[codicts-css-switcher id=”346″]

Global Law Experts Logo
confidentiality in arbitration malaysia

Our Expert in Malaysia

Confidentiality and Data Protection in Arbitration in Malaysia (2026): What Businesses Need to Know

By Global Law Experts
– posted 2 hours ago

Confidentiality in arbitration Malaysia has become a front-line commercial concern for in-house counsel, dispute lawyers and corporate decision-makers evaluating how to protect sensitive information through 2026, and this guide is written to give them practical, enforcement-focused answers. Arbitration remains attractive precisely because it is private, but privacy is not automatic protection, and recent data-protection developments, including the significant amendments introduced by the Personal Data Protection (Amendment) Act 2024 and guidance from the Department of Personal Data Protection (JPDP), have raised the stakes. Businesses seated in Malaysia, or resolving cross-border disputes here, now need a coherent strategy covering contract drafting, personal data compliance, emergency measures, evidence handling and court enforcement.

This article delivers exactly that: a clear framework, a side-by-side comparison of protective measures, sample clauses, a decision framework and a practical playbook. Read it as a compliance and drafting resource rather than a survey of the law.

Why confidentiality in arbitration Malaysia matters to businesses

Arbitration is a private process, but privacy and confidentiality are not the same thing. Privacy means outsiders cannot attend the hearing; confidentiality means the parties, tribunal and administering institution owe duties not to disclose documents, submissions, evidence and awards. In Malaysia, unlike in some jurisdictions, the Arbitration Act 2005 was amended in 2018 to introduce express confidentiality provisions (sections 41A and 41B), but the scope and exceptions of those duties still depend heavily on what the parties have agreed and what the tribunal directs. Where a dispute reaches the courts, for interim relief, challenge or enforcement, some material may enter the public record unless protective steps are taken.

The categories of material at risk are broad. Commercial secrets such as pricing models, supply-chain terms and proprietary technology are frequently at the centre of a dispute. Personal data, employee records, customer information, communications, attracts obligations under the Personal Data Protection Act 2010. Third-party information disclosed under document production can expose a party to separate liabilities. Because these categories overlap in most commercial arbitrations, treating confidentiality in arbitration Malaysia as a single, well-planned workstream, rather than an afterthought once a dispute begins, is now essential risk management. Rising cross-border trade means more disputes with international counterparties and more data crossing borders during proceedings.

The legal framework that shapes arbitration confidentiality in Malaysia

Two legal pillars shape how confidentiality operates in Malaysian arbitration: the Arbitration Act 2005 (as amended) and the Personal Data Protection Act 2010 (as amended). Sector-specific and corporate disclosure rules may also be relevant. Understanding how they interact is the foundation of any protective strategy.

Arbitration Act 2005 and Model Law influence

The Arbitration Act 2005 is based on the UNCITRAL Model Law on International Commercial Arbitration, which gives tribunals broad authority to determine procedure, including directions on the handling of documents and evidence. Following amendments in 2018, sections 41A and 41B of the Act introduced express confidentiality obligations: broadly, no party may publish, disclose or communicate information relating to the arbitral proceedings or an award, subject to specified exceptions (such as disclosure required by law, to protect or pursue a legal right, or to enforce or challenge an award). Even so, these statutory provisions are qualified and do not cover every eventuality, which is why parties should not rely on the Act alone.

The practical lesson is to convert the tribunal’s procedural powers into explicit orders and to underpin them with tailored contractual obligations.

PDPA 2010 and JPDP guidance in arbitration

The Personal Data Protection Act 2010, administered by the JPDP, governs the processing of personal data in commercial transactions. The Personal Data Protection (Amendment) Act 2024 introduced significant changes, including data breach notification requirements, mandatory data protection officer appointment in certain cases, and revised cross-border transfer provisions, which have been coming into force in phases with accompanying JPDP guidance. When personal data is collected, reviewed, disclosed or transferred during an arbitration, that processing can fall within the PDPA’s scope. Parties acting as data controllers must consider lawful bases for processing, security safeguards, retention limits and the rules on cross-border transfer.

