NC · article
Rolling Out ChatGPT Enterprise or Copilot in Malaysia: A PDPA Checklist
Enterprise AI tools inherit your existing permissions, your data flows and your staff's habits. The governance you need before a pilot, what to check per vendor, and what the policy should actually say.
part of Hiring and Scoping AI Work · 9 articles
The short answer: before a Malaysian company rolls out ChatGPT Enterprise, Microsoft Copilot or Gemini, it needs three things in place - clean file permissions, because these tools can surface anything a user can already open; a documented basis for cross-border transfer under the amended PDPA, because none of them offers a Malaysian data region; and a short acceptable use policy signed off by your DPO. The licence is the easy part. The prerequisites are what decide whether the rollout is defensible.
This is not legal advice. It is a practitioner’s view of the technical and governance work. Confirm the legal position for your organisation with your Data Protection Officer or counsel. Vendor terms change frequently; every vendor fact below is dated to the documentation as I retrieved it on 22 September 2026.
Why Is Generative AI Governance a PDPA Question Now?
Because the law changed underneath the tools. The Personal Data Protection (Amendment) Act 2024 came into force in stages during 2025, and Mayer Brown’s summary sets out the changes that matter for an AI rollout: data processors are now directly subject to the Security Principle, the old cross-border “whitelist” has been replaced with a risk-based framework, data subjects gained a right to data portability, and the maximum fine rose from RM300,000 to RM1,000,000.
Two obligations took effect on 1 June 2025. According to DLA Piper’s briefing on the Commissioner’s guidelines, a data breach must be notified to the Commissioner within 72 hours, and to affected individuals within seven days of notifying the Commissioner where significant harm is likely. Qualifying organisations must also appoint a Data Protection Officer and notify the Commissioner within 21 days of the appointment.
Put together, a generative AI tool stops being a productivity purchase. It is a new processor and a new transfer route, and a confidential HR file surfaced to the wrong person may be a notifiable breach with a 72-hour clock.
Why Are File Permissions the Real Prerequisite?
This is the point most rollout plans miss. Copilot-style tools do not create new access; they make existing access usable. Microsoft’s own Copilot data, privacy and security documentation (dated July 2026) is explicit: Copilot “only surfaces organizational data to which individual users have at least view permissions”, and it tells customers to use the permission models in SharePoint and elsewhere to make sure the right people have the right access.
Read that the other way round. Every SharePoint site shared with “Everyone except external users”, every “anyone with the link” folder in Drive, every Teams channel that absorbed a salary spreadsheet years ago was accessible before, but finding it required knowing it existed. An assistant that searches everything you can open removes that obscurity overnight. Oversharing was a latent problem; AI makes it an active one.
I saw the same mechanism, in a different form, hardening a pharmaceutical AI platform for enterprise pilot. The security assessment found an endpoint where one tenant could read another tenant’s documents because a query lacked a tenant filter, and a separate isolation gap in the retrieval pipeline’s vector store. The AI layer was not the cause. It faithfully inherited whatever access model sat underneath it, and that model had holes. The fix was in the access layer, not the prompts - the pattern is covered in multi-tenant RAG isolation.
Google says the same of Gemini: its Workspace privacy hub states that Gemini abides by your organisation’s existing controls. And OpenAI’s enterprise privacy page (updated 8 January 2026) says ChatGPT respects existing permissions for connected apps. Respecting broken permissions faithfully is still exposure.
What About Staff Already Using Personal Accounts?
Assume they are. Microsoft’s 2024 Work Trend Index, a survey of 31,000 knowledge workers across 31 markets, found that 78% of AI users were bringing their own AI tools to work, rising to 80% at small and medium-sized companies.
So the choice is not between AI and no AI; it is between AI you can see, configure and log, and AI you cannot. A consumer account gives you no retention control, no audit trail and no contract covering the transfer, and a blanket ban mostly pushes usage onto personal phones. Provide a sanctioned tool quickly, then make the unsanctioned route the inconvenient one.
What Should the Rollout Checklist Look Like?
Three phases. Each has an exit condition, and the pilot should not start until the first phase is genuinely complete rather than scheduled.
Phase 1: Before the pilot
- Name an owner and involve the DPO. One accountable executive, plus your DPO or data protection lead signing off the data flows. If you meet the DPO thresholds, that person should already exist.
- Run an oversharing sweep. Find sites, drives and channels shared organisation-wide or by open link, prioritising HR, finance, legal and customer data. Fix the worst before any licence is assigned.
- Label what is sensitive. Sensitivity labels or equivalent classification on the repositories that matter, so controls can follow the data rather than the folder.
- Decide the transfer basis. Map where prompts, files and outputs are stored and processed, and document the cross-border basis under the Commissioner’s guidelines (see below).
