The Cameras Are Watching Us. But Who Is Watching the People Behind the Cameras?
The Edge ran a cover story this week on smart city surveillance in Malaysia. Thousands of CCTV cameras across the city, some with facial recognition capability, all feeding into command centres operated by government agencies.
The official framing is always the same. Public safety. Crime prevention. Smart city. And honestly, I get it. There is a genuine argument for surveillance infrastructure in a busy city.
But here is the question nobody in the official statements seems to want to answer.
We keep talking about cameras watching the public. Nobody is talking about what happens when the people behind the cameras misuse what they see.
What this article covers
- Why internal misuse by government staff is a real and underdiscussed risk
- Why PDPA does not fully protect you from government surveillance
- What the April 2026 DPIA guidelines say about large-scale data processing
- The questions the government has not answered publicly
- What good governance of a surveillance system actually looks like
This Is Not a Hypothetical
I want to bring up something we wrote about recently. A resident filed a complaint through DBKL's official portal about a construction contractor. DBKL then took that resident's personal phone number and passed it directly to the contractor being complained about.
That was one person's phone number. One government officer. One decision to misuse access to data they legitimately held.
Now imagine the same dynamic applied to a city-wide surveillance system with thousands of cameras and facial recognition capability.
An officer who wants to track an ex-partner. A supervisor who wants to monitor a whistleblower. A politically connected individual who wants to know the movements of someone inconvenient. A junior staff member who pulls footage and shares it through WhatsApp because someone asked them to.
None of this requires hacking. None of this requires a sophisticated cyberattack. It just requires someone with system access and no meaningful accountability. We have already seen what that looks like at the smaller scale. We should be asking serious questions about it at this one.
The Real Question Is Access Control
When a surveillance system is installed, the technical conversation gets all the attention. How many cameras. What resolution. Does it have facial recognition. How does it feed into the command centre.
The question that almost never gets asked publicly: who can access the footage, at what level of authority, and is every single access logged and audited?
In a properly governed system, pulling footage is not a casual action. An officer needs a justification. That justification creates a record. The record is reviewed by someone independent of the operation. An officer who accesses footage without a valid reason faces real consequences.
Is that what exists here? I genuinely do not know. And that is the problem. There has been no public disclosure of the access control framework for these systems. No published policy on who can query facial recognition results. No independent audit mechanism that reports to anyone outside the very agency operating the system.
We are being asked to trust the system without being shown how the system actually works on the inside.
PDPA Does Not Protect You Here
This is the part that should concern everyone, and it rarely gets explained clearly.
PDPA has an exemption for national security and public order. In practice, this means government surveillance systems can operate outside the scope of data protection law. The agency running the cameras has fewer legal obligations around your biometric data than a shopping mall running a loyalty programme has around your purchase history.
The same law that requires a water filter company to handle your phone number responsibly does not clearly apply to a system that is recording your face in a public space, matching it against a database, and potentially logging your movements across the city.
That is not a position I can defend. And I do not think the public should be comfortable with it either.
The argument for the exemption is that security agencies need operational flexibility. That is fair to a point. But operational flexibility and zero accountability are not the same thing. Most mature democracies manage to run surveillance infrastructure while still maintaining oversight mechanisms. The exemption should not mean the public has no recourse at all.
The April 2026 Guidelines Exist for Exactly This
In April 2026, JPDP released the Data Protection Impact Assessment guideline. It states clearly that any processing of personal data involving 20,000 or more individuals, or sensitive data like biometrics for 10,000 or more individuals, requires a formal risk assessment before deployment begins.
A city-wide surveillance system covering millions of residents and visitors is precisely what this guideline was designed to address. The assessment would force the operator to document what data is collected, who can access it, how long it is retained, what happens if there is a breach, and what safeguards prevent misuse.
Was a DPIA conducted before these cameras went up? Was it reviewed independently? Was any part of it made available to the public?
If yes, I would genuinely like to see it. If no, then the deployment proceeded without the risk assessment that the spirit of the 2026 framework requires for exactly this scale of data processing.
The Questions That Have Not Been Answered
These are not unreasonable things to ask. They are the baseline requirements for any system handling personal data at this scale, and the public has a right to know the answers.
Who has access to the live footage and the facial recognition database, and at what seniority level? Is every access logged with a timestamp, a user ID, and a documented reason? Who reviews those logs, how often, and who do they report to? Is there an independent oversight body, separate from the agency running the cameras, with authority to investigate complaints? What is the retention period for footage not linked to an active investigation? What is the process when a staff member is found to have accessed footage without a valid reason? Has that ever happened, and if so what was the outcome?
Until these questions have public answers, the conversation about smart city surveillance is incomplete. The cameras are one part of the system. The people operating the cameras are the other part. Both need governance.
Government Staff Are Human
I want to be clear about something. I am not suggesting the officers running these systems have bad intentions. Most of them do not. They are doing a job.
But good intentions do not replace good governance. The DBKL officer who passed a complainant's number to a contractor probably thought they were being helpful. The bank officer who WhatsApped a customer using a number from a form probably thought they were just following up. Neither of them set out to violate anyone's rights. They just had access to data, no clear policy telling them what not to do with it, and no system making them accountable if they did.
Scale that up to a citywide surveillance network and the stakes are not a leaked phone number. They are someone's location history. Their daily routine. Who they meet. Where they go. All of it tied to their face.
The absence of a published governance framework does not mean misuse is happening. It means we have no way of knowing if it is. And that gap, between what we are told and what we can verify, is where public trust erodes.
We are watching the city get smarter. We are still waiting for the accountability to catch up.