Key Takeaway
- AWS Malaysia now gives public agencies a local cloud region, meaning government data no longer has to be stored outside the country.
- Malaysia’s National Cloud Computing Policy (NCCP), launched in August 2025, sets four levels of data sensitivity that determine where and how government data can be stored.
- The Cyber Security Act 2024 makes cybersecurity checks and incident reporting legally required for agencies that handle critical national systems.
- Government agencies across the region are already using AI services in Malaysia for document processing and case management, with time savings reported in pilot programmes.
- VSTECS KU, Malaysia’s first authorised AWS distributor, gives agencies and channel partners local access to the full AWS service catalogue.
Introduction
Before August 2024, every Malaysian government agency using AWS had its data stored in servers outside the country. There was no local option. For agencies dealing with sensitive citizen records or government operations, that created a real compliance problem. Data leaving Malaysian borders raised questions about security, privacy, and legal obligations.
AWS Malaysia changed that. The AWS Asia Pacific (Malaysia) Region launched in August 2024, and government data can now be stored and processed within Malaysia by default. For IT managers at public agencies, this matters in practical terms. It determines which systems can migrate to the cloud, how compliance requirements are met, and whether AI tools can run on sensitive data without that data ever leaving the country.
Two major policies have also shifted the ground since then. The National Cloud Computing Policy (NCCP) set formal rules for how government data must be classified and stored. The Cyber Security Act 2024 made cybersecurity practices legally binding for agencies managing critical systems. Anyone planning a government cloud project in 2026 needs to work within both.

What Is AWS Malaysia?
AWS stands for Amazon Web Services, one of the world’s largest cloud computing providers. “Cloud computing” means using remote servers to store, manage, and process data, rather than running everything on physical hardware at your office or agency.
AWS Malaysia is the name for the AWS Asia Pacific (Malaysia) Region: a set of data centres physically located in Malaysia, connected to AWS’s global network. The key difference from other AWS regions is location. Data stored here stays within Malaysian borders by default, rather than being processed in Singapore or elsewhere.
That matters because of how Malaysian law now treats government data. The NCCP sorts government information into four sensitivity levels: public, internal, restricted, and confidential. The most sensitive category, confidential, must be stored on cloud infrastructure physically located in Malaysia, with strict access controls and encryption applied. A data centre in another country cannot satisfy that requirement. The local AWS region can.
Agencies that had been holding off on cloud adoption because of data location concerns now have a concrete option.
How the NCCP and Cyber Security Act 2024 Shape Cloud Decisions
Two policies now set the rules for public sector cloud projects in Malaysia, and both came into effect within roughly a year of each other.
The National Cloud Computing Policy (NCCP) was adopted on 3 August 2025. It is Malaysia’s first government-wide cloud policy. It covers how agencies adopt cloud technology, how data must be classified and protected, how agencies share data with each other, and how cloud use connects to broader goals like digital inclusion and environmental targets. The most immediate obligation for IT teams is data classification. Every dataset an agency holds needs to be assigned one of the four sensitivity levels, and the cloud setup must match that level’s requirements.
The Cyber Security Act 2024 (CSA 2024) works alongside the NCCP with a narrower focus on security. It applies to what the government calls National Critical Information Infrastructure, or NCII. These are the systems that keep essential services running: things like utilities, communications, transport, and government administration. Agencies that operate or depend on NCII systems must carry out regular cybersecurity assessments, report security incidents to the National Cyber Security Agency (NACSA) within a set timeframe, and follow sector-specific security standards. Failing to report an incident is an offence, with fines of up to RM 500,000.
Data protection in Malaysia now spans more than just the Personal Data Protection Act. The Cyber Security Act 2024 and the NCCP together mean agencies have to think about data security, data classification, and incident response as one connected picture, not separate checklists.
Where does AWS fit into this? AWS public sector cloud deployments come with security controls built into the base setup. These include encryption (scrambling data so only authorised parties can read it), access management tools that control who can view or change data, and automatic activity logging. An agency migrating to AWS does not have to build these controls from scratch. They are part of the standard infrastructure.

