logo
‘Collection of metadata poses risks'

‘Collection of metadata poses risks'

The Star18-06-2025

PETALING JAYA: Like puzzle pieces scattered across a table, bits of digital data may appear meaningless on their own.
But with enough time, as well as location and behavioural clues, a recognisable picture can emerge.
That is the concern raised by cybersecurity experts over a government initiative to collect anonymised mobile phone data.
The Mobile Phone Data (MPD) programme, introduced by the Malaysian Communications and Multimedia Commission (MCMC), is intended to support public policy, particularly in tourism and infrastructure planning.
Although authorities have emphasised that the data excludes names and identification numbers, experts warn that by combining the anonymous data with other metadata such as tower location, timestamps and user behaviour, it could still expose individuals to reidentification and cyber threats.
According to AI Society president Dr Azree Shahrel Ahmad Nazri, even coarse location data such as cell tower logs can be used to build a person's detailed behavioural profile.
'From just a few days of movement data, researchers can predict who you are with over 90% accuracy,' he claimed when contacted.
'This is why metadata is not truly anonymous.'
MCMC, in a media briefing last week, clarified that IMEI numbers and SIM card IDs were not among the data fields requested.
However, Azree Shahrel cautioned that even without those identifiers, centralising metadata still poses significant cybersecurity risks.
He also warned that such repositories could become high-value targets for hackers, cybercriminals or foreign actors.
'If breached, this data could form a detailed map of user routines, enabling highly targeted attacks or surveillance,' he said.
He suggested that persistent identifiers, such as anonymised mobile numbers, be replaced with session-based tags, and that precise timestamps be aggregated to reduce the risk of tracking individuals.
Universiti Malaysia Sarawak lecturer Chuah Kee Man echoed those concerns, pointing out that the MPD does not currently violate the Personal Data Protection Act 2010 (PDPA), as anonymised metadata and government agencies fall outside its scope.
However, he argued that this legal blind spot still raises red flags.
'The collection is occurring without the public's explicit consent or even knowledge.
'And while it may not breach the PDPA directly, it creates ethical and legal issues surrounding the erosion of privacy rights,' he said.
He warned that once data is stored at this scale, it could potentially be used for political profiling, social control or surveillance.
'The integrity of how this data is used relies entirely on those managing it – both now and in the future,' he said.
He called for a shift in approach, including the principle of data minimisation, where only essential data is collected, and for the implementation of informed consent policies.
'If the government insists on collecting such data, it must demonstrate a clear need and adopt every possible measure to protect users,' he said.
Cybersecurity specialist Fong Choong Fook said public concern about the MPD programme is not unfounded, especially given previous data breaches involving government-linked agencies.
'One of the most notable cases was in 2017, when the personal data of 46 million Malaysians was leaked after the MCMC outsourced work to a contractor.
'Incidents like these continue to shape public scepticism,' he said.
The massive data breach in 2017, believed to affect almost the entire population of Malaysia, included lists of mobile phone numbers, identity card numbers, home addresses and SIM card data of 46.2 million customers from multiple mobile phone and mobile virtual network operators.
'Take note that the PDPA does not apply to MCMC. This means that if a data leak were to occur, MCMC would not be held liable,' he said, highlighting a gap in accountability.
Fong urged the government to be transparent about the anonymisation process and to release a clear set of guidelines outlining how the data is managed, what safeguards are in place and how privacy is protected.
'There should be a publicly accessible framework, or at least a white paper that can be scrutinised by independent experts.
'We cannot continue operating in a black box,' he said.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Parents alarmed as TikTok trend distracts teens, drains pocket money
Parents alarmed as TikTok trend distracts teens, drains pocket money

New Straits Times

time4 hours ago

  • New Straits Times

Parents alarmed as TikTok trend distracts teens, drains pocket money

GEORGE TOWN: Young people are becoming increasingly fixated on the TikTok trend known as "Player Knockout Battle" or "PK Battle", to the point that some are missing school and using their money to buy digital gifts. According to Kosmo!, PK Battle is a live competition between two social media users who compete to earn digital gifts from viewers. Losers are often subjected to various punishments, such as having flour thrown on their faces, being drenched with water, or being made to run outside late at night. Marketing officer Aina Azli, 45, said her 16-year-old daughter's behaviour had changed drastically after getting hooked on the trend, which is commonly livestreamed at all hours of the day. "She no longer focuses on her studies. She spends her time glued to her phone, laughing out loud and pointing at the screen, sometimes staying up until early morning and even skipping school just to watch it," she said. Another parent, known only as Rohaida, 46, said her 13-year-old son had been using his daily RM10 pocket money to buy digital gifts for PK Battle participants. "These gifts can cost as little as 35 sen or up to RM4. He has spent as much as RM50 a week on them," she said. Father of four Hakim Ismail, 42, urged the Malaysian Communications and Multimedia Commission (MCMC) to block the trend, warning of its potential impact on children's mental health. "We also urge the Royal Malaysia Police (PDRM) to investigate platforms that can negatively influence users' emotions and behaviour," he said. Previously, Pertubuhan Damai Revolusi Masyarakat president L. Francis said the MCMC and PDRM should take action, describing PK Battle as a harmful form of online gambling that wastes time and could trigger social issues, including extortion, bullying, and sexual exploitation.

