Communications, Media and Technology

With the development and growth in the communications, media and technology, sectors, the firm has correspondingly built a practice focused on these industries, particularly in the areas of information technology, outsourcing, e-commerce, communications, media and entertainment, to help our clients to succeed in this environment, not just by understanding the factors that drive change but by implementing practical solutions that enhance productivity, competitiveness and value. We have advised domestic and international clients in this sector, as well as clients in various other industries, including financial institutions, in their procurement of IT solutions and outsourcing. In addition to this, we advise the Government and regulators on regulatory policy in the digital economy.

Our ability to harness the relevant skills and expertise across various practices enables us to advise on a full range of issues ranging from corporate transactions such as mergers and acquisitions and joint ventures, to outsourcing and facilities management, software and hardware systems acquisitions and procurement, intellectual property rights, and the licensing, compliance and regulation issues in highly regulated sectors.

With the breadth of our experience, and our continued close working relationship with industry regulators, our team is able to provide the requisite expertise and insight into the commercial and regulatory environment of the industry.

Latest insights

Introduction

The Cybercrimes Bill 2026 (“the Bill”) would repeal the Computer Crimes Act 1997 and establish a broader Malaysian framework for preventing, investigating and prosecuting cybercrimes.

In its efforts to become a global technological hub by 2030, the Malaysian government designed this Bill to complement the other existing laws on online harm including the Online Safety Act 2025 and the Cyber Security Act 2024, in order to enhance Malaysia’s national cybersecurity.

The Bill has extra-territorial effect where the relevant computer system, programme or computer data is in Malaysia, connected to Malaysia, sent to or used with a Malaysian system, or where the affected person is a Malaysian citizen. This means offshore platform operations may still be caught where Malaysian users, systems or data flows are involved.

Service Providers

A key issue for platforms is the Bill’s broad definition of “service provider”. It covers persons, whether licensed under the Communications and Multimedia Act 1998 or not, who enable users to communicate via computer systems, process or store computer data for communications services or users, or provide information and communication services.

Social media, messaging, hosting and similar services are therefore likely to fall within the Bill’s service-provider duties, data-retention requirements and law-enforcement assistance obligations.

Key Offences

The Bill enhances the CCA’s offences for unauthorised access, interception, interference with computer data or systems, misuse of devices or credentials, computer-related forgery and computer-related fraud.

These provisions primarily target bad actors. However, they have been enhanced and are relevant to platform security, incident response, evidence preservation and cooperation with investigations.

The content-related offences are particularly noteworthy.

  • Section 22 recognises the offence of identity theft by criminalising the possession or control of any identity information of another person with the intention to commit or facilitate the commission of an offence.
  • Section 23 criminalises making available computer-generated or manipulated audio or visual content that resembles a real person, object, place, entity or event, falsely appears authentic, and is intended to commit or facilitate an offence.
  • Section 24 criminalises making intimate images available by means of a computer system, with higher penalties where the conduct is intended to humiliate, harm, coerce or intimidate the person depicted. The explanatory statement expressly covers AI-generated, manipulated or synthesised intimate images, including content generated using generative AI platforms.

The Bill imposes a general duty on service providers to take “necessary measures” to prevent their services from being used for cybercrimes. The scope of “necessary measures” is not clearly defined and creates compliance uncertainty.

An authorised officer, in consultation with the Malaysian Communications and Multimedia Commission, may issue written notices requiring service providers to prevent cybercrimes or assist enforcement, with non-compliance punishable by a fine of up to RM1 million, imprisonment of up to 10 years, or both.

Investigation Powers

The Bill gives the relevant law enforcement authorities sweeping investigation powers, including preservation and disclosure of computer data, real-time collection of traffic data, and interception or retention of content data within a service provider’s technical capability.

The Bill also places an obligation on platforms to supply the authorities with the necessary password, encryption code, decryption code, software or hardware and any other means required to enable comprehension of recorded information in the computer system or computer data during investigations.

Section 41 of the Bill grants the Public Prosecutor discretionary powers to authorise an enforcement officer to enter any premises and install any device for the interception, retention, collection or recording of content data.

These powers are accompanied by confidentiality obligations and significant penalties for non-compliance.

The Minister may also require service providers to retain specified non-content computer data where necessary for national security or public safety and proportionate to law-enforcement purposes.

Comments

Overall, platforms should expect increased exposure to law enforcement requests, data-handling obligations, confidentiality restrictions and operational requirements to prevent misuse of their services.

Collectively, the social media and internet messaging licensing regime under the Communications and Multimedia Act 1998, the Cyber Security Act 2024, the Online Safety Act 2025 and this Bill create a dense web of regulatory obligations for digital platforms.

