Tann Asia or its respective member firms.

Please note also that whilst the information in this publication is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as legal advice or a substitute for specific professional advice for any particular course of action as such information may not suit your specific business and operational requirements. You should seek legal advice for your specific situation. In addition, the information in this publication does not create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on the information in this publication.

CONTACTS

Malaysia,
+603 2267 2626
+601 6311 9187
Malaysia,
+60 3 2273 1919
+60 3 2267 2664
Malaysia,
+60 3 2273 1919
+60 3 2267 2732
Malaysia,
+603 2273 1919
+603 2267 2616
Malaysia,
+603 2267 2626
+601 2377 7792
Malaysia,
+60 3 2273 1919
+60 3 2267 2665
Malaysia,
+60 3 2273 1919
Malaysia,
+601 7362 3459
+603 2267 2669

Country

Share