You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 9, 2021

Employee Vaccine Mandates and Vaccination Status Data Privacy in Cambodia

In response to the COVID-19 pandemic, the Cambodian government has issued a range of policies and measures, including movement restrictions, necessary quarantines, prohibitions on large gatherings, and selective lockdowns. Simultaneously, business operators have been developing and implementing business continuity plans to manage their way through the pandemic and beyond.

With the wide availability of vaccines in Cambodia, some employers are considering whether to mandate workers to get vaccinated against the coronavirus, prompting the question: What are the legal risks and implications of such a mandate in Cambodia?

While the Labor Law does require employers to cover the cost of vaccinations against epidemics, during which the Ministry of Health (MOH) can also order extraordinary preventative measures at work sites, Cambodian law does not expressly prohibit employers from requiring employees to be vaccinated. There are also no laws or regulations specifying accommodation requirements for employees who refuse to be vaccinated due to health, religious, or other reasons. (It may be worth noting here as well that health checks are a regular part of the hiring process, and new employees have to submit to a health check before starting work.)

The government did issue a sub-decree on April 11, 2021, that requires vaccinations for public officials, and for certain groups of people, based upon their working and business conditions, to undergo vaccinations as determined by the MOH. The ministry has not yet issued any regulations mandating that employees of businesses in Cambodia receive a COVID-19 vaccine, or addressing the issue of employees who may want to opt out of vaccination.

Absent regulations from the MOH, the focus turns to the country’s Constitution, which in Article 31 guarantees all citizens equal treatment under the law without regard to race, color, gender, language, religious belief, political tendency, birth origin, social status, wealth, or other status. Additionally, Cambodian Labor Law prohibits discrimination in employment based on race, color, gender, religion, political opinion, ancestry, social origin, or union membership or activities. The authorities would likely decide on a case-by-case basis whether the conditions set out by employers are reasonable for a specific job, and whether they would constitute “discrimination in employment.”

From the above, it seems that discriminating against employees based on their willingness to be vaccinated would not contravene the Constitution or the Labor Law, but it is unclear whether rejecting or terminating an employee who refuses to be vaccinated due to religion or other protected status would be deemed discrimination in employment under Cambodian law. The Labor Law recognizes only two grounds for termination without the payment of severance: serious misconduct by the employee and force majeure. Therefore, if an employer terminated employment because the employee refused vaccination, it could be deemed termination without a valid reason, which would entitle the employee to compensation for the termination.

Nonetheless, the risk of this to companies mandating vaccination of employees against the coronavirus is low, as the Labor Law mandates that employers pay for vaccinations during epidemics and allows the MOH to order extraordinary preventative measures at work sites.

Vaccination Status and Data Privacy

Data privacy questions are also being raised during these uncertain times, as employers are interested in keeping track of the vaccination status of their employees, and many have wondered if this information would constitute “personal data” under the various data protection laws around the world.

Cambodia does not yet have comprehensive data protection legislation. The most recent update to the country’s data protection landscape was in the E-commerce Law, which contains provisions for the protection of consumer data gathered over the course of electronic communication—a scope that is limited to virtual or digital data protection. Other data protection matters typically fall under the right to privacy, which is protected in broad terms under the Constitution, the Civil Code, and the Criminal Code.

Cambodian laws also fail to define “personal data.” The E-commerce Law defines “data” as “a group of numbers, characters, symbols, messages, images, sounds, videos, information, or electronic programs that are prepared in a form suitable for use in a database or an electronic system.” Due to the absence of a definition of “personal data,” it remains plausible that in an employment context any employee data, including information concerning an employee’s vaccination, might be viewed by the regulatory and enforcement authorities as personal data of the employees.

Under Cambodia’s E-commerce Law, anyone who stores private information (in an e-commerce context) must use all means to ensure that such information is safely protected to avoid loss, access, use, modification, leakage, and disclosure of the information. Employers are obligated to pay for vaccinations during an epidemic and it would be necessary to keep records in order to prove that the employer has satisfied its obligations under Cambodian law. Nevertheless, under Cambodia’s Labor Law, in general, workers’ health records collected by medical personnel are confidential, and the information contained in them cannot be given to an employer or a third party (with some exceptions for the health and labor inspectors) that could identify the employee. Data extracted from the files that do not identify the individuals can, however, be used for public health.