While the policy intent of combating cybercrimes and harmful content is well-intentioned, there is a risk of regulatory overreach. The cumulative effect of expansive content-takedown powers, broadly-defined “necessary measures” obligations, mandatory data retention requirements, and wide-ranging enforcement discretions may have an impact on freedom of speech and burden platforms with disproportionate compliance costs.

In practice, law enforcement authorities may focus on policing platform operators rather than pursuing actual threat actors and irresponsible users who create and disseminate harmful content. The scope for regulatory intrusion into user privacy—through data retention and real-time interception powers—also warrants careful monitoring.

A proportionate and effective framework should balance online safety objectives against free expression, privacy interests, and the need to target enforcement resources at those who cause actual harm.

This article is for general informational purposes only and does not constitute legal advice. Please contact us if you require advice on how these developments may affect your business.

Article
Communications, Media and Technology

The New Cybercrimes Bill – Necessary Protection Or Overregulating The Digital Space

The Personal Data Protection Commissioner’s Office (“JPDP”) has issued three new non-binding guidelines under the Personal Data Protection Act 2010 (“PDPA”): Data Protection by Design, Data Protection Impact Assessment, and Automated Decision-Making and Profiling. Together, they advance Malaysia’s data protection framework from reactive compliance to proactive, risk-based governance aligned with global standards.

Data Protection by Design

The DPbD Guideline requires embedding personal data protection throughout the data processing lifecycle—from design to decommissioning. It is structured around proactiveness, end-to-end protection, transparency, and user-centricity, applying these across the seven Personal Data Protection Principles. The DPbD Guideline encourages a risk-based approach tailored to each organisation’s processing activities.

Data Protection Impact Assessment

The DPIA Guideline provides guidance on identifying, assessing, and managing risks in personal data processing. A DPIA is required where processing is likely to result in high risk—determined quantitatively (more than 20,000 data subjects, or 10,000 data subjects where sensitive personal data (including financial data) is involved) or qualitatively (potential legal or significant effects on the data subject, systematic monitoring of the data subject, use of innovative technologies, denial or restriction of the data subject’s rights, tracking of the data subject’s location or behaviour, targeting of children or vulnerable individuals, and automated decision-making and profiling that present a high risk to the data subject). The Guideline prescribes the five-step “DEICA” methodology (Describe, Evaluate, Identify, Consider, Assess) and requires that DPIAs be refreshed every two years.

Automated Decision-Making and Profiling

The ADMP Guideline addresses automated systems used in personal data processing, despite the PDPA not containing specific provisions on such activities. It applies where outcomes may have legal or significant effects on data subjects (e.g., financial, employment, or service access decisions). Compliance with the Notice and Choice Principle is required, preserving the data subject’s right to withdraw consent. Notably, AI must not be the sole factor in decisions concerning data subjects, and the use of ADMP itself triggers the requirement for a DPIA.

JPDP’s power to issue guidelines

The PDPA confers on JPDP functions that include issuing guidance. Each of the three documents—the DPbD, DPIA and ADMP Guidelines—expressly records that it is issued by JPDP pursuant to subsection 48(g) of PDPA. They supplement the Act and related subsidiary instruments and are not intended to override them or to be prescriptive.

Are the Guidelines binding or legally effective?

The DPbD, DPIA and ADMP Guidelines provide guidance and promote good practice; they expressly state that they supplement and do not override the Act or subsidiary legislation. A failure to follow a Guideline does not, by itself, constitute an offence unless such non-compliance triggers a breach of the PDPA or subsidiary legislation.      

Conclusion

Taken together, these guidelines form a cohesive framework reinforcing the obligations of data controllers and processors under the PDPA. The DPbD Guideline embeds privacy at the design stage, the DPIA Guideline ensures high-risk processing is rigorously assessed, and the ADMP Guideline addresses the particular challenges of automated technologies and AI.

If you have any questions or require any additional information, please contact Nadarashnaraj Sargunaraj or the partner you usually deal with in Zaid Ibrahim & Co. This alert was prepared with the assistance of Hana Wong Xin Yi, Associate in Zaid Ibrahim & Co.

This alert is for general information only and is not a substitute for legal advice.

