The Bar Council today urged the government to put in place new laws to safeguard unauthorised use of personal data obtained from the hi-tech microchip-embedded Malaysian 'smart' national identity card, popularly known as MyKad.

"There is no doubt that MyKad offers advantages and convenience but it is important to ensure that such advantages are not accompanied by a negative impact on privacy," said its president Kuthubul Zaman Bukhari in a statement.

Currently, there are no laws to prevent the unauthorised accessing of a MyKad holder's details such as personal identification, drivers' license and international passport data, health records, travel information and the public key infrastructure (PKI) digital certificate - a function which authenticates one's identity when transacting over the Internet.

The missing legal protection, said Kuthubul, raised legitimate concerns as to who may have access to such data, for what purpose the information may be used, and whether the data could be altered.

Given that MyKad readers are easily obtainable, it would be a simple matter to record information contained in a MyKad and subsequently put it to unauthorised use, he added

A Pembaca Kad Mini (mini card reader), sold at various Kedai Pos, is used to access the information stored in a MyKad. This device is priced at RM30 and is available to the public.

Draft laws now

Kuthubul said the government should immediately implement laws and safeguards to prevent the misuse of MyKad personal data including those which restrict access to a cardholder's information to a 'need-to-know' basis only and with the consent of the cardholder.

He also urged the government to make public the Personal Data Protection Bill that has been at the drafting stage since December.

The MyKad was first introduced in Sept 2001, making Malaysia a pioneer country in the use of the 'smartcard' - a plastic card embedded with a 64k microchip capable of storing a variety of information in addition to functioning as a cash card.