What Does AI Deployment in Malaysia’s Public Sector Actually Look Like?
AI services in Malaysia are already running inside government, not on the horizon. A generative AI pilot programme involving Malaysian public sector officers found that participants saved an average of 3.25 hours per week on manual tasks. The National AI Office coordinates AI adoption across Malaysian government agencies. It was established in December 2024 and is working on a national AI action plan for the years ahead.
On the AWS platform, two services are commonly used for government AI work. Amazon Bedrock gives agencies access to large language models. These are AI systems trained on large amounts of text that can summarise documents, answer questions, and draft responses, without the agency needing to build or maintain the AI system itself. Amazon SageMaker is used for building and running custom machine learning models. These are AI tools trained on an agency’s own data to carry out specific tasks, like flagging unusual patterns in records or sorting incoming requests by type.
For most government agencies, the technology side of AI adoption is no longer the main challenge. Getting the data governance right, meaning deciding who can access what, under what rules, and with what audit trail, is where the real preparation work sits.
AWS public sector agencies across Southeast Asia have used these tools for document summarisation, automated sorting of incoming case files, and citizen-facing services. Results vary by project, but the use cases are established rather than experimental.
How Malaysia’s Data Protection Requirements Translate to Cloud Architecture
Getting data protection right in Malaysia now means working across three overlapping rules. The Personal Data Protection Act (PDPA) governs how personal data is collected and used. The Cyber Security Act 2024 covers how critical systems must be secured and how incidents must be reported. The NCCP determines how government data must be classified and stored.
For agencies handling citizen data, three practical questions determine the cloud architecture: where does the data sit, who is allowed to access it, and what is the process when something goes wrong? In the AWS Malaysia region, data stays within the country by default. Access is controlled through permission settings that specify exactly which users or systems can reach which data. Every action within the environment is automatically logged, creating a record that can be reviewed during an audit or after a security incident. This is what NACSA requires from agencies operating critical systems.
The Data Sharing Act 2025 adds a further layer specific to data protection in Malaysia’s inter-agency context. When agencies share data, those sharing arrangements must be documented and auditable. Cloud environments with built-in activity logging are better placed to meet this requirement than older on-premises systems where tracking data movement requires additional tools.
Agencies that have already moved to the cloud are not starting the compliance process from zero. The core technical controls are already in place. The remaining work is configuration, written documentation of policies, and keeping those policies current as the regulatory picture changes.

What AWS Public Sector Support Means for Malaysian Agencies in Practice
Government agencies in Malaysia do not purchase AWS services the same way a private company would. The Malaysian government signed a Cloud Framework Agreement (CFA) with AWS. This is a pre-negotiated contract that sets the terms and security standards any government agency can use when adopting AWS, so each department does not need to negotiate its own contract from scratch.
VSTECS KU, as Malaysia’s first authorised AWS distributor, is the local link between AWS and the agencies and technology partners that work with government clients. This means technical support, training, and service access are available locally rather than through AWS’s international channels.
For IT leads scoping a cloud migration or an AI project, the starting point is identifying which of the four NCCP sensitivity levels applies to the data involved. That classification determines which cloud setup is appropriate, which AWS services apply, and what compliance documentation the project needs to produce. VSTECS KU’s professional services team works through that assessment with agencies and their partners, from initial scoping through to deployment.
Frequently Asked Questions
1. What does having a local AWS region mean for government data storage?
It means government data can be stored and processed within Malaysia by default. Before the AWS Asia Pacific (Malaysia) Region launched in August 2024, using AWS meant data was processed in data centres in other countries. Now, agencies can keep data within Malaysian borders, which is required for the most sensitive categories of government data under the NCCP.
2. Which public agencies are already using AWS in Malaysia?
At the time of the regional launch in August 2024, AWS named several Malaysian government bodies as users of its infrastructure. These included the Department of Statistics Malaysia, the National Digital Department, Smart Selangor, Radio Televisyen Malaysia, and the Federal Agricultural Marketing Authority.
3. How does the Cyber Security Act 2024 affect data protection obligations for public agencies in Malaysia?
Agencies that operate or depend on National Critical Information Infrastructure (NCII) systems must carry out cybersecurity risk assessments, report security incidents to NACSA within a defined period, and follow sector-specific security codes. Failing to report an incident carries fines of up to RM 500,000. Cloud infrastructure with automatic logging and access controls supports agencies in meeting these reporting and audit obligations.
4. Are AI services in Malaysia ready for public sector deployment?
For specific use cases, yes. A public sector pilot programme in Malaysia reported time savings of around 3.25 hours per officer per week on manual tasks. Amazon Bedrock (for accessing AI language models) and Amazon SageMaker (for building custom AI models trained on an agency’s own data) are already in active use across public sector agencies in Southeast Asia for tasks like document processing and case management.
5. How can agencies access AWS services without a separate procurement process?
Through the Cloud Framework Agreement between AWS and the Malaysian government, which sets pre-negotiated terms that any agency can use directly. VSTECS KU, as Malaysia’s first authorised AWS distributor, provides local support through the AWS Partner Network. Channel partners working on government projects can source services and assistance without going through AWS’s international channels.
Two things reshaped Malaysia’s public sector cloud picture in the past two years. The AWS Asia Pacific (Malaysia) Region gave agencies a local data residency option for the first time. The NCCP and Cyber Security Act 2024 gave that choice a legal framework to sit within. For IT leads at public agencies, both shifts together mean the path for a cloud project is clearer than before: the rules are written down, the infrastructure exists to meet them, and the procurement terms are already in place. VSTECS KU’s professional services team can help agencies work through that process, from scoping data classification requirements to deployment on AWS.