• Home
  • News
    • Press Statements
    • Speeches
    • Bar News
    • AGMs and EGMs
    • In Memoriam
    • Legal and General News
    • Court Judgments
  • Members
    • Circulars
    • Sijil Annual and Payments
    • Benefits
    • Peer Support Network
    • Practice Management
    • Professional Development
    • Opportunities for Practice
    • Mentor-Mentee Programmes
    • Laws, BC Rulings and Practice Directions
    • Resources
    • Become a Member
  • Find
    • Legal Directories
    • BC Legal Aid Centres
    • State Bar Committees
    • Law Firms | Areas of Practice
    • Jobs
    • Useful forms
  • About Us
    • Malaysian Bar and Bar Council
    • President's Corner
    • Committees
    • Previous Committees
    • Contacts
    • Advertising
  • Public
    • Complaints
    • Legal Aid
    • Notices
    • Compensation Fund
  • Search
  • Login
Search for

New login method: If first-time login, the password is your NRIC No. Call 20502191 for help.

 
Lost your password? Remember Me

 
No User ID/Password for firm? Click here for more information. Forgot Firm Username/Password?

Set a new password

If you have lost your password, you must set a new password. To begin this process, please key in your 12-digit NRIC No. below.

Forgot Firm Username/ Password?

Please enter name of firm or registered email address, indicate whether you want to retrieve your firm's username or password, and click "Submit".

Username Password
 
Access to Member Portal

Please key in your membership number, and click "GO"

BC
Resume Practice Request

Please key in your membership number, and click "GO"

BC
Newly-Called Request

Please key in your pupil code, and click "Submit"

Pupil Code

Change Password


Please enter your Password and Confirm Password then click on the Change Password button.
You will receive a new password shortly. Use this new password to access the site.

Password:
Confirm Password:
 
Change Password


Shortcut
  • Legal Directory
  • Find a Job
  • CPD
  • Online Shop
  • e-Library
  • Payments
  • Complaints
  • Committees

Search the site

  • Search Me
Member Login
  • BC Online Facilities
  • Login Type 2
  • Login Type 3
  • Login Type 4
  • About Us
  • President's Corner
  • Press Statements
About Us
Malaysian Bar and Bar Council
  • About Us
  • Bar Council Members
  • Bar Council Secretariat
  • Elections
President's Corner
  • Roll of Presidents
  • Press Statements
Committees
  • * Committees | Introduction
  • Ad Hoc Committee on Conditional Fee Rules (Re Non-Personal Injuries)
  • Ad Hoc Committee on Conditional Fee Rules (Re Personal Injuries)
  • Ad Hoc Committee on Contempt of Court
  • Ad Hoc Committee on Legal Services Blueprint
  • Ad Hoc Committee on Personal Data Protection
  • Ad Hoc Pandemic Response
  • Ad Hoc Peer Support Network
  • Advocacy Training
  • Arbitration
  • Bahasa Melayu
  • Building
  • Child Rights
  • Civil Law
  • Committee on AMLA
  • Committee on Orang Asli Rights
  • Committee on Reform to the Legal Sector
  • Common Bar Course
  • Constitutional Law Committee
  • Construction Law
  • Conveyancing Practice
  • Corporate and Commercial Law
  • Court Liaison
  • Criminal Law
  • Cyberlaw
  • Environment and Climate Change
  • Family Law
  • Finance
  • Human Rights
  • Industrial and Employment Law
  • Intellectual Property
  • International Malaysia Law Conference 2022
  • International Malaysia Law Conference 2023
  • International Professional Services
  • Islamic Finance
  • IT, Innovation and Future in Technology
  • Law Reform and Special Areas
  • LawCare
  • Legal Databases Liaison
  • Legal Profession
  • Mediation
  • Migrants, Refugees and Immigration Affairs Committee
  • National Legal Aid
  • National Young Lawyers and Pupils
  • Personal Injury Claims and Awards
  • Professional Indemnity Insurance
  • Professional Standards and Development
  • Publications
  • Risk Management
  • Shipping and Admiralty Law
  • Small Firms Practice
  • Solicitors' Remuneration Enforcement
  • Sports
  • Syariah Law
  • Task Force on Independent Police Complaints and Misconduct Commission ("IPCMC") and Police Accountability
  • Women's Rights
  • Yayasan Bantuan Guaman Kebangsaan Committee
Previous Committees
  • * Previous Committees | Introduction
  • Ad Hoc Committee on Amendments to the LPA
  • Ad Hoc Committee on Anti-Money Laundering
  • Ad Hoc Committee on Benchmarking Law Firms
  • Ad Hoc Committee on Judicial Commission
  • Ad Hoc Committee On National Legal Aid Foundation
  • Ad Hoc Committee on Quality and Standards
  • Ad Hoc Committee on Rules and Regulations
  • Alternative Dispute Resolution
  • Gender Issues & Equal Opportunities (2005-2007)
  • Institutional and Law Reform
  • International Malaysia Law Conference 2012
  • International Malaysia Law Conference 2014
  • International Malaysia Law Conference 2016
  • International Malaysia Law Conference 2018
  • International Malaysia Law Conference 2020
  • LawCare Fund Management
  • Library
  • Malaysian Law Conference 2007
  • Malaysian Law Conference 2010
  • Motor Insurance Review Ad Hoc Committee
  • No-Fault Liability Scheme
  • Practice Management Support
  • Safer Malaysia
  • Standing Committee for the Promotion of Best Practices by Detaining Authorities (2005-2007)
  • Standing Committee on Court Rules (2005-2007)
  • Standing Committee on Eliminating Discrimination (2005-2007)
  • Standing Committee to Review LPA 1976
  • Study Loan
  • Task Force on Combined Rules of Court
  • Task Force to Review the Compendium of Personal Injury Awards
Contacts
  • Web Administrator
  • Complaints
  • Legal Aid Centres
  • State Bar Committees
  • Bar Council Secretariat
  • Bar Council Members
  • Bar Council
Advertising
  • Advertise with Bar Council
  • Go back to list
Press Release | Transparency and Protection of Privacy Crucial for Personal Data Collected through the MySejahtera Application 27 Feb 2023 6:16 pm

