Over the past week, Malaysians learned not through a public announcement, but through leaked information that the Malaysian Communications and Multimedia Commission (MCMC) had requested detailed mobile phone data from all major telcos in the country, including CelcomDigi, Maxis, U Mobile, TM, and YTL.
In its own official statement, MCMC confirmed that it had requested Mobile Phone Data from every major telco in Malaysia. They say the data is anonymised. They say itβs for official statistics, for network planning, for tourism, for policy-making.
Yesterday, the 5 telcos have also confirmed that they have complied with MCMCβs directive to submit Mobile Phone Data without Personally Identifiable Information.
But hereβs my fundamental question to the MCMC:
What does privacy mean to you?
Because to most Malaysians β to most users β what just happened doesnβt feel like planning. It feels like surveillance. Quietly executed, vaguely explained, and worryingly broad.
This Isnβt Just βDataβ β Itβs a Map of Our Lives

Even if names and IC numbers are removed, usage patterns including cell tower location data still paints a vivid picture of individual behaviour.
You donβt need someoneβs name when you can track:
- Where their phone sleeps at night (home),
- Where it wakes up in the morning (work),
- And how it moves hour by hour.
Thatβs not anonymised. Thatβs identity β reconstructed.
Call Logs? Internet Use? Why So Quiet?

Youβve said the data doesnβt include Personally Identifiable Information. But letβs be honest β you didnβt say it excludes call logs or Internet usage patterns either.
So letβs ask clearly:
- Are you collecting metadata like call time, duration, and frequency?
- Are you looking at data usage, browsing behaviour, or app patterns?
- How is this kind of granularity necessary for policymaking?
For the Ministry of Tourism (MOTAC), wouldnβt aggregate roaming stats, regional SIM activations, or tower handovers be enough?
Do we really need to trace where tourists go, when they call, and how they scroll?
Anonymised by Whom? Audited by Whom?
Youβve said telcos can either anonymise the data before sending it to you, or pass it on for you to process internally.
That raises more questions than it answers:
- What is the minimum standard for anonymisation?
- Who verifies that standard has been met?
- What encryption protocol is used to protect data in transit?
- Whoβs accountable once the data lands inside MCMCβs systems?
- And what prevents re-identification when all the ingredients are still there?
Anonymity isnβt just a checkbox β itβs a technical, ethical, and legal challenge.
Did You Not Have This Before?
Youβve framed this as a move to improve βgranular statistics.β That sounds useful. But it also sounds like a convenient answer.
So let me ask:
- What data did you rely on before this?
- If MCMC never had this kind of mobile device-level data before β how were broadband policies or tourism reports being generated all this time?
- If we were already planning with less data, is this level of intrusion actually necessary β or just more convenient?
- And if telcos already provide network KPIs β like signal strength, dropped call rates, and coverage gaps β how is this new dataset adding value beyond what they already submit?
PDPA and the Government Loophole

Under Section 45 of the Personal Data Protection Act (PDPA), government agencies may be exempt. That includes MCMC.
But letβs be clear:
Legal exemption is not the same as public accountability.
Just because you can request this data doesnβt mean you should. In fact, the lack of legal guardrails should mean even more transparency β not less.
Youβre collecting more data than any private company ever could. And yet, you operate outside the laws that govern them.
That should worry everyone.
βMutual Agreementβ Isnβt Public Consent
Youβve said this initiative was discussed with telcos, the Department of Statistics Malaysia (DOSM), the Ministry of Tourism, and even the UN.
Great. But none of those parties represent the public.
There was no public consultation, no transparency report, no opportunity for users to opt-in or opt-out.
βMutual agreementβ behind closed doors is not the same as informed consent.
20 Questions Malaysians Deserve Answers To

Youβve said your intention is to support evidence-based policymaking. Thatβs a good goal.
But data collection of this scale demands clear answers. Here are 20:
- What exact data are you collecting β and what are you not collecting?
- Are call logs, Internet activity, or app usage part of this dataset?
- Who determines whether the data is truly anonymised?
- Whatβs the minimum technical standard telcos must meet to process the data themselves?
- How is this different from what MNOs already submit in regular reports?
- How long is the data retained β and what safeguards exist?
- What encryption protocols are used for data in transit and storage?
- What does βanonymisedβ mean when you still usage logs and location data?
- Is there any risk of re-identification β and whoβs responsible if it happens?
- Who audits or oversees MCMCβs handling of this data?
- What legal protections apply to users if the data is leaked or misused?
- Will this become a routine data collection, or is it a one-off?
- Why is such detailed data necessary for tourism policy?
- Can you explain how this improves network planning in ways not already possible?
- Why wasnβt the public notified before the data was requested?
- Can users opt-out, or at least be informed when their data is used?
- Is this linked to any third-party data processors or foreign consultants?
- Will MCMC publish a full data transparency and privacy impact report?
- Why should Malaysians trust that this wonβt be misused β now or in the future?
- What does privacy mean to MCMC?
This Isnβt About Paranoia β Itβs About Trust
Iβm not against data. Iβm not against planning. Iβm not even against public policy using technology.
But I am against invisible decisions made without public knowledge.
Privacy isnβt just about hiding something β itβs about having control over how youβre seen, tracked, and used. Itβs about power. And right now, MCMC is holding all of it β with no meaningful oversight.
So hereβs what Iβm asking:
- Be honest about what youβre collecting.
- Justify why you need it β clearly and publicly.
- Put meaningful limits in place β and prove they work.
Until then, weβre not being paranoid.
Weβre just paying attention.
Sincerely,
A Malaysian who cares very much about his privacy β and the privacy of his fellow countrymen.
Source: https://tinyurl.com/ms4w24jv