JPDP investigates unauthorised disclosure of Maxis customer data on social media, warns data controllers to strengthen security measures.
PUTRAJAYA: The Personal Data Protection Department (JPDP) is investigating the unauthorised disclosure of account and phone bill details belonging to a Maxis customer on social media recently.
In a statement today, the department said action would be taken if investigations found any non-compliance with the Personal Data Protection Principles or Section 130 of the Personal Data Protection Act 2010.
It said every data controller must comply with the seven Personal Data Protection Principles, including ensuring customers’ personal data is protected against unauthorised access and disclosure.
“Data controllers are also reminded to continuously strengthen technical and organisational security measures, while ensuring data storage infrastructure and network systems are maintained at an appropriate level of security,” it said.
Earlier, a Threads user claimed to know the phone bill details of entrepreneur and social media influencer Khairul Amin Kamarulzaman, better known as Khairul Aming.
In response, Maxis confirmed yesterday that the incident involved unauthorised access and that the individual responsible had been identified, with legal action being taken.
Meanwhile, Communications Minister Datuk Seri Fahmi Fadzil said the Malaysian Communications and Multimedia Commission (MCMC) would obtain a full report on the alleged leak of Khairul Aming’s personal information.
He stressed that no individual should have access to another person’s personal information or to telecommunications companies’ inventory and systems.
“This includes anyone who intentionally distributes Personally Identifiable Information (PII), as it is an offence under the Personal Data Protection Act,” he said.









