© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.
[Feature Article] MalaysiaKini: Esha Clause – Why Punishment Alone Cannot Protect Children
Esha Clause - Why Punishment Alone Cannot Protect Children
by Thulasy Suppiah, Managing Partner

MALAYSIA has recently undergone a significant shift in its legal approach to bullying and cyberbullying, driven largely by public outrage over tragic losses of life. The most notable result is Section 507D(2) of the Penal Code—widely dubbed the “Esha Clause.”
This provision criminalises threatening, abusive or insulting conduct intended to provoke a person to harm themselves or another person, or that the perpetrator knew or ought to have known was likely to do so. If that provocation results in a suicide attempt or death by suicide, the maximum prison sentence rises to ten years.
Having this law on the books sends a strong moral message. However, the public must understand the harsh legal reality: a severe penalty does not guarantee an easy conviction, nor does it act as an immediate shield for victims.
In a criminal court, proving that bullying took place may only be half the battle. The ongoing investigation into the tragic death of 14-year-old Keziah Nisha may become an important test of this clause.
While police are presently investigating the case under Section 507B, the investigation remains active and no final charging decision has been announced. It would therefore be premature to conclude that Section 507D (2) has been ruled out.
Nevertheless, the case highlights the immense difficulty at the heart of the Esha Clause. Prosecutors must prove not merely that the conduct was cruel or distressing, but that the accused intended to provoke self-harm or knew or ought to have known that the conduct was likely to do so. Where suicide followed, they must also prove that it occurred as a result of that provocation. Human distress rarely has a single, tidy cause. Where mental health, accumulated incidents, and other pressures overlap, establishing that connection beyond a reasonable doubt becomes a monumental hurdle.
But there is a deeper limitation to the Esha Clause. It is fundamentally an after-the-fact tool. It can hold a perpetrator accountable after threatening or abusive conduct has occurred, but it cannot by itself provide the immediate protection a vulnerable person may urgently need.
Criminal law can punish and deter, but it cannot substitute for protecting a victim in real time. Although the Esha Clause applies regardless of the victim’s age, its limitations are especially serious when children are involved. Children depend heavily on parents, teachers and school administrators to recognise the danger and intervene before bullying escalates into self-harm.
True protection therefore depends on what happens during the critical hours and days after a child first reports bullying or shows signs of distress. Yet Malaysia has moved from fragmented legal protections to an increasingly crowded anti-bullying framework. Beyond the Penal Code, we now have the Online Safety Act and the Anti-Bullying Act 2026, which established the Tribunal for Anti-Bullying.
While these measures serve different purposes, making sense of them in the midst of a crisis can be daunting. Teachers and school administrators must currently navigate the 2023 bullying guidelines, the sweeping 402-page 2026 Safe School Management Guidelines, the separate Student Protection Policy, the SAFE framework, and procedural reporting timelines such as SOP 1:3:7.
Having multiple laws and thick policy documents is not the same as having a cohesive safety net. When a child is facing severe psychological distress, a terrified parent or an overwhelmed teacher does not have time to solve an administrative puzzle. They need a single, unambiguous “no-wrong-door” emergency triage protocol. This must include an immediate suicide risk assessment, interim protection, and a designated response coordinator.
The Esha Clause is necessary, but it is not a safety net. The true measure of our national anti-bullying framework should not be how severely we can punish a perpetrator after the fact, but whether we can protect a victim in time. If a child facing bullying has attempted suicide or is already gone, our frontline intervention system has failed to reach that child in time. To truly honour Esha and the other victims who inspired these reforms, early intervention must become our first and most urgent line of defence.
Written By:
Thulasy Suppiah,
Managing Partner,
Suppiah & Partners,
UG-13, Lexa Galleria, 45, Jalan 34/26,
Wangsa Maju, 53300 Kuala Lumpur.
Handphone no: 012-4915238
© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.
More Featured Articles
[Feature Article] The Star: When the Cloud is Threatened by Drought
When the Cloud is Threatened by Drought
by Thulasy Suppiah, Managing Partner
THE devastating flood in Tibet and Nepal has once again drawn attention to the growing environ-mental risks facing fragile moun-tain regions in a warming world.
Closer to home, Malaysia faces a different climate challenge. As the country grapples with a strengthening El Nino, SPAN (National Water Services Commission) recently reported that nine of 49 major dams sup-plying raw water in Peninsular Malaysia and Labuan were at warning levels, two on alert and one critical.
El Nino is a naturally occurring climate phenomenon, but it is unfolding in a world warmed by human activity. Forecasts point to a very strong event extending into 2027, and Malaysian authori-ties have warned of pressure on domestic water supply, agricul ture and industrial activity.
