LepakLah
Tech

The Online Safety Act Gives You a Clock: 5 Deadlines That Start When You Report Content

Malaysia's Online Safety Act 2025 came into force in January 2026, and its subsidiary regulations put hard timeframes on platforms — one hour to acknowledge your report, 12 hours to tell you the status. Here is the clock that now runs when you hit report.

Lepaklah Editorial6 min read
A smartphone screen showing a folder of social media apps held in someone's hand.
A smartphone screen showing a folder of social media apps held in someone's hand.

Most people who report a post in Malaysia expect the same thing to happen: nothing, slowly. That changed on 1 January 2026, when the Online Safety Act 2025 came into force along with four sets of subsidiary regulations — and one of those regulations does something the old complaint form never did. It puts a clock on the platform.

The Act itself is Act 866. The timing rules sit in the Online Safety (Period) Regulations 2025. Together they mean that when you tap report, a countdown starts, and missing it is a regulatory problem for the platform rather than a customer-service one.

Here is what the clock actually looks like.

1. One Hour to Acknowledge Your Report

The first deadline is the shortest. Once a licensed provider receives a user report of harmful content, it must acknowledge receipt within one hour.

An acknowledgement is not a decision — it is the platform confirming your report exists and has entered the queue. But it is now a timed obligation rather than a courtesy, and it starts everything that follows.

2. Twelve Hours to Tell You What's Happening

From that acknowledgement, the provider has 12 hours to complete an initial assessment and notify you of the status of your report.

Twelve hours does not mean the content comes down in twelve hours. It means you should know within half a day whether the report was dismissed, is under assessment, or has already triggered action. Silence past that point is the thing to note, because it is what the regulations were written to stop.

3. Four Hours to Lock Content Down — or None at All

If a report is not dismissed, the provider must, within four hours of that point, make the content inaccessible to all users for 24 hours.

Think of it as a hold rather than a verdict. The material goes dark while assessment finishes. Confirmed as harmful content, it must be made permanently inaccessible within 12 hours of that determination. Cleared, it must be restored within four hours. The regulations are not a one-way takedown pipe — a wrong call has a restoration clock attached to it too.

Priority harmful content skips that queue entirely. The Act reserves that label for two things: child sexual abuse material and financial fraud. For those, the provider must immediately make the content inaccessible to all users for 24 hours. If assessment confirms it, permanent removal follows within one hour. If not, restoration follows within one hour.

Putting scam content in the same tier as child sexual abuse material is a deliberate policy choice, and it tells you how Malaysia now categorises online financial fraud. If money has already moved, though, the takedown timeline is not your first call — reporting to NSRC 997 is, and that is a separate, faster channel.

4. Fifteen Days for You to Push Back

Here is the deadline that belongs to you rather than the platform.

If you are an aggrieved user — because your report was dismissed, or because you disagree with what the provider did — you have 15 days from being notified of that action to inquire into the decision.

The provider then has to come back to you: five days for priority harmful content, seven days for everything else.

That 15-day window is easy to miss precisely because nothing prompts you. If a report comes back dismissed and it matters, the calendar starts that day.

5. Content Hosted Elsewhere Goes Through MCMC and Your ISP

Not everything lives on a licensed platform. When harmful content sits outside the service of a licensed applications service provider, a different route applies.

You report it to MCMC. If MCMC issues a written instruction to a licensed network service provider — in practice, your internet provider — the NSP must restrict the material within its network in the period stated in that instruction, make it permanently inaccessible to all users, and notify MCMC in writing of what it did so MCMC can update you.

Slower, and it involves a regulator rather than an app. But it closes the obvious gap: content parked on a website that has no report button at all.

Who the Clock Actually Applies To

Two limits are worth being clear about.

The Act binds providers, not users. MCMC's own FAQ states that the ONSA applies to service providers and not to the individual users of their platforms. This is not a law that creates new offences for posting — other legislation does that work.

Only licensed providers are in scope. From 1 January 2026, internet messaging and social media services with at least eight million users in Malaysia are deemed registered as applications service provider class licensees under section 46A of the Communications and Multimedia Act 1998. That eight-million threshold determines who the clock applies to, and lawyers at Rahmat Lim & Partners note it may be lowered, which would pull smaller platforms in.

The teeth: failing the prescribed duties can expose a provider to a financial penalty of up to RM10 million. Missing the prescribed periods can draw a fine of up to RM1 million.

It is also one layer in a stack. Licensing for social media and messaging services started on 1 January 2025. Then on 1 June 2026, two MCMC codes took effect — the Risk Mitigation Code and the Child Protection Code, the second of which drives the under-16 account rules now reaching existing users. Your rights over the data those platforms hold sit under a different statute entirely, which we broke down in the PDPA rights you actually have.

Knowing which door to knock on is half the exercise. Harmful content goes to the platform and then MCMC. Data goes through PDPA. Money goes through NSRC.

FAQ

When did Malaysia's Online Safety Act come into force?

The Online Safety Act 2025 (Act 866) came into force on 1 January 2026, together with four sets of subsidiary regulations covering fees, the form of undertaking, prescribed periods, and the Online Safety Appeal Tribunal.

How fast must a platform respond to my report in Malaysia?

Under the Online Safety (Period) Regulations 2025, a licensed provider must acknowledge your report within one hour and notify you of its status within 12 hours of that acknowledgement.

What counts as priority harmful content?

Child sexual abuse material and financial fraud. Both trigger immediate restriction for 24 hours and a one-hour deadline for permanent removal or restoration once assessment is done.

Can I appeal if my report is dismissed?

Yes. An aggrieved user has 15 days from being notified of the provider's action or dismissal to inquire into the decision. The provider must respond within five days for priority harmful content or seven days otherwise.

Does the Online Safety Act apply to every app?

No. It applies to licensed applications service providers and content applications service providers. Messaging and social media services with at least eight million users in Malaysia are deemed registered as licensees, and MCMC has signalled the threshold may be lowered later.

Lepaklah Editorial

Researched and edited by the LepakLah team.

More from the team
Read us on Google more often.Pick LepakLah as a preferred source and our stories rank higher in your results.
One letter, most Sundays.No noise. Unsubscribe anytime.