Cybersecurity is the lifeblood of operations - Cybersecurity compliance reminders for Taiwanese businesses setting up factories in Southeast Asia

2025-10-01

35

During the initial establishment phase of Taiwanese businesses setting up factories in Southeast Asia, cybersecurity and data compliance are often overlooked major risks. Different countries have different requirements for data storage, cross-border transfers, and DPOs (Data Protection Officers). Failure to comply can result in fines, shutdowns, and even damage to business reputation. 1. Vietnam: The Cybersecurity Law and Decree 53 require sensitive data to be stored locally and may mandate the establishment of representative offices. 2. Thailand: The PDPA (Personal Data Protection Act) requires the appointment of a DPO for large-scale processing of personal or sensitive data. 3. Indonesia: The PDP Law, effective from 2024, requires the establishment of a DPO for public services or sensitive data processing, and cross-border transfers must comply with protection standards or obtain consent.

During the initial setup phase, the primary challenges for Taiwanese businesses entering Southeast Asia to establish factories are often considered to be "human resources, land, and supply chain." However, the real risks often stem from cybersecurity and data compliance . Many companies mistakenly believe that their parent company's IT policies are sufficient, only to discover once operations have commenced that each country has different regulations. Ignoring these can lead to violations and fines. This article compiles key regulations in Vietnam, Thailand, Malaysia, and Indonesia to help startups identify compliance gaps.


Vietnam: Data localization and representative office requirements

Since 2022, Vietnam has faced pressure from local data policies and regulations, and implemented supplementary provisions of the Cybersecurity Law in Decree 53/2022, requiring that if foreign companies or online service providers collect sensitive data (such as IP addresses, accounts, and contact information) from Vietnamese users, this data must be stored on servers located in Vietnam.

In June 2025, Vietnam passed a new Personal Data Protection Law (PDPL, Law No. 91/2025/QH15), which will take effect in January 2026, strengthening regulations on cross-border data transfer, processing of sensitive and core data, and user rights. Additionally, the Data Law will come into effect in July 2025, expanding regulations to areas such as non-personal data digital data products/services and data intermediaries.

For foreign-invested enterprises, if they continue to rely on overseas cloud bases (such as AWS Singapore) to store user data, or fail to make localized adjustments to data storage, cross-border transmission and other processes, they may be in violation of Vietnam's new regulations.


Thailand: Mandatory Appointment of PDPA and DPO

Thailand's Personal Data Protection Act (PDPA), which came into full effect in June 2022, is the data privacy regulation in Southeast Asia most similar to the EU's GDPR. According to the PDPA, companies must have a legal basis and obtain the consent of the individuals before collecting, processing, or storing personal data. When companies handle large amounts of data, sensitive data, or conduct systematic surveillance, they must appoint a Data Protection Officer (DPO) responsible for overseeing compliance, employee training, and communication with regulatory authorities.

Failure to appoint a Director of Productivity (DPO) or comply with other key regulations can result in administrative fines of up to THB 5,000,000 . There are precedents —one company was fined THB 7,000,000 for failing to appoint a DPO and for data breaches. For startups, these regulations and fines represent potential hidden costs that should not be ignored.


Malaysia: Starting in 2024, companies handling large volumes of data will be required to set up a Data Processing Point (DPO).

Malaysia's PDPA 2010 was amended in 2024 and will take effect in phases starting in 2025. From June 1, 2025 , some companies' data controllers/data processors will be required to appoint at least one data point officer (DPO) .


Triggering conditions include:

  • The company’s main business involves large-scale personal data processing (such as a large number of customers, employees or transaction records).
  • Involves sensitive information (such as health, finances, religion, politics, and criminal records).
  • Or conduct systematic and regular monitoring (such as financial transaction monitoring, employee monitoring).

According to the 2025 DPO appointment guidelines , DPOs should be fluent in Malay and English and, in principle, reside in Malaysia (for more than 180 days per year) or be readily contactable locally to ensure effective interaction with competent authorities and stakeholders.

This means that after foreign companies set up factories in Malaysia, they can no longer rely on the "parent company's legal counsel" to handle matters remotely, but must instead appoint a qualified local DPO.

Failure to comply with PDPA obligations can result in a fine of up to RM1,000,000 and potential criminal charges, posing a significant risk to a company's reputation and operations.


Indonesia: PDP Law and Cross-border Transmission Standards

Indonesia passed the PDP Law in 2022, which came into full effect in 2024. This law, like the GDPR, emphasizes legality, transparency, purpose limitation, and data subject rights.

Indonesia adopts a "conditional mandate" approach to appointing DPOs : companies that are large-scale users of public services, large-scale data processing, or sensitive data (such as health, biometrics, and criminal records) must appoint a DPO.

Furthermore, while Indonesia does not mandate data localization, cross-border data transfers require that the receiving country's data protection level be comparable to Indonesia's; otherwise, the consent of the parties involved or a binding contract is necessary. This poses a significant challenge to multinational ERP/cloud system architectures.


Frequently Asked Questions

Q1: Can my data be stored directly on AWS Singapore?

👉 Standards vary greatly from country to country:

  • Vietnam: Sensitive personal data must be stored locally; cross-border data requires impact assessment and approval from the competent authority.
  • Thailand: Allowed, but the receiving country's protection level must be confirmed, and a transmission agreement must be signed or consent obtained.
  • Malaysia: Prohibited in principle, unless on a whitelist, with consent, or under contractual protection.
  • Indonesia: Feasible, but requires equivalent safeguards or contracts, and must be reported to the competent authorities.

Q2: Is it mandatory for companies to establish a DPO?

👉 Different standards:

  • Vietnam: There is no explicit requirement, but it is necessary to set up a representative office or a designated contact point.
  • Thailand: If large amounts of or sensitive data are handled or surveillance is conducted, a Directorate of Public Security (DPO) must be appointed.
  • Malaysia: Starting from June 1, 2025, companies handling large-scale personal data processing must set up a Data Owner (DPO).
  • Indonesia: DPO is mandatory for public service providers, large-scale or sensitive data processing providers.

Q3: What documents or procedures are required for cross-border data transfer?

👉 Common requirements include:

  • Impact assessment and approval by competent authorities (Vietnam, Indonesia).
  • Cross-border data transfer contracts or standard contract terms (Thailand, Indonesia, Malaysia).
  • Data subject consent form (commonly used in Malaysia, Thailand, and Indonesia);
  • Whitelist system (Malaysia).


[Service Inquiry Form] Let any idea turn into action!



鼎新數智購

5 Followers

鼎新數智在東南亞深耕近二十年,於越南、馬來西亞、泰國為新南向的服務軸心,向外包含印尼、菲律賓、柬…等國提供服務,具備豐富的跨國營運管理知識與在地服務團隊,為製造企業全球化提供數智化解決方案。
知識主題
成立方案

We use our own and third-party cookies for analytics and to show you ads based on your browsing habits and profile. For more information, see our Privacy PolicyPrivacy Policy.