Against this backdrop, Malaysia is rapidly expanding its data centre footprint. Globally, data centres accounted for about 1.5% of electricity consumption in 2024, with the International Energy Agency (IEA) projecting demand to more than double by 2030.
The concern is not only the pace of growth but its concentra-tion in hubs such as Malaysia, too. The question is whether our resource planning can keep pace.
To its credit, the government has begun to respond. The Investment, Trade and Industry Ministry’s Guidelines for Sustainable Development of Data Centres encourage facilities to avoid water-stressed areas and use reclaimed water.
A dedicated Data Centre Task Force (DCTF) has also been estab-lished to assess utility capacity before projects are approved.
But El Nino presents a harder question: Are we assessing water availability under normal condi-tions, or stress-testing projects against severe drought?
Our environmental framework also deserves another look. Under the Environmental Quality Act 1974, data centres are not explicitly identified as a stan-dalone “prescribed activity” requiring an Environmental Impact Assessment (EIA).
Given the scale of new hyper-scale facilities, major projects should be assessed for cumula-tive regional demand rather than in isolation.
Operators should disclose actu-al water-use efficiency and electricity consumption and also demonstrate credible plans to reduce reliance on potable water during periods of stress.
El Nino offers a real-world stress test of whether Malaysia’s digital infrastructure is resilient to the climate in which it must operate.
Written By:
Thulasy Suppiah,
Managing Partner,
Suppiah & Partners,
UG-13, Lexa Galleria, 45, Jalan 34/26,
Wangsa Maju, 53300 Kuala Lumpur.
Handphone no: 012-4915238
© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.
More Featured Articles
[Feature Article] The Star & MalaysiaKini: The Unfinished Business of Merdeka
The Unfinished Business of Merdeka
By Thulasy Suppiah, Managing Partner of Suppiah & Partners
As we mark 69 years of independence, Merdeka must be understood not merely as a historical milestone from 1957, but as an ongoing, living project. While we have long secured our political sovereignty, our journey toward true social and economic independence remains unfinished.
This divide is starkly visible in our daily lives. In digital spaces, public debates too often devolve into categorising citizens by race, casually reducing individuals to a “Type.” This digital tribalism proves that the colonial legacy of “divide and rule” has simply mutated, finding new life in algorithms, anonymity, and manufactured outrage.
Recent investigations and data paint a deeply concerning picture of these fractures across three critical areas:
In employment, a study by the Centre for Governance and Political Studies (Cent-GPS) demonstrated that job applicants face drastically skewed callback rates based on ethnicity despite having identical qualifications.
In housing, research by Architects of Diversity (AOD) revealed that nearly half of Klang Valley rental listings impose racial criteria, forcing marginalised tenants to pay a “discrimination tax” in higher rents just to secure a home.
In our digital discourse, an undercover investigation by media platform The Fourth exposed how social hostility is often not organic, but manufactured. Irresponsible parties fund hidden agencies, cybertroopers, and comment seeders to artificially amplify polarising talking points, creating a false illusion of widespread communal division.
These practices persist due to a glaring legislative and regulatory vacuum. We currently have a crucial window of opportunity to begin addressing these structural flaws.
In housing, as the government finalises the Residential Tenancy Bill, it is imperative that lawmakers include explicit anti-discrimination clauses. Enacting tenancy reform without addressing racial screening merely treats the symptoms of an unfair market while ignoring its root cause. We cannot claim to legislate fairness if we leave legal loopholes for unjust exclusion.
In employment, private corporations must move beyond performative diversity statements and institutionalise objective hiring safeguards, such as blind recruitment processes that evaluate candidates solely on professional merits before personal demographics are revealed.
In our digital sphere, regulatory frameworks must evolve to demand strict transparency for funded online campaigns, ensuring the public knows when social media discourse has been artificially manufactured by shadowy actors.
Yet, there is profound reason for optimism. Divisive rhetoric is steadily losing its grip on the younger demographic. Young Malaysians—born into a hyper-connected world—are increasingly recognizing that the shared struggles of stagnant wages, housing affordability, and economic uncertainty do not discriminate by race, looking past the manufactured narratives designed to compartmentalise them.
Away from the political arena and the extremes of social media, the authentic Malaysian experience has always been defined by profound warmth, shared spaces, and the quiet solidarity we show one another during national crises. As we look toward our seventh decade as an independent nation, true Merdeka requires us to bridge the gap between the unity we live and the fairness we legislate.
Only by actively rejecting the practices that fracture us can we move a step closer to fulfilling the true promise of Merdeka.
Written By:
Thulasy Suppiah,
Managing Partner,
Suppiah & Partners,
UG-13, Lexa Galleria, 45, Jalan 34/26,
Wangsa Maju, 53300 Kuala Lumpur.
Handphone no: 012-4915238
© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.
More Newsletter
[Feature Article] The Star Newspaper: Is Corporate Malaysia Serious About Protecting Our Data?