In short, the confidentiality strategy and the data-protection strategy must be designed together, a document production exercise that is confidential as between the parties can still breach the PDPA if personal data is handled unlawfully. This interplay is at the heart of confidentiality in arbitration Malaysia in 2026.

Corporate disclosure obligations

Companies filing and disclosure obligations administered by the Companies Commission of Malaysia (SSM) can also matter for arbitration, because corporate records, resolutions, filings, beneficial-ownership information, are often produced as evidence. Where corporate information is already required to be filed or is on the public register, that changes both its confidentiality status and the argument for or against redaction. Counsel should check whether material sought in production is separately subject to statutory filing or disclosure, and align the arbitral confidentiality plan with any applicable statutory obligations to avoid inconsistent positions that a counterparty could exploit. The current filing requirements should be verified directly against SSM’s published directives.

Core confidentiality protections parties can deploy

There is no single mechanism that protects everything. In practice, parties layer several measures, and the right combination depends on the sensitivity of the material, the urgency, and whether court involvement is likely. The table below compares the principal tools available for confidentiality in arbitration Malaysia so decision-makers can see at a glance what each achieves and where it falls short.

Measure Scope Strengths Limitations Enforceability in Malaysia Practical drafting / steps
Contractual confidentiality clause Binds the parties to keep proceedings, documents and awards confidential Certain, negotiated in advance, defines scope and sanctions Binds only the signatories; no automatic reach to non-parties Enforceable as a contractual obligation via the courts Draft at contract stage; define scope, exceptions, duration, PDPA compliance and remedies
Statutory confidentiality (ss 41A–41B AA 2005) Statutory duty not to publish or disclose information relating to the arbitration or award, subject to exceptions Applies by operation of law where parties have not agreed otherwise Qualified by statutory exceptions; scope may be narrower than parties expect Supported by the Arbitration Act 2005 Rely on as a baseline but supplement with express contractual terms
Tribunal confidentiality directions Procedural orders governing handling of documents and evidence in the reference Flexible, tailored to the dispute, backed by tribunal’s procedural authority Primarily bind participants in the reference; enforcement against third parties is indirect Supported by the Arbitration Act 2005 procedural powers Request early procedural order; define confidentiality tiers and access controls
Emergency arbitrator orders Urgent interim relief, including sealing and preservation, before tribunal is constituted Fast; available before full tribunal exists Time-limited; may require confirmation by the full tribunal Depends on institutional rules and later tribunal/court support Apply under applicable institutional rules; request confidentiality and preservation expressly
Seat-based PDPA safeguards Data-protection controls over personal data processed and transferred Addresses regulatory (not just contractual) risk; protects individuals’ data Compliance burden; does not by itself keep commercial secrets confidential Enforced by JPDP under the PDPA regime Data mapping, minimisation, redaction, transfer safeguards, consent/notice
Court injunctions Restrains threatened or actual breach of confidentiality Coercive; can bind third parties; supports damages and contempt Public, adversarial, potentially exposes the very material at issue Enforceable by the courts, including contempt sanctions Apply for interim injunction with supporting evidence and confidentiality of the application itself

Choosing between these measures is a matter of judgement, but the guidance is straightforward. Rely on a contractual confidentiality clause as the baseline in every commercial agreement, because it gives certainty and defines remedies before any dispute arises, supplementing the statutory duties under sections 41A–41B. Layer tribunal directions on top once a reference begins, to fill gaps the contract did not anticipate and to control day-to-day handling of evidence. Use an emergency arbitrator when material is at imminent risk before the tribunal exists. Turn to court injunctions only when a breach threatens or occurs and no arbitral mechanism can act quickly enough, accepting the trade-off that court proceedings are public.