The Malaysian Bar refers to the recent Auditor-General’s Report pertaining to records stored in the MySejahtera application (“App”), which reveals a troubling state about leakage and possible misuse of data.  Among these causes for concern is a “super admin” account that has downloaded three million information sets through various IP (Internet Protocol) addresses.  Another disturbing fact is that the App has sustained 1.12 million attacks on it.1   

Apprehension regarding data security goes back to more than a year ago when the Malaysian Cabinet made the decision to appoint a corporate body to take over the management and maintenance of the App through appointment, as opposed to the usual open tender.  This decision was made by the Cabinet during a meeting in November 2021.2   Questions with regard to the decision were raised in a hearing on 24 March 2022 by the Parliament’s Public Accounts Commission.3 

The Malaysian Bar notes that our previous Health Minister, Khairy Jamaluddin, regularly stressed that the Government owns all personal data collected through the use of the App.  He also constantly emphasised that data collected from all 38 million registered users are protected by the Malaysian Government.4 

However, despite such assurances, there have been multiple reports that raise more questions.  These include the appointment of a corporate body to purchase the App as opposed to conducting an open tender,5 true ownership of the App, protection of privacy of App users, level of privacy accorded to all data collected, exposure of personal data to a foreign company, and the accountability of the corporate body appointed to purchase or license the App. 

Searches at the Companies Commission of Malaysia led to the finding that a Singaporean company, Entomo Pte Ltd, is the sole shareholder of Entomo Malaysia Sdn Bhd (previously known as KPISoft Malaysia Sdn Bhd).  The company claims to legally own the software used to develop the App.6  

Not only is it of grave concern that the appointment of Entomo Malaysia was not conducted through open tender, no agreement was entered into between the Malaysian Government and KPISoft Malaysia, aside from a Non-Disclosure Agreement (“NDA”).7  The fact that a foreign company is the sole shareholder of Entomo Malaysia and owns the software for the App, is also deeply perturbing.  It is also discovered that the Malaysian Government has no apparent control over a licensing deal between Entomo Malaysia and MySejahtera Sdn Bhd, giving the latter a perpetual licence to develop and support the App until 2025.8 

The Malaysian Bar further notes that the Minister of Communications and Digital, Fahmi Fadzil, has instructed Cyber Security Malaysia to carry out investigations into the audit findings.9  On this note, we urge the Government to release the details of the NDA, the events that led to confusion of ownership, and the true names of all service providers.  These disclosures should be made in the current Parliament sitting so that all issues can be debated to assure the public that national security and the privacy of App users are protected. 

