Malaysia encryption policy

Malaysia's New Cybercrime Law Lets Officers Demand Decryption Keys Without a Warrant

Section 36 of Malaysia's Cybercrimes Bill 2026 compels passwords and decryption codes with no judicial pre-authorisation, and RM100,000 fines for refusal.

Malaysia's Compelled-Decryption Power, By the Number… People of Internet Research · Malaysia RM100,000 Max fine for refusal Or up to 3 years' imprisonment, or… 8,014 Online fraud charges, Jan-May 2026 Already exceeds the 6,140 charges … 61 Bill clauses total Replaces the Computer Crimes Act 1… 28 Days from tabling to passage Tabled June 22, passed both houses… peopleofinternet.com
Malaysia's Compelled-Decryption Power,… People of Internet Research · Malaysia RM100,000 Max fine for refusal 8,014 Online fraud charges, Jan-May… 61 Bill clauses total 28 Days from tabling to passage peopleofinternet.com

Key Takeaways

Malaysia's Cybercrimes Bill 2026 cleared its final parliamentary hurdle on July 20, 2026, when the Dewan Negara approved it unanimously and without amendment, following the Dewan Rakyat's passage on July 1. The bill, tabled June 22 by Deputy Prime Minister Ahmad Zahid Hamidi, now awaits royal assent and gazettement before replacing the Computer Crimes Act 1997 — a 61-clause statute meant to bring Malaysia's cyber law into line with the Budapest Convention and the UN Convention Against Cybercrime.

Most of the bill is uncontroversial modernization: provisions on deepfakes, non-consensual intimate-image distribution, ransomware, and AI-enabled fraud address real gaps in a nearly 30-year-old law. But one clause has drawn a joint rebuke from ARTICLE 19, the Centre for Independent Journalism (CIJ), and Sinar Project. Section 36(1)–(2) lets any authorised officer conducting a search demand passwords, encryption or decryption codes, and the software or hardware needed to access data — without prior judicial approval. Refusal is prosecuted as obstruction under Section 46, carrying a fine up to RM100,000 (roughly $25,000) or up to three years in prison, or both.

The Case for the Bill

The government's justification is not manufactured. Malaysia recorded 8,014 online-fraud charges between January and May 2026 alone, already surpassing the 6,140 charges for all of 2025, according to reporting cited by the South China Morning Post. Zahid told the Dewan Rakyat the bill does not grant "absolute power" and does not override existing statutes including the Official Secrets Act 1972; data-preservation notices, he said, require investigators to justify the request in writing. A newly merged Cybersecurity and Cryptology Development Centre under the National Cyber Security Agency (NACSA), stood up June 3, 2026, gives Malaysia institutional capacity it previously lacked. Investigators genuinely do need lawful, timely access to devices in fraud and exploitation cases, and a legal mechanism for compelling technical cooperation is a defensible tool in principle — most democracies have one in some form.

Where the Design Breaks Down

The defect isn't that Malaysia created a compelled-decryption power — it's how the power is triggered and enforced. Section 36 sets no independent authorisation standard: an officer conducting a search can issue the demand on the spot, with no magistrate, no warrant threshold, and no judicial review built into the clause itself. As the joint statement from ARTICLE 19, CIJ and Sinar Project puts it, this falls short of the "thorough, independent judicial oversight" that any interference with privacy should require, and it leaves no articulated standard an officer must meet before issuing the order.

The criminal penalty compounds the problem. Section 46 does not distinguish between someone who refuses to cooperate and a service provider that simply cannot decrypt end-to-end encrypted communications passing through its own systems — a technical reality, not an excuse. Threatening RM100,000 fines or prison time for a company (or an individual) that lacks the mathematical ability to comply doesn't deter crime; it either pressures providers to weaken their own encryption architecture or drives compliant services out of the market. The civil society coalition's sharper concern is the chilling effect on journalistic source protection, whistleblowers, human rights defenders, and attorney-client communications — categories of speech Malaysia's constitution and its international commitments are supposed to protect, and precisely the users for whom warrantless seizure of decryption keys is most consequential.

International human rights law's three-part test for restricting expression — legality, necessity and proportionality, and legitimate aim — is the right yardstick here, and Section 36 struggles on the second prong. A search warrant already authorises seizure of a device; requiring a separate judicial sign-off specifically for a decryption demand, with a defined evidentiary threshold, would preserve investigative capability while closing the arbitrary-access gap. That is a modest, workable fix, not a repeal of the government's enforcement tools.

Part of a Wider Pattern

Malaysia isn't acting in isolation. EFF flagged Canada's Bill C-22, the "Lawful Access Bill," on June 18, 2026, for similarly threatening encryption with insufficient debate on amendments. Encryption-weakening riders are becoming a template move inside broader cybercrime and online-safety packages, precisely because they're easier to pass when bundled with popular provisions like deepfake and fraud offences that command genuine cross-party support.

That bundling is also the fix's opening. Nothing in Section 36 needs the rest of the bill to fail — Parliament, or the King in assenting, could condition compelled-decryption powers on judicial authorisation without touching the fraud, deepfake, or ransomware provisions the government has real evidence for. Malaysia has the caseload to justify a stronger cybercrime law. It doesn't have the justification to let a single search officer, unsupervised, hold the keys to a journalist's sources.

Sources & Citations

  1. Sinar Project: Cybercrimes Bill 2026 threat to expression and privacy
  2. Bernama: Dewan Rakyat Approves Cybercrimes Bill 2026
  3. SCMP: Malaysia cracks down on cybercrime with new rules
  4. Free Malaysia Today: Dewan Negara passes Cybercrimes Bill 2026
  5. EFF: Canada Is Forging Ahead with Its Dangerous Surveillance Bill