You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 17, 2025

DNA: Data Protection and Cybersecurity Regulation in Southeast Asia

Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to Data Protection and Cybersecurity Regulation in Southeast Asia, a wide-ranging guide published by Drew Network Asia (DNA). The resource provides a comprehensive overview of data protection and cybersecurity laws across the region, offering practical insight into compliance requirements and regulatory developments affecting organizations that handle personal data or operate digital services in Southeast Asia.

The guide begins with a regional overview, including the broader ASEAN context and cooperation initiatives. Jurisdiction-specific chapters follow a consistent structure—covering data privacy and governance obligations, security requirements and breach notification, outsourcing and cross-border data transfers, and broader accountability and compliance measures. This format allows readers to compare regulatory approaches across markets such as Brunei, Indonesia, Malaysia, the Philippines, Singapore, and others.

In addition to the country chapters, the publication addresses cybersecurity and privacy engineering challenges, providing guidance for organizations and outlining obligations applicable to data controllers, processors, and intermediaries. A dedicated section on data breach management across ASEAN examines notification requirements, response considerations, and practical steps for managing incidents in a regional or global context.

The guide is intended to serve as a practical reference, and the authors note that specific legal requirements may vary depending on sector, processing activity, or evolving legislation. Readers seeking more detailed advice can contact the practitioners listed in each chapter.

The full guide is available for download using the button below or directly from the DNA website.

RELATED INSIGHTS​ 

November 24, 2021
Attorneys from Tilleke & Gibbins have provided the latest update to the Thailand contribution to Doing Business in…, a Q&A-style guide published by Thomson Reuters Practical Law that presents an overview of the legal framework for doing business in 63 jurisdictions worldwide. The Thailand chapter of the guide outlines Thailand’s legal system and key laws applicable to foreign companies doing business in the country. The chapter specifically covers the following main topics: Legal system: Thailand’s court system and codified legal system. Foreign investment: Lists of reserved business activities, restrictions on doing business with certain jurisdictions, exchange controls and currency regulations, and grants and incentives available to investors. Business vehicles: Ordinary partnerships, registered ordinary partnerships, limited partnerships, private limited companies, and public companies. Environment: Main laws and regulations, factory operation. Employment: Laws, employment contract requirements, work permits, and termination and redundancy. Tax: Taxes on employment, tax and nontax resident employees and businesses, corporate income tax, value added tax, special business tax, municipal tax, stamp duty, dividends, interest, intellectual property royalties. Competition: Important aspects of Thailand’s regulatory regime surrounding competition, centered around the updated Trade Competition Act. Antibribery and corruption: Laws, compliance requirements, regulatory authority. Intellectual property: Patents, trademarks, registered and unregistered designs, and copyright. Marketing agreements and advertising: Regulation of marketing agreements, Thailand’s Consumer Protection Act, direct marketing, role of the Consumer Protection Board and Food and Drug Administration. E-commerce: E-commerce laws and regulations, marketing and sales via online platforms. Data protection: An outline of Thailand’s Personal Data Protection Act. Product liability: Procedures and regulations for product liability and product safety, including the Unsafe Goods Liability Act and the Consumer Case Procedure Act. Product liability: Key regulatory authorities for trade competition, environmental issues, and financial services. To browse, download, or print the Thailand chapter, please visit the Practical Law website.
October 25, 2021
Michael Ramirez, a counsel in Tilleke & Gibbins’ dispute resolution group in Bangkok, has updated the firm’s contribution to the Global Attorney-Client Privilege Guide, published by Lex Mundi. The newly expanded guide provides information on what constitutes attorney-client privilege in over 70 countries around the world. The Thailand section of the guide contains in-depth information on the function and applications of attorney-client privilege in Thailand (or, as explained in the guide, an equivalent concept enshrined in Thai law), including coverage of the following topics: Privilege in corporations Common interest doctrine Litigation funding Crime-fraud exception Work product doctrine/litigation privilege Other privileges including mediation, accountant-client and settlement negotiation The interactive guide features expert contributions by Lex Mundi member firms from jurisdictions worldwide. Readers can browse the contributions, generate country-specific reports, and compare attorney-client privilege in multiple jurisdictions. For more information, please visit the Lex Mundi website.
October 19, 2021
On September 9, 2021, Laos announced a new pilot program to allow the mining and trading of cryptocurrency. Notification No. 1158, issued by the Prime Minister’s Office, provides for an electricity sale-purchase agreement with six companies involved in the pilot program. Under the notification, the six companies authorized by the prime minister to mine and trade cryptocurrency in Laos will pay a capped fee for energy they use in data processing or mining cryptocurrency. This effectively establishes a sandbox in which these six companies may mine and trade cryptocurrency—including on international cryptocurrency exchanges. The Ministry of Technology and Communications (MTC) is in charge of coordinating the program, together with the Ministry of Finance, the Bank of the Lao PDR, the Ministry of Planning and Investment, the Ministry of Energy and Mines, the Ministry of Public Security, and Électricité du Laos. The MTC is also charged with drafting the rules of the pilot program and setting the conditions on which the participating companies can mine, sell, and purchase cryptocurrency in Laos. One of the six selected companies will also act as a coordinator for the other companies and report to the government on any benefits of cryptocurrency observed during the pilot program. The next step is for the MTC to compile data analysis from each of the other government agencies and submit the conclusions to a meeting of the prime minister and the deputy prime ministers before the pilot program is implemented. The pilot program was originally scheduled to start in September, but there has not yet been any update on the implementation of the program, which nonetheless is expected to start in the near future.
October 19, 2021
In September 2021, the Bank of Thailand (BOT) issued its Guidelines on Data Governance to provide financial institutions with recommendations on how to ensure that their data governance will be in compliance with accepted international principles. While there are no penalties for noncompliance, financial institutions should view the recommendations as minimum standard expectations for their data governance in Thailand. The BOT guidelines set forth five main data governance principles: Data Governance Policy Financial institutions should set forth their data governance policy in writing in accordance with their business size, business operations, business complexity, and data risk. The policy should cover all types of data, including data related to services from third parties or business partners, as well as provide information on the data governance structure, data lifecycle management, protection of data security and data privacy, and incident management. Financial institutions should inform their employees and other relevant parties of the policy to ensure their compliance. In addition, the data governance policy must be approved by the designated board or committee of the financial institution, and be reviewed and revised in response to significant changes. Data Governance Structure Financial institutions should establish a data governance structure with three lines of defense, supervised by an oversight committee. The first line of defense comprises data management personnel, a data approver, and data users; the second comprises a risk management unit and a compliance unit; and the third is an audit unit. While the chosen data governance structure can be tailored to the characteristics of the institution, the structure should cover all of these roles and duties, and must not contravene the principle of checks and balances. The data governance structure should also be supported by sufficient personnel and equipment, as well as a clear plan—reviewed and revised as necessary—for building awareness at