You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 24, 2025

Myanmar Affirms Cryptocurrency Controls

A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC).

The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities.

The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives.

Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.

RELATED INSIGHTS​ 

February 11, 2021
After approximately a decade drafting general personal data protection laws and formulating a regime to protect personal data and privacy rights, Thailand finally issued the country’s first unified personal data protection legislation in 2019. The public was surprised when the draft Personal Data Protection Act (PDPA) was published for the final round of hearings. The draft PDPA largely adopted the preeminent personal data protection standards as expressed in the European Union’s General Data Protection Regulation (GDPR). The government expressed its objective to enhance personal data protection standards in Thailand to meet international standards, which would permit cross border transfers of personal data to Thailand, without any material limitations. The PDPA, which was finally published in the Government Gazette in May 2019, also established a new independent regulator, the Personal Data Protection Commission (PDPC), tasked with enforcing the PDPA. All members of the commission must possess the qualifications required by the PDPA. The PDPA was enacted with a grace period of one year for the requirements relating to the processing of personal data—which would provide businesses with sufficient time to adjust their practices to ensure compliance with the new requirements. It is a significant undertaking for businesses to adjust from having no general law on data protection to being required to meet high international data protection standards comparable to those in the GDPR. GPDR concepts that were incorporated into the PDPA include (1) purpose limitation, (2) transparency, (3) lawfulness and fairness, and (4) data minimization. When collecting personal data, data controllers are required to establish a lawful basis to allow for such collection and processing of personal data. The lawful bases for general personal data are also similar to those under the GDPR, with concepts such as contractual necessity, legal obligation, legitimate interest, vital interest, and consent. Special types of
February 2, 2021
On February 1, 2021, through Thailand’s Ministry of Digital Economy and Society, the Office of Personal Data Protection Commission announced that it will arrange public hearing sessions for the first set of subordinate regulations under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). Subordinate regulations on the following topics will be covered during the consultations: Consent Privacy notices Responsibilities of data controllers Cross-border data transfers Data protection officers Security measures Compliance processes Sensitive personal data It is anticipated that the draft subordinate regulations will be circulated (in Thai) to registered attendees ahead of the sessions. Participation by video conferencing will be available. In addition, at the First ASEAN Digital Ministers’ Meeting on January 21 and 22, 2021, the ASEAN Data Management Framework (DMF) and the Model Contractual Clauses for Cross Border Data Flows (MCCs) were approved in order to promote the secure free flow of data between ASEAN countries, including Thailand. The development of the Thai PDPA is expected to factor into these DMF and MCC initiatives, potentially allowing businesses in Thailand to transfer data between neighboring countries within the region, in addition to the permitted transfer between countries whitelisted under the European General Data Protection Regulation (GDPR). These initiatives were led by the Singapore Personal Data Protection Commission, and more details are expected in due course. Prior to the PDPA effective date on June 1, 2021, substantial further developments are expected to give further clarification and guidance for businesses, and to ease their compliance concerns. For more information on this development, or any other aspect of data protection in Thailand, please contact Tilleke & Gibbins’ data protection team led by Athistha (Nop) Chitranukroh ([email protected]).
January 29, 2021
Members of Tilleke & Gibbins’ technology team contributed the Vietnam chapter of the recently published Data Protection Laws of the World (10th Edition), a widely consulted handbook to privacy and data protection laws across more than 100 different jurisdictions.
January 14, 2021
On November 26, 2020, the Notification of the Ministry of Finance Re: Addition to Other Business Relating to Digital Assets B.E. 2563 (2020) (the Digital Asset Business Notification) and the Notification of the Ministry of Finance Re: Licensing of Digital Asset Business No. 2 B.E. 2563 (2020) (the Digital Asset Business Licensing Notification) were published in the Thai Government Gazette. Additional Digital Asset Businesses The new Digital Assets Business Notification adds two new categories of digital assets business to the list prescribed in the Royal Decree on Digital Asset Businesses B.E. 2561 (2018). Digital Asset Fund Manager is defined as a person who manages funds from digital assets for another person for benefits, or holds themselves out to the general public as being ready to do so, in the ordinary course of business. It does not include the management of digital assets as prescribed by the Securities and Exchange Commission (SEC). Digital Asset Advisory Service is defined as a person who provides consultations to other people, directly or indirectly, regarding the value of digital assets; the suitability of investment in digital assets; or the buying, selling, or exchanging of any digital assets in the ordinary course of business in return for service fees or other compensation. However, this does not include consultations as a part of or relating to a digital asset exchange, digital asset broker, digital asset dealer, digital asset fund manager, or other personal consultation as prescribed by the SEC. Additional Digital Asset Licensing Requirements The Digital Asset Business Licensing Notification amends the definition of “License Applicant” to include cryptocurrency exchanges, digital token exchanges, cryptocurrency brokers, digital token brokers, cryptocurrency dealers, digital token dealers, cryptocurrency fund managers, digital token fund managers, cryptocurrency advisory services, and digital token advisory services. Additional requirements for granting licenses have also been added