Article
Communications, Media and Technology

Design. Assess. Automate—Safely: Malaysia’s New PDPA Guidelines at a Glance

As the world accelerates into the era of the Fourth Industrial Revolution, Malaysia is taking bold steps to secure its place at the forefront of digital transformation. Through the myDIGITAL initiative and the Malaysia Digital Economy Blueprint, the nation aims to evolve into a high-income, tech-driven powerhouse by 2030. Central to this vision are the development of robust data centre infrastructure and the strategic integration of artificial intelligence. In this article, our partners Cheong Yuen Wei, and Senior Associate Vivienne Caitlin Michael explore Malaysia’s digital ambitions, the opportunities that lie ahead, and the challenges of building a future-ready, inclusive digital economy in the ASEAN region.

Read the full article here.

Publication
Communications, Media and Technology

Lexology In-Depth: Artificial Intelligence Law Malaysia

The Malaysian Communications and Multimedia Commission (“MCMC”) announced on 1 August 2024 that a new regulatory framework for Internet messaging service and social media service will come into effect on 1 January 2025.

Two Ministerial orders were gazetted on 1 August 2024 to amend the following subsidiary legislation under the Communications and Multimedia Act 1998 (“CMA”):

(i)       Communications and Multimedia (Licensing) Regulations 2000; and

(ii)      Communications and Multimedia (Licensing) (Exemption) Order 2000

With the amendments, service providers of “Internet messaging services” and “social media services” with more than 8 million users in Malaysia must be registered under an Applications Service Provider Class (“ASP (C)”) licence under the CMA (collectively referred to as the “Relevant Service Providers”).

“Internet messaging services” and “social media services” are defined as follows:

Internet messaging services” means an applications service which utilizes Internet access service that enables a user to communicate any form of messages with another user.

Social media services” means an applications service which utilizes Internet access service that enables two or more users to create, upload, share, disseminate or modify content.

MCMC has also published an Information Paper and FAQ Guide on the new licensing framework which can be accessed here.

MCMC has stated that end users of services offered by these Relevant Service Providers will not be affected by the new regulatory framework. It also reiterated that end users can expect a safer online environment, better protection against harmful content, and clearer avenues for addressing complaints and concerns.

The Relevant Service Providers are given a grace period of five months from 1 August 2024 to apply for the ASP (C) licence and comply with the relevant licensing requirements. The validity period for ASP (C) licence held by the Relevant Service Providers is one year from the registration date and the licence is required to be renewed annually.

For further enquiries, you may contact Nadarashnaraj Sargunaraj, Stanley Lee Wai Jin,  Vivienne Caitlin Michael of Zaid Ibrahim & Co.

Article
Communications, Media and Technology

Gone Viral!!! New Licensing Framework for Internet Messaging and Social Media Platforms in Malaysia!!

This article highlights predictions from Global KPMG Legal Services leadership from around the world on how data, privacy and cyber security issues will affect the future of legal functions and legal practice. As predictions, they are not intended to guarantee any future outcomes.

Today’s legal teams are challenged by rapid technological innovations. Generative artificial intelligence (gen AI) and other new technologies are being adopted across legal functions and broader businesses at breakneck speed. While productivity is being pushed to new heights, organizations are being exposed to a new range of risks, including data privacy breaches, loss of attorney-client privilege, heightened regulatory scrutiny, ransomware and related reputational damage.

At the same time, new abilities to access, manipulate and analyze huge pools of data are compelling legal professionals, regulators and policy innovators to balance technology’s potential to drive positive social change against the dangers of exposing large swathes of sensitive personal information.

How will these trends reshape the legal functions of the future? Here are KPMG professionals’ top five predictions:

1. As gen AI becomes ever more embedded into legal function processes, legal teams will need to understand how and when to keep humans in the loop to maintain the skills needed to guard against the related risks.

The application of gen AI and other new technologies to legal work will significantly increase efficiency and productivity. These gains will grow as legal professionals get more comfortable with these powerful solutions and continue to develop more constructive ways to employ them.

Dependence on gen AI will grow apace, however, and legal teams will need to stay vigilant about the attendant risks. For example, using gen AI to inform legal advice could lead to data breaches that could affect privilege. And eventually, as gen AI subsumes ever more routine legal activities previously done by junior lawyers and paralegals, there will be fewer people in the organization with the skills to do that type of work.

Legal professionals will need to avoid the tendency to simply accept that a computer’s output is correct without questioning the reasoning behind it. They will need to develop the skills to work backwards from the output to explain how a legal conclusion was derived and independently verify whether it is accurate. Attorneys will also need to be purposeful in determining which processes are a good fit for AI and where they still need to maintain the skills to verify the legitimacy and accuracy of AI output.

2. A raft of new legislation will emerge to address a wide array of AI-related issues.

As new AI legislation is enacted, legal teams will move beyond building AI for their own use cases to advising their businesses on the AI implementation. Legal departments will need to understand all of these different rules so they can establish legal frameworks that enable the organization to innovate and use AI. This use must follow ever-evolving new laws and regulations and must proceed in a safe and trusted way.

