Snapshot of Legal Developments – Q2 of 2016
This marks a new series of articles that I am writing, with the aim of providing you with a snapshot of important legal developments to keep you informed of the significant legal developments in the technology, media and telecommunications sphere in Malaysia on a quarterly basis. Issuance of Compounding Regulations pursuant to the Personal Data Protection Act 2010 On 15 March 2016, the Commissioner issued the Personal Data Protection (Compounding of Offences) Regulations 2016 (“Compounding Regulations”). The Compounding Regulations provides a list of offences which are prescribed to be “compoundable offences”. For offences which are compoundable, the Commissioner may offer data users an opportunity to pay a monetary penalty (which penalty can be up to half of the maximum fine stipulated in the Personal Data Protection Act 2010 (“PDPA”) within the time period stipulated in the offer. If no payment is received within the stipulated period, prosecution for the offence will be instituted against the data user. It is important to note that only some and not all offences under the PDPA and its regulations are compoundable. The issuance of the Compounding Regulations points to the focus of the Commissioner and the Personal Data Protection Department (“PDP Department”) moving to the next phase of implementation of the PDPA, namely investigation and enforcement. Most data users would favour the use of compounds as it is likely to reduce the penalties for not complying with the PDPA significantly, as well as save both the prosecution’s and alleged offender’s time and costs, as parties would be spared the time and expense of court proceedings. Malaysia to step up cybersecurity measures in the capital market and national defence sectors On 21 March 2016, the Securities Commission Malaysia (“SC”) published a consultation paper seeking public feedback on the proposed regulatory framework relating to the management of cyber security risk by capital market participants. The SC recognises that with the increased dependency on information technology and Internet connectivity, there is a need to put in place cyber security policies and procedures to safeguard and protect the confidentiality, integrity and availability of information systems used by capital market participants. Sound management of cybersecurity risk has been identified as a critical component to further strengthen the resilience of the Malaysian capital markets. Towards this objective, the SC intends to introduce regulatory requirements to guide the capital market participants to achieve a certain state of cybersecurity resilience. The SC recommends that the board of directors of capital market participants set a clear direction and give adequate priority in their respective board’s agenda for the effective management of cybersecurity risk and require their senior management to develop and implement appropriate cybersecurity frameworks (which includes policies, procedures, awareness programmes and risk reporting mechanisms) throughout their organisations. On the defence front, the Deputy Defence Minister Datuk Seri Mohd Johari Baharum, during his keynote address at the Cyber Security Conference in conjunction with the 15th Defence Services Asia Exhibition and Conference on 20 April 2016, proposed a three-pronged approach to enhance cybersecurity in Malaysia. The three-pronged approach consists of: reorientation of the design philosophy of the Information Communications Technology (ICT) systems, in particular focusing on cyber defence systems to ensure all computing systems reflect uniform reliance; establishment of inter-disciplinary centres, specifically on the need to connect academia, the private sector, national laboratories and the government in sharing information and offering innovative and creative solutions; and getting the military defence and security community to provide “leadership by example” and “provide support to the national and global efforts in meeting cybersecurity challenges to the defence and security domains”. The above announcement was made in response to the rising threat of cyber-attacks in Malaysia. Cyber Security Malaysia (a government agency tasked with being Malaysia’s Cyber Security Reference and Specialist Centre) reported that 11,900 cybersecurity-related cases were recorded in 2015, as compared to only 1,038 cases recorded in 2007, which may lead to some legislative reforms to bolster and/or to introduce new legislation that deals with cybersecurity threats to Malaysia’s critical information infrastructure. Land Public Transport Commission to regulate ride-sharing and taxi-booking apps by Q4 of 2016 Following an endorsement by the Special Economic Committee chaired by the Prime Minister of Malaysia, ride-sharing and taxi-booking apps such as Uber and Grab may be subject to a new regulatory framework to be introduced by the Land Public Transport Commission (“SPAD”) by Q4 of 2016. This proposal was made in response to the rising tide of a new form of competition introduced by these third party ride-sharing and taxi-booking apps and complaints filed by the incumbent taxi companies. Although no draft of the regulatory framework has yet been circulated, it is understood that for the conventional taxi industry, a profit-sharing concept or guaranteed percentage of the day’s income for the taxi drivers will be introduced. For the private car drivers, they would be required to obtain a public service vehicle license and register themselves with SPAD for vetting purposes, before they are allowed to offer their services. Private car drivers are also required to send their vehicles for annual inspections and take up passenger insurance coverage, much like what taxi drivers are currently required to adhere to. It is also understood that this third-party ride-sharing and taxi-booking companies may be subject to local taxation laws when the regulatory framework is introduced, as the government has realised that there is a potentially massive outflow of the Ringgit due to the widespread use of these booking apps. Several laws, such as the Land Public Transport Act 2010, Road Transport Act 1987 and Communications and Multimedia Act 1998, will need to be amended to facilitate these new changes. The Amendment Bills may be tabled in Parliament during its sitting in October 2016, and “if everything goes well, a new dawn of taxi industry may begin the end of the year,” SPAD chairman said. Spectrum reallocation in the telecommunications industry On 27 January 2016, the Prime Minister of Malaysia, Dato Sri Mohd Najib bin Razak, during the Budget 2016 recalibration, announced that
Snapshot of Legal Developments – Q2 of 2016 Read More »






