马来西亚5G反诈基站监测技术上线 | 网络安全与电信合规新要求
作者:东南亚合规中心编辑团队
TL;DR · 核心要点
马来西亚数字国家公司(DNB)联合爱立信在全球首次试点商用5G网络中基于RAN与网管系统的非法基站识别技术,旨在拦截诈骗短信发送源。该举措属网络安全与消费者保护范畴,非直接税政文件,但触发《2022年个人数据保护法》(PDPA)、《1998年通讯与多媒体法令》(CMA)及《2023年国家网络安全政策》下的合规义务。关键点:1)所有持牌电信运营商须接入DNB统一5G基础设施并共享必要信令数据;2)须在MCMC规定时限内完成RAN侧检测接口对接;3)需向MCMC提交年度网络安全事件响应报告;4)涉及用户位置/通信元数据处理的企业须通过PDPA数据保护影响评估(DPIA)。对企业影响:外资通信设备商、云通信平台及SMS营销服务商须重新审核其基站部署、API调用权限及数据留存策略,避免违反CMA第233条(非法干扰通信)及PDPA第6条(未经同意处理个人数据)。
✅ 合规行动清单 · Compliance Checklist
- ›所有持牌电信运营商须于2026年9月30日前完成与DNB 5G网络管理系统的RAN侧检测接口对接,并向MCMC提交技术验证报告
- ›面向马来西亚用户提供短信服务的外资CPaaS平台,须在2026年6月30日前完成PDPA数据保护影响评估(DPIA)并向PDPC备案
- ›在马销售或部署基站设备的外国供应商,须确保产品固件支持MCMC定义的非法发射器特征指纹库,并取得SIRIM型式认证
- ›Licensed telcos must complete RAN-side integration with DNB’s detection system and submit technical validation reports to MCMC by 30 September 2026
- ›Foreign CPaaS providers serving Malaysian end-users must conduct and register a PDPA Data Protection Impact Assessment (DPIA) with the PDPC by 30 June 2026
- ›Overseas base station equipment vendors must embed MCMC-defined illegal transmitter signature detection firmware and obtain SIRIM Type Approval before market entry
English Summary
This announcement describes Malaysia's world-first commercial 5G network enhancement—developed by DNB and Ericsson—to detect illegal base stations (IMSI-catchers) used for scam messaging. While not a tax regulation, it triggers binding compliance under the Communications and Multimedia Act 1998 (CMA), Personal Data Protection Act 2010 (PDPA), and National Cyber Security Policy 2023. Licensed telcos must integrate with DNB’s detection system per MCMC directives. Equipment vendors, CPaaS providers, and SMS aggregators must ensure their infrastructure complies with CMA Section 233 (unauthorized interception) and PDPA Section 6 (lawful data processing). Affected entities must complete RAN interface alignment by Q3 2026 and submit annual cybersecurity incident reports to MCMC. Non-compliance may incur fines up to RM500,000 or imprisonment. Foreign businesses operating in Malaysia’s telecom ecosystem must conduct DPIAs and update data processing agreements accordingly.
⚡ 这篇文章的要点太复杂?让 AI 帮你 30 秒解读
立即咨询 →