Scope assessment
Whether and how the Act applies to each service.
The Online Safety Act 2025 has been in force since 1 January 2026. We help licensed platforms and the businesses that build for them understand their duties, draft the Online Safety Plan, and set up reporting and response processes that meet the prescribed timelines.
A compliance service for the Online Safety Act 2025: confirming scope, mapping the prescribed duties to your product, drafting the Online Safety Plan and designing the processes behind it.
The Act imposes duties on licensed application and content application service providers, including reducing exposure to harmful content, user guidelines, reporting and assistance mechanisms, protecting child users, acting on priority harmful content and preparing an Online Safety Plan. Failing a prescribed duty can cost up to RM10 million. Codes under the Act are still being developed, so the plan must be built to the Act and regulations in force and updated as codes arrive.
Whether and how the Act applies to each service.
Each prescribed duty mapped to product and process.
Drafted, owned and evidenced.
Processes built to the prescribed periods.
Age assurance, defaults and protections balanced with the PDPA.
Updates as MCMC codes are issued.
Know whether you are in.
Not just intentions.
Processes sized to the periods.
Child safety without over-collecting data.
Updated as codes arrive.
Services and user base.
Duties to controls.
Online Safety Plan and processes.
Walkthrough of reporting scenarios.
Updates for codes and changes.
Applicability per service.
Every prescribed duty.
Drafted and evidenced.
Reporting, response and escalation.
Tracking codes and changes.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
It binds licensed application and content application service providers, and platforms with at least eight million Malaysian users are deemed registered. We assess each service.
Not yet. The plan is built to the Act and regulations in force and updated when MCMC issues codes.
The document that records how a provider meets its duties, with owners, controls and evidence.
Yes. Many small platforms are not directly bound but want to meet expectations of licensed partners.
It can if age assurance collects too much data. We balance both.
Tell us your services and user base. We will assess scope and quote.