You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 1, 2025

Myanmar Cybersecurity Law Takes Effect

On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities.

Below are some key provisions, implications, and penalties under the Cybersecurity Law.

  • Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders.
  • VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers.
  • Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated.
  • Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws.
  • Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with over 100,000 users are required to apply for the latter license. Noncompliance with this requirement will be subject to a fine of at least MMK 100 million (approx. USD 47,600), and any proceeds resulting from the violation will be confiscated.
  • Penalties for unsolicited communications. Individuals who transmit unwanted and unsolicited messages, emails, or data via a network will be subject to imprisonment for 1–2 years, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both.
  • Penalties for cyber misuse. Engaging in cyber misuse—including the alteration, deletion, or sale of computer programs or data, as well as the unauthorized control and execution of computer systems, programs, or electronic data—will be subject to imprisonment from 6 months to 3 years, a fine of MMK 1–20 million (approx. USD 476–9,530), or both.
  • Penalties for online theft or mischief. Committing or inciting others to commit online theft or mischief using cyber resources will be subject to imprisonment for 2–7 years and the possibility of additional fines.
  • Penalties for unapproved online gambling. Operating an online gambling system without proper authorization may result in imprisonment for 6 months to 1 year, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both, with the proceeds from such activities being confiscated. If the offender is a corporation or organization, the minimum fine is MMK 20 million, and the illicit proceeds will also be confiscated. The law does not address how online gambling platforms can obtain official approval.

Myanmar’s Cybersecurity Law represents a significant step in the country’s regulation and oversight of digital security and online activities. Businesses, digital platform providers, cybersecurity service providers, and VPN providers need to understand these requirements and ensure compliance to prevent substantial penalties.

Nonetheless, given that services such as VPNs are very widely used, it remains to be seen how these new far-reaching regulations will actually be enforced.

 

This article was prepared with the assistance of Tilleke & Gibbins intern Ian Michael Yam.

