A team in a strategy workshop around a whiteboard of sticky notes

HubSpot and data protection in Malaysia, Singapore and the Philippines.

Compliance is a design input, not a final sign-off.

HubSpot can be run in line with Malaysia's PDPA, Singapore's PDPA and the Philippines' Data Privacy Act, but the compliance work is yours. HubSpot hosts data in the EU, Canada, Australia and the US, not Southeast Asia, so moving to HubSpot is a cross-border transfer to document.

Who should careCTO, CEOMetric it movesSecurity and compliance risk

At a glance

Three laws, one cross-border question.

MalaysiaPDPA
Transfer
Several bases, including a transfer impact assessment
Breach notice
As soon as practicable
DPO
Above thresholds
SingaporePDPA
Transfer
Comparable protection, for example written agreements
Breach notice
Within 3 calendar days of assessment
DPO
Always
PhilippinesData Privacy Act
Transfer
Accountability, model contractual clauses
Breach notice
Within 72 hours
DPO
Always
No Southeast Asian data centre. HubSpot hosts in
European UnionCanadaAustraliaUnited States

Summarised from DLA Piper country guides and HubSpot's data centre page, as cited below.

This page is operational guidance, not legal advice. Confirm your obligations with counsel in each market.

Where does HubSpot store customer data?

HubSpot hosts data in four regions: the European Union, Canada, Australia and the United States. It has no data centre in Southeast Asia, and states that it “doesn't have any immediate plans for additional data centers” (HubSpot). Whichever region you choose, treat the move as a cross-border transfer from the first design workshop.

What does Malaysia's PDPA require?

The PDPA amendments, phased in through 2025, changed the rules that matter most for a CRM project (Mayer Brown):

  • Cross-border transfers. The whitelist is gone. Transfers can rely on one of several bases, including a destination with substantially similar law or an adequate level of protection, assessed through a transfer impact assessment, as well as consent, contractual necessity, or safeguards such as binding corporate rules and contractual clauses.
  • Breach notification. Controllers must notify the Commissioner as soon as practicable, and affected individuals where a breach causes significant harm.
  • Data Protection Officers. Appointment is mandatory where thresholds are met, including processing personal data of more than 20,000 data subjects (DLA Piper).
  • Processors and penalties. Data processors now carry direct obligations, and the maximum fine rose to RM1,000,000.

What does Singapore's PDPA require?

The Personal Data Protection Commission (PDPC) enforces the Act. Organisations transferring personal data overseas must ensure the recipient provides a standard of protection comparable to the PDPA, for example through written agreements. Every organisation must appoint at least one Data Protection Officer. A notifiable breach must be reported to the PDPC as soon as practicable and no later than three calendar days after assessing it, and affected individuals told where significant harm is likely (DLA Piper).

What does the Philippines' Data Privacy Act require?

The National Privacy Commission (NPC) enforces the Data Privacy Act of 2012. The Philippines follows an accountability principle: the organisation stays responsible for personal data it transfers, and the NPC issued model contractual clauses for cross-border transfers in May 2024. Reportable breaches must be notified to the NPC and affected individuals within 72 hours of knowledge. Registration is mandatory for organisations with 250 or more employees, among other thresholds (DLA Piper).

What should a HubSpot rollout include?

  • A data map: every source system, data set and its legal basis, by market.
  • Transfer documentation for each market before any data moves.
  • A decision on what not to migrate. Records with no purpose are a liability.
  • Consent and opt-out handling for email, WhatsApp, Viber, LINE and SMS.
  • Named DPOs where required, and a breach playbook that meets the shortest deadline in scope.
  • Clear limits on what AI agents may read, write and say about personal data.

Design compliance in from day one.

A strategy call maps your data, your markets and the transfer documentation each one needs.