
In one of our recent articles, we discussed the Cybercrimes Bill 2026 and how Malaysia’s technology legal framework continues to expand to deal with phishing, fraudulent payment instructions and other forms of modern cybercrime. But if there is one communication channel that almost every Malaysian will immediately associate with scams and phishing, it would probably be the humble short messaging service or otherwise better known as SMS.
Think about it for a moment. Despite the prevalent use of internet messaging services such as WhatsApp, Telegram and WeChat, on any given day, most of us will still receive at least a few SMS messages that do not come from our friends or family. It could be a TAC or OTP from the bank, a parcel delivery notification, a payment reminder from our mobile network operator, or a promotion from a retailer we bought something from months ago. Some of us may also still remember, perhaps not too fondly, the days of ringtone, wallpaper, daily jokes and horoscope subscriptions that somehow found their way into our monthly phone bills. What many do not realise, however, is that behind every one of those messages sits a regulatory framework that governs who may send them, through which number, on what terms, and what happens when things go wrong.
That framework is the Commission Determination on the Mandatory Standards for the Provision of Mobile Content Services, Determination No. 3 of 2025 (“MCS Determination”), which was issued by the Malaysian Communications and Multimedia Commission (“MCMC”) on 12 September 2025. In a nutshell, the MCS Determination regulates how mobile content and services, ranging from subscription content, contests and donations to notifications, advertisements and SMS broadcasts, are offered and delivered to mobile users in Malaysia, and it sets out the obligations of each licensee involved in the delivery chain, namely the mobile content service providers, the mobile network operators and the network service providers that issue short codes.
While the MCS Determination is primarily directed at licensees, its practical reach is considerably wider, as banks, e-commerce platforms, logistics companies, healthcare providers, retailers and practically any business that sends SMS to its customers will, in one way or another, be relying on a licensee that is subject to the MCS Determination.
Therefore, in this article, we set out the top 7 key takeaways from the MCS Determination that mobile content service providers, telcos, in-house legal and compliance teams should understand. And in our future article, we will pivot and look at the same framework from the perspective of the businesses that send messages to their customers.
Key Takeaway 1: What is the MCS Determination and Why Does It Matter?
Of course, the starting point is to understand what the MCS Determination actually is, and where it sits within the broader regulatory framework.
The important point to note here is that the MCS Determination is a mandatory standard, and not merely a voluntary industry code or a set of best practice guidelines. In other words, compliance with the MCS Determination is not optional for the licensees it applies to, and non-compliance with a mandatory standard is an offence under the Communications and Multimedia Act 1998 (“CMA”). Beyond the criminal exposure, as we will see further below, the MCS Determination also contains its own very practical enforcement tools, including the suspension of short codes and mandatory refunds to customers.
Back then, mobile content was largely about premium SMS subscriptions, where customers paid for ringtones, wallpapers, horoscopes, quizzes and contests through their phone bills or prepaid credit, and the regulatory concerns of the day were largely about customers being subscribed to services they never knowingly agreed to, and being charged for content they never really asked for.
Fast forward to today, and the landscape looks very different. Most of the SMS traffic we receive now consists of OTPs, account alerts, appointment or billing reminders, delivery updates and marketing campaigns, much of it free to receive. At the same time, a growing amount of mobile content is now purchased through websites and mobile applications, and billed directly to the customer’s mobile account. And, of course, SMS has become one of the most abused channels for scams, which has understandably shifted the regulator’s priorities. The MCS Determination is essentially MCMC’s response to that changed landscape, as it expressly extends to electronic platforms and introduces, among others, multi-level verification for subscriptions, rules on recycled mobile numbers, spend limits and a duty to authenticate the origination of messages. The MCS Determination set the rules for how mobile content and services, from paid subscriptions to notifications, advertisements and SMS broadcasts, may be offered and delivered to mobile users in Malaysia, and allocate the obligations among the mobile content service providers who offer them, the mobile operators who bill for them, and the network service providers who issue the short codes the mobile content services run on.
Key Takeaway 2: What Exactly Is a Mobile Content Service?
The second key takeaway is to understand what actually falls within the definition of mobile content services (“MCS”), because it is probably wider than most people would expect.