Within these frameworks, legal teams need to set business-optimized guardrails so they can make the most of business opportunities while preventing their organizations from incurring risk.

Smart use of technology will be a key to managing these new compliance obligations. gen AI and large language model AI can ingest, decipher, summarize and automate data and regulatory and compliance rules to a much wider degree than any current technology. Legal professionals who learn how to use technology for both improving productivity and policing its use will have a distinct competitive advantage.

3. Privacy laws and approaches to open data innovation will continue to diverge. The more AI is relied on, the more the risks increase, leading to more rigorous requirements aimed at protecting personal data on one hand while enabling its use for productivity gains and positive social change on the other.

Revolutionary AI systems have enormous potential to help solve various societal problems, such as disease and vendor diversity-based discrimination. However, these systems require copious amounts of personal data to create reliable statistical conclusions, raising issues about whether the right permissions and safeguards are in place for processing that data.

Regulatory restrictions on data usage, such as data localization and data sovereignty rules, will continue to increase. However, there will be some push and pull as some jurisdictions, such as the UK, attempt to simplify those rules in order to encourage innovation, sharing of data and open data. For example, the EU Data Act aims to allow public authorities to make public data available for purposes of the wider community via a public data trust.

Legal teams are likely to increase their use of AI-enabled privacy technology to demonstrate compliance as new data protection legislation comes onstream. This technology can also make legal data analysis more efficient and ultimately help make legal decisions more consistent.

4. With gen AI’s ability to create and transform, data sources will become more opaque and harder to trace, leading to more data privacy and intellectual property disputes.

As machine learning, large language models and gen AI continue to advance and collect huge volumes of data, it will become increasingly difficult to trace and verify the sources used to train these technologies. Currently, we have seen disputes over AI’s use of copyrighted texts and artworks in generating new works. The inability to prove who “owns” a source of original data could frustrate attempts to gain intellectual property protection for AI-generated results.

Challenges in tracing data could also cause companies to run afoul of data privacy legislation by hampering their ability to comply with legislated data subject rights, such as access or erasure requests.

In-house privacy teams will need to expand their focus to streamline processes and controls and adapt to AI-related risks and regulations. Legal departments will also need to have the ability to quickly develop internal policies, procedures and controls to keep up with the pace of new usage.

5. Legal departments will be on the front lines of defending against cyber attacks and upholding organizational resilience.

Cyber security threats are likely to multiply in the future as cyber criminals become adept at using gen AI for writing ransomware, bypassing protections, spreading misinformation and other offences. Legal teams will be called on to respond to these risks on a number of fronts by:

  • advising companies on consistent policies for responding to and dealing with ransomware attacks
  • working with in-house technology or operational teams to implement or adopt appropriate cybersecurity technology to protect the organization’s data (in compliance with stricter data protection/cyber security laws).
  • educating people across the company on cyber risks, including the guardrails needed to mitigate those risks and what red flags to watch out for
  • ensuring that the people responsible for complying with data security and privacy legislation:
    • have the skills to understand the sources of cyber risks and related safeguards
    • maintain their human connections within the organization so they can ensure AI uses remain safe and secure.

Governments can also be expected to get involved to ensure businesses in their jurisdiction have appropriate cyber security policies and governance in place. In the near future, we are likely to see legislation enacted to mandate organizational resilience on adopting stronger cyber security technology and efficient response to cyber security breach. Legal professionals will need to help their organizations develop approaches to complying with these rules.

This article is prepared by Usman Wahid, Partner, Head of Technology Law at KPMG Law in the UK; Nadarashnaraj Sargunaraj, Head of Technology, Privacy and Cybersecurity, Zaid Ibrahim & Co. ; and Isabel Simpson, Partner, Data Protection, Technology and Telecommunications Practice Group lead, EMA.

Article
Communications, Media and Technology

5 predictions: How AI, data privacy and cyber security could transform legal practices

With the constant evolution of technology, the regulatory landscape has evolved to accommodate the dynamic nature of financial technology. Regulatory bodies are actively engaging in dialogue with industry players to ensure that the sector is up to date and relevant while maintaining the integrity of the financial system.

The regulatory environment in Malaysia reflects a balance between fostering technological advancements and safeguarding the interests of both businesses and consumers in the rapidly evolving fintech ecosystem. In this article Jonathan Lim Hon Kiat, Co-Head Corporate TMT team highlights the key regulatory developments in Malaysia in 2023.

Publication
Communications, Media and Technology

Fintech Developments in Malaysia Highlights