On 1 July 2026, the Cybercrimes Bill 2026 was passed in the Malaysian Parliament to replace the outdated Computer Crimes Act 1997. While meant to address modern cyber offences like AI scams and identity theft, a report by ARTICLE 19 warns that its vague language and broad scope risk turning the bill into a weapon for state censorship. Coming at a time when digital freedoms in Malaysia are already under fire, the bill effectively hands the government a new tool to suppress dissent, compounding existing overreach under the Communication and Multimedia Act 1998 (CMA), the Cybersecurity Act, and the Online Safety Act (ONSA).
Key concerns of the bill include surveillance and censorship abuses, significant unchecked enforcement powers as well as deficient safeguards. The bill’s primary danger lies in its lack of human rights and procedural safeguards, granting the state unaccountable control over computer-related activities. Warrantless searches and seizures are allowed if “an authorised officer is satisfied” that “he has reasonable cause to believe” that obtaining a search warrant would “adversely affect” the investigation. These authorised officers include any police officer, public officer, or officer of the Commission (Malaysian Communication and Multimedia Commission (MCMC)) as determined by the Minister.
Under the provisions of Section 36, authorised officers can compel the disclosure of passwords, encryption or decryption codes, and hardware or software. Furthermore, Sections 38 and 39 allow them to order the preservation and forced disclosure of user data simply if they deem it “reasonably required” for an investigation. Permitting such invasive access in the absence of independent judicial oversight directly violates the right to privacy and invites systemic surveillance abuse.