Cambodian citizens have broad data privacy rights under Cambodian law of general application, and the country’s existing legal framework applicable to data protection implies a general disclosure or notification obligation. Personal data can only be collected, used, or disclosed for purposes that the individual understands and has consented to. Employers should thus obtain consent from employees regarding how their data will be used, and if the use differs from the purpose that was initially told to the employees, new consent must be obtained. In other words, storing or using information on employees’ vaccination status—which would be new information with a new purpose—would require new consent from the employees.

In the meantime, employers should obtain employees’ written consent to keep records of vaccination status on the grounds that the employer is obliged to pay for such vaccinations under the Labor Law and needs to keep records of its compliance with the law.

Conclusion

Like most countries, Cambodia does not have specific legal provisions addressing employee vaccination mandates in a pandemic, though the Constitution, the Labor Law, and other measures and regulations hint at how such an action might be viewed. As noted above, these do give reason to believe that such mandates face a low risk of being penalized. Another new and uncertain topic is whether keeping information on employees’ vaccination status would trigger data protection obligations. Under the circumstances, it is prudent for employers to treat this as they would other employee personal data.

The ongoing COVID-19 pandemic is forcing governments, businesses, and individuals around the world to figure out how responses to these unexpected situations can be made to fit under existing legal frameworks. However, it is always safest to seek expert advice that is tailored to a company’s unique needs and challenges. With clear advice and measured actions, businesses will be able to pass the current volatility and strategize to their benefit in the months and years that follow.

