AskLegal.my

Malaysia’s New Online Safety Code: What You Can Expect When You Report Harmful Content

9 min read · Published · Verified

Smartphone wrapped in a chain and secured with a combination lock

About this guide: This explainer uses an incident reported on 2026-06-01 as a starting point. The legal rules below are general; they do not decide anyone's guilt, liability or individual case.

Since 1 June 2026, MCMC’s Risk Mitigation Code has required covered licensed online services to assess harmful-content risks and put practical safeguards in place. Users can report content they believe is harmful, and separate regulations set response periods. But this is mainly a platform-accountability law: it does not guarantee that every disputed post will be removed, repay a scam loss, or replace a police or bank report.

What happened

On 1 June 2026, the Malaysian Communications and Multimedia Commission’s Risk Mitigation Code took effect under the Online Safety Act 2025. The Act itself had already come into force on 1 January. The newer code fills in the operational part: what covered licensed service providers should actually do to reduce users’ exposure to harmful content.

Malay Mail reported on the first day of enforcement that the code requires major online platforms to assess risks, improve moderation and reporting systems, verify advertisers for paid goods-and-services ads, label certain manipulated or AI-generated media, examine recommendation systems and provide user safety controls. New Straits Times had reported when MCMC published the code on 22 May that it would take effect on 1 June after industry and public consultation. These reports describe a completed regulatory step, not a proposal or Bill.

The hook matters because many Malaysians have had the same frustrating experience: you report a scam advertisement or threatening post, receive an automated reply, then have no idea what happens next. The new framework does not promise that every report will go your way. It does, however, put duties, records and timelines around how covered services handle harmful-content risks and user reports.

There is also a separate Child Protection Code, effective on the same date. It deals with age verification, parental controls, safer default settings and search or recommendation systems for child users. This article stays focused on the Risk Mitigation Code and the reporting process available to ordinary users.

The starting point is the Online Safety Act 2025, or Act 866. Sections 13 to 20 impose duties on licensed applications service providers and licensed content applications service providers. In plain language, those are covered online-service and content-platform operators, not every person with a social-media account. The duties include reducing exposure to harmful content, publishing user guidelines, supplying safety tools, offering reporting and assistance mechanisms, protecting child users, dealing with priority harmful content, and preparing an Online Safety Plan.

The Act’s First Schedule defines nine groups of harmful content. They include child sexual abuse material, financial fraud, obscene or indecent content, threatening or abusive material that may cause harassment, distress, fear or alarm, material that may incite violence or terrorism, material that may induce a child to self-harm, material promoting public ill-will or disturbing public tranquillity, and material promoting dangerous drugs. Financial fraud and child sexual abuse material are classed as ‘priority harmful content’, meaning the reporting system treats them more urgently. Educational content about financial fraud is expressly excluded from the financial-fraud category.

The Risk Mitigation Code was issued under section 80 and works with section 13. It requires a suitable and sufficient risk assessment. Providers must consider Malaysian user demographics, risky design features, emerging online behaviour and heightened-risk periods such as elections or national crises. They must keep written records and review the assessment annually. The code then calls for proportionate measures covering moderation, user controls, child safety, service design and safety policies.

Some duties are very concrete. Paid advertisements for goods or services should come only from advertisers or users verified against government-issued identity or registration records, subject to privacy law. Recommendation systems must be tested and adapted to reduce harmful exposure. Certain generated or manipulated images, audio or video that closely resemble real people, objects, places or events and are likely to look authentic must be made clearly distinguishable through prominent labels or markings.

For reports, section 21 says a user may report content they believe is harmful through the provider’s determined channel. The Online Safety (Period) Regulations 2025 require a covered provider to acknowledge a report made through its official channel within one hour, then notify the reporting user in writing of its status and assess it within 12 hours after acknowledgement. A report may still be dismissed if it is frivolous, vexatious, not made in good faith, trivial or duplicates another report.

If the provider dismisses the report, the user has 15 days from written notification to ask about that dismissal and give reasons why it should be reconsidered. The provider must notify the user of its decision within seven days after receiving that inquiry. Under section 24, a user may also report believed harmful content to MCMC, whether or not the user has first reported the same content to the provider. The regulations set a one-hour acknowledgement period for an official-channel report to MCMC and 24 hours after acknowledgement for MCMC to assess it and notify the user of its status.

A major limit sits in section 2: the Act does not apply to a ‘private messaging feature’, defined as a feature for communicating content to a specific and limited number of recipients chosen by the user, subject to any prescribed further characteristics. So a public scam advertisement and a one-to-one scam message may not fall into the same ONSA route. Other laws and reporting channels can still apply to the private message.

How does this impact me?

For you, the first practical change is that a platform report should be more than a decorative button. Use the platform’s official reporting channel, choose the closest harmful-content category and keep the acknowledgement. The legal timelines run from an official-channel report, so a public comment tagging the platform or a message to an unrelated support account may not start the same process.

