- Published on
Malaysian Banking Law – Banking Secrecy, Confidentiality, Personal Data Protection and Banker’s Duties
Introduction
Banking secrecy is one of the most fundamental obligations imposed upon banks and financial institutions. It protects confidential information entrusted by customers to banks and forms a cornerstone of the banker-customer relationship.
The duty serves several important purposes:
PART I – STATUTORY FRAMEWORK UNDER THE FSA 2013
Section 132 FSA 2013 – Restriction on Inquiry into Customer Affairs
General Rule
Section 132 protects customers from arbitrary governmental interference.
Neither:
The purpose is to safeguard banking privacy and prevent unjustified investigations.
Exception
BNM may inquire into customer affairs where necessary to exercise its statutory functions under:
Case Scenario
Facts
A customer receives several unexplained overseas transfers amounting to RM20 million.
BNM suspects money laundering and requests the customer’s account records from the bank.
The customer argues that disclosure breaches banking secrecy.
Solution
The argument fails.
Section 132(2) expressly permits BNM to obtain such information when exercising regulatory powers.
Critical Analysis
The provision balances:
Section 133 FSA 2013 – Statutory Duty of Secrecy
General Rule
Section 133 imposes a strict statutory duty of confidentiality upon:
The obligation continues indefinitely, including after employment ends.
Scope of Protection
The duty covers:
Public Information Exception
The secrecy obligation does not apply where information:
Criminal Liability
A person who breaches section 133 commits an offence punishable by:
Further Disclosure Prohibited
Section 133(3) prohibits a person who knowingly receives unlawfully disclosed information from making any further disclosure.
Thus liability may extend beyond the original wrongdoer.
Section 134 FSA 2013 – Permitted Disclosures
Although secrecy is the general rule, section 134 recognises that confidentiality cannot be absolute.
A bank may disclose information:
The 18 Permitted Disclosures under Schedule 11
1. Customer’s Written Consent
Disclosure authorised by the customer.
2. Deceased Customer’s Estate
Disclosure for probate, administration and faraid purposes.
3. Bankruptcy and Winding-Up
Disclosure involving bankrupt individuals and insolvent companies.
4. Litigation Involving the Bank
Disclosure in civil or criminal proceedings involving:
Disclosure necessary to comply with garnishee proceedings.
6. Court Orders
Disclosure pursuant to orders of courts not lower than the Sessions Court.
7. Enforcement Agencies
Disclosure for investigations conducted under written law.
8. PIDM
Disclosure for performance of statutory functions by PIDM.
9–10. Capital Market Authorities
Disclosure involving:
Disclosure for tax administration and international information exchange.
12. Credit Reporting Agencies
Disclosure to registered credit reporting agencies.
13. Supervisory Authorities
Disclosure to local and foreign regulators performing supervisory functions.
14. Centralised Group Functions
Disclosure for:
Disclosure relating to:
Disclosure to outsourced service providers.
17. Consultants and Adjusters
Disclosure to professional advisers engaged by the bank.
18. Suspicion of Criminal Activity
Disclosure where the bank reasonably suspects that an offence has been, is being or may be committed.
Confidentiality During Court Proceedings
Even when disclosure is permitted, the court may:
PART II – CONFIDENTIALITY UNDER CONTRACT AND EQUITY
Tan Eng Seong v Malayan Banking Bhd
Principle
Disclosure of customer information to the customer’s brother constituted a breach of the implied contractual duty of confidentiality.
Significance
Wong Yeng Mun v CIMB Bank Berhad
Principle
The bank negligently sent account statements to the wrong address.
The statements were opened by the customer’s wife.
Significance
Tan Lay Soon v Kam Mah Theatre Sdn Bhd
Principle
Confidentiality belongs to the customer.
Consent to disclosure may be:
PART III – EXTRA-TERRITORIAL DISCLOSURE
Attorney General of Hong Kong v Zauyah Wan Chik
Principle
Banking secrecy legislation does not automatically operate outside Malaysia.
Disclosure compelled by foreign court proceedings may not create criminal liability in Malaysia.
Significance
The administration of justice may justify disclosure.
PART IV – ILLEGALLY OBTAINED INFORMATION
Wako Merchant Bank v Lim Lean Heng
Principle
Information obtained in breach of banking secrecy provisions remains admissible if relevant.
Significance
The law distinguishes between:
PART V – PUBLIC INFORMATION
Hj Salleh Hj Janan v Financial Information Services Sdn Bhd
Principle
Publicly available court records are not confidential.
Information published in:
Significance
Banking secrecy protects confidential information, not information already in the public domain.
