AskLegal.my

Security wants to keep your MyKad. JPN says they can't — and scanning it may be worse.

10 min read

You pull up at a condo. The guard asks for your IC. You hand it over, he gives you a visitor pass, and you get it back on the way out. Everyone does this. It happens thousands of times a day across Malaysia.

The National Registration Department says it's against the law.

In June 2025, JPN issued a statement that was about as unambiguous as government statements get: security guards do not have the authority or right to request, hold or scan the MyKad of members of the public. Only five categories of officers can, under Regulation 7(1) of the National Registration Regulations 1990.

And it added something that matters more every year: using electronic devices to scan MyKad data is also not allowed, because that engages the Personal Data Protection Act 2010.

Only JPN officers, police officers, Customs officers, military personnel on duty, and civil servants authorised by the JPN Director-General may inspect or hold your MyKad. A security guard is none of those. You can decline. Your driving licence is a different document with a different legal basis, which is why people offer it instead — but that has its own problems. And a guard scanning your IC into a system raises PDPA questions that got considerably sharper when the 2024 amendments came fully into force in June 2025.

1. The rule, and who it actually covers

Regulation 7(1) of the National Registration Regulations 1990 limits who may inspect a person's identity and require production of a MyKad. JPN listed the five categories in its 2025 statement:

  • JPN (National Registration Department) officers
  • Police officers
  • Customs officers
  • Military personnel on duty
  • Civil servants authorised by the Director-General of National Registration

That's the list. A security guard isn't on it. Neither is a building manager, a receptionist, or a JMB committee member.

JPN's position has been consistent over time. In December 2022, then-Director-General Datuk Ruslin Jusoh told Utusan Malaysia that the MyKad is a national security document that cannot be held by another individual, and that guards or building management cannot arbitrarily require visitors to hand it over. He invited people to report it to JPN.

The reasoning is about forgery, not inconvenience. JPN has been dealing with a rise in document forgery — 491 arrests through various operations from 2020 to November 2022, of which 289 involved MyKad offences including fake ICs, using someone else's IC, and holding more than one. Every unnecessary handover of a national identity document is an opportunity in that chain.

2. Recording your details vs holding your card

This distinction is what makes the practice survivable in real life.

Recording details — a guard writing down your name and IC number, or noting your car plate — is a different thing from taking possession of the card itself. The common guidance is that recording particulars for a visitor log is not the same as retaining the document.

Retaining the card is the problem. Holding your MyKad in a drawer until you leave means an unauthorised person has custody of a national security document, and JPN says that's an offence.

A note on gated communities. There's a distinction that circulates widely: guards at formal gated communities on private property, or at stratified condominiums managed by a JMB or MC, are treated differently from guards at informal gated schemes on public roads. The argument is that private property owners can set entry conditions, whereas a guard on a public road has no such authority at all.

We'd flag this honestly: JPN's 2025 statement was blanket, without carving out private premises. The private-property argument is about a landowner's right to condition entry, not about any power to hold identity documents. Nobody has produced authority for a guard on private property being permitted to retain a MyKad. The safest reading is that recording details may be acceptable in a private development, and retention isn't acceptable anywhere.

3. What about your driving licence?

This is the workaround everyone uses, and it's better — but not clean.

The driving licence isn't governed by the National Registration Regulations, so Regulation 7(1) doesn't apply to it. That's why offering your licence instead of your IC is the standard Malaysian compromise.

But consider what you're actually handing over: your name, IC number, address, photograph and licence class, in someone else's custody for the duration of your visit. If it's lost, you're the one at JPJ replacing it. And it's still personal data being collected, so the PDPA questions below apply just the same.

A better compromise: offer to have your details recorded rather than surrendering any document. Most guards will accept it if you're pleasant about it.

4. The scanner problem — this is the part that's new

Walk into a commercial building in KL now and you may be asked to put your IC into a scanner. This became a public issue in 2025 after a viral post showed exactly that at a commercial building.

JPN's response was direct: scanning MyKad data with electronic devices is not allowed, and it falls under the PDPA 2010.

Why this matters more than it did a few years ago: the Personal Data Protection (Amendment) Act 2024 came into force in stages through 2025, with full implementation from 1 June 2025. The changes are substantial:

  • "Data user" became "data controller", with obligations extending to data processors
  • Mandatory data breach notification to the Personal Data Protection Commissioner as soon as practicable, with affected individuals notified within seven days of that initial notification
  • Mandatory Data Protection Officer appointment for certain organisations
  • Biometric data — fingerprints and facial scans — expressly within scope
  • Increased penalties, with figures up to RM1 million discussed across the amended framework

So a building that scans and stores visitors' IC data is processing personal data in a commercial context, with all the consent, security and breach obligations that brings. If that database leaks, it's a notifiable breach.