The second change is better grounds for a follow-up. If a report is dismissed, you can point to the content, explain which statutory category you believe applies and ask for review within the 15-day period. Keep it factual. For a scam advertisement, save the URL, account name, date, screenshots and payment details before the material disappears. Do not keep forwarding dangerous content merely to prove it exists.

The law does not turn MCMC into a compensation tribunal. Removing a scam advertisement does not automatically recover money already transferred. If money has just left your account, contact your bank immediately and use the current official scam-response channels shown by your bank or the authorities. Make a police report where appropriate. A platform report tackles the content; the banking and criminal-reporting steps tackle the loss and possible offence.

The code also does not give users a simple automatic right to sue a platform whenever harmful material stays online. It creates regulatory duties and enforcement machinery. Whether someone has a separate civil claim depends on the facts and other law. That is a lawyer-specific question, not something a report acknowledgement decides.

What this incident teaches us

The strongest part of this framework is the move from reactive deletion to system design. Scam ads do not spread only because one bad actor uploads them. Verification gaps, recommendation systems and easy repeat-account creation can help harmful material travel. The code asks providers to examine those systems, not only the final post. That is a more realistic way to deal with harm at scale.

Still, a deadline is not the same as a favourable outcome. The one-hour and 12-hour periods concern acknowledgement, status notification and assessment. They do not mean every ordinary harmful-content report must produce permanent removal within 12 hours. Priority harmful content has its own temporary inaccessibility and determination process, while other harmful content follows a different route. Readers should be careful with headlines that reduce the framework to ‘platforms must delete anything reported within hours’. That is not what the legal text says.

There is a speech safeguard too. Paragraph 2.4 of the Risk Mitigation Code reflects section 13(3): measures should not unreasonably or disproportionately limit a user’s expression. In everyday terms, platforms still have to distinguish actual scheduled harmful content from criticism, reporting, education, satire and ordinary disagreement. The Act itself excludes anti-fraud awareness or education from the financial-fraud category.

The final lesson is evidence. A clean timeline — what appeared, where it appeared, when you reported it, the reference number and what reply arrived — helps far more than an angry paragraph with no link. The new rules make process matter. Users will get the most from them by using the correct channel and preserving the paperwork.

The verdict

Malaysia’s new online-safety framework gives ordinary users a clearer reporting pathway and puts real system-level duties on covered platforms. That is useful, especially for scam content. But keep the promise in proportion: it regulates platforms and response processes; it does not guarantee removal, compensation or a criminal outcome. Report through the official channel, keep evidence, follow up on time and use bank, police or emergency routes separately when the situation needs them.

What can I do if this happens to me?

  • Preserve the exact post or advertisement URL, account handle, date and time, screenshots and any transaction record before reporting it.
  • Use the platform’s official in-app or web reporting channel and save the acknowledgement, case number and every written response.
  • Name the closest relevant category — for example, financial fraud or threatening material — and explain briefly what the content does. Stick to verifiable facts.
  • If the provider dismisses your report, ask for a review within 15 days of receiving the written dismissal and give clear reasons.
  • You may also lodge a harmful-content report with MCMC through its official complaint channel; keep that acknowledgement and status notice too.
  • For a recent money transfer, contact your bank immediately and follow verified official scam-response and police-reporting steps. Do not wait for the platform review.
  • If there is an immediate threat to safety, contact emergency services or the police rather than relying only on content moderation.

FAQ

Does the Online Safety Act apply to me as an ordinary social-media user?

The platform duties discussed here apply to covered licensed service providers, not individual users. Your own posts can still be governed by other Malaysian laws and the platform’s terms. The Act gives users reporting routes, but it is not a general licence to post anything without consequence.

Must a platform remove every post I report within 12 hours?

No. The 12-hour period is for written status notification and assessment after acknowledgement of an official-channel report. Removal rules depend on the provider’s assessment and whether the material is priority harmful content or another form of harmful content. A report may also be dismissed on the grounds stated in the Act.

Can I report directly to MCMC without reporting to the platform first?

Yes. Section 24 allows a user to report believed harmful content to MCMC regardless of whether the same content was first reported to the provider. Use MCMC’s official channel so the prescribed acknowledgement and assessment periods apply.

Does this law cover a scam message sent privately to me?

The Act excludes a private messaging feature as defined in section 2. That does not make the scam lawful. Report it through the relevant platform, bank and law-enforcement channels, but do not assume the ONSA process is the only or correct legal route for a private message.

Will reporting a scam advertisement get my money back?

Not by itself. A platform report may help restrict harmful content, but it is not a refund or compensation process. Contact your bank urgently after a transfer and make the appropriate official reports. Recovery depends on timing and facts, and is never guaranteed.

This article is general legal information, not legal advice, and reading it does not create a lawyer–client relationship.

This guide explains Act 866, the Online Safety (Period) Regulations 2025 and MCMC’s Risk Mitigation Code as retrieved on 27 July 2026. It does not decide whether a particular post is harmful content, whether a service is covered, or whether you have a civil claim. Codes, platform channels and MCMC procedures can change; check the current official materials for an actual report.

Spot something outdated or wrong? Tell us — we’ll verify and correct it.

Key sources (5) — how this was verified