Under the MCS Determination, MCS refers to mobile content and services which are subscribed to and activated within the service providers’ own platform, provided through any communications system (which includes mobile devices, fixed devices and electronic platforms), and billed via direct carrier billing offered by the mobile operators. These services are typically designed to leverage the portability and connectivity of mobile devices to provide entertainment, information and utility directly to customers, for which charges may be imposed over and above the standard network charges. Specifically, the MCS Determination provides that MCS consists of one or more of the following:
ⅰ. the provision of content to any person, including but not limited to entertainment, news updates, education, and information, visual and audio media;
ⅱ. the provision of a service to any person, including but not limited to subscriptions, notifications, advertisements, contest participation, donation and voting;
ⅲ. a combination of (i) and (ii), but excluding value-added services provided by the mobile operators, such as call waiting, caller ID, voicemail and roaming; or
ⅳ. SMS Broadcast, which is defined as the service of sending a one-way free SMS to a customer, usually for the purpose of advertisement or announcement.
Of the four, SMS Broadcast is probably the one that most of us would be most familiar with today, as it is, in all likelihood, the type of SMS that we receive the most. Think of the message from a retailer announcing its latest in-store promotion, a bank informing us of a new credit card campaign, or a service provider announcing upcoming scheduled maintenance. And unlike the premium subscription services that the previous framework was largely concerned with, SMS Broadcast brings a much wider range of businesses, many of which would never think of themselves as being in the mobile content business at all, within the orbit of the MCS Determination.
It is also worth noting how broadly “customer” is defined. A customer is not only an end user who subscribes to or acquires an MCS, but also a potential subscriber or acquirer, and even an end user who is merely offered the MCS, whether for free or otherwise. In other words, the protections under the MCS Determination do not only kick in once someone has paid for something. They apply from the moment an end user is offered the service. This also raises a rather interesting question. A business that purchases SMS Broadcast from an MCS provider, in order to send notifications or promotional messages to its own end customers, is itself acquiring an MCS, and on a plain reading of the definition, such a business would also appear to fall within the meaning of a “customer”. We will come back to this point in the next key takeaway.
Key Takeaway 3: Understand Who’s Who in the MCS Ecosystem
The third key takeaway is to understand the different parties within the MCS ecosystem, because the MCS Determination allocates different obligations to each of them. Paragraph 3.1 of the MCS Determination makes it clear that it applies to MCS providers, PCS providers and network service providers, as the case may be.
If we may use a simple analogy, which we will be returning to throughout this article, the MCS ecosystem can perhaps be understood as a shopping mall.
The “network service provider” is essentially the mall owner. It issues the short codes, the 5-digit numbers that start with either “2”, “3” or “6” from which MCS is delivered, to MCS providers, much like a mall owner leasing out shop lots to its tenants. And just like a responsible mall owner, the network service provider is required to ensure that its tenants are properly licensed, and to close a tenant’s shop when MCMC instructs it to do so.
The “MCS provider” is the tenant operating the shop. It is an applications service provider under the CMA that provides the MCS, whether through messaging services via short codes, internet access services, or both. The MCS provider is the party that deals directly with the customer, and it therefore carries the bulk of the obligations under the MCS Determination, from how subscriptions are obtained to how advertisements are presented and how complaints are handled. Interestingly, a mobile operator can also be an MCS provider if it provides MCS itself.
The “PCS provider”, or public cellular service provider, is essentially the mobile operator that provides the cellular service, the billing and the mobile content platform. Returning to our mall analogy, the PCS provider is more like the payment counter, as it is the party that actually collects the money from the customer, whether by adding the charges to the monthly postpaid bill or deducting them from prepaid credit. Hence, it is also the party responsible for monitoring customers’ accumulated charges and applying spend limits.
Finally, the “customer” is the shopper, being the end user who is offered, subscribes to or acquires the MCS.
Now, what about the bank, the e-commerce platform or the clinic that simply wants to send an OTP or an appointment reminder to its own customers? The answer is not as straightforward as it may first appear. Such a business is clearly not an MCS provider, a PCS provider or a network service provider, and in that sense, it is not a tenant, a mall owner or a payment counter. However, as mentioned in the preceding key takeaway, a “customer” includes an end user who acquires the MCS, whether for free or otherwise, and a business that acquires SMS Broadcast from an MCS provider does precisely that. In our view, therefore, the reading is that such a business will also be considered a customer for the purposes of the MCS Determination, Returning to our mall analogy, such a business therefore sits somewhere between a shopper and a brand selling its products through the tenant’s shop, and as we will explore in our next article, this position comes with a rather interesting set of practical implications, including the possibility that a business may be able to rely on certain protections under the MCS Determination directly, and not only on whatever it manages to negotiate into its contract with its provider.
Key Takeaway 4: Every Subscription Must Start, and End, With the Customer
The fourth key takeaway is that the MCS Determination places the customer firmly in control of every subscription, from the very beginning to the very end.
