Regional Round-Up: Malaysia Q2 2026

BNM Issues New Interoperable Fund Transfer Framework

On 30 June 2026, Bank Negara Malaysia (“BNM”) published the Interoperable Fund Transfer Framework (“IFTF”), which supersedes the Interoperable Credit Transfer Framework (“ICTF”) issued on 23 December 2019. The IFTF principally applies to licensed banks, licensed Islamic banks, prescribed development financial institutions, approved issuers of designated payment instruments, approved operators of payment systems and registered merchant acquirers.

The IFTF sets out requirements governing interoperable fund transfer services provided through Malaysia’s shared payment infrastructure – the Real-time Retail Payments Platform operated by Payments Network Malaysia Sdn. Bhd. (PayNet) – which connects bank accounts and non-bank e-money accounts and facilitates account-to-account (“A2A”) fund transfers and purchase transactions, including through interoperable Quick Response (“QR”) codes.

Key updates within the IFTF include:

  1. New requirements relating to cross-border A2A fund transfers and cross-border purchase transactions through QR codes. This is an expansion given the previous ICTF only addressed domestic A2A fund transfers;
  2. Phasing out of proprietary QR code networks by 30 June 2028, with no new merchants to be onboarded to such proprietary networks during the 2-year transition period;
  3. Widening of access to the shared payment infrastructure, with more types of financial institutions and other regulated entities in Malaysia being given access, subject to objective, non-discriminatory and risk-based access requirements; and
  4. Strengthening of and updates to rules relating to governance, competition, and oversight requirements.

Affected institutions should therefore review their QR payment arrangements, merchant onboarding processes, access or sponsorship arrangements, and operational readiness for cross-border services.

For more information, click here to read our Legal Update.

Malaysia Competition Law: MyCC's Enforcement Overhaul

The Competition (Amendment) Bill 2026 and the Competition Commission (Amendment) Bill 2026 (together, “Bills“), which amend the Competition Act 2010 (“CA 2010“) and the Competition Commission Act 2010, respectively, were tabled before Parliament on 23 June 2026. These Bills were passed by the Dewan Rakyat on 6 July 2026, with both scheduled to be tabled in the Dewan Negara during its sitting between 20 July and 4 August 2026.

The proposed amendments aim to strengthen various aspects of the CA 2010, including provisions relating to investigations and enforcement, and the Malaysia Competition Commission’s (“MyCC“) and Competition Appeal Tribunal’s decision-making procedures. These include:

  1. Broadened scope: The amendments expand the scope of the CA 2010 from just “commercial activity” to both “commercial activity” and “economic activity”. Additionally, under the Bills,  the prohibition on anti-competitive agreements will now apply to all forms of agreements, not just horizontal and vertical agreements.
  1. Greater investigative and enforcement powers: New powers will be introduced for MyCC including: (i) expanded powers to compel the production of information and documents; (ii) broader search and seizure powers; (iii) the power to issue warning letters to enterprises; and (iv) the power to impose late payment charges under competition laws.

  2. Greater incentives for cooperation with MyCC: These will take the form of: (i) a new offence for attempting to obstruct MyCC’s investigations and enforcement activities; (ii) a new settlement mechanism; (iii) a strengthened leniency regime; and (iv) a new whistleblower regime.

  3. Appeals: Appeals by any person, including MyCC, to the Malaysian High Court on questions of law and on the amount of financial penalties imposed, will now be allowed.

Businesses should track these developments closely.

For more information on the principal changes and their practical implications, please refer to our July 2026 Legal Update titled “Malaysia Competition Law: MyCC’s Enforcement Overhaul.

Cybercrime Bill 2026 Tabled and Passed by Dewan Negara

On 22 June 2026, the Cybercrime Bill 2026 (“Bill”) was tabled for first reading in the Malaysian Parliament. The Bill was passed by the Dewan Negara on 20 July 2026. This is a significant step in Malaysia’s efforts to strengthen its legal and enforcement framework against increasingly complex online threats. The Bill is intended to repeal the Computer Crimes Act 1997 (“CCA”) and to enable Malaysia to meet its international obligations under the Budapest Convention (Council of Europe Convention on Cybercrime) and the United Nations Convention Against Cybercrime.

The Bill significantly expands Malaysia’s cybercrime framework beyond the existing offences under the CCA, which principally address (i) unauthorised access to computer material; (ii) unauthorised access with intent to commit further offences; (iii) unauthorised modification of computer contents; and (iv) wrongful communication. In particular, it introduces specific offences addressing newer forms of cyber-enabled conduct, including (i) computer-related forgery and fraud; (ii) identity theft; (iii) transmission of computer-generated or manipulated content; and (iv) dissemination of intimate images.

The Bill also introduces a new category of offences relating to the National Digital Identity Service, which includes:

  1. knowingly sharing one’s credentials or other means of accessing one’s digital identity; and
  2. obtaining, retaining, supplying, transmitting or otherwise making available of another person’s credentials,

knowing or having reason to believe that such credentials will be used or likely to be used for the purpose of committing or facilitating the commission of an offence.

The Bill retains and updates certain existing cybercrime concepts, while introducing enhanced penalties and new offences aimed at modern cyber-enabled harms. It is a reflection of a broader approach to cybercrime regulation, extending beyond attacks against computer systems to address (i) the misuse of digital identities and credentials; (ii) computer-enabled fraud and forgery; (iii) harmful or manipulated digital content; and (iv) other forms of cyber-enabled harm.

