Social Media Entrepreneur Phone Bill Data Leak, Who’s To Blame?

The Malaysian Digital Economy Consumers Association (myDigitalConsumer) has called for stronger personal data protection laws and tighter safeguards across both the public and private sectors following the alleged disclosure of social media entrepreneur Khairul Aming’s telephone bill.

The association said the incident, which was reported by local media and is currently under investigation by the authorities, underscores the urgent need to strengthen the protection of Malaysians’ personal data.

It stressed that the case should not be viewed as an isolated incident, warning that unauthorised access to personal information—including telecommunications records, identity details, financial information and government records—could expose consumers to identity theft, fraud and other cyber-enabled crimes.

In a statement today, myDigitalConsumer said Malaysians are increasingly concerned that possession of a person’s MyKad number could allow unauthorised individuals to piece together personal information from multiple sources if identity verification processes are inadequate.

The association warned that such information could be exploited for identity theft, impersonation, financial fraud and social engineering attacks.

myDigitalConsumer also raised concerns over the widespread practice of security personnel at gated residential communities, commercial buildings and private premises photographing visitors’ MyKad or driving licences during registration.

It said photographic copies of these documents contain substantially more personal information than is necessary for visitor management, while consumers are often unaware of where the images are stored, how long they are retained, who has access to them or whether they are adequately protected.

According to the association, the practice appears inconsistent with key personal data protection principles such as purpose limitation, data minimisation, security, retention limitation and accountability.

The association urged the government to review Section 3 of the Personal Data Protection Act 2010 (PDPA), which currently exempts the Federal and State Governments from the legislation.

It argued that consumers should enjoy the same level of protection regardless of whether their personal information is held by a government agency or a private organisation.

myDigitalConsumer noted that many major personal data incidents reported in recent years have involved public sector databases, making it timely to extend statutory data protection obligations to government entities.

The association also pointed to the European Union’s General Data Protection Regulation (GDPR) as an example of a framework that applies consistently across both public and private sectors.

While acknowledging that Malaysia need not adopt the GDPR in its entirety, it said the country should incorporate internationally recognised best practices covering accountability, transparency, data security, breach notification and individual privacy rights.

Latest News

Must read