MétaCan
Menu
Back to cohort
Record W2211806804

Limitations of Malaysia’s Data Protection Bill

2010· article· en· W2211806804 on OpenAlexaboutno aff
Graham Greenleaf

Bibliographic record

VenueSSRN Electronic Journal · 2010
Typearticle
Languageen
FieldSocial Sciences
TopicPrivacy, Security, and Data Protection
Canadian institutionsnot available
Fundersnot available
KeywordsData Protection Act 1998NoticePersonally identifiable informationBusinessInformation privacy lawLawStatutory lawState (computer science)Independence (probability theory)Information privacyPolitical sciencePrivacy policy
DOInot available

Abstract

fetched live from OpenAlex

Malaysia's Personal Data Protection Bill 2009 adds a distinct new flavour to Asia’s growing array of data protection laws. The Bill applies only to personal data in ‘commercial transactions’. The largest omission is that the public sector is not covered at all (s3(1)). Malaysia has no existing protections for personal information which limit State abuses of privacy. This Bill can only be said to cover part of the private sector, and only then subject to many exceptions, particularly where any State-related activities are concerned. Within its scope it may still be valuable, but the narrow scope must always be kept in mind.Malaysia will have a Personal Data Protection Commissioner appointed by the Minister (s47), with a normal range of powers. The Commissioner will be appointed for up to three years, and may be re-appointed (s53), but he or she may also be dismissed by the Minister, who only needs to ‘state the reason’. There is no point pretending that this Commissioner’s office is like that of other Privacy Commissioners in the Asia-Pacific. Those in Australia, New Zealand, Canada and Hong Kong have statutory provisions underwriting their independence which are not found here. The seven Personal Data Protection Principles in the Bill’s ss5-12 (General; Notice and Choice; Disclosure; Security; Retention; Data Integrity; and Access) are influenced strongly by the EU data protection Directive rather than by the OECD Guidelines or APEC Framework. The Act will have no application to processing outside Malaysia, with the interesting exception of where data is intended to be further processed in Malaysia. Temporary exports of data from Malaysia for purposes of processing breaching the Act will therefore be subject to it. It applies to anyone ‘established in Malaysia’ or who uses equipment in Malaysia. Personal data may not be transferred outside Malaysia unless the destination is on a ‘whitelist’ specified by the Minister, after receiving the Commissioner’s advice. The Minister can so specify a place if it has in force a law ‘substantially similar’ to the Malaysian Act, or the place ensures ‘an adequate level of protection … which is at least equivalent to the level of protection’ provided by Malaysia’s Act. There are exceptions similar to those found in Article 26 of the EU data protection Directive, but some which go considerably further than the Directive, including where ‘the data user has taken all reasonable precautions and exercised all due diligence’. Data users who breach one of the Principles commit an offence carrying substantial fines or even imprisonment . However, as with the Hong Kong law, reliance on enforcement notices has the fatal flaw that breaches that have caused harm, but are unlikely to be repeated, fall outside the scope of the Act. Overall, the ‘enforcement pyramid’ in this Act is completely deficient. While this Bill has many deficiencies, privacy legislation even of these modest dimensions will be a step forward for Malaysians.[Postscript: The Bill was enacted in 2009, but not brought into force. The Malaysian government announced in 2012 that the Bill would be brought into force in June 2012, but that instead of the Commissioner, who has not been appointed, a new Department will be set up to administer the Act.]

Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.

How this classification was reachedexpand

Full frame distilled prediction

Teacher imitation

Not calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.

metaresearch head score (Codex)0.004
metaresearch head score (Gemma)0.002
Version: codex-gemma-dda1882f352aValidation status: machine_predicted_unvalidated
Candidate categoriesnone
Consensus categoriesnone
DomainCandidate signal: none · Consensus signal: none
Study designCandidate signal: Theoretical or conceptual · Consensus signal: Theoretical or conceptual
GenreCandidate signal: Empirical · Consensus signal: Empirical
Teacher disagreement score0.353
Threshold uncertainty score0.964

Codex and Gemma teacher scores by category

CategoryCodexGemma
Metaresearch0.0040.002
Meta-epidemiology (narrow)0.0000.000
Meta-epidemiology (broad)0.0000.000
Bibliometrics0.0000.000
Science and technology studies0.0010.000
Scholarly communication0.0000.001
Open science0.0010.000
Research integrity0.0000.002
Insufficient payload (model declined to judge)0.0000.000

Machine scores (provisional)

The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.

Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.

Opus teacher head0.081
GPT teacher head0.311
Teacher spread0.229 · how far apart the two teachers sit on this one work
Validation statusscore_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from it

Classification

machine, unvalidated

Machine predicted; a candidate call from one teacher head, not a consensus.

The models applied no category: nothing in the taxonomy fit this work.
Study designTheoretical or conceptual
Domainnot available
GenreEmpirical

How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".

Quick stats

Citations8
Published2010
Admission routes1
Has abstractyes

Explore more

Same venueSSRN Electronic JournalSame topicPrivacy, Security, and Data ProtectionFrench-language works237,207