This page is operational guidance, not legal advice. Confirm your obligations with counsel in each market.
Where does HubSpot store customer data?
HubSpot hosts data in four regions: the European Union, Canada, Australia and the United States. It has no data centre in Southeast Asia, and states that it “doesn't have any immediate plans for additional data centers” (HubSpot). Whichever region you choose, treat the move as a cross-border transfer from the first design workshop.
What does Malaysia's PDPA require?
The PDPA amendments, phased in through 2025, changed the rules that matter most for a CRM project (Mayer Brown):
- Cross-border transfers. The whitelist is gone. Transfers can rely on one of several bases, including a destination with substantially similar law or an adequate level of protection, assessed through a transfer impact assessment, as well as consent, contractual necessity, or safeguards such as binding corporate rules and contractual clauses.
- Breach notification. Controllers must notify the Commissioner as soon as practicable, and affected individuals where a breach causes significant harm.
- Data Protection Officers. Appointment is mandatory where thresholds are met, including processing personal data of more than 20,000 data subjects (DLA Piper).
- Processors and penalties. Data processors now carry direct obligations, and the maximum fine rose to RM1,000,000.
What does Singapore's PDPA require?
The Personal Data Protection Commission (PDPC) enforces the Act. Organisations transferring personal data overseas must ensure the recipient provides a standard of protection comparable to the PDPA, for example through written agreements. Every organisation must appoint at least one Data Protection Officer. A notifiable breach must be reported to the PDPC as soon as practicable and no later than three calendar days after assessing it, and affected individuals told where significant harm is likely (DLA Piper).
What does the Philippines' Data Privacy Act require?
The National Privacy Commission (NPC) enforces the Data Privacy Act of 2012. The Philippines follows an accountability principle: the organisation stays responsible for personal data it transfers, and the NPC issued model contractual clauses for cross-border transfers in May 2024. Reportable breaches must be notified to the NPC and affected individuals within 72 hours of knowledge. Registration is mandatory for organisations with 250 or more employees, among other thresholds (DLA Piper).
What should a HubSpot rollout include?
- A data map: every source system, data set and its legal basis, by market.
- Transfer documentation for each market before any data moves.
- A decision on what not to migrate. Records with no purpose are a liability.
- Consent and opt-out handling for email, WhatsApp, Viber, LINE and SMS.
- Named DPOs where required, and a breach playbook that meets the shortest deadline in scope.
- Clear limits on what AI agents may read, write and say about personal data.