Issuance of New Guidelines under the Malaysian Personal Data Protection Act 2010

On 30 April 2026, the Personal Data Protection Commissioner (“Commissioner”) issued three new Guidelines under the Personal Data Protection Act 2010 (“PDPA”), namely the: (i) Data Protection Impact Assessment (“DPIA”) Guideline; (ii) Data Protection by Design (“DPbD”) Guideline; and (iii) Automated Decision-Making and Profiling (“ADMP”) Guideline (collectively, the “Guidelines”). Together, these Guidelines provide practical guidance on how organisations should comply with their obligations under the PDPA.

The key areas addressed under each of the Guidelines are summarised as follows:

  1. DPIA Guideline: This sets out, among others, when and how data controllers should carry out DPIAs to identify, assess and manage personal data protection risks before proceeding with planned processing activities. A DPIA is required where processing is likely to result in high risk to data subjects, including where prescribed quantitative thresholds are met or qualitative factors indicate heightened risk, such as (i) processing that may have legal or otherwise significant effects on data subjects; (ii) systematic monitoring; (iii) use of innovative technologies; (iv) tracking; (v) processing involving children or vulnerable individuals; or (vi) high-risk automated decision-making and profiling. 

For more information, click here to read our Legal Update.

  1. DPbD Guideline: This provides guidance on applying a DPbD approach by encouraging data controllers and data processors to integrate personal data protection considerations and measures into the design and development of projects, systems, programmes, processes and technologies from the outset. The DPbD approach requires privacy considerations to be taken into account throughout the entire data processing lifecycle, by default, and promotes a proactive approach focused on anticipating and preventing privacy risks rather than reacting to data protection issues after they arise. The DPbD Guideline also identifies four core elements of DPbD, namely, (i) proactiveness; (ii) end-to-end protection; (iii) transparency; and (iv) user-centricity.

For more information, click here to read our Legal Update.

  1. ADMP Guideline: This sets out guidance on the processing of personal data involving ADMP, including where artificial intelligence is used. It confirms that, although the PDPA does not currently contain specific provisions regulating ADMP, such processing nonetheless remains subject to the Personal Data Protection Principles under the PDPA. The ADMP Guideline clarifies the two constituent concepts: (i) “Automated decision-making”, which refers to decisions made wholly or partly by automated means, with minimal human involvement; and (ii) “Profiling”, which refers to the automated processing of personal data to evaluate, analyse or predict aspects relating to a data subject, such as their preferences, behaviour or characteristics. The ADMP Guideline applies where an ADMP process may produce legal effects concerning a data subject, or otherwise significantly affect them. Data protection officers are required to exercise their judgement in assessing, on a case-by-case basis, whether the threshold has been met in respect of any given processing activity.

For more information, click here to read our Legal Update.

Federal Court Finds Company Director can Simultaneously be an Employee Despite the Absence of a Written Employment Contract: Acexide Technology Sdn Bhd & Anor v Chang Heng Keong & Another Appeal [2026] CLJU 2221

Facts

In a case pertaining to claims of unlawful dismissal, the two respondents (Chang and Woon) were directors in the appellant Company and held 36% and 10% shareholding, respectively, with the remaining 54% shares held by the other director (Lim) and his son. At the behest of Lim, a Company Extraordinary General Meeting (EGM) was convened where Lim, by virtue of his majority shareholding held with his son, passed resolutions to remove the two respondents as directors. The two respondents thereafter filed a claim for unlawful dismissal.

Rulings of Industrial Court, High Court and Court of Appeal

The Industrial Court ruled that the respondents did not fall within the definition of “workman” under the Industrial Relations Act 1967 (and thus could not claim to be unlawfully dismissed), finding that individuals who were the directing mind and will of a company, such as directors, do not qualify as employees. The respondents’ application for judicial review to the High Court was similarly unsuccessful. The Court of Appeal however overturned these decisions, holding that the respondents were indeed employees, and the fact that there was no written contract of employment did not mean that an oral contract of employment could not subsist between them and the Company.

Ruling of the Federal Court

The Federal Court ultimately upheld the Court of Appeal’s decision. In determining that the respondents were employees of the Company, the Federal Court relied on the conduct of the parties, including the fact that the Company had made statutory contributions on behalf of the respondents, and the fact that the respondents were listed in the Company’s register of employees, as Project Director and Technical Director, respectively. In response to the Company’s argument that the statutory concept of “workman” is predicated upon a contract of employment in which the employee is answerable to a superior employing authority (and that as directors of the Company, the respondents were not subject to any supervision and/or a superior-subordinate relationship), the Federal Court held that as the respondents held the functional titles of Project Director and Technical Director, respectively, they must have reported to either the Managing Director or the Board of Directors accordingly. The fact that the respondents were themselves members of the Board was irrelevant.

For more information, click here to read our Legal Update, authored by Partner Sivaram Prasad.

Please note that whilst the information in this Update is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as a substitute for specific professional advice

CONTACTS

Malaysia,
+60 3 2273 1919
+60 3 2267 2699
Malaysia,
+603 2273 1919
Malaysia,
+603 2267 2626
+601 2377 7792
Malaysia,
+603 2273 1919
+603 2267 2647
Malaysia,
+601 7362 3459
+603 2267 2669
Malaysia,
+60 3 2273 1919
+60 3 2267 2729
Malaysia,
+603 2273 1919
+603 2267 2616
Malaysia,
+60 3 2273 1919

Country

Share