PART VI – BANKER’S PROFESSIONAL DUTY
Bank Utama (M) Bhd v Insan Budi Sdn Bhd
Facts
The plaintiff obtained an international trade facility to finance the importation and sale of raw sugar.
The plaintiff instructed the bank to issue a confirmed irrevocable transferable SWIFT Telegraphic Transfer.
The bank used the wrong transmission procedure and attempted to send the SWIFT instruction by facsimile.
As a result:
Held
The Court of Appeal held the bank liable.
Principle 1 – Concurrent Liability
A professional adviser may be liable simultaneously:
The bank possessed specialist knowledge regarding SWIFT procedures.
The customer could not reasonably be expected to understand technical banking processes.
The bank therefore had a duty to advise the customer that SWIFT transfers cannot be transmitted by facsimile.
Significance
Modern banks are not merely executors of instructions.
They are professional service providers expected to exercise reasonable care and expertise.
PART VII – BANKING SECRECY AND THE PERSONAL DATA PROTECTION ACT 2010 (PDPA)
Relationship Between Banking Secrecy and Personal Data Protection
Banking secrecy and personal data protection operate alongside one another.
While the FSA 2013 protects confidential banking information, the Personal Data Protection Act 2010 (PDPA) protects personal data handled by commercial organisations, including banks.
The PDPA makes it unlawful for commercial organisations to:
Criminal Penalties under the PDPA
Depending on the nature of the offence, penalties may include:
Section 141(2)
The Seven Personal Data Protection Principles
Banks must comply with seven statutory principles.
1. General Principle (Section 6)
Personal data must:
2. Notice and Choice Principle (Section 7)
Customers must be informed:
3. Disclosure Principle (Section 8)
Personal data must not be disclosed without consent unless authorised by law.
This principle closely complements banking secrecy obligations under section 133 FSA 2013.
4. Security Principle (Section 9)
Banks must implement appropriate security measures to protect data.
Examples include:
5. Retention Principle (Section 10)
Personal data must not be retained longer than necessary.
Once the purpose has been fulfilled, unnecessary data should be destroyed or anonymised.
6. Data Integrity Principle (Section 11)
Personal data must remain:
7. Access Principle (Section 12)
Customers must generally be allowed to:
Alliance Bank v AmBank Dispute (2018)
Facts
Alliance Bank commenced legal proceedings against AmBank alleging misappropriation of sensitive information.
The dispute involved former Alliance Bank employees who had joined AmBank.
Alliance Bank alleged that electronic records showed confidential internal information being transferred to a former employee after his departure.
The information allegedly reached senior personnel within the competing bank.
The dispute was subsequently resolved amicably.
Significance
The case illustrates that confidentiality obligations extend beyond customer information.
Banks must also protect:
Chia Sun Huat v United Overseas Bank (Malaysia) Bhd
Facts
A purchaser agreed to buy property from a vendor whose property was charged to UOB.
To complete the purchase, the purchaser requested a redemption statement from UOB.
The vendor could not be contacted.
Although a purported letter of authority existed, the bank could not verify its authenticity.
UOB refused to release the redemption statement.
The purchaser sued.
Held
The High Court held that UOB was not liable.
The bank was bound by its duty of secrecy and could not release confidential information without proper authority.
Legal Principle
A bank is entitled to refuse disclosure where:
Comprehensive Case Scenario
Facts
A purchaser requests a redemption statement from a bank concerning a property owner who cannot be contacted.
The purchaser presents an unsigned authority letter and insists that the transaction cannot proceed without disclosure.
The bank refuses.
The purchaser alleges obstruction and negligence.
Solution
Applying Chia Sun Huat v UOB:
The bank is entitled to refuse disclosure.
The redemption statement contains confidential customer information.
Without verified authority or a statutory exception under section 134 FSA 2013, disclosure would breach banking secrecy.
Critical Analysis
The decision demonstrates the strict nature of banking confidentiality.
Commercial convenience cannot override a bank’s legal obligations.
Banks must verify authority before releasing customer information, even where refusal may delay a transaction.
Key Examination Principles
Section 132 FSA 2013
Tan Eng Seong
Conclusion
Malaysian banking secrecy law is built upon a comprehensive framework comprising sections 132–134 FSA 2013, the Personal Data Protection Act 2010, contractual obligations, equitable principles and tortious duties. The law protects customer information not only from unauthorised disclosure but also from misuse, mishandling and improper processing. The various cases demonstrate that confidentiality belongs to the customer, extends beyond account balances to all customer affairs, survives termination of employment, and remains enforceable through criminal, civil and equitable remedies. At the same time, carefully defined statutory exceptions ensure that secrecy does not obstruct justice, regulatory supervision, legitimate commercial transactions or the public interest.