Practical translation: you can reasonably ask what the scan is for, where the data goes, how long it's kept, and who the data protection officer is. Most building managements have no answer, which tells you something about how carefully the system was set up.

If it's a facial recognition or fingerprint system, that's biometric data — squarely within the amended PDPA, and worth being more careful about than an ordinary visitor log.

5. What to actually say at the guardhouse

The legal position is clear. The practical position is that you're standing at a barrier and want to get to your friend's unit.

A script that works:

  1. "Boleh saya bagi details je? JPN kata pengawal tak boleh pegang MyKad." Offer your name, IC number and unit you're visiting for the log.
  2. If they insist, ask to speak to the supervisor or the JMB/MC representative — not because the guard is wrong-headed, but because they're following an instruction and can't change it.
  3. Offer an alternative — your driving licence, or a photo of your IC rather than the card.
  4. If it's genuinely refused and you can't get in, that's a matter for the management, and the resident you're visiting is the person with standing to raise it.

Please be decent about this. Security guards in Malaysia are typically low-paid, often migrant workers, following a written instruction from a JMB or building owner. They didn't draft the policy and they can't waive it. Winning an argument with the person at the barrier achieves nothing except making someone's night worse. The policy is set several levels above them.

If you want to change it: raise it with the JMB or MC, in writing, citing JPN's June 2025 statement. That's the level where the practice actually gets fixed.

If you want to report it: JPN accepts reports about unauthorised holding of MyKads. A police report is also available.

6. If you're on the management side

If you sit on a JMB, MC or run a building:

  • Don't retain visitors' MyKads. JPN has stated this is unlawful and that action can be taken.
  • Record particulars instead — name, IC number, unit visited, time in and out.
  • If you use a scanning or biometric system, you're a data controller under the amended PDPA. That means a lawful basis for collection, a retention policy, security measures, breach notification readiness, and potentially a DPO.
  • Review your standing instructions to guards. The guard at the gate is executing what you wrote, and the exposure sits with the organisation, not with him.

What to actually do

  • You can decline to hand over your MyKad — only five categories of officers may inspect or hold it.
  • Offer details for the log instead. That's usually enough.
  • Driving licence is a fallback, not a right they have either — it's just outside the National Registration Regulations.
  • Ask what happens to scanned data. Purpose, retention, security. You're entitled to know.
  • Be kind to the guard. Escalate to management, not at the barrier.
  • Report to JPN if a card is being retained as a matter of policy.
  • If you're on a JMB: fix the standing instruction before someone reports it.

FAQ

Can a security guard legally hold my MyKad?

No. JPN stated in June 2025 that guards have no authority to request, hold or scan a MyKad, and that only five categories of officers may do so under Regulation 7(1) of the National Registration Regulations 1990.

What if they refuse to let me in?

A private property owner can set conditions of entry, but that's a dispute with the management, not a power to hold your document. Ask for the supervisor or JMB representative, and let the resident you're visiting take it up.

Is giving my driving licence better?

It's outside the National Registration Regulations, which is why it's the common workaround. But you're still handing over personal data and risking loss of the document. Offering details for the log is better than either.

Can they photocopy or photograph my IC?

That's collection of personal data in a commercial context, so PDPA obligations apply — purpose, consent, security, retention. Ask what it's for and how long they keep it.

They scanned my IC into a machine. Is that legal?

JPN has said scanning MyKad data with electronic devices is not allowed and engages the PDPA. If you're concerned, ask the building for their data protection contact, and you can raise it with JPDP.

What can I do about it?

Raise it in writing with the JMB or management citing JPN's statement, report it to JPN, or lodge a police report. Arguing at the guardhouse won't change a policy the guard didn't write.

I'm a resident and my guests keep complaining. Take it to your JMB or MC meeting with JPN's June 2025 statement. Management-level change is the only thing that works.

Does this apply to offices and commercial buildings too?

The Regulation 7(1) limit on who may inspect or hold a MyKad isn't specific to residential premises. The 2025 scanner controversy involved a commercial building.

This article is general legal information, not legal advice, and reading it does not create a lawyer–client relationship.

There is a widely-circulated distinction between formal gated communities on private property and informal schemes on public roads, and we've flagged that it exists — but JPN's own statements have been blanket, and we could not find authority permitting any security guard to retain a MyKad. Treat the private-property argument as contested rather than settled. PDPA obligations changed substantially with the 2024 amendments phased in through 2025, so organisations should take their own advice on compliance.

Spot something outdated or wrong? Tell us — we’ll verify and correct it, with the correction noted.

Key sources (9) — how this was verified