And treat PDPA safeguards as non-optional wherever personal data is involved, running in parallel with all of the above. The strongest position combines contractual, statutory, tribunal and data-protection measures, escalating to the courts only when coercive relief is genuinely needed.

Sample draft clauses for confidentiality clauses in arbitration

The following are illustrative examples only and must be adapted to the transaction; they are not bespoke legal advice.

  • General confidentiality clause (example). “The parties shall keep confidential all awards, orders, submissions, documents and evidence produced in the arbitration, and the existence of the proceedings, save where disclosure is required by law, to protect or pursue a legal right, to enforce or challenge an award, or with the written consent of the other party.”
  • PDPA-aligned data transfer clause (example). “Where personal data is processed or transferred for the purpose of the arbitration, each party shall comply with the Personal Data Protection Act 2010, apply data minimisation and appropriate security measures, and shall not transfer personal data outside Malaysia except in accordance with the cross-border transfer requirements of the Act and any applicable consent or notice obligations.”

A well-drafted limited-disclosure clause should also name the permitted recipients, external counsel, experts, insurers and the tribunal, and require them to be bound by equivalent obligations.

PDPA considerations: handling personal data in arbitration

Data protection is now inseparable from confidentiality in arbitration Malaysia. A confidentiality strategy that ignores the PDPA leaves a regulatory gap that a counterparty or the JPDP can act on.

Is arbitration covered by the PDPA?

The PDPA governs the processing of personal data in respect of commercial transactions. When a party collects, organises, discloses or transfers personal data during an arbitration arising from a commercial relationship, that activity can amount to processing under the Act. Data controllers should identify a lawful basis for the processing, apply the security and retention principles, and consider whether any exemption applies. The safest course is to assume the PDPA applies to personal data handled in the reference and to build compliance in from the outset, documenting the lawful basis and the safeguards. Because exemptions are narrow and fact-specific, counsel should verify the current position against JPDP guidance rather than assume that “litigation-style” carve-outs cover arbitral disclosure.

Cross-border transfer of personal data

Cross-border disputes routinely require personal data to move between jurisdictions, to foreign counsel, offshore experts or an institution abroad. The PDPA restricts transfers of personal data outside Malaysia unless the conditions in the Act are met; the 2024 amendments revised this regime, and the JPDP has issued guidance on acceptable transfer mechanisms. Practical safeguards include obtaining consent or providing notice where required, using contractual protections analogous to standard contractual clauses, limiting transfers to what is strictly necessary, and ensuring the recipient applies equivalent security. Where a transfer is unavoidable, document the basis for it and the safeguards applied.

Practical steps: minimise, redact, secure

Operational discipline reduces both confidentiality and data-protection risk. Adopt these steps as standard:

  • Data mapping. Identify what personal data exists in the evidence set and where it sits before production begins.
  • Data minimisation. Produce only what is relevant and necessary; resist over-broad requests.
  • Redaction and pseudonymisation. Remove or mask personal identifiers that are not material to the issues.
  • Secure e-filing and hearing technology. Use encrypted platforms, access controls and audit logs for exchange and hearings.
  • Retention and destruction. Agree how long material is kept after the award and how it is securely destroyed.

Emergency arbitrators and confidentiality

Emergency arbitrator procedures, available under the rules of institutions such as the Asian International Arbitration Centre (AIAC), allow a party to obtain urgent interim relief before the full tribunal is constituted. Where confidentiality is at risk, for example, a threatened publication of sensitive documents, or the need to preserve evidence quickly, an emergency application can seek not only substantive relief but also express confidentiality and sealing measures. When applying, request that the emergency arbitrator order the preservation of evidence, restrict access to the application materials, and direct that the existence and content of the emergency proceedings remain confidential.

Because emergency relief is time-limited and often subject to confirmation by the full tribunal, plan for continuity: ensure that the confidentiality protections obtained on an emergency basis are carried forward into the tribunal’s first procedural order. Where coercive enforcement against a third party is needed and the arbitral route is too slow, an emergency arbitrator order can be paired with an application to the courts, keeping in mind that court proceedings carry a public dimension.

