Is corporate Malaysia serious about protecting our data?


FOR Malaysians, the cycle has become exhaustingly predictable. From massive ransomware attacks crippling statutory bodies to recent headlines of employees casually leaking sensitive customer billing details online, the public is caught in a continuous loop of data compromises.

While the nature of these threats varies wildly – ranging from highly sophisticated, artificial intelligence-driven external cyberattacks to rudimentary internal snooping – the corporate response is almost always identical. The public is inevitably met with a standard public relations script: The company assures us it was an “isolated incident”, claims no broader systems were compromised and reiterates that they take data privacy “very seriously”.

However, as these incidents compound, a critical legal and governance question must be asked: How can the public independently verify these claims?

When a breach occurs, how do we know if the data controller truly implemented all necessary and reasonable security measures prior to the failure, or if their architecture was fundamentally inadequate from the start?

This is particularly relevant when examining insider threats.

If a company’s system architecture allows an employee to casually browse a customer’s sensitive billing or identification details without a verified, logged business justification, it points to a systemic failure in basic internal access controls. If an organisation fails to implement fundamental “Zero Trust” protocols internally, it is difficult to trust their capacity to defend against complex, external cyber threats.

Recognising the importance of these risks, the Personal Data Protection Department earlier this year issued guidelines on Data Protection by Design (DPbD) and Data Protection Impact Assessments (DPIA).

These guidelines should not be treated as mere administrative guidance. DPbD encourages organisations to build privacy safeguards into their systems from the outset, rather than addressing weaknesses only after deployment. Where proposed data processing is likely to pose a high risk, the DPIA requires data controllers to identify, assess and reduce those risks before processing begins.

Yet, the persistent pattern of data leaks suggests that much of corporate Malaysia is treating these critical guidelines as mere paperwork exercises to be filed away, rather than architectural mandates to be engineered into their daily operations.

We cannot continue to accept a culture where data security is only prioritised after a crisis has occurred.

Suing a rogue employee or issuing an apology after data has already surfaced online or on the dark web is purely reactive.

To break this loop, regulatory oversight must fundamentally shift. Regulators must move beyond issuing post-incident fines and begin conducting proactive, unannounced audits of corporate access controls.

Data controllers must be compelled to actively demonstrate exactly how data protection principles are hardcoded into their systems.

Until companies are held accountable for their internal architecture before a breach happens, the public will remain vulnerable to the next “isolated incident”.

THULASY SUPPIAH

Kuala Lumpur

The writer is a lawyer focusing on artificial intelligence, data centres and cybersecurity.

Get 20% OFF The Star Digital Access

Monthly Plan

RM 13.90/month

RM 11.12/month

Billed as RM 11.12 for the 1st month, RM 13.90 thereafter.

Best Value

Annual Plan

RM 12.33/month

RM 9.87/month

Billed as RM 118.40 for the 1st year, RM 148 thereafter.

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Letters

Be mindful of those in need of public transport�
Rehabilitation programmes must evolve with the times�
Every story shapes a child�
Letting Malaysia fly on the global stage again
Why local products must win on value
Every child's right to belong: Why Malaysia must end marriage-based citizenship discrimination
Understanding and cooperation appreciated during CRS optimisation period
A wake-up call for Malaysia’s trade strategy
No one should fall through the cracks
Should litigants write court orders?

Others Also Read