This study aims to compare the regulatory frameworks governing fintech innovation, blockchain and digital assets, and investor data protection in the capital markets of Indonesia and Malaysia. It employs normative legal research using statute, comparative, and conceptual approaches. The analysis is based on primary legal materials, including legislation, regulatory guidelines, supervisory instruments, and official policy documents, as well as secondary legal materials, including academic literature and policy reports. The collected materials are examined through descriptive and comparative legal analysis. The findings demonstrate that Indonesia and Malaysia pursue broadly similar regulatory objectives through licensing, governance requirements, supervisory mechanisms, risk management, and investor protection. However, the two jurisdictions differ significantly in their institutional architecture. Indonesia adopts an integrated financial-sector regulatory approach under the Financial Services Authority, whereas Malaysia applies a more specialised capital-market supervisory model through the Securities Commission Malaysia. These institutional differences influence regulatory coherence, supervisory coordination, legal certainty, and regulators' capacity to address technology-specific risks. The findings imply that Indonesia should strengthen inter-institutional coordination and technology-specific supervisory standards, while both jurisdictions should ensure that innovation policies remain closely connected with cybersecurity, operational resilience, and investor protection. The originality of this study lies in integrating fintech regulation, digital asset governance, and investor data protection within a single comparative legal framework focused on regulatory coherence and institutional design.