Protecting sensitive evidence and hearings

Most confidentiality breaches happen in the mechanics of document production and hearings, not in the award itself. Controlling those mechanics is where practical protection is won or lost in confidentiality in arbitration Malaysia.

Document production protocols and protective orders

Establish a protective order early that defines confidentiality tiers, for example, “confidential” and “attorneys’ eyes only”, and specifies who may access each tier. Combine this with disciplined redaction of irrelevant sensitive content, a clear protocol for challenging designations, and forensic controls over electronic evidence so that metadata and hidden content are not inadvertently disclosed. In e-discovery, agree the scope of collection, use search terms to limit over-collection, and quarantine privileged or personal data before exchange. A protective order that names permitted recipients and imposes equivalent obligations on experts and third-party providers closes the most common leakage points.

Virtual hearings and tech-enabled confidentiality

Virtual and hybrid hearings are now routine and introduce distinct risks. Use platforms with strong encryption, require authenticated access, and restrict the ability to record or screen-capture. Control document display so that only relevant material is on screen, and manage breakout rooms and waiting rooms carefully. A short counsel checklist should confirm: encrypted platform selected; attendee list verified and limited; recording disabled or controlled; secure document repository with access logs; and a protocol for handling technical breaches. Treat the hearing technology as part of the evidence chain and confirm that any hosting provider is bound by confidentiality and data-protection obligations.

Remedies and enforcement of confidentiality orders in Malaysia

Protective measures are only as strong as the remedies behind them. Malaysian courts provide meaningful enforcement for breach of confidentiality, and understanding the routes available is essential.

Court remedies for breach of confidentiality

Where a party breaches or threatens to breach a confidentiality obligation, the courts can grant an interim or final injunction to restrain disclosure, award damages for loss caused by the breach, and, where a court order is disobeyed, sanction the breach as contempt. Costs orders can follow. Because an application to court can itself expose the material at issue, applicants should ask the court to protect the confidentiality of the application, limit the evidence read into the public record, and seek sealing where appropriate. The choice to litigate a breach is therefore a strategic one, weighed against the risk of further exposure.

Enforcing tribunal confidentiality orders and awards

Tribunal directions and awards are supported by the Arbitration Act 2005. Awards may be recognised and enforced through the High Court under section 38 of the Act, and tribunal protective measures gain practical force through the parties’ contractual undertakings and the court’s supervisory role. Court intervention in arbitration is limited by design under section 8 of the Act, which reinforces confidentiality by keeping matters within the private process; but the same limits mean that coercive steps against non-parties usually require a separate court application. Disclosure to a court will generally be confined to what is necessary, for example, to enforce or challenge an award, and parties can ask the court to restrict disclosure to that narrow purpose.

Any decision to enforce or resist disclosure should be grounded in the specific facts and the latest authorities, and the current procedural detail should be confirmed against the primary legislation and applicable rules of court.

Drafting checklist and operational playbook

Use this checklist to embed confidentiality across the lifecycle of a dispute:

  • Pre-arbitral. Include a robust confidentiality clause and a PDPA-aligned data clause in the underlying contract; identify sensitive data categories in advance.
  • Clause drafting. Define scope, permitted recipients, exceptions (legal requirement, enforcement, consent), duration, sanctions and PDPA compliance.
  • Commencement. Seek an early tribunal procedural order setting confidentiality tiers, access controls and secure exchange platforms.
  • During the reference. Apply data mapping, minimisation, redaction and pseudonymisation; control hearing technology; log access to sensitive material.
  • Escalation triggers. Move to an emergency arbitrator or court injunction the moment a serious breach threatens; do not wait.
  • Post-award. Confirm retention and secure destruction of material; keep the award confidential save where disclosure is permitted; check any applicable statutory disclosure obligations.