RELATED INSIGHTS​ 

January 13, 2026
On January 9, 2026, Thailand’s Securities and Exchange Commission (SEC) filed a criminal complaint with the Economic Crime Suppression Division (ECD) against five individuals for unauthorized operation of a digital-asset dealer business under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This precedent-setting case signals that the regulator is willing to pursue crypto enforcement against natural persons even in the absence of a licensed platform entity. Background and Implications The case follows the SEC’s October 2025 public warning about the use of iris-scanning technology in exchange for certain digital tokens. In its warning, the SEC cautioned that exchanging or trading these specific tokens with unlicensed service providers exposes users to heightened fraud, scam, and money laundering risks. Unlike prior regulatory enforcement matters, which involved platform-level administrative fines for operational or compliance failures, this case targets misconduct by individuals who may not be professional traders but openly advertised their willingness to buy these tokens from the public, opened individual over-the-counter (OTC) trade channels for these tokens, and facilitated off-exchange transactions in a manner resembling ordinary commercial dealing. This enforcement action establishes a clear precedent that natural persons engaging in public-facing digital-asset dealing may face criminal liability under Thai law, even without operating through a corporate or licensed platform structure. Outlook The alleged offenders may not settle this crime by payment of fines. Following the SEC’s referral, the ECD will undertake further investigation, after which prosecutors may review the case and proceed to court. The SEC has stated that it will cooperate fully with enforcement agencies throughout the criminal enforcement process.
January 9, 2026
Vietnam has taken a decisive step into the global artificial intelligence regulatory landscape with the promulgation of the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law), adopted on December 10, 2025, and effective from March 1, 2026. As one of the earliest comprehensive, standalone AI statutes in Southeast Asia, the AI Law signals Vietnam’s ambition to position itself as both an innovation-friendly and governance-conscious AI market. In doing so, the legislature has also streamlined Vietnam’s AI regulatory architecture. The AI Law repeals most AI-related provisions previously embedded in the Law on Digital Technology Industry No. 71/2025/QH15, consolidating AI governance under a single, unified legal framework. This structural move underscores an intent to provide greater regulatory clarity and coherence for businesses operating across the AI value chain. Against this backdrop, the key question for AI developers, providers, deployers, and governance teams is how the new risk-based framework will shape compliance expectations, operational decisions, and governance design in practice. This article examines the new AI Law through that practical lens, focusing on what it means for AI businesses operating in or into Vietnam. Scope of Application The AI Law applies broadly to Vietnamese organizations and individuals, as well as foreign entities that participate in AI-related activities within Vietnam. The law expressly excludes AI activities conducted solely for national defense, security, and cryptography purposes. A defining feature of the AI Law is that it regulates by role, not by industry. It distinguishes between: Developers, who design, build, train, test, or fine-tune AI models and have direct control over the technical methods, training data, or model parameters; Providers, who place AI systems on the market or put them into use under their own names; Deployers, who use AI systems under their control in professional, commercial, or service-provision activities; Users, who interact with AI
January 9, 2026
Thailand continues to advance its legal and regulatory framework for the technology sector, with several key laws undergoing review and proposed amendments. These developments reflect Thailand’s broader efforts to ensure that its regulatory landscape keeps pace with rapid technological change and aligns more closely with international standards and best practices. The following are key legal developments and proposed legislative reforms in 2026 that are expected to impact businesses operating in the technology sector and the broader Thai business landscape. Data Privacy and Cybersecurity Personal Data Protection Act B.E. 2562 (2019) Following the full enforcement of Thailand’s Personal Data Protection Act (PDPA) in June 2022, businesses and practitioners have identified practical implementation challenges and interpretative issues. These challenges were reflected in an effectiveness assessment conducted by the Personal Data Protection Committee (PDPC) in late 2024. The PDPC published a set of principles for public consultation to identify issues and directions for potential amendments to the PDPA. Key issues: Emerging issues include clarifying the definitions of “data controller,” “data processor,” and “criminal record”; revisiting the scope of sensitive personal data to better reflect Thailand’s context; proposing amendments to the hierarchy of legal bases to avoid misconceptions of consent as the default legal basis; and clarifying the required level of expressiveness for explicit consent, as well as rules for collecting personal data from other sources. Current status: The first round of public consultation has concluded. Next steps: The proposed amendments are proceeding to a revised draft following the consultation outcomes. Cybersecurity Act B.E. 2562 (2019) Thailand is moving forward with proposed amendments to enhance the effectiveness of its national cybersecurity framework, as evolving digital technologies bring new risks such as misinformation, system intrusions, and attacks on critical infrastructure, making cybersecurity a national priority. Key issues: The amendments aim to clarify and strengthen
January 8, 2026
Thailand’s Digital Government Development Agency (DGA) has proposed new standards that would require government agencies to select cloud services exclusively from a preapproved shortlist of providers. The draft Digital Government Standards re: Cloud Service Provider Standards aims to strengthen procurement confidence and reduce risks associated with selecting cloud service providers that do not meet the required standards. A public hearing period on these standards concluded on December 27, 2025. The DGA will now review submitted comments and consider revising the standards accordingly. Shortlisted Cloud Service Provider Tiers The draft standards establish three tiers of cloud service providers based on their assessed service capability levels, core qualifications, and certifications. The DGA sets qualification requirements for each tier, and it is at the discretion of each agency to select the tier of cloud service provider that best suits its operational needs, as follows: Tier 1 cloud service providers are suitable for providing services involving disclosable official data. Tier 2 cloud service providers are suitable for handling official data and protected data, such as personal data, which requires a high-security public cloud (e.g., virtual private cloud). Tier 3 cloud service providers are suitable for providing services to agencies with specific regulatory and security requirements that handle highly protected data, such as the national security system. These providers must offer sovereign or hybrid cloud as stipulated by the Ministry of Digital Economy and Society. All tiers of cloud service providers must be legal entities incorporated under Thai law and can be authorized distributors of offshore cloud service providers. However, each tier will be subject to different requirements, including infrastructure obligations. Government agencies are encouraged to select a cloud service provider appropriate for their intended use. For example, if a government agency intends to procure cloud services for operating applications that process personal data,