Introduction
Banking secrecy is one of the most fundamental obligations imposed upon banks and financial institutions. It protects confidential information entrusted by customers to banks and forms a cornerstone of the banker-customer relationship.
The duty serves several important purposes:
- Protecting customer privacy;
- Preserving confidence in the banking system;
- Promoting trust in financial institutions;
- Protecting sensitive commercial information; and
- Ensuring disclosure only where authorised by law.
- Section 132 Financial Services Act 2013 (FSA 2013) – Restriction on inquiry into customer affairs;
- Section 133 FSA 2013 – Statutory duty of secrecy;
- Section 134 FSA 2013 – Permitted disclosures and exceptions; and
- Personal Data Protection Act 2010 (PDPA) – Protection of personal data handled by commercial organisations, including banks.
- Contract law;
- Tort law;
- Equity; and
- Regulatory obligations.
- Criminal liability;
- Civil liability;
- Regulatory sanctions; and
- Equitable remedies
PART I – STATUTORY FRAMEWORK UNDER THE FSA 2013
Section 132 FSA 2013 – Restriction on Inquiry into Customer Affairs
General Rule
Section 132 protects customers from arbitrary governmental interference.
Neither:
- The Minister of Finance; nor
- Bank Negara Malaysia (BNM)
The purpose is to safeguard banking privacy and prevent unjustified investigations.
Exception
BNM may inquire into customer affairs where necessary to exercise its statutory functions under:
- The Financial Services Act 2013;
- The Islamic Financial Services Act 2013; or
- The Central Bank of Malaysia Act 2009.
Case Scenario
Facts
A customer receives several unexplained overseas transfers amounting to RM20 million.
BNM suspects money laundering and requests the customer’s account records from the bank.
The customer argues that disclosure breaches banking secrecy.
Solution
The argument fails.
Section 132(2) expressly permits BNM to obtain such information when exercising regulatory powers.
Critical Analysis
The provision balances:
- Customer privacy; and
- Financial system integrity.
Section 133 FSA 2013 – Statutory Duty of Secrecy
General Rule
Section 133 imposes a strict statutory duty of confidentiality upon:
- Banks;
- Financial institutions;
- Directors;
- Officers;
- Employees;
- Agents; and
- Former employees and agents.
The obligation continues indefinitely, including after employment ends.
Scope of Protection
The duty covers:
- Savings accounts;
- Current accounts;
- Fixed deposits;
- Financing facilities;
- Investment accounts;
- Credit information;
- Transaction histories;
- Customer identities;
- Financial standing; and
- Any information acquired through the banker-customer relationship.
Public Information Exception
The secrecy obligation does not apply where information:
- Has already become lawfully available to the public;
- Is disclosed to BNM for statutory purposes; or
- Is disclosed in anonymous or aggregated form.
Criminal Liability
A person who breaches section 133 commits an offence punishable by:
- Imprisonment up to 5 years;
- Fine up to RM10 million; or
- Both.
Further Disclosure Prohibited
Section 133(3) prohibits a person who knowingly receives unlawfully disclosed information from making any further disclosure.
Thus liability may extend beyond the original wrongdoer.
Section 134 FSA 2013 – Permitted Disclosures
Although secrecy is the general rule, section 134 recognises that confidentiality cannot be absolute.
A bank may disclose information:
- Under Schedule 11; or
- With written approval from BNM.
The 18 Permitted Disclosures under Schedule 11
1. Customer’s Written Consent
Disclosure authorised by the customer.
2. Deceased Customer’s Estate
Disclosure for probate, administration and faraid purposes.
3. Bankruptcy and Winding-Up
Disclosure involving bankrupt individuals and insolvent companies.
4. Litigation Involving the Bank
Disclosure in civil or criminal proceedings involving:
- Customers;
- Guarantors;
- Sureties; and
- Competing claimants.
Disclosure necessary to comply with garnishee proceedings.
6. Court Orders
Disclosure pursuant to orders of courts not lower than the Sessions Court.
7. Enforcement Agencies
Disclosure for investigations conducted under written law.
8. PIDM
Disclosure for performance of statutory functions by PIDM.
9–10. Capital Market Authorities
Disclosure involving:
- Securities Commission;
- Stock exchanges;
- Clearing houses; and
- Trade repositories.
Disclosure for tax administration and international information exchange.
12. Credit Reporting Agencies
Disclosure to registered credit reporting agencies.
13. Supervisory Authorities
Disclosure to local and foreign regulators performing supervisory functions.