Telegram didn't comply with many content removal requests, says Fahmi
Telegram didn't comply with many content removal requests, says Fahmi

Free Malaysia Today

time2 days ago

  • Free Malaysia Today

Telegram didn't comply with many content removal requests, says Fahmi

Communications minister Fahmi Fadzil said MCMC had flagged 1,188,528 pieces of harmful content across social media platforms as of June 24. KUALA LUMPUR : Telegram failed to comply with many of the requests made by the Malaysian Communications and Multimedia Commission to remove harmful content on the platform, says communications minister Fahmi Fadzil. Among all social media platforms, he said, Telegram has the lowest rate of compliance – less than 50% – to MCMC's requests to remove content. 'I have ordered MCMC to call Telegram for a meeting next week to discuss the issue,' he told reporters following an event at Pantai Dalam this morning. On June 19, MCMC filed a civil suit against Telegram and two of its channels for allegedly spreading harmful content that could erode trust in public institutions and threaten social order. MCMC said the two channels – 'Edisi Siasat' and 'Edisi Khas' – were found to have published content that violated provisions under the Communications and Multimedia Act 1998 (CMA). 'This marks the first such action taken against a social media platform provider, particularly since Telegram holds an application service provider (class) licence. 'The move follows Telegram's serious failure to address content that has been repeatedly reported to it, despite multiple negotiation and cooperation efforts by MCMC,' it said. Fahmi said that as of June 24, MCMC had flagged 1,188,528 pieces of harmful content across various social media platforms. However, only 173,642 of those requests were complied with. 'Of this number, 51% of the content removed were online gambling ads, while 24% were online scams. 'We will take strict action to ensure Malaysians do not become victims of cybercrime,' he said. He said MCMC can only make requests, but the platforms themselves have to do what is necessary to ensure the content cannot be accessed in the country.

Telegram ignored over half of Malaysia's takedown requests, says Fahmi
Telegram ignored over half of Malaysia's takedown requests, says Fahmi

Borneo Post

time2 days ago

  • Borneo Post

Telegram ignored over half of Malaysia's takedown requests, says Fahmi

Fahmi says Telegram has shown the lowest compliance rate among all major social media platforms in Malaysia, acting on fewer than half of MCMC's takedown requests. – The Borneo Post photo KUALA LUMPUR (June 28): Malaysian authorities are escalating pressure on Telegram after accusing the messaging platform of routinely ignoring requests to take down harmful content — a move that has led to a rare civil suit and threats of stricter regulation. In a Free Malaysia Today report, Communications Minister Datuk Fahmi Fadzil said Telegram has shown the lowest compliance rate among all major social media platforms in Malaysia, acting on fewer than half of the Malaysian Communications and Multimedia Commission's (MCMC) takedown requests. 'I have ordered MCMC to call Telegram for a meeting next week to discuss the issue,' Fahmi told reporters today after an event in Pantai Dalam. The remarks come days after MCMC filed a civil lawsuit against Telegram and two of its prominent channels — Edisi Siasat and Edisi Khas — for allegedly disseminating content that could erode trust in public institutions and threaten social order. The regulator said the two channels had published material in breach of Malaysia's Communications and Multimedia Act 1998 and that this was the first time legal action had been taken against a social media platform with a local licence. Telegram is registered as an application service provider (class) in Malaysia. 'The move follows Telegram's serious failure to address content that has been repeatedly reported to it, despite multiple negotiation and cooperation efforts by MCMC,' the commission said in a statement. Fahmi added that MCMC had flagged over 1.18 million pieces of harmful content across platforms as of June 24 this year. Only 173,642 of those were removed. 'Of this number, 51 per cent of the content removed were online gambling ads, while 24 per cent were online scams,' he said. 'We will take strict action to ensure Malaysians do not become victims of cybercrime.' While MCMC has no power to directly remove content itself, it can issue requests and expects platform providers to comply. Fahmi stressed that the platforms ultimately bear the responsibility for restricting access to such material in Malaysia. – Malay Mail fahmi fadzil harmful content take down request telegram

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store