You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 17, 2025

DNA: Data Protection and Cybersecurity Regulation in Southeast Asia

Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to Data Protection and Cybersecurity Regulation in Southeast Asia, a wide-ranging guide published by Drew Network Asia (DNA). The resource provides a comprehensive overview of data protection and cybersecurity laws across the region, offering practical insight into compliance requirements and regulatory developments affecting organizations that handle personal data or operate digital services in Southeast Asia.

The guide begins with a regional overview, including the broader ASEAN context and cooperation initiatives. Jurisdiction-specific chapters follow a consistent structure—covering data privacy and governance obligations, security requirements and breach notification, outsourcing and cross-border data transfers, and broader accountability and compliance measures. This format allows readers to compare regulatory approaches across markets such as Brunei, Indonesia, Malaysia, the Philippines, Singapore, and others.

In addition to the country chapters, the publication addresses cybersecurity and privacy engineering challenges, providing guidance for organizations and outlining obligations applicable to data controllers, processors, and intermediaries. A dedicated section on data breach management across ASEAN examines notification requirements, response considerations, and practical steps for managing incidents in a regional or global context.

The guide is intended to serve as a practical reference, and the authors note that specific legal requirements may vary depending on sector, processing activity, or evolving legislation. Readers seeking more detailed advice can contact the practitioners listed in each chapter.

The full guide is available for download using the button below or directly from the DNA website.

RELATED INSIGHTS​ 

July 31, 2022
Thailand’s Securities and Exchange Commission (SEC) has announced three new regulatory requirements, which primarily require digital asset business operators to provide investors with training or a knowledge test on cryptocurrencies and to disclose information about the quality of their service and IT usage capacity. The amended SEC notification detailing these new obligations was promulgated on July 1, 2022; however, the measures come into effect separately, as detailed below. Training or Testing on Cryptocurrency From August 30, 2022, cryptocurrency exchanges, brokers, and dealers must provide guidance and education to their clients on basic asset allocation suitable to their capacity. These types of digital asset business operators must also provide for training or a knowledge test on cryptocurrency. The content should at least cover cryptocurrency, blockchain technology, digital wallets, and an overview of the market and investments. The following types of clients are exempted from these requirements: Existing clients of the digital asset business operators before July 1, 2022; New clients of the operator who already have experience investing in cryptocurrency before using the service of the business operator; and Institutional investors, ultra-high-net-worth investors, and high-net-worth investors. If the clients are legal entities other than those mentioned above, their representatives or appointed persons are required to undergo training or testing. The training or knowledge test is a prerequisite to using a digital asset business operator’s services. Operators are not allowed to provide their services to clients who do not undergo training or testing. Disclosure of Service Quality and IT Usage Capacity From January 1, 2023, cryptocurrency/digital token exchanges, brokers, and dealers are required to disclose to the SEC information about the quality of their services (including any technological errors and complaints from clients), and their IT usage capacity. For more information about the latest SEC rules and regulations for digital assets,
July 25, 2022
Vietnam’s current Law on E-Transactions was passed in 2005 and has been effective since March 1, 2006. This law is considered a framework law, developed based on the Model Law on E-Commerce of the United Nations Commission on International Trade Law (UNCITRAL). According to the Ministry of Information and Communications (MIC), over the past 17 years, the implementation and application of e-transactions has shown significant evolution in certain areas demanding high levels of international integration, such as banking and e-commerce, but has faced difficulties in other areas due to a lack of detailed guidance. In addition, with the strong growth and breakthrough development of digital technologies such as artificial intelligence, big data, biometrics, and blockchain, and in the context of the ongoing Industrial Revolution 4.0 and the development of digital government, digital economy, and digital society, the 2005 Law on E-Transactions has revealed its shortcomings. Therefore, the government of Vietnam has entrusted the MIC to take the lead in drafting a new Law on E-Transactions, which will replace the old 2005 law in order to meet the country’s development needs. Accordingly, the MIC published a Draft Law on E-Transactions (“Draft Law”) for public consultation from May 4 to July 4, 2022. The latest accessible version of the Draft Law at the time of writing is Version 4. The effective date of the Draft Law is still not yet determined, though this law is expected to be submitted to the National Assembly for its review and comments in October 2022 and approval in May 2023. The following are some key contents of the Draft Law: 1. Scope of Application Unlike the current law, which explicitly excludes certain areas such as the issuance of certificates of land use rights and marriage certificates from the scope of application, the Draft Law attempts
July 19, 2022
On June 23, 2022, Thailand’s Securities and Exchange Commission (SEC) opened a public hearing period on regulatory controls for initial coin offering (ICO) portals that serve as financial advisors to digital token issuers. The proposed measures aim to prevent conflicts of interest; allow ICO portals to outsource certain functions; and establish additional notification obligations for ICO portals. The public hearing is open for general comments until July 23, 2022, and the new legislation is expected to be issued soon after that. During the public hearing period, any interested parties can comment on the SEC’s proposed principles. The key proposed points are outlined below. Conflicts of Interest Similar to SEC-approved financial advisors for securities offerings, ICO portals must be clear of conflicts of interest when representing issuers in a coin offering. According to the draft regulation, the following conflicts of interest are prohibited: The ICO portal (and certain individuals as specified by the SEC) directly or indirectly holds a prohibited amount of shares in the issuer, its affiliates, or its subsidiaries. If the issuer is not a listed company, any shareholding or portion thereof is prohibited. If the issuer is a listed company on the Stock Exchange of Thailand (SET), the shares held by the ICO platform may not total more than five percent of the total voting rights. The issuer (and certain individuals as specified by the SEC) directly or indirectly holds shares in the ICO portal in any amount if the ICO portal is not a listed company, or totaling more than five percent of the voting rights if the ICO portal is listed on the SET. Any of the ICO portal’s directors or executives, or the head of the department responsible for screening the ICO project, is also a director in the issuer. The ICO portal has
June 30, 2022
On May 30, 2022, Thailand’s Securities and Exchange Commission (SEC) announced that it would start regulating ready-to-use utility tokens, a type of digital token that had previously been exempted from the SEC’s approval and regulatory control. A public forum was open for comments from various stakeholders until June 29, 2022, and the draft regulation is expected to be issued soon. So far, the SEC has only supervised the issuance of not-ready-to-use utility tokens—digital tokens with the underlying right to acquire specific goods or services, which cannot be utilized upon issuance but at a later date. Due to the growing digital asset industry and lack of regulatory control, ready-to-use utility tokens have become more popular and many are listed for trading in digital asset exchanges. The SEC claimed that it is now necessary to regulate ready-to-use utility tokens as some issuers appeared to be exploiting the regulatory loophole to manipulate the price and supply of these tokens in both the primary and secondary markets, while providing insufficient data disclosure to investors. The SEC’s proposed principles include the following key points: Pre-Approval Requirements The same pre-approval requirement applicable to not-ready-to-use utility tokens will apply to ready-to-use utility tokens which an issuer intends to list on a digital asset exchange. This means that the issuer must proceed with the standard formalities, i.e., obtaining prior approval from the SEC, filing a draft prospectus, and offering the approved tokens via a SEC-approved ICO portal operator only. The SEC offers a fast-track (15 days) approval for qualifying ready-to-use utility tokens, which are those with plain-vanilla characteristics; with an offering price corresponding to the value of the underlying goods/services; for which the supply of goods and services does not vary with the price of the tokens (i.e., fixed coins); and which are not intended to be