- Set retention. Decide how long prompts and responses are kept, and make sure your retention schedule and breach response plan both cover them.
- Lock connectors down. Start with third-party apps, agents and connectors off, and enable them one at a time against a named use case.
- Publish the acceptable use policy. Short, specific and signed off before anyone has access.
Exit condition: the DPO has signed the data flow map, and the oversharing sweep found nothing critical left open.
Phase 2: The pilot
- Choose pilot users by data exposure, not enthusiasm. Include at least one team whose permissions are messy, because that is where problems surface.
- Red-team your own tenant. Have pilot users deliberately ask for things they should not see: salaries, disciplinary files, board papers, customer identity documents. Every hit is a permissions fix, not an AI fix.
- Turn on and actually review the logs. Confirm prompts and responses are captured where your investigators can reach them, and rehearse finding one.
- Test prompt injection through documents. A file or email can carry instructions the assistant follows. The mechanics are in prompt injection defence in production RAG.
- Measure one outcome per team. Hours saved on a named task, not “satisfaction”. It is the number the board will ask for.
Exit condition: red-team findings closed, one log retrieval rehearsed end to end, and a measured result for at least one workflow.
Phase 3: Scale
- Expand by department, re-sweeping permissions for each. Every new group brings its own repositories.
- Train on the policy, not the tool. What never goes into a prompt and how to report a mistake matter more than prompt tips.
- Add the AI tool to your breach playbook. A misdirected prompt or an over-broad answer needs a triage route that can meet the 72-hour window.
- Review vendor terms quarterly. Residency regions, retention defaults and model subprocessors change; your transfer assessment should be re-checked when they do.
- Report to the board. Adoption, incidents and measured value. How boards should oversee this is covered in AI strategy for boards in Malaysia.
What Should You Check for Each Tool?
The table below compares the three tools on the points that matter for a PDPA assessment, drawn from each vendor’s documentation as retrieved on 22 September 2026. Treat it as the questions to ask, and verify the answers against your own contract.
| ChatGPT Enterprise | Microsoft Copilot | Gemini for Workspace | |
|---|---|---|---|
| Training on your data | Not by default, unless you opt in | Prompts, responses and Graph data not used to train foundation models | Not without your prior permission or instruction |
| Retention | Admin-controlled; deleted chats removed within 30 days unless legally required | Stored with your Microsoft 365 content; Purview retention policies apply | Admin-controlled for Gemini in Workspace apps |
| Data residency | At-rest regions include Singapore, Japan, India, Australia; no Malaysia region; new Enterprise/Edu customers | Residency commitments via Product Terms, ADR and Multi-Geo; non-EU queries may be processed in the US, EU or other regions | Data regions are US or Europe; Gemini coverage needs Enterprise Plus or Assured Controls |
| Permission exposure | What users paste or upload, plus connected apps (admin-controlled) | Everything the user can view in Microsoft 365, plus Graph connectors and agents | Everything the user can access in Workspace |
| Audit logs | Conversation and GPT audit log via the Enterprise Compliance API | Content search and Microsoft Purview over Copilot interactions | Admin audit logs and Reporting API for Gemini activity |
| Admin controls | SAML SSO, feature and app controls | Agent allow-listing in the admin centre; sensitivity labels honoured | Existing Workspace controls, IRM and client-side encryption |
Sources: OpenAI’s enterprise privacy commitments and data residency help article(in-region inference is currently limited to Europe, the US and the UAE); Microsoft’s Copilot privacy documentation(Microsoft 365 Copilot is now branded Microsoft Copilot); Google’s Gemini privacy hub, data regions guide and the June 2025 announcement extending data regions to Gemini features.
The row that decides most rollouts is permission exposure. ChatGPT Enterprise starts narrow and widens as you connect apps; Copilot and Gemini start wide, because they sit inside the suite where your documents already live.
How Does Cross-Border Transfer Apply to AI Prompts?
On the vendor documentation above, a prompt containing personal data typed in Kuala Lumpur will be stored and processed outside Malaysia. The conservative working assumption, and the one I would put to your DPO, is that this is a cross-border transfer.
The Commissioner’s Cross-Border Personal Data Transfer Guidelines, issued on 29 April 2025 and summarised by Mayer Brown, set out the available bases: a destination with substantially similar law or adequate protection, supported by a transfer impact assessment valid for up to three years; consent; contractual necessity; legal purposes; or due-diligence mechanisms such as binding corporate rules, contractual clauses and recognised certifications. For an enterprise AI tool, the realistic routes are usually a transfer impact assessment for the vendor’s processing locations, backed by the contractual terms in your agreement. Consent is rarely workable for staff and customer data at scale.
Residency options help but do not settle the question. Choosing Singapore storage for ChatGPT Enterprise still leaves inference, external integrations and some metadata outside that region, by OpenAI’s own account. Document what actually moves.