Decision framework: which protection to choose

Take a position rather than hedging. Use these prescriptive rules:

  • Choose contractual confidentiality clauses when you are negotiating the underlying agreement, you want certainty and defined remedies, and you can bind all relevant parties in advance. This is the default and should always be in place, supplementing the statutory duties.
  • Choose tribunal confidentiality orders when the reference has begun, the contract is silent or insufficient, and you need tailored, procedural control over how documents and evidence are handled among the participants.
  • Choose emergency arbitrator orders when confidential material is at imminent risk, the full tribunal is not yet constituted, and you need fast preservation, sealing or restraint under the applicable institutional rules.
  • Seek court injunctions when a breach is threatened or has occurred, you need coercive relief that can bind third parties or attract contempt sanctions, and no arbitral mechanism can act quickly enough, accepting the public nature of court proceedings and asking the court to protect the material.

Conclusion and recommended next steps

Confidentiality in arbitration Malaysia in 2026 is a discipline, not a default. The businesses best protected are those that draft strong contractual clauses, rely on the statutory confidentiality provisions where they apply, secure early tribunal directions, build PDPA compliance into every document production, and keep emergency and court remedies in reserve for genuine breaches. Start by auditing your standard arbitration clauses, map where personal data will flow in any live or anticipated dispute, and prepare a protective-order template you can deploy at commencement. Treat data protection and confidentiality as one integrated workstream, and escalate decisively when material is at risk.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Lim Tuck Sun at Chooi & Co, a member of the Global Law Experts network.

Sources

  1. Department of Personal Data Protection (JPDP) Malaysia
  2. Attorney General’s Chambers of Malaysia, Legislation Portal
  3. UNCITRAL, Model Law on International Commercial Arbitration
  4. Malaysian Bar
  5. Companies Commission of Malaysia (SSM)

FAQs

Does the PDPA apply to arbitration disclosures in Malaysia?
Yes, where personal data is processed during an arbitration arising from a commercial transaction, that processing can fall within the Personal Data Protection Act 2010, administered by the JPDP. Parties should identify a lawful basis, apply security and minimisation, and address cross-border transfer conditions. Verify any exemption against current JPDP guidance rather than assuming a blanket carve-out for disclosure.
The Arbitration Act 2005 contains express confidentiality provisions (sections 41A and 41B, introduced by the 2018 amendments) imposing a duty not to publish or disclose information relating to the arbitration or the award, subject to specified exceptions. These statutory duties are qualified, so parties should still supplement them with tailored contractual confidentiality clauses and tribunal directions.
Tribunals have broad procedural powers under the Arbitration Act 2005 to direct how documents and evidence are handled, and awards can be recognised and enforced through the courts. Coercive relief against non-parties, or restraint of a threatened breach, usually requires a separate court application, but tribunal directions carry real force among the participants and through the parties’ contractual undertakings.
Include a clear scope (proceedings, documents, evidence, award and the existence of the dispute), defined permitted recipients, precise exceptions (legal requirement, enforcement or challenge, written consent), duration, sanctions for breach, and express PDPA compliance for any personal data. Ensuring all relevant parties are bound strengthens enforceability.
Apply data minimisation, obtain consent or give notice where required, and use contractual safeguards analogous to standard contractual clauses to bind foreign recipients to equivalent protection. Transfer only what is necessary, document the basis and safeguards, and confirm any notification or condition required under the PDPA before the transfer occurs.
Remedies include interim and final injunctions to restrain disclosure, damages for loss caused by the breach, contempt sanctions where a court order is disobeyed, and costs. When applying to court, ask for the confidentiality of the application itself to be protected so that enforcement does not expose the material you are trying to safeguard.
30% rule belgium
By Global Law Experts

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Confidentiality and Data Protection in Arbitration in Malaysia (2026): What Businesses Need to Know

Send welcome message

Custom Message