DBKL Gave a Complainant's Phone Number to the Contractor Being Complained About
I saw this post on X.com, regarding a resident who filed a dust pollution complaint through DBKL's official portal, adudbkl. Standard civic stuff. Person has a problem, submits it through the proper channel, waits for resolution.
Then the construction contractor WhatsApp messaged them. "Ajak ngeteh." Invited them for tea.
The resident asked the obvious question: how did you get my number? The contractor's reply was straightforward. "I receive your number from DBKL cos they want me to clarify this issue."
So DBKL took a citizen's personal phone number, collected when they filed a complaint, and handed it directly to the party being complained about. The post went viral. And honestly, it should have.
Quick Summary
- A DBKL officer shared a complainant's personal phone number with the construction contractor subject to the complaint.
- This violates the Personal Data Protection Act 2010 (PDPA) on multiple counts: secondary use, disclosure without consent, and no lawful basis for the transfer.
- Government agencies are not exempt from PDPA. They are data controllers under the Act.
- The affected person can file a complaint with the Personal Data Protection Commissioner (PDPC).
- Internally, this incident points to a failure in access control, staff training, and data governance.
What the PDPA Actually Says About This
The PDPA has a principle called purpose limitation. When you give your phone number to a government portal to file a complaint, that number can only be used for that purpose. Not to facilitate a meeting with the other party. Not to help the contractor "clarify" anything.
There is no lawful basis in the Act for DBKL to transfer a complainant's personal data to the subject of that complaint. Not "legitimate interest." Not "operational necessity." Certainly not tea.
And it gets worse. The officer who shared the number wasn't just mishandling data. They were actively working against the complainant's own interests. The person filed a complaint. DBKL turned that person's contact information into a tool for the party being complained about to reach them directly.
Whatever the intent was, the effect is clear: the complainant was exposed to contact from the very party they had an ongoing dispute with. That's not a minor process error. That's a fundamental failure of data stewardship.
Government Agencies Are Not Exempt
One thing worth clearing up: some people assume that PDPA applies only to private companies. It doesn't.
Government bodies in Malaysia that process personal data in the course of their functions are data controllers. PDPA applies. The 2024 amendment, which increased penalties and introduced mandatory breach notification, also applies.
DBKL collects personal data at scale. Every resident who files a complaint, applies for a permit, or registers anything through the city council's systems is trusting that their data will be handled lawfully. That trust was broken here.
And the case was marked "selesai." Resolved. With no follow-up action recorded.
Where the Internal Failure Actually Happened
As a DPO, when I look at an incident like this, the first question isn't "who did it." It's "how was this even possible?"
A few things had to go wrong at once for this to happen.
Access without justification. A complaint handler should be able to see the complaint. They should not have unchecked ability to extract personal contact details and forward them to external parties. If they can do that without any system alert or approval step, the access controls are too permissive.
No separation between complainant data and the respondent's access path. In a complaint management system, the complainant's personal contact information has no reason to reach the other party. The system should not facilitate that path at all. If it does, by design or by neglect, that's a design flaw that creates this kind of exposure.
Staff who don't understand purpose limitation. The officer who shared the number likely thought they were being helpful, facilitating resolution. That's a training problem. "I need to resolve this complaint" is not a lawful basis to share a complainant's phone number with a contractor. Staff who handle complaints need to understand this distinction explicitly, not as an assumption.
No accountability mechanism. The case was closed with no action. That suggests no one reviewed what the officer actually did to "resolve" it. A proper data governance structure includes audit trails for data access and sharing. Someone should have seen this.
What the Affected Person Can Do
If you were the one whose number was shared without your consent, you have options under PDPA 2024.
You can file a complaint with the Personal Data Protection Commissioner (PDPC). The Commissioner has the power to investigate data controllers, including government agencies, and to direct them to take corrective action.
Document everything first. Screenshots of the WhatsApp conversation, the contractor's admission that they received your number from DBKL, the original complaint acknowledgment from adudbkl, and the ticket number. The more evidence you have, the clearer the paper trail.
You can also write formally to DBKL demanding an explanation under your data subject rights. Under PDPA, you have the right to know what personal data they hold about you and how it has been used. A formal written request creates a record and often triggers a more serious internal response than a portal complaint alone.
What Organisations Should Take From This
Most organisations, government and private, will read this story and think: we wouldn't do that. Maybe. But the honest question is whether you know your staff wouldn't do that.
Data breaches and violations in Malaysia are rarely caused by hackers. The majority involve an employee doing something that seemed reasonable to them at the time, with data they had legitimate access to, for a purpose they convinced themselves was justified.
The fix is not complicated. It's not expensive. It requires three things that are consistently underprioritised: access controls that match actual job functions, staff training that covers not just "don't share data" but specifically why purpose limitation exists and what it means in practice, and an audit trail that lets someone catch these things before they go viral on Threads.
A DPO's job is partly to prevent incidents like this. But more practically, it's to create conditions where an officer doesn't reach for someone's phone number to pass to a contractor, because they know that's not how it works.
DBKL almost certainly has a privacy notice somewhere on their portal. What they may not have is a culture, a system, and trained people who treat that notice as an actual operating commitment rather than a legal footnote.
That gap is where incidents like this one live.