You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 17, 2025

DNA: Data Protection and Cybersecurity Regulation in Southeast Asia

Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to Data Protection and Cybersecurity Regulation in Southeast Asia, a wide-ranging guide published by Drew Network Asia (DNA). The resource provides a comprehensive overview of data protection and cybersecurity laws across the region, offering practical insight into compliance requirements and regulatory developments affecting organizations that handle personal data or operate digital services in Southeast Asia.

The guide begins with a regional overview, including the broader ASEAN context and cooperation initiatives. Jurisdiction-specific chapters follow a consistent structure—covering data privacy and governance obligations, security requirements and breach notification, outsourcing and cross-border data transfers, and broader accountability and compliance measures. This format allows readers to compare regulatory approaches across markets such as Brunei, Indonesia, Malaysia, the Philippines, Singapore, and others.

In addition to the country chapters, the publication addresses cybersecurity and privacy engineering challenges, providing guidance for organizations and outlining obligations applicable to data controllers, processors, and intermediaries. A dedicated section on data breach management across ASEAN examines notification requirements, response considerations, and practical steps for managing incidents in a regional or global context.

The guide is intended to serve as a practical reference, and the authors note that specific legal requirements may vary depending on sector, processing activity, or evolving legislation. Readers seeking more detailed advice can contact the practitioners listed in each chapter.

The full guide is available for download using the button below or directly from the DNA website.

RELATED INSIGHTS​ 

January 24, 2024
On 17 April 2023, the Vietnamese government issued the Personal Data Protection Decree, which is set to take effect 1 July 2023 without any transitional period. The PDPD is considered to be the first comprehensive document on data protection in Vietnam. Accordingly, it provides detailed regulations on the rights of data subjects, consent requirements and requirements for data processing impact assessments and outbound transfer impact assessments. In 2024, the adoption of the Law on the Protection of Consumer Rights and the Law on Electronic Transactions will play a vital role regarding data protection. The LPCR will require traders to obtain consent to collect consumer data and establish a mechanism enabling consumers to select the information they consent to traders collecting. Consumers must also be allowed to express consent in a suitable form. For special processing purposes — such as sharing, disclosure, or transfer of personal data to third parties, and use of personal data to send advertisements and to introduce products — the LPCR requires a mechanism which enables data subjects to clearly opt in to give, or not give, their consent. This requirement is similar to procedures currently required for regulated stakeholders under the PDPD. In the same vein, the LET strictly forbids the acts of trading data to protect Vietnamese personal data. The government is anticipated to provide more details relating to data privacy guidelines after the issuance of the Draft Law on Telecommunications. Accordingly, the draft requires enterprises to provide the requisite information — such as service user’s name and address, number and location of transmitting or receiving servers, call times, IP address and other personal information supplied by the service user when entering a contract — to the relevant authority, as per a request which is made in accordance with the law. Amendments to Decree
January 24, 2024
Thailand’s Personal Data Protection Act came into full effect on 1 June 2022 and various subordinate regulations have since been issued by the Personal Data Protection Committee. These include regulations on security measures to be implemented by data controllers, data breach notification requirements, a mandatory obligation to appoint a data protection officer when the processing activity requires regular monitoring of personal data or a system due to the large scale of personal data, administrative measures and data processors’ record of processing activities. As some areas under the PDPA still require further clarifications, a series of public consultations for the remaining draft subordinate regulations is anticipated in 2024. Potential areas include data protection impact assessments and cross-border transfers of personal data, which are crucial for organizations and particularly for entities with establishments in other jurisdictions. PDPA enforcement by Thai regulators was silent until the last quarter of 2023, when the PDPC published details about complaints that have been lodged to the Expert Committee. The committee is designated by virtue of the PDPA and has the power to make determinations related to imposing administrative fines and other penalties. Enforcement in 2024 is expected to become more active and potentially more serious, which means organizations should pay closer attention to ensure compliance with the PDPA. Similar to the GDPR, the PDPA also has extraterritorial effect. Once the subordinate regulation on international cooperation has been issued by the PDPC, this should clarify how PDPA enforcement against organizations located outside of Thailand will be conducted by Thai regulators. With respect to sector-specific data protection legislation, in September 2023, Thailand’s National Broadcasting and Telecommunications Commission issued the Notification of the NBTC Re: Measures to Protect Telecommunications Service Users’ Rights in regard to Personal Data, Privacy Rights, and Freedom of Telecommunications, which replaces the previous notification.
January 19, 2024
On November 24, 2023, the National Assembly of the Socialist Republic of Vietnam adopted Law No. 24/2023/QH15 on Telecommunications (“Telecom Law 2023”) after a lengthy period of extensive discussions and revisions. The Telecom Law 2023 is set to take effect on July 1, 2024, except for the requirements relating to basic telecom services on the internet (otherwise known as over-the-top services, or “OTT”), data center services, and cloud computing services, which will take effect on January 1, 2025. Some important highlights of the Telecom Law 2023 are discussed below. Updates on Telecom License Requirements With a few exceptions and save for certain types of telecom services, enterprises in Vietnam are required to obtain Telecom Licenses in order to provide telecom services. There are two types of Telecom Licenses: licenses for the provision of telecom services, and licenses for telecom operations. Telecom Licenses can be granted in two forms. The first is separate licensing, which is for telecom services with network infrastructures that use radio frequencies or operate in areas with special requirements set by the government. The second is group licensing, which covers telecom services with network infrastructure (except in certain cases), telecom services without network infrastructure (except in certain cases), and telecom operations. New Regulations for OTT, Data Center, and Cloud Computing Services The Telecom Law 2023 provides the definitions for OTT services, data center services, and cloud computing services, recognizing them as different types of telecom services. It also outlines the rights and obligations of service providers in these fields. Regarding market-entry conditions, foreign direct investments in OTT services, data center services, and cloud computing services are subject to no restrictions on share ownership ratio or capital contribution. Foreign investors can establish 100% foreign-owned enterprises in Vietnam to offer these services. Enterprises offering these services are not
January 12, 2024
Thailand’s Revenue Department (RD) has issued a notification requiring electronic platforms to report their revenue from business operators on their platform. With this information, the RD intends to track business operators’ income from the sale of goods and services through electronic platforms in order to facilitate accurate and efficient tax collection. The notification, which was enacted on December 27, 2023, took effect on January 1, 2024. Under the notification, electronic platforms are required to compile a “special account” containing information on the revenue received from each business operator on their platform and submit it to the RD through the department’s electronic reporting system within 150 days of the end of the fiscal year. The notification defines “electronic platforms” as entities that intermediate between business operators (i.e., sellers of goods or providers of services via the electronic platform) and consumers for the purpose of enabling electronic transactions between the parties. This covers online marketplace operators, ride-hailing operators, food delivery operators, and so on. This reporting requirement applies to electronic platforms registered in Thailand that have (or previously had, starting from the notification’s effective date) annual revenue exceeding THB 1 billion (approx. USD 28.5 million), except for electronic platforms under the supervision of the Bank of Thailand or the Office of the Securities and Exchange Commission, such as payment service providers and cryptocurrency exchanges. Electronic platforms can appoint a third party to prepare and submit the required special account information to the RD on their behalf. Compliance Steps As the requirements established by this notification mean that the RD will now have direct access to information on the income earned by vendors and merchants on electronic platforms, these business operators—whether corporate or individual—should ensure that they faithfully disclose their earnings, submit tax payments correctly, and file income tax returns in a