At the starting point, all acquisitions or subscriptions of MCS must be initiated by the customers themselves, and the customer’s consent or request must be recorded by the MCS provider in the transaction logs. The MCS provider must not automatically subscribe a customer to a subscription-based service simply because the customer acquired a single or one-time MCS, must not combine a one-off acquisition with a subscription-based service, and must not provide an unsolicited “free” MCS that requires the customer to unsubscribe, failing which the customer is automatically subscribed and charged.
Returning to our mall analogy, this is like a shop that cannot automatically sign a shopper up for a monthly membership just because the shopper bought a single item, or hand the shopper a “free sample” that quietly turns into a paid monthly delivery unless the shopper remembers to cancel it. Those who remember the premium SMS days will immediately recognise exactly which practices these rules are aimed at.
For MCS provisioned via SMS, the MCS provider must designate a specific subscription keyword, which cannot be a generic or commonly used expression such as “yes” or “ok” that may increase the risk of a customer subscribing accidentally, and must send an SMS requesting the customer to confirm the request, which constitutes the double confirmation process. Customers must also be able to request information using easily accessible terms such as “help” or “bantuan”, and where the MCS provider receives an unrecognised or invalid keyword, it must respond at no cost with the correct keyword to terminate the subscription.
On renewals, the MCS provider must send a renewal confirmation at no cost, clearly stating that the renewal confirmation is free, together with the price of renewal, the exact chargeable content, the subscription expiry date and the steps to unsubscribe, and must confirm to the customer once an auto-renewal has been carried out.
On termination, the MCS provider must terminate a subscription upon receiving the customer’s request through any preferred platform, including SMS, email or in-application, must comply immediately, must not send any further MCS after the termination, and must send a free termination notification.
Key Takeaway 5: Short Codes Are the Lifeline of Every MCS
The fifth key takeaway is that short codes are, quite literally, the lifeline of every MCS delivered via SMS, and the MCS Determination is very specific about how they are to be used.
Under paragraph 9.1, MCS providers and PCS providers must ensure that MCS is delivered only through a 5-digit short code starting with the number ‘2’ or ‘3’, and that SMS Broadcast is delivered only through a 5-digit short code starting with the number ‘6’, although MCMC may allow the use of other short codes from time to time. This is why, if you look closely, the OTPs, alerts and promotional messages you receive from businesses will typically come from a 5-digit number beginning with ‘6’.
If an MCS provider chooses to change its short code, it must notify the network service providers at least 10 working days before the change, inform all active subscribers at no cost, and apply the same terms, prices and charges to customers who re-register for the same MCS under the new short code.
More importantly, short codes can be switched off. Where an MCS provider is found not to be in compliance with the MCS Determination, the network service provider through which the MCS is provisioned must, upon receiving a written notice from MCMC, suspend the relevant short code and the associated MCS. The suspension may only be lifted if MCMC is satisfied that the non-compliance has been rectified, and an MCS provider whose short code is suspended cannot apply for any new short code for the duration of the suspension unless MCMC approves otherwise.
Returning to our mall analogy, this is effectively the mall owner closing the shop on MCMC’s instructions, with the tenant unable to simply open another shop next door in the meantime. The consequences do not stop there either, as MCS providers must, upon receiving a written notice from MCMC, refund customers any charges imposed in breach of the MCS Determination, in monetary form rather than free content unless the customer agrees otherwise, and must not charge customers at all for any MCS found to be non-compliant.
And while this is primarily a risk for the MCS provider, one can easily imagine the knock-on effect on every business whose messages are delivered through that suspended short code, which is precisely one of the issues we will be exploring in our next article.
Key Takeaway 6: Marketing and Pricing Must Be Clear and Fair
The sixth key takeaway relates to how MCS is marketed, priced and supported, and the overarching theme here is clarity and fairness to the customer.
On advertising, MCS providers must provide customers with sufficient, clear, accurate, true and up-to-date information, in simple and straightforward language, in all MCS advertisement materials, and in line with the Malaysian Communications and Multimedia Content Code. Every MCS advertisement message sent to a customer’s device must be recorded in a transaction log, and important information such as the price and frequency of the service must be displayed on the same page or screen as the subscription button, regardless of whether the advertisement appears via SMS, TV, radio, print, website, mobile device or electronic platform. In other words, the price should never be hidden two screens away from the “subscribe” button.
