You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 17, 2025

DNA: Data Protection and Cybersecurity Regulation in Southeast Asia

Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to Data Protection and Cybersecurity Regulation in Southeast Asia, a wide-ranging guide published by Drew Network Asia (DNA). The resource provides a comprehensive overview of data protection and cybersecurity laws across the region, offering practical insight into compliance requirements and regulatory developments affecting organizations that handle personal data or operate digital services in Southeast Asia.

The guide begins with a regional overview, including the broader ASEAN context and cooperation initiatives. Jurisdiction-specific chapters follow a consistent structure—covering data privacy and governance obligations, security requirements and breach notification, outsourcing and cross-border data transfers, and broader accountability and compliance measures. This format allows readers to compare regulatory approaches across markets such as Brunei, Indonesia, Malaysia, the Philippines, Singapore, and others.

In addition to the country chapters, the publication addresses cybersecurity and privacy engineering challenges, providing guidance for organizations and outlining obligations applicable to data controllers, processors, and intermediaries. A dedicated section on data breach management across ASEAN examines notification requirements, response considerations, and practical steps for managing incidents in a regional or global context.

The guide is intended to serve as a practical reference, and the authors note that specific legal requirements may vary depending on sector, processing activity, or evolving legislation. Readers seeking more detailed advice can contact the practitioners listed in each chapter.

The full guide is available for download using the button below or directly from the DNA website.

RELATED INSIGHTS​ 

August 31, 2023
When your company suffers a data breach, taking prudent, careful action can limit and perhaps even rectify some of the damage. First of all, it is important to document everything, starting with the time the data breach was discovered. Secure the data systems and preserve all evidence so that investigators can determine what happened, and begin following the protocol that all companies handling personal data should have in place to guide their data breach response. It is also crucial to seek timely legal assistance to ensure that every aspect of the response is planned and carried out according to the law. While applicable legal advice for each situation can only be obtained by consulting a legal advisor, this guide gives an overview of what companies in Southeast Asian jurisdictions can expect if they suffer a data breach. This guide from Tilleke & Gibbins is a quick-reference resource covering key regulatory issues regarding data breach responses in Cambodia, Laos, Myanmar, Thailand, and Vietnam. The full guide can be downloaded through the button below.
August 23, 2023
Introduction The idea of the metaverse rose to prominence in the public discourse in 2021, most notably when Facebook renamed itself Meta and announced a new focus on launching a virtual, immersive world. The initial excitement around the metaverse has since faded, with worsening economic conditions having a particularly acute effect on companies in the technology sector. When Meta CEO Mark Zuckerberg announced in March 2023 that artificial intelligence (AI) was the company’s “single largest investment,” many took this as a sign of the company shifting focus away from the metaverse. However, there remains significant interest in the metaverse from both businesses and consumers. Zuckerberg himself reaffirmed Meta’s focus on the metaverse, highlighting how developments in AI will improve virtual reality (VR) and augmented reality (AR) technology. Meanwhile, Roblox, a metaverse gaming platform, announced that in Q1 2023, its number of daily active users had increased to 66 million. Most recently, the announcement by Apple of its new ‘Vision Pro’ AR headset is reported to have renewed interest in the metaverse among developers. A particular area of interest in the developing metaverse is digital fashion and retail. In its Metaverse Fashion Trends Report 2022, Roblox found that nearly three in four users aged 14 to 24 spend money on digital fashion items. Roblox itself has partnered with fashion brands Burberry, Gucci, Tommy Hilfiger, and others, to offer experiences and items for use on the platform. In March 2023, Decentraland, a metaverse platform with a decentralized governance structure, hosted the Metaverse Fashion Week, featuring brands such as Adidas, Coach, and DKNY. As businesses continue to invest and look for opportunities to expand into the metaverse, whether through traditional e-commerce or more innovative digital asset offerings, it is important that they consider the ways in which new and existing laws apply
August 22, 2023
On August 17, 2023, the Thai government rolled out a royal decree that provides certain exemptions to data controllers’ obligations under the Personal Data Protection Act B.E. 2562 (PDPA). The royal decree, which will come into effect after the lapse of 150 days from its publication in the Government Gazette, reflects the government’s ongoing quest to strike a balance between privacy, state interests, and the data protection regulatory burden on organizations. The royal decree seeks to clarify the circumstances in which data controllers—including business operators and state agencies—are exempt from certain PDPA requirements on the collection, use, and disclosure of personal data and data subject rights. In doing so, it establishes three foundational pillars in considering exemptions: Collection or requests for personal data are to be for the public interest pursuant to the purpose and scope prescribed by any law authorizing a state agency to carry out a certain action, without imposing an undue burden on the data controller responsible for disclosing the personal information. Data controllers can share personal data without the data subject’s consent if legally authorized state agencies request it and specify the statutory provisions granting authority to request the data. Data subjects and data controllers of requested personal data must have the right to submit complaints to the PDPA’s Expert Committee or seek its expertise for clarification or determination. Under the three foundational pillars, data controllers will be partially exempted from certain requirements under the PDPA when the following state agencies request personal data: The National Anti-Corruption Commission or other government entities with mandates aligned with anticorruption laws; The Revenue Department, Customs Department, Excise Department, or other governmental units operating under taxation laws; Local governmental bodies recognized by the Personal Data Protection Committee (PDPC), or any government unit with mandates as per the laws related
July 31, 2023
On July 13, 2023, Thailand’s Personal Data Protection Committee (PDPC) published a draft notification on the requirements for appointment of a data protection officer (DPO). Under the Personal Data Protection Act B.E. 2562 (PDPA), data controllers or data processors must appoint a DPO if: The data controller or data processor is a state agency as prescribed by the PDPC (the list of state agencies was published in the Government Gazette on July 18, 2023); The activities of the data controller or data processor in relation to the processing of the personal data require “regular monitoring of the personal data or the system,” by reason of “having large-scale personal data” as prescribed by the PDPC; or The core activity of the data controller or data processor is related to the processing of special categories of personal data (e.g., health-related data, biometric data, etc.). The draft notification’s criteria for determining whether a processing activity (1) requires regular monitoring of the personal data or the system, and (2) involves large-scale personal data are outlined below. General Principles When determining whether processing of personal data requires regular monitoring due to having large-scale personal data, it is likely that only the “core activity” of the data controller or data processor is to be taken into consideration. The term “core activity” denotes an essential and integral activity directly related to the primary operations of the data controller or data processor and does not include any supplementary business activities. Regular Monitoring of Personal Data or Systems According to the draft notification, activities related to processing personal data require regular monitoring of the personal data or the system if: The core part of the data controller’s or data processor’s activities consists of tracking, monitoring, analyzing, or predicting the behavior, attitude, or profile of individuals; and These activities