KUALA LUMPUR: The Personal Data Protection Department (JPDP) has opened an investigation into Maxis over the unauthorised disclosure of customer account and billing data. The department said it is acting under the Personal Data Protection Principles and Section 130 of the Personal Data Protection Act 2010 in relation to the unlawful collection or disclosure of personal data.
The case began with the leak of private account and billing details belonging to Khairul Aming, a cosmetics entrepreneur and social media personality. A user on Threads publicly claimed to hold details of his phone bill, including an alleged outstanding balance of RM498 and records of digital spending.
JPDP warned that it will take enforcement action and impose the corresponding penalties if the telecommunications company is found to have breached the law. The warning was issued as the department confirmed it is examining the case, signalling that the matter is being treated as a possible breach of statutory obligations rather than an isolated customer complaint.
How the case came to light
Communications Minister Datuk Fahmi Fadzil directed the Malaysian Communications and Multimedia Commission (MCMC) to obtain a full report on the matter. Speaking at the International Regulators Conference (IRC) 2026 in Kuala Lumpur, he said the allegations posted on Threads indicated that unauthorised parties were able to view sensitive data held in the company's internal systems.
- JPDP investigation under the PDPA 2010
- MCMC instructed to obtain a full report
- Allegations of unauthorised access to internal systems
- Company representatives said to be contacting Khairul Aming
Fahmi said he had met representatives of the company, who told him they are in contact with Khairul Aming to deal with the matter. He stressed that sharing personally identifiable information without consent is a serious offence under the PDPA, and urged other victims to lodge reports with the MCMC so that a chain of evidence can be built.
JPDP is conducting an investigation under the Personal Data Protection Principles and Section 130 of the Personal Data Protection Act 2010 in relation to the unlawful collection or disclosure of personal data, it said.
The seven principles that bind data controllers
JPDP reminded all data controllers that they are bound by seven core principles requiring customer data to be safeguarded against unauthorised access. Under the PDPA those principles cover lawful grounds for processing, notice and choice, limits on disclosure, security, retention, data integrity and access, and they apply to any organisation that processes personal data in a commercial transaction.
The department called on companies to strengthen technical and organisational security measures so that data storage systems and networks meet adequate security standards. That wording points to controls such as access management, encryption, monitoring and staff procedures, and to the need to show that they are in place rather than merely intended.
- Lawful grounds for processing personal data
- Notice and choice for the individual
- Limits on disclosure to third parties
- Security, retention, integrity and access obligations
Why billing data attracts attention
Telecommunications billing records carry more than a monthly figure. They link an identity to a phone number, to usage patterns and to spending behaviour, and they are often the data set against which other accounts are verified. A leak of that material can support fraud, impersonation and social engineering, which is why regulators treat unauthorised disclosure as a serious matter rather than a minor privacy nuisance.
The JPDP reminded all data controllers that they are bound by seven core principles requiring customer data to be safeguarded against unauthorised access.
The disclosure also raises the question of how far inside the organisation the access extended. The minister's remarks referred to sensitive data held in the company's internal systems, which suggests the concern is not only with what was published but with who was able to look at it. Investigations of this kind typically examine access logs, permissions and the accounts used to query billing records.
What it means for Malaysia's cloud and data centre market
For organisations in Malaysia, the case is a reminder that data protection obligations follow the data wherever it is stored. Whether records sit in an on-premise system, a private cloud or a managed data centre, the data controller remains answerable for access controls, monitoring and the ability to produce records when an investigation begins.
Demand tends to follow for services that make compliance demonstrable: logging and audit trails, encryption and key management, identity and access governance, and the segregation that keeps one compromised account from reaching an entire customer database. Buyers in regulated sectors increasingly ask providers to evidence these controls before contracts are signed.
The wider signal for Malaysia's cloud and data centre market is that enforcement attention is now part of the operating environment. Providers that can support data residency, clear audit trails and documented incident procedures give their customers a defensible position when a regulator asks how personal data was protected. That is a commercial advantage as much as a compliance one.
Source: Malay Mail



