THE National Registration Department (NRD) has issued a firm reminder that security guards are not legally authorised to request, retain, or scan the MyKad (national identity card) of members of the public.
The clarification comes amid growing concern over the improper handling of personal data in public and private premises.
In a statement to Bernama, NRD explained that only five categories of officers are permitted under Regulation 7(1) of the National Registration Regulations 1990 to inspect or handle MyKad: officers of NRD, police officers, customs officers, on-duty military personnel, and public officers authorised by the Director-General of the National Registration Department.
“Any action by security guards to request or retain identity cards is in breach of the law and may result in legal consequences,” the department said.
NRD also underscored that scanning a MyKad using electronic devices is not permissible, as it falls under the scope of the Personal Data Protection Act 2010 (PDPA). This law governs how personal data is collected and processed by private entities.
“Any processing of personal data by private parties is subject to the Personal Data Protection Act 2010, which outlines obligations and safeguards for protecting individuals’ personal information,” NRD added.
The department’s clarification followed a viral social media post alleging that a security guard at a commercial premise had used an electronic device to scan a visitor’s MyKad. The incident raised questions from the public about the legality and privacy implications of such actions.
In response, NRD advised the public not to hand over their MyKad to unauthorised individuals and to report any suspected violations to the relevant authorities.
While building security is important, so too is respect for privacy and adherence to the law. The MyKad is a highly sensitive document containing biometric and personal information, and its misuse—even under the guise of access control—raises significant legal and ethical concerns.
This incident serves as a timely reminder that data security starts with awareness. Organisations, especially those in the private sector, must ensure that security personnel are properly briefed on the legal limits of their authority.
Equally, the public must remain vigilant and know their rights when it comes to personal data protection. - June 10, 2025