Malaysia data protection

Malaysia's New MyKad Needs a Statutory Data Regime Before Banks and Telcos Get Access to It

The new MyKad's biometric database sits behind a PDPA that exempts government, leaving commercial uses and age-verification plans without clear rules.

New MyKad and MyDigital ID at a glance People of Internet Research · Malaysia ~24M People covered by new MyKad Cardholders in the national ID rol… 53 Security features on card Many to be added progressively. 12M MyDigital ID registrations As of end of June 2026. peopleofinternet.com
New MyKad and MyDigital ID at a glance People of Internet Research · Malaysia ~24M People covered by new MyKad 53 Security features on card 12M MyDigital ID registrations peopleofinternet.com

Key Takeaways

Malaysia's National Registration Department (JPN) opened applications on 17 September 2026 for a new-generation MyKad, a national ID for about 24 million people, according to Biometric Update. The card carries 53 security features, a dual-interface chip and support for live facial matching against JPN records. The technology is not the problem. The problem is that the legal regime for the biometric database behind it is unclear.

The case for the card

The strongest argument for the upgrade is fraud resistance. A polycarbonate card with layered security features and a chip that can be checked against a central record is harder to forge than an older card. Identity fraud harms citizens directly, and a national ID that relying parties can trust lowers the cost of opening a bank account, registering a SIM or proving eligibility for a service. JPN has also shown restraint on one point: the QR code is, per the same report, "currently restricted to authorized enforcement use, cannot be read by ordinary smartphone cameras and is not intended for payments." Limiting a feature at launch is a sensible way to start.

That argument deserves respect, and it is why this piece does not oppose the card. Our objection is narrower: a stronger credential makes the rules governing the data behind it more important, not less.

The legal gap

The Personal Data Protection Act 2010 (Act 709) is the country's general data-protection statute. Section 3(1) says plainly that "This Act shall not apply to the Federal Government and State Governments." The statute text also frames the Act as regulating personal data in "commercial transactions," so it was never designed as a general limit on state databases.

So the biometric records JPN holds are not clearly covered by the PDPA's principles on notice, security, retention and access. Public-sector sharing is addressed elsewhere: the Data Sharing Act 2025 (Act 864), which the Digital Department hosts, sets a framework for exchange between government agencies. That is a different question from what rights a citizen has over their own face template held by a registry.

Legal commentary has long flagged the ambiguity. A Mondaq analysis notes that no court has interpreted the scope of the exemption, and that the definitions in the Interpretation Acts are broad enough that agencies could plausibly count as "government." It also notes that government-owned companies, having separate legal personality, are not exempt. Where a claim exists, it may lie in negligence rather than under the statute. That is thin protection for a database covering roughly 24 million people.

Where commercial use raises the stakes

The gap widens once the private sector arrives. NexG Bhd, the card's supplier, has pitched QR verification to telecommunications operators, banks and retail merchants and floated an optional eWallet, per Biometric Update. JPN has not activated any of this.

The result would be a hybrid: a government registry as the source of truth, private firms as the relying parties. Banks and telcos are covered by the PDPA for their own processing, but the registry they would query is not. No published rule currently says who audits the queries, what a bank may retain from a match result, or what redress exists if a facial match wrongly fails. Those are the questions a proportionate regime answers before launch. A pro-innovation stance does not mean skipping them. Commercial uptake depends on public trust, and trust depends on rules that people can read.

The age-verification collision

The timing matters because of the Online Safety Act 2025 debate. Malay Mail reported on 16 September that experts see risks in requiring MyKad or MyDigital ID for social-media age checks. Suhakam's Children's Commissioner warned that MyKad information could be leaked, stolen or misused, and MCMC's own consultation found stakeholders worried about centralised databases and about excluding stateless children, asylum seekers and refugees.

MyDigital ID registration linked to the new card opens on 1 October. MyDigital ID already had 12 million registrations as of the end of June, according to The Star, citing Deputy Prime Minister Ahmad Zahid Hamidi's parliamentary reply. If age checks route through the same identity layer, a service that started as a card upgrade becomes infrastructure for controlling access to speech platforms. That is a materially different risk profile. It argues for privacy-preserving age assurance, such as tokens that confirm "over 16" without disclosing identity, rather than presenting a national ID to every platform.

What a proportionate fix looks like

The card may well be a good product. The open question is whether the law around it will be ready by 1 October, when MyDigital ID registration linked to it opens. If not, Malaysia will have built a stronger identity credential on top of the same accountability gap.

Sources & Citations

  1. Personal Data Protection Act 2010 (Act 709) text
  2. Data Sharing Act 2025 (Act 864), Digital Department
  3. Biometric Update: Malaysia launches new MyKad
  4. Mondaq: Does the PDPA apply to government agencies?
  5. Malay Mail: MyKad for age verification
  6. The Star: MyDigital ID hits 12 million users