The issue of ownership between the Malaysian Government and MySejahtera Sdn Bhd is indeed disturbing.10   The ownership of the App, all source codes, the relevant user interface, and all personal data collected through the App should have been fully owned by the Government, and this should have been established from the outset. 

Ownership and control of all personal data collected through the App is of utmost priority, as any entity or person armed with such massive data and the right technological tools will be able to map out demographics, social behaviours, and social norms with a greater degree of accuracy as compared to any other mobile application in Malaysia.  If not governed, this may lead to unregulated management and abuse of personal data collected, and at worst, possible breaches of privacy, social engineering, and data abuses affecting national security.

Liabilities and responsibilities of any corporate body having anything to do with the App should not just be governed by a contract between a corporate body and the Government; it should also be governed by a privacy regime in Malaysia to protect all personal data collected by the Malaysian Government or any entity collecting personal data on its behalf.  Currently, Malaysia does not have such a privacy regime. 

Personal data in Malaysia is governed by the Personal Data Protection Act 2010 (“PDPA”), of which the Malaysian Government and State Governments are excluded from this Act.  This Act is only applicable where personal data is collected in respect of commercial transactions, and is not applicable to personal data collected through the use of the App, as in this context, data is being collected and used for the purpose of public health.

With that in mind, the Malaysian Bar urges the Government to establish and enact a Privacy Act to protect the privacy of data collected by the Malaysian Government and/or State Governments, or any corporation under the aegis of one or the other. 

We also implore the Government to provide federal legislative framework on freedom of information laws so as to ensure transparency and accountability relating to Federal Government and State Government contracts, and provision of information. 

With Malaysia entering into the age of the Industrial Revolution 4.0, the protection of its citizen’s personal data is no longer a fringe benefit, but an absolute necessity.  With more users moving into the metaverse, the privacy and security of users are increasingly threatened, unless the problems in relation to security and privacy are nipped in the bud right now.  It is about time Malaysians are given the requisite protection from any possible manipulation by usage of the App. 

 

Karen Cheah Yee Lynn
President
Malaysian Bar 

27 February 2023


1 “Audit raises questions over MySejahtera records”, Free Malaysia Today, 16 February 2023. 
2 “PAC recommends Govt to take ownership of MySejahtera via MAMPU”, The Edge Markets, 4 October 2022. 
3 “Tindakan Susulan Kementerian Sains, Teknologi dan Inovasi (MOSTI), Kementerian Kesihatan Malaysia (KKM) dan Kementerian Kewangan (MOF) bagi Syor-Syor Laporan PAC Parlimen Berhubung Perolehan Vaksin COVID-19 dan Penggunaannya Terhadap Rakyat Malaysia”, Laporan Prosiding 08.03.2022 di dalam Laporan Jawatankuasa Khas Kira-Kira Wang Negara (PAC), Dewan Rakyat Parlimen Penggal Ke-14.
4 “MySejahtera app still under govt, not sold to private entity”, New Straits Times, 27 March 2022. 
5 “Appointment of private company via direct negotiation to manage MySejahtera is worrying, says Tok Mat”, The Star, 28 Mar 2022. 
6 “Singaporean Company Is MySejahtera Software Owner’s Sole Shareholder”, CodeBlue, 29 March 2022.
7 “Appointment of KPISoft to develop MySejahtera overpriced, inconsistent with govt procurement rules — PAC”, The Edge Markets, 4 October 2022. 
8 “MySJ To Get MySejahtera Intellectual Property, Licensing For RM338.6Mil From App Developer”, CodeBlue, 28 March 2022. 
9 “Cyber Security Malaysia probing audit findings on data leak”, Malaysiakini, 23 February 2023. 
10 “Khairy: Details of MySejahtera users safe and protected”, The Star, 29 Mar 2022.

© Copyright Reserved 2023. Bar Council Malaysia.
 

I'm a

 
 
 
 
 

I'm a