RELATED INSIGHTS​ 

May 2, 2025
Attorneys from Tilleke & Gibbins have updated the latest edition of Doing Business in Thailand, a Q&A-style guide from Thomson Reuters Practical Law that offers an overview of key legal considerations for companies operating in jurisdictions worldwide. The contribution outlines the country’s legal and regulatory framework for foreign investment and business operations and reflects the latest legislative developments. The chapter addresses the following core topics: Legal system: Structure of the courts and the codified nature of Thai law. Foreign investment: Business restrictions under the Foreign Business Act, sector-specific regulations, exchange control rules, and investment incentives. Business vehicles: Overview of partnerships, private and public limited companies, and other legal entities. Employment: Labor protections, employment contracts, foreign worker requirements, and termination procedures. Tax: Corporate and personal income tax, indirect taxes, and tax obligations for residents and non-residents. Intellectual property: Registration and enforcement of patents, trademarks, designs, and copyrights. Data protection: Key provisions of the Personal Data Protection Act and related compliance obligations. Competition law: Regulatory framework under the Trade Competition Act. Anti-bribery and corruption: Relevant legislation and enforcement mechanisms. E-commerce and digital business: Legal regime for online transactions and digital platforms. Marketing and advertising: Consumer protection laws and regulations affecting advertising and marketing practices. Product regulation and liability: Safety standards, liability regimes, and roles of enforcement authorities. Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
April 30, 2025
With a favorable crypto climate from the Trump administration in the United States, Thailand is ready for digital asset platforms and has market appetite. This article highlights the country’s regulatory initiatives supporting the growth of digital assets like crypto, stablecoins, and smart contracts, along with efforts to establish clear oversight. Bank of Thailand Sandbox Stablecoins used as a medium of payment, particularly those pegged to the Thai baht (THB) for public use, are considered as mirroring fiat currency, which violates the Currency Act B.E. 2501 (1958). These can also be classified as e-money under the Payment Systems Act B.E. 2560 (2017). The Bank of Thailand (BOT) urges issuers to engage in preconsultation prior to implementation, due to concerns about stablecoins being used in place of THB currency. Other FX- or asset-backed stablecoins are not recognized as legal tender under Thai law, and users must bear their own risks. The BOT recognizes the potential and benefits of these technologies in reducing operational costs for financial service providers and addressing the needs of financial service users. Consequently, the BOT issued a sandbox framework in June 2024. In particular, the enhanced regulatory sandbox allows nonlicensed entities to test financial innovations in controlled conditions. These tests must have a clearly defined duration (usually under one year) and involve a limited user group with an exit strategy. Several programmable payment projects—automated transactions with predefined conditions for the payment of goods and services—were piloted under this sandbox, which closed for applications in September 2024. Eight participants are planning to launch their test runs this year, some of which include asset tokenization or exchange global stablecoins in their programmable payment projects. Thai Securities and Exchange Commission Sandbox Given that digital asset businesses fall under the Royal Decree on Digital Asset Businesses B.E. 2561 (2018), supervised by
April 30, 2025
The Bank of Thailand (BOT) is accepting public comments until May 2, 2025, on three draft notifications that will institute an enhanced supervision scheme and impose additional requirements for systemically important retail payment system (SIRPS) operators to align with international standards and encourage open infrastructure and competition. The SIRPS operators will be determined by the BOT from the “designated payment system operators” under the Payment Systems Act B.E. 2560 (2017). SIRPS Designation The BOT will announce a list of payment system operators designated as SIRPS operators and thus subject to enhanced supervision. The BOT will evaluate whether the payment system operator should be deemed a SIRPS operator when it meets the criteria in either the BOT’s quantitative or qualitative assessments, which cover the following: Quantitative assessment: The payment system’s transaction values, market share, cross-border payment network scale and value, and settlement with other financial market infrastructure. Qualitative assessment: The payment system’s function as a part of the country’s payment system infrastructure, the significance of the system users’ roles in the payment services, the substitutability of the payment system, and the impact level on the public and users in the event of an emergency or system suspension. Supervision of SIRPS Business Operations SIRPS operators will be subject to heightened supervision in three areas, in addition to various BOT regulations on designated payment system supervision, as follows: Governance: SIRPS operators will be required to have a balanced board composition with an independent director and directors with varied expertise, establish subcommittees to assist the board in supervising the operator’s compliance with its policy and strategy, and have senior executives overseeing risk and technology security separately from the executives overseeing business operations. Risk management and security: SIRPS operators will be required to have comprehensive risk management to ensure system stability and security. This
April 28, 2025
In recent years, Vietnam has positioned itself among the leading countries in the world in terms of digital asset ownership and trading volume. This rapid adoption reflects the country’s growing digital economy and the increasing engagement of individuals and businesses in blockchain-based financial activities. Central to this growth are Resolution No. 57-NQ/TW of the Politburo dated December 22, 2024, on breakthroughs in science, technology, innovation, and national digital transformation with a vision to 2045 (“Resolution 57”) and Resolution No. 03/NQ-CP of the Government dated January 9, 2025, promulgating the Action Plan to Implement Resolution 57 (“Resolution 03”), which outline a flexible and innovative policy framework that embraces pilot programs for emerging technologies to lay the groundwork for Vietnam’s legislative framework concerning cryptocurrency and blockchain technologies. Regulatory clarity in terms of digital assets and blockchain technologies is now more critical than ever for businesses and investors. In light of this, Vietnam is currently in the process of introducing three key legal instruments, with drafts of the Law on Digital Technology Industry (“Draft DTI Law”), Resolution of the National Assembly on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Financial Center Resolution”), and Resolution of the Government on the Pilot Implementation of Crypto Asset Markets in Vietnam (“Draft Crypto Pilot Resolution”) nearing promulgation. Current Regulatory Direction and Schedule Vietnam’s regulatory framework for crypto assets and blockchain has been in a developmental stage since 2017, focusing on directions, plans, and schedules rather than established regulations. In February 2024, under Decision No. 194/QD-TTg of the Prime Minister, the Ministry of Finance (MOF) was assigned to draft a legal framework to either prohibit or regulate virtual assets and service providers by May 2025, signaling a clearer regulatory direction. In March 2025, Directive No. 05/CT-TTg of the Prime Minister directed the MOF