Is Corporate Malaysia Serious About Protecting Our Data?
By Thulasy Suppiah, Managing Partner of Suppiah & Partners
For Malaysians, the cycle has become exhaustingly predictable. From massive ransomware attacks crippling statutory bodies to recent headlines of internal employees casually leaking sensitive customer billing details online, the public is caught in a continuous loop of data compromises.
While the nature of these threats varies wildly—ranging from highly sophisticated, AI-driven external cyberattacks to rudimentary internal snooping—the corporate response is almost always identical. The public is inevitably met with a standard public relations script: the company assures us it was an “isolated incident,” claims no broader systems were compromised, and reiterates that they take data privacy “very seriously.”
However, as these incidents compound, a critical legal and governance question must be asked: How can the public independently verify these claims? When a breach occurs, how do we know if the data controller truly implemented all necessary and reasonable security measures prior to the failure, or if their architecture was fundamentally inadequate from the start?
This is particularly relevant when examining insider threats. If a company’s system architecture allows an employee to casually browse a customer’s sensitive billing or identification details without a verified, logged business justification, it points to a systemic failure in basic internal access controls. If an organisation fails to implement fundamental “Zero Trust” protocols internally, it is difficult to trust their capacity to defend against complex, external cyber threats.
Recognising the importance of these risks, the Personal Data Protection Department (JPDP) earlier this year issued guidelines on Data Protection by Design (DPbD) and Data Protection Impact Assessments (DPIA).
These guidelines should not be treated as mere administrative guidance. DPbD encourages organisations to build privacy safeguards into their systems from the outset, rather than addressing weaknesses only after deployment. Where proposed data processing is likely to pose a high risk, the DPIA requires data controllers to identify, assess and reduce those risks before processing begins.
Yet, the persistent pattern of data leaks suggests that much of corporate Malaysia is treating these critical guidelines as mere paperwork exercises to be filed away, rather than architectural mandates to be engineered into their daily operations.
We cannot continue to accept a culture where data security is only prioritised after a crisis has occurred. Suing a rogue employee or issuing an apology after data has already surfaced online or on the dark web is purely reactive.
To break this loop, regulatory oversight must fundamentally shift. Regulators must move beyond issuing post-incident fines and begin conducting proactive, unannounced audits of corporate access controls. Data controllers must be compelled to actively demonstrate exactly how data protection principles are hardcoded into their systems.
Until companies are held accountable for their internal architecture before a breach happens, the public will remain vulnerable to the next “isolated incident.”
Written By:
Thulasy Suppiah,
Managing Partner,
Suppiah & Partners,
UG-13, Lexa Galleria, 45, Jalan 34/26,
Wangsa Maju, 53300 Kuala Lumpur.
Handphone no: 012-4915238
© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.
More Newsletter
[Media Feature] The Star: Keeping AI in Check
Keeping AI in check
Quoted by The Star on 27 July 2026
by Ragananthini Vethasalam and Divya Theresa Ravi


© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.
More Featured Articles
[Media Feature] The Star: Safeguards Needed for CCTV Data
Safeguards Needed for CCTV Data
Quoted by The Star on 18 June 2026
by Martin Carvalho, Ragananthini Vethasalam and Divya Theresa Ravi

© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.
More Featured Articles
[Media Features] The Star: Scam Victim’s Successful Bid Sets Precedent for Banks
Scam Victim’s Successful Bid Sets Precedent for Banks
Quoted by The Star on 22 May 2026
by Thulasy Suppiah, Managing Partner

© 2025 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.
More Featured Articles
[Feature Article] The Star Newspaper: Banks Must Rethink Fraud Controls as AI Risks Rise
Banks Must Rethink Fraud Controls as AI Risks Rise
Published by The Star on 20 May 2026
By Thulasy Suppiah, Managing Partner of Suppiah & Partners
The recent Sessions Court ruling ordering a local bank to pay RM166,000 for failing to monitor anomalous transactions represents a critical inflection point for corporate governance in Malaysia. By holding the institution liable for ignoring sudden, uncharacteristic account activity, the court effectively dismantled the legacy defence that merely having a secure system—such as sending automated SMS alerts—absolves an organisation of its duty of care.
The ruling sets a clear legal baseline: financial institutions cannot remain passive when faced with glaring transactional anomalies. It reinforces the expectation that financial compliance requires active, intelligent monitoring of escalation triggers, particularly when a transaction drastically deviates from established customer behaviour.
However, if our institutions are currently facing legal liability for missing traditional, rudimentary anomalies, they are alarmingly exposed to the incoming wave of AI-driven financial manipulation. What used to be neatly divided into IT risk versus finance risk is now one combined problem. Cybersecurity and financial compliance can no longer sit in separate rooms.
