Malaysia's National Registration Department (JPN) opened applications on 17 September 2026 for a new-generation MyKad, a national ID for about 24 million people, according to Biometric Update. The card carries 53 security features, a dual-interface chip and support for live facial matching against JPN records. The technology is not the problem. The problem is that the legal regime for the biometric database behind it is unclear.
The case for the card
The strongest argument for the upgrade is fraud resistance. A polycarbonate card with layered security features and a chip that can be checked against a central record is harder to forge than an older card. Identity fraud harms citizens directly, and a national ID that relying parties can trust lowers the cost of opening a bank account, registering a SIM or proving eligibility for a service. JPN has also shown restraint on one point: the QR code is, per the same report, "currently restricted to authorized enforcement use, cannot be read by ordinary smartphone cameras and is not intended for payments." Limiting a feature at launch is a sensible way to start.
That argument deserves respect, and it is why this piece does not oppose the card. Our objection is narrower: a stronger credential makes the rules governing the data behind it more important, not less.
The legal gap
The Personal Data Protection Act 2010 (Act 709) is the country's general data-protection statute. Section 3(1) says plainly that "This Act shall not apply to the Federal Government and State Governments." The statute text also frames the Act as regulating personal data in "commercial transactions," so it was never designed as a general limit on state databases.
So the biometric records JPN holds are not clearly covered by the PDPA's principles on notice, security, retention and access. Public-sector sharing is addressed elsewhere: the Data Sharing Act 2025 (Act 864), which the Digital Department hosts, sets a framework for exchange between government agencies. That is a different question from what rights a citizen has over their own face template held by a registry.
Legal commentary has long flagged the ambiguity. A Mondaq analysis notes that no court has interpreted the scope of the exemption, and that the definitions in the Interpretation Acts are broad enough that agencies could plausibly count as "government." It also notes that government-owned companies, having separate legal personality, are not exempt. Where a claim exists, it may lie in negligence rather than under the statute. That is thin protection for a database covering roughly 24 million people.
Where commercial use raises the stakes
The gap widens once the private sector arrives. NexG Bhd, the card's supplier, has pitched QR verification to telecommunications operators, banks and retail merchants and floated an optional eWallet, per Biometric Update. JPN has not activated any of this.
The result would be a hybrid: a government registry as the source of truth, private firms as the relying parties. Banks and telcos are covered by the PDPA for their own processing, but the registry they would query is not. No published rule currently says who audits the queries, what a bank may retain from a match result, or what redress exists if a facial match wrongly fails. Those are the questions a proportionate regime answers before launch. A pro-innovation stance does not mean skipping them. Commercial uptake depends on public trust, and trust depends on rules that people can read.
The age-verification collision
The timing matters because of the Online Safety Act 2025 debate. Malay Mail reported on 16 September that experts see risks in requiring MyKad or MyDigital ID for social-media age checks. Suhakam's Children's Commissioner warned that MyKad information could be leaked, stolen or misused, and MCMC's own consultation found stakeholders worried about centralised databases and about excluding stateless children, asylum seekers and refugees.
MyDigital ID registration linked to the new card opens on 1 October. MyDigital ID already had 12 million registrations as of the end of June, according to The Star, citing Deputy Prime Minister Ahmad Zahid Hamidi's parliamentary reply. If age checks route through the same identity layer, a service that started as a card upgrade becomes infrastructure for controlling access to speech platforms. That is a materially different risk profile. It argues for privacy-preserving age assurance, such as tokens that confirm "over 16" without disclosing identity, rather than presenting a national ID to every platform.
What a proportionate fix looks like
- Bring the registry under a statute. Either amend the PDPA or pass a dedicated identity law setting purpose limits, retention rules, audit logging and an independent complaint route for the biometric database.
- Gate commercial access in law. Any bank or telco use of QR or facial matching should require a published rule on what may be retained, with a regulator empowered to suspend access.
- Keep enforcement-only means enforcement-only. Any widening of QR access should be announced and legislated, not switched on by supplier contract.
- Decouple age assurance from the national ID. Platforms should be able to accept privacy-preserving alternatives.
The card may well be a good product. The open question is whether the law around it will be ready by 1 October, when MyDigital ID registration linked to it opens. If not, Malaysia will have built a stronger identity credential on top of the same accountability gap.