KUALA LUMPUR: In line with Malaysia’s agenda to expand the digitalisation of public services, government agencies, statutory bodies, and local authorities have been reminded to exercise greater caution and responsibility in the use of Quick Response (QR) codes.
This is especially when QR codes are utilised as a registration mechanism for official events, engagement sessions, public services, and transactions involving personal data.
In a statement today, the Malaysian Digital Economy Consumers Association said the use of QR codes generated through insecure, low-cost, or poorly governed platforms may expose users to cybercrime risks, including identity misuse, unauthorised interception of personal data, and fraudulent activities that could lead to financial losses and unauthorised access to banking accounts.
The association reminded all public agencies that create and deploy QR codes to ensure that they:
- Do not use untrusted or unverifiable third-party QR code generators that lack adequate security features and clear data governance practices.
- Ensure that all QR code destinations (URLs, forms, or applications) are legitimate, secured (HTTPS-enabled), and do not collect data beyond what is strictly necessary.
- Avoid the use of static QR codes for sensitive purposes, particularly those involving identity verification, personal information, or access to internal systems.
- Implement regular security audits and continuous monitoring of all QR codes distributed to the public.
“These measures are essential to prevent malicious actors from exploiting public trust in official government-related digital engagements,” the statement read.
It added that all guidelines for mobile application development and the deployment of digital technologies by public agencies must incorporate compliance with the principles of the Personal Data Protection Act (PDPA), including:
- Notice and Choice Principle
- Disclosure Principle
- Security Principle
- Retention and Data Disposal Principle
“Although certain exemptions apply to government agencies under the PDPA, voluntary and ethical compliance remains critical as a consumer protection feature and as a means of maintaining public confidence in government digital services.
“The digitalisation of public services must not come at the expense of security and consumer protection. All government agencies are urged to prioritise cybersecurity, personal data protection, and system integrity in every digital initiative undertaken.
“A secure, integrated, and ethical approach will not only safeguard citizens but also strengthen public trust in the nation’s public sector digital transformation,” the statement read.