What Should the Acceptable Use Policy Actually Say?
A useful policy fits on two pages and answers five questions.
- Which tools? The approved tools by name, and a plain statement that personal accounts on consumer AI services are not to be used for company data.
- Which data never goes in? Name the categories: identity card numbers, health and financial information about individuals, credentials, and anything under legal privilege or client confidentiality. Examples beat definitions.
- Who owns the output? The person who uses it. AI output is a draft; the human is accountable for checking facts, figures and tone before it leaves the building.
- How are mistakes reported? A named route, with an explicit statement that prompt reporting is expected and will not be punished. The 72-hour notification window leaves no room for a mistake that surfaces a week late, so a hidden mistake is the expensive kind.
- Who decides the grey areas? One contact, usually the DPO or their delegate.
Malaysia’s National Guidelines on AI Governance and Ethics, published by MOSTI in September 2024, are not legally binding, but their seven principles, including transparency, accountability and privacy and security, give the policy a recognisable local anchor. The PDP Commissioner’s page for the Amendment Act also lists guidelines on data protection impact assessment, data protection by design and automated decision-making, which are worth reading before any use case moves beyond drafting and summarising. Which departmental use cases are worth the effort is covered in generative AI use cases for Malaysian companies.
What Changes When You Move Beyond Off-the-Shelf Chat?
Build your own assistant over company documents and the controls the vendor provided become yours to build. On the pharmaceutical platform, that meant an audit trail covering AI queries, input guardrails for prompt injection and data exfiltration patterns, and output guardrails for personal data and secrets, each with test cases proving they worked. It also means handling deletion properly: personal data in embeddings and caches is still personal data, as covered in right to erasure in vector databases.
If you want an independent view of whether a system you have built, or are about to deploy, actually behaves as your policy says it should, AI assurance is the engagement I run for exactly that question.
Frequently Asked Questions
Does using ChatGPT Enterprise or Copilot in Malaysia count as a cross-border transfer under the PDPA?
Treat it as one unless your counsel concludes otherwise. As of September 2026, none of the three major tools offers a Malaysian data region: OpenAI lists Singapore as its nearest data residency region, Google Workspace data regions cover the United States and Europe, and Microsoft states that customers outside the EU may have Copilot queries processed in the US, EU or other regions. Under the Commissioner’s Cross-Border Personal Data Transfer Guidelines issued in April 2025, that means choosing and documenting a transfer basis, such as a transfer impact assessment or contractual clauses, before personal data goes into prompts.
Do we need a Data Protection Officer before rolling out generative AI?
If you meet the thresholds, you should already have one, because DPO appointment became mandatory on 1 June 2025. The guidelines apply where you process personal data of more than 20,000 data subjects, sensitive personal data including financial information of more than 10,000 data subjects, or carry out regular and systematic monitoring. Either way, whoever owns data protection should sign off the rollout, because they will own the breach notification clock if something goes wrong.
What should a generative AI acceptable use policy say for a Malaysian company?
Five things, in plain language: which tools are approved and that personal accounts are not; which categories of data may never go into a prompt; that the human who uses an output owns it and must check it; how staff report a mistake, such as pasting the wrong file, without fear; and who to ask when unsure. Keep it to two pages. A policy nobody reads is a record that you told them, not a control.
Is Microsoft Copilot safer than ChatGPT Enterprise for PDPA compliance?
Neither is safer by default; they fail in different places. Copilot reaches everything a user can already open in Microsoft 365, so its main risk is oversharing in SharePoint, OneDrive and Teams. ChatGPT Enterprise holds what users paste or upload plus whatever apps you connect, so its main risk is what goes into prompts and which connectors you allow. Choose on where your data lives and how clean your permissions are, not on the vendor badge.
Fix the Permissions, Then Buy the Licences
The companies that roll these tools out well are rarely the ones with the most detailed policy. They are the ones that cleaned up who can see what before they gave everyone a search engine over it, wrote down where the data goes, and made reporting a mistake easier than hiding one.
If you are planning a rollout and want the permissions sweep, transfer mapping and policy done as one piece of work, how I work with Malaysian companies covers the engagement, or you can book a consultation to talk through your environment.
Read Next
Ready to discuss your AI project?
Book a free 30-minute discovery call to explore how AI can transform your business. Or if you already have a codebase, get an instant architecture report at SystemAudit.dev No technical knowledge needed, results in 3 minutes.
About the Author
Nic Chin is an AI Architect and Fractional CTO who helps companies design and deploy production AI systems including RAG pipelines, multi-agent systems, and AI automation platforms. He has delivered enterprise AI solutions across the UK, US, and Europe, and provides AI consulting in Malaysia and Singapore.