A proposed social media ban for under-16s risks pushing youths into darker digital spaces while exposing Malaysians to serious data security threats
THE governmentβs plan to restrict children under 16 from accessing social media by June, using the framework of the Online Safety Act (Onsa), signals a strong commitment to youth protection. However, a βtotal lockoutβ approach and the proposed MyKad-based age verification raise critical practical and cybersecurity concerns.
A sweeping ban is a blunt regulatory tool that is notoriously difficult to enforce. Banning youths will inevitably drive them to use Virtual Private Networks or migrate to encrypted messaging apps like Telegram, rendering them entirely invisible to parents and regulators. What we need is to foster digital literacy alongside these restrictions.
In this context, Metaβs recent rollout of revamped βteen accountsβ offers a highly instructive case study. By placing younger users under strict default settings for privacy, disabling recommendations for sensitive content and embedding mandatory parental controls, Meta has provided a tangible blueprint for what βsafety by designβ looks like in practice, rather than relying on reactive moderation after the fact.
From a regulatory standpoint, this is a significant and welcome shift. By mandating safe, highly restricted environments, we give youths a secure βtraining groundβ to develop digital resilience. Rather than pursuing an unenforceable blanket ban, policymakers should use this model to establish an industry-wide baseline.
The Malaysian Communications and Multimedia Commission regulatory sandbox should pivot from testing how to block youths entirely, to testing how to protect them.
The upcoming Onsa subsidiary instruments should make these strict default privacy settings and restricted algorithmic feeds a mandatory licensing condition for all platforms operating in Malaysia. This brings us to a major cybersecurity concern. The Communications minister recently suggested standardising βage verificationβ using official government documents like the MyKad. If this verification requires platforms to directly collect and store MyKad, we are facing a massive risk.
Social media platforms suffer massive data breaches. The 2021 Facebook data leak exposed details of 533 million users and in 2023, hackers posted email addresses linked to 200 million Twitter accounts.
If social media giants cannot guarantee the absolute security of user data based on these past incidents, trusting them to directly verify and store our MyKad could expose millions to severe identity theft. Trading one potential harm for another, more severe one is a deeply flawed policy.
Furthermore, if age verification requires platforms to collect and store MyKad, it does not meet the spirit of data minimisation under Section 6 of Malaysiaβs Personal Data Protection Act (PDPA).
The General Principle of the PDPA dictates that personal data processed must be βadequate but not excessiveβ in relation to its purpose. We cannot create a system where Onsa requirements actively conflict with the spirit of the PDPA.
If age verification is deemed absolutely necessary, we must look to privacy-preserving global best practices. Rather than submitting MyKad to tech companies, Malaysia should adopt the βdouble-blind tokenised approachβ recommended by Australiaβs eSafety commissioner. This approach involves an independent, regulated third party that verifies a userβs age. This verifier then provides a secure token to the social media platform, confirming only that the user meets the age requirement.
Crucially, the platform never receives or handles the userβs personal identification documents, thereby protecting their privacy.
We must protect our youths but not at the expense of their digital literacy or national data security.
By pivoting towards mandated βsafety by designβ and privacy-preserving tokenisation, Malaysia can create a gold-standard regulatory framework that avoids the dangerous pitfalls of blunt bans and mass data collection.
Thulasy Suppiah is a managing partner at Suppiah and Partners. Comments: letters@thesundaily.com
Source: balanced-youth-online-safety-beats-blanket-bans
Disclaimer
The views and opinions expressed in this article are solely those of the author and do not necessarily reflect the official stance of Kritik.com.my. As an open platform, we welcome diverse perspectives, but the accuracy and integrity of contributed content remain the responsibility of the individual writer. Readers are encouraged to critically evaluate the information presented.