AI does not necessarily create new categories of fraud; it amplifies existing ones with devastating precision. The 2024 Arup incident, where a multinational engineering firm lost US$25mil after an employee transferred funds based on a deepfake video call with fabricated “senior management,” serves as the global anchor case. It proves an uncomfortable reality: we can no longer trust the channel. Relying on email authenticity, or even live video confirmation, is now an outdated assumption.
Furthermore, AI enables virtually undetectable fraud at scale. Instead of a single large, suspicious transfer, malicious actors can execute hundreds of micro-transactions over time. In this modern “One Cent Thief” scenario, each transaction sits comfortably below automated detection limits and approval thresholds, yet aggregates into significant corporate losses.
This is where our current regulatory frameworks face a critical gap. The Cybersecurity Act 2024 provides a strong foundation for strengthening system resilience and reporting breaches. However, AI introduces a fundamentally different risk. It does not necessarily hack the system; rather, it manipulates how human decisions are made. While current cybersecurity laws protect the infrastructure, they do not fully address the deception embedded within the financial workflow itself.
To survive this shift, corporate boards and audit committees must recognise that the answer is not simply telling employees to “be careful.” Financial approval systems must be actively redesigned to withstand deception. High-risk actions—such as large payments, urgent transfers, or changes to vendor bank details—must trigger mandatory, independent, out-of-band verification using pre-approved contact channels.
Equally critical is the human factor. Fraud often succeeds not because a policy does not exist, but because an employee is pressured by urgency or perceived authority into bypassing it. Corporate culture must empower people to pause, question, and escalate suspicious, time-sensitive instructions. Crucially, no employee should ever be penalised for slowing down a transaction to exercise independent judgment.
The future of financial security is not just building stronger firewalls. It is disciplined human decision-making, better audit trails, and structured verification built directly into financial processes. As the recent court ruling demonstrates, the expectation of accountability is not new. The law is simply evolving to demand that our internal controls are robust enough to manage exactly how decisions are made and acted upon.
© 2025 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.
More Featured Articles
[Feature Article] The Star Newspaper: AI Adoption Cannot Justify Dismissal
AI ADOPTION CANNOT JUSTIFY DISMISSAL
Published by The Star on 13 May 2026
By Thulasy Suppiah, Managing Partner of Suppiah & Partners
A recent Chinese court ruling—declaring that replacing a worker with AI to cut costs does not legally justify termination—serves as a stark warning: rapid technological adoption cannot bypass established labour protections.
For Malaysia, where TalentCorp projects nearly 700,000 workers will face disruption from AI, digitalisation and the green economy within three to five years, this is a legal reality we must urgently confront.
Under the Industrial Relations Act 1967, terminations require “just cause or excuse.” While companies will inevitably claim “redundancy” to justify AI-driven layoffs, procuring an enterprise AI license is not a legal blank cheque. The burden remains on employers to prove a role has genuinely ceased to exist.
If a company dismisses junior staff but uses algorithms to produce the exact same volume of work—still requiring human prompting, editing, and supervision—the role has simply evolved, not disappeared. Claiming redundancy here could be successfully challenged in the Industrial Court as a sham.
However, the most profound threat to our workforce is not the legally actionable layoff; it is “invisible displacement.” This silent attrition occurs when departing employees are simply not replaced because AI absorbs their workload. No termination letter is issued, and no legal claim arises, but entry-level opportunities permanently evaporate.
We must acknowledge the employer’s reality: in a hyper-competitive global landscape, it is economically irrational to artificially sustain obsolete roles. The law can punish unfair dismissals, but it cannot compel companies to create new jobs.
While TalentCorp anticipates the emergence of 120 new high-value roles, placing the burden entirely on workers to aggressively upskill is a flawed strategy. We cannot rely on 20th-century labour laws to manage 21st-century technological disruption. We urgently need a new “digital social contract” bridging statutory reform and corporate governance.
First, the Human Resources Ministry must establish modernised guidelines explicitly defining “technological redundancy.” The Industrial Court should not be left to interpret AI displacement using decades-old precedents designed for factory closures. We need clear statutory definitions that distinguish genuine business restructuring from opportunistic AI cost-cutting.
Second, corporate governance must evolve. Adopting enterprise AI is a profound human resources event, not merely an IT procurement. Environmental, Social, and Governance (ESG) standards should encourage internal workforce impact audits. Before defaulting to silent attrition or redundancy, employers hold a duty of care to explore how at-risk workers can be transitioned to manage the very AI systems replacing their tasks.
AI will undoubtedly alter existing roles, but more importantly, it will dictate the jobs companies choose not to create tomorrow. True job security in the algorithmic age requires not just an agile workforce, but modernised labour laws and a corporate sector willing to take responsibility for its technological upgrades.
© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.