14. Centralised Group Functions
Disclosure for:
- Audit;
- Risk management;
- Compliance;
- Finance; and
- Information technology.
Disclosure relating to:
- Mergers;
- Acquisitions;
- Capital raising; and
- Disposal of business assets.
Disclosure to outsourced service providers.
17. Consultants and Adjusters
Disclosure to professional advisers engaged by the bank.
18. Suspicion of Criminal Activity
Disclosure where the bank reasonably suspects that an offence has been, is being or may be committed.
Confidentiality During Court Proceedings
Even when disclosure is permitted, the court may:
- Conduct proceedings in camera;
- Restrict access to documents;
- Prohibit publication; and
- Make confidentiality orders.
PART II – CONFIDENTIALITY UNDER CONTRACT AND EQUITY
Tan Eng Seong v Malayan Banking Bhd
Principle
Disclosure of customer information to the customer’s brother constituted a breach of the implied contractual duty of confidentiality.
Significance
- Confidentiality is an implied contractual term.
- Relatives remain third parties.
- Nominal damages may be awarded.
Wong Yeng Mun v CIMB Bank Berhad
Principle
The bank negligently sent account statements to the wrong address.
The statements were opened by the customer’s wife.
Significance
- Confidentiality belongs to the customer.
- Negligent disclosure may create liability.
- Banks must maintain proper safeguards.
Tan Lay Soon v Kam Mah Theatre Sdn Bhd
Principle
Confidentiality belongs to the customer.
Consent to disclosure may be:
- Express; or
- Implied.
PART III – EXTRA-TERRITORIAL DISCLOSURE
Attorney General of Hong Kong v Zauyah Wan Chik
Principle
Banking secrecy legislation does not automatically operate outside Malaysia.
Disclosure compelled by foreign court proceedings may not create criminal liability in Malaysia.
Significance
The administration of justice may justify disclosure.
PART IV – ILLEGALLY OBTAINED INFORMATION
Wako Merchant Bank v Lim Lean Heng
Principle
Information obtained in breach of banking secrecy provisions remains admissible if relevant.
Significance
The law distinguishes between:
- Criminal liability for disclosure; and
- Admissibility of evidence.
PART V – PUBLIC INFORMATION
Hj Salleh Hj Janan v Financial Information Services Sdn Bhd
Principle
Publicly available court records are not confidential.
Information published in:
- Court records;
- Newspapers; or
- The Gazette
Significance
Banking secrecy protects confidential information, not information already in the public domain.
PART VI – BANKER’S PROFESSIONAL DUTY
Bank Utama (M) Bhd v Insan Budi Sdn Bhd
Facts
The plaintiff obtained an international trade facility to finance the importation and sale of raw sugar.
The plaintiff instructed the bank to issue a confirmed irrevocable transferable SWIFT Telegraphic Transfer.
The bank used the wrong transmission procedure and attempted to send the SWIFT instruction by facsimile.
As a result:
- The overseas bank could not process the transaction;
- The supplier terminated the contract;
- The downstream sale failed; and
- The plaintiff suffered losses.
- Breach of contract; and
- Negligence.
Held
The Court of Appeal held the bank liable.
Principle 1 – Concurrent Liability
A professional adviser may be liable simultaneously:
- In contract; and
- In negligence.
The bank possessed specialist knowledge regarding SWIFT procedures.
The customer could not reasonably be expected to understand technical banking processes.
The bank therefore had a duty to advise the customer that SWIFT transfers cannot be transmitted by facsimile.
Significance
Modern banks are not merely executors of instructions.
They are professional service providers expected to exercise reasonable care and expertise.
PART VII – BANKING SECRECY AND THE PERSONAL DATA PROTECTION ACT 2010 (PDPA)
Relationship Between Banking Secrecy and Personal Data Protection
Banking secrecy and personal data protection operate alongside one another.
While the FSA 2013 protects confidential banking information, the Personal Data Protection Act 2010 (PDPA) protects personal data handled by commercial organisations, including banks.
The PDPA makes it unlawful for commercial organisations to:
- Sell personal information;
- Misuse personal data; or
- Permit unauthorised third parties to access such information.
- Retail banking customers;
- Consumer financing;
- Guarantors;
- Corporate borrowers; and
- Credit facilities.
Criminal Penalties under the PDPA
Depending on the nature of the offence, penalties may include:
Section 141(2)
- Fine up to RM100,000;
- Imprisonment up to 1 year; or
- Both.
- Fine up to RM500,000;
- Imprisonment up to 3 years; or
- Both.
The Seven Personal Data Protection Principles
Banks must comply with seven statutory principles.
