
When it comes to the building of public or national infrastructure, the Malaysian government frequently adopts a concession model, granting a private entity the right to operate and manage a public infrastructure asset for a specified period. These concession projects typically follow a Build-Operate-Transfer (BOT) model, essentially allowing the government to leverage private capital and expertise to build and operate the relevant infrastructure, then take the asset back at the end of the agreed concession term. One can say that the BOT model is now rather mature, having gone through many rounds of trials and tests.
In the digital age, infrastructure is no longer physical – there is an increasing need for the government to establish and deploy national digital infrastructure as well. When the building of national digital infrastructure is supposed to adopt a government concession model, applying the typical concession agreement built and fine-tuned for physical infrastructure will simply not work. In the case of digital infrastructure, what exactly gets transferred at the end? How should the concessionaire’s service level be measured? Can the government step in and operate the digital infrastructure at any point in time? All these concerns have to be addressed very differently in the case of a concession involving digital infrastructure, and we will be examining 5 key drafting points of a concession agreement involving digital infrastructure in this article.
Where the BOT Model Strains
- 1. The Transfer Obligation
- When a highway reverts to the government, ownership and operation of the highway, essentially its upkeep and maintenance, is transferred to the government. When a digital platform is to revert to the government, however, what is actually being transferred? The source code of the digital platform would be the most obvious answer. Unlike a physical asset, several concerns surround the taking over of source code. For one, does the concessionaire even have the right to transfer the ownership of the source code – if open-source components or background intellectual property rights are used, the transfer of these components may present a challenge. Hence, in the concession agreement involving digital infrastructure, it is very common to see controls on the use of open-source components and background intellectual property, ensuring upfront that the source code that is developed will not be subject to any encumbrance that impedes transfer. The government may also require the use of source code escrow to facilitate the transfer.
- 2. Data Ownership and Portability
- Another key point to note is that the operation of a digital platform will often require working data – the data which the concessionaire has been processing using the platform throughout the concession period. It would be pointless for the government to take back the source code of the digital platform without the data which the platform is meant to be processing. As such, a concession agreement involving a digital platform will certainly address the ownership and transfer of data to be processed or generated through the use of the digital platform. To ensure the availability of the data at the end of the concession period and to facilitate the transfer thereof, one measure we have seen is for the government to require the accompanying data to be hosted on a government-maintained server, and for the government to have access to such data throughout the concession term.
- 3. Obsolescence
- Physical infrastructure depreciates over time, slowly and predictably; software, however, carries the issue of obsolescence. With how quickly technology advances and evolves, what may be the cutting-edge technology today may just be obsolete five years later. For a concession agreement involving a software system, especially where the concession period is going to be significantly longer, it would be important to build in refresh and upgrade obligations on the part of the concessionaire. Commonly, this would be one of the mandates of the steering committee established to supervise the operation of the concession platform. Where newer technology becomes available, or technological development compels certain upgrading or enhancement of the concession platform, there should be some mechanisms to require the concessionaire to upgrade or enhance the platform accordingly. Otherwise, the government may be inheriting, at handover, a platform that was modern at signing but a liability at the point of transfer.
- 4. Service Levels
- A digital platform, especially one designed for national purpose, is expected to be available continuously, at defined performance levels. Service level commitments, uptime guarantees, and remedies for degradation are common and often offered by default by the software providers in commercial technology contracts. In the case of a government concession involving a digital platform, however, these mechanisms may not be accepted as easily by the concessionaire, for the simple reason that it is oftentimes tasked with developing the solution from scratch, based on the requirements of the government. As such, it would be difficult for most concessionaires to commit to high service levels and uptime, with serious consequences for falling short, for a system that they have not had years to fine-tune and perfect. In light of these reasons, an appropriate service level mechanism in a concession agreement involving a digital platform is one of the most negotiated provisions and may take some level of creative structuring – for example, a lower revenue share to the government during the initial years of the concession, or even a waiver of service credits during those years.
- The government, on the other hand, may need to impose stringent requirements to conduct acceptance testing, stress testing, load testing and capacity testing of the platform to ensure that it is able to support the contemplated use case and user traffic. Additionally, there will certainly be a need for the government to review the concessionaire’s disaster recovery and business continuity plans to ensure risks are adequately addressed and mitigated, and for the government to have a contractual right to audit these plans from time to time and to require periodic testing of them, with the ability to request changes where the test findings are unsatisfactory.
- 5. Termination, Step-In and Handover
- Concession agreements typically give the government step-in rights and provide end-of-term handover mechanics. For a digital platform, it means being handed a live and likely complex platform that is supposed to be operating continuously. Upon handover, the government is expected to run it without disruption, which is pretty much impossible unless there is a comprehensive knowledge transfer. Because of this, a concessionaire can expect that a concession agreement will almost certainly have extensive provisions on transition, knowledge transfer and documentation standards to ensure that the government’s takeover of the digital platform can be as seamless as possible. In some cases that we have seen, the government would even demand the secondment of its personnel to the concessionaire’s team from an early stage of the concession to begin knowledge transfer as early as possible.
When it comes to the structuring of a concession agreement involving the establishment of a new digital platform, most people tend to treat it just like any other conventional concession agreement for physical infrastructure. The reality is that a conventional concession agreement is simply not suited to the nuances of a custom-made digital platform. To get the concession agreement right, the most useful thing to do is perhaps to understand what the government must actually be able to do with the system on the day the concession ends, and start working backwards from there to ensure that the concession agreement provides the necessary controls and mechanisms to achieve the end objectives.
The Technology Practice Group at Halim Hong & Quek frequently advises and assists clients in their technology projects with the government, whether it is on-premises solutions or cloud-based offerings. If you have any questions or would like to enquire about our services, please feel free to reach out to the partners and co-heads of the Technology Practice Group, Lo Khai Yi and Ong Johnson, for more information.
Our Technology Practice Group continues to be recognised by leading legal directories and industry benchmarks. Recent accolades include FinTech Law Firm of the Year at the ALB Malaysia Law Awards (2024 and 2025), Law Firm of the Year for Technology, Media and Telecommunications by the In-House Community, FinTech Law Firm of the Year by the Asia Business Law Journal, a Band 2 ranking by Chambers and Partners and a Tier 3 ranking by Legal 500 on FinTech, as well as a Tier 4 ranking by Legal 500 on Technology, Media and Telecommunications.
About the authors
Lo Khai Yi
Partner
Co-Head of Technology Practice Group
Technology, Media & Telecommunications (“TMT”), Technology
Acquisition and Outsourcing, Telecommunication Licensing and
Acquisition, Cybersecurity
ky.lo@hhq.com.my.
◦
Ong Johnson
Partner
Head of Technology Practice Group
Fintech, Data Protection,
Technology, Media & Telecommunications (“TMT”),
IP and Competition Law
johnson.ong@hhq.com.my
More of our Tech articles that you should read:
- • How to Conduct a BNPL Business in Malaysia under the CCA 2025: Top 10 Key Takeaways
- • Exit and Step-In Rights in Artificial Intelligence-as-a-Service
- • Managing Liability in Agentic AI Deployment