Where an MCS includes marketing, prompt or inducement messages as part of the service, the MCS provider must give customers the option to opt out of receiving such messages before or at the start of the service. Once a customer opts out, the MCS provider must immediately stop sending promotional content through the platform chosen by the customer, even if the customer still has an active subscription, and it must not send any marketing messages to customers who have terminated the related subscription.
On pricing and charges, MCS providers must set their prices in accordance with the rate-setting principles under section 198 of the CMA, and prominently display clear and accurate price information for any chargeable content before or at the point of delivery. The PCS providers, being the payment counter in our mall analogy, must also maintain a system to monitor customers’ accumulated MCS charges, detect significant increases in usage and promptly notify customers once their charges reach a predefined threshold, and must apply a spend limit for MCS charges, which may only be changed at the customer’s request.
Key Takeaway 7: Gatekeeping and Authentication
The seventh and final key takeaway relates to the general obligations under the MCS Determination, which, in our view, reveal quite clearly the direction in which MCMC is heading.
First, the network service providers act as gatekeepers. They must ensure that every MCS provider whose services are provisioned through their network is duly registered as an applications service provider licensee with MCMC, and must not charge customers for any MCS provided by unlicensed providers. MCMC may also require network service providers to implement and maintain a system that automates compliance with the MCS Determination, and any such system must be operated independently and in a non-discriminatory manner, and cannot be owned, operated or supported by another MCS provider.
Second, and particularly interesting from a scam-prevention perspective, MCS providers, PCS providers and network service providers must ensure the authenticity of mobile origination and mobile termination in respect of the MCS provided, whether through a local or international gateway. Put simply, the licensees in the chain must be able to stand behind where a message actually comes from, which goes to the very heart of the spoofing and impersonation tactics that scammers so often rely on.
Third, MCS providers must ensure that all content and advertisements comply with the CMA, the Content Code and the General Consumer Code, and, together with the PCS providers, must adopt security measures to prevent security risks in the delivery of MCS.
Taken together, the message is clear. Compliance with the MCS Determination is not meant to be a paper exercise, as MCMC has given itself the tools to audit, verify and, where necessary, switch off non-compliant services.
Closing Thoughts
The MCS Determination may not attract the same level of attention as the Online Safety Act 2025 or the Cybercrimes Bill 2026, but in many ways, it touches our daily lives far more frequently than either of them, as almost every OTP, alert, reminder or promotional message we receive passes through the framework it regulates. With the MCS Determination, what we are seeing is a framework that has been brought up to date with how mobile content is actually offered and consumed today, from SMS to websites and mobile applications, with a much stronger emphasis on customer control, transparency and, increasingly, the fight against scams.
If you have any questions on the MCS Determination, mobile content services, A2P messaging, telecommunications licensing, direct carrier billing or the broader technology regulatory framework in Malaysia, please feel free to reach out to the partners in our Technology Practice Group, Lo Khai Yi and Ong Johnson, for a consultation. We have extensive experience advising on technology law, telecommunications licensing and regulation, data protection, cybersecurity and digital platforms, and would be pleased to assist licensees, businesses, boards and in-house teams in understanding and complying with the evolving regulatory requirements for mobile content services in Malaysia.
The Technology Practice Group of Halim Hong & Quek continues to be recognised by leading legal directories and industry benchmarks. Recent accolades include FinTech Law Firm of the Year at the ALB Malaysia Law Awards (2024, 2025 and 2026), Law Firm of the Year for Technology, Media and Telecommunications by the In-House Community, FinTech Law Firm of the Year by the Asia Business Law Journal, a Band 2 ranking for FinTech by Chambers and Partners, and a Tier 3 ranking by Legal 500. The strength of the practice is further reflected in the individual recognition of its partners, including a Band 1 ranking for FinTech by Chambers and Partners within the Technology Practice Group.
About the authors
Lo Khai Yi
Partner
Co-Head of Technology Practice Group
Technology, Media & Telecommunications (“TMT”), Technology
Acquisition and Outsourcing, Telecommunication Licensing and
Acquisition, Cybersecurity
ky.lo@hhq.com.my.
◦
Ong Johnson
Partner
Head of Technology Practice Group
Fintech, Data Protection,
Technology, Media & Telecommunications (“TMT”),
IP and Competition Law
johnson.ong@hhq.com.my
More of our Tech articles that you should read:
- • Consumer Credit Act 2025: 10 Key Takeaways on Malaysia’s New Authorisation Regime
- • Exit and Step-In Rights in Artificial Intelligence-as-a-Service
- •Telecommunication Towers M&A: Unpacking the Transaction