1. General Principle (Section 6)
Personal data must:
- Be processed lawfully;
- Be necessary for the intended purpose; and
- Generally be processed with the customer’s consent.
2. Notice and Choice Principle (Section 7)
Customers must be informed:
- Why data is collected;
- How it will be used; and
- Their rights regarding the data.
3. Disclosure Principle (Section 8)
Personal data must not be disclosed without consent unless authorised by law.
This principle closely complements banking secrecy obligations under section 133 FSA 2013.
4. Security Principle (Section 9)
Banks must implement appropriate security measures to protect data.
Examples include:
- Password protection;
- Encryption;
- Secure databases;
- Restricted access systems; and
- Workplace security controls.
5. Retention Principle (Section 10)
Personal data must not be retained longer than necessary.
Once the purpose has been fulfilled, unnecessary data should be destroyed or anonymised.
6. Data Integrity Principle (Section 11)
Personal data must remain:
- Accurate;
- Complete;
- Current; and
- Up to date.
7. Access Principle (Section 12)
Customers must generally be allowed to:
- Access their personal data; and
- Request corrections where information is inaccurate.
Alliance Bank v AmBank Dispute (2018)
Facts
Alliance Bank commenced legal proceedings against AmBank alleging misappropriation of sensitive information.
The dispute involved former Alliance Bank employees who had joined AmBank.
Alliance Bank alleged that electronic records showed confidential internal information being transferred to a former employee after his departure.
The information allegedly reached senior personnel within the competing bank.
The dispute was subsequently resolved amicably.
Significance
The case illustrates that confidentiality obligations extend beyond customer information.
Banks must also protect:
- Internal business information;
- Commercial strategies;
- Trade secrets; and
- Sensitive operational data.
Chia Sun Huat v United Overseas Bank (Malaysia) Bhd
Facts
A purchaser agreed to buy property from a vendor whose property was charged to UOB.
To complete the purchase, the purchaser requested a redemption statement from UOB.
The vendor could not be contacted.
Although a purported letter of authority existed, the bank could not verify its authenticity.
UOB refused to release the redemption statement.
The purchaser sued.
Held
The High Court held that UOB was not liable.
The bank was bound by its duty of secrecy and could not release confidential information without proper authority.
Legal Principle
A bank is entitled to refuse disclosure where:
- Authority cannot be verified; and
- Disclosure would reveal confidential customer information.
Comprehensive Case Scenario
Facts
A purchaser requests a redemption statement from a bank concerning a property owner who cannot be contacted.
The purchaser presents an unsigned authority letter and insists that the transaction cannot proceed without disclosure.
The bank refuses.
The purchaser alleges obstruction and negligence.
Solution
Applying Chia Sun Huat v UOB:
The bank is entitled to refuse disclosure.
The redemption statement contains confidential customer information.
Without verified authority or a statutory exception under section 134 FSA 2013, disclosure would breach banking secrecy.
Critical Analysis
The decision demonstrates the strict nature of banking confidentiality.
Commercial convenience cannot override a bank’s legal obligations.
Banks must verify authority before releasing customer information, even where refusal may delay a transaction.
Key Examination Principles
Section 132 FSA 2013
- Restricts arbitrary inquiries.
- Allows BNM investigations.
- Creates the statutory duty of secrecy.
- Covers all customer information.
- Continues after employment ends.
- Breach attracts criminal sanctions.
- Creates exceptions to secrecy.
- Contains 18 permitted disclosures.
- Allows disclosure with BNM approval.
- Protects personal data.
- Imposes seven statutory principles.
- Creates additional criminal liability for misuse of personal information.
Tan Eng Seong
- Confidentiality is an implied contractual duty.
- Negligent disclosure creates liability.
- Confidentiality belongs to the customer.
- Consent may be implied.
- No automatic extra-territorial effect.
- Illegally obtained evidence remains admissible.
- Public facts are not confidential.
- Banks may be liable concurrently in contract and negligence.
- Professional duty may include a duty to advise.
- Banks may refuse disclosure where authority is uncertain.
- Confidentiality overrides commercial convenience.
Conclusion
Malaysian banking secrecy law is built upon a comprehensive framework comprising sections 132–134 FSA 2013, the Personal Data Protection Act 2010, contractual obligations, equitable principles and tortious duties. The law protects customer information not only from unauthorised disclosure but also from misuse, mishandling and improper processing. The various cases demonstrate that confidentiality belongs to the customer, extends beyond account balances to all customer affairs, survives termination of employment, and remains enforceable through criminal, civil and equitable remedies. At the same time, carefully defined statutory exceptions ensure that secrecy does not obstruct justice, regulatory supervision, legitimate commercial transactions or the public interest.
0 Comments