You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 1, 2025

Myanmar Cybersecurity Law Takes Effect

On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities.

Below are some key provisions, implications, and penalties under the Cybersecurity Law.

  • Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders.
  • VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers.
  • Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated.
  • Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws.
  • Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with over 100,000 users are required to apply for the latter license. Noncompliance with this requirement will be subject to a fine of at least MMK 100 million (approx. USD 47,600), and any proceeds resulting from the violation will be confiscated.
  • Penalties for unsolicited communications. Individuals who transmit unwanted and unsolicited messages, emails, or data via a network will be subject to imprisonment for 1–2 years, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both.
  • Penalties for cyber misuse. Engaging in cyber misuse—including the alteration, deletion, or sale of computer programs or data, as well as the unauthorized control and execution of computer systems, programs, or electronic data—will be subject to imprisonment from 6 months to 3 years, a fine of MMK 1–20 million (approx. USD 476–9,530), or both.
  • Penalties for online theft or mischief. Committing or inciting others to commit online theft or mischief using cyber resources will be subject to imprisonment for 2–7 years and the possibility of additional fines.
  • Penalties for unapproved online gambling. Operating an online gambling system without proper authorization may result in imprisonment for 6 months to 1 year, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both, with the proceeds from such activities being confiscated. If the offender is a corporation or organization, the minimum fine is MMK 20 million, and the illicit proceeds will also be confiscated. The law does not address how online gambling platforms can obtain official approval.

Myanmar’s Cybersecurity Law represents a significant step in the country’s regulation and oversight of digital security and online activities. Businesses, digital platform providers, cybersecurity service providers, and VPN providers need to understand these requirements and ensure compliance to prevent substantial penalties.

Nonetheless, given that services such as VPNs are very widely used, it remains to be seen how these new far-reaching regulations will actually be enforced.

 

This article was prepared with the assistance of Tilleke & Gibbins intern Ian Michael Yam.

RELATED INSIGHTS​ 

January 21, 2025
Vietnam’s Ministry of Information and Communications has released the latest version of its draft Law on the Digital Technology Industry (DTI Law), marking a significant step toward comprehensive regulation of digital technologies and notably addressing artificial intelligence (AI). The draft law was deliberated in the National Assembly on January 6, 2025, and is expected to be adopted in May 2025. Once in effect, the law will modernize Vietnam’s existing information technology regulatory framework. Background Vietnam has been steadily building its regulatory framework for AI since January 2021, when the prime minister issued Decision No. 127/QD-TTg on the National Strategy for Research, Development, and Application of Artificial Intelligence until 2030. While various ministries have been tasked with issuing guidance documents and technical standards, Vietnam still lacks a comprehensive legal framework specifically addressing AI and digital technologies. The draft DTI Law aims to fill this gap by providing a structured approach to regulating the digital technology industry. Scope and Definitions The draft DTI Law establishes a broad framework governing digital technology industry activities, initiatives for developing the digital technology sector, and rights and obligations of organizations and individuals in the industry. The draft law also proposes the creation of various incentives, primarily in the form of tax benefits, for encouraging foreign direct investment, talent acquisition and development, and industry growth. The draft law introduces several important definitions, particularly around AI, which is defined as digital technology that simulates human intelligence to generate content, forecasts, suggestions, and decisions based on human-determined goals. The draft distinguishes between different categories of AI systems: High-risk AI systems: Those posing risks to health, safety, rights, and legitimate interests. High-impact AI systems: Distinguished by their broad scope, large user base, and significant computational resources for training. Standard AI systems: Basic systems that apply AI for automated analysis
January 20, 2025
Thailand’s official draft Platform Economy Act (PEA) was released on January 15, 2025, for public comment until February 15, 2025. The draft PEA is positioned as a general or overarching law for digital intermediary services and digital platform service businesses. The official release of the draft came after the sharing of the set of principles that would form the basis for the official draft PEA in November 2024. The draft PEA incorporates those principles and adds more detailed provisions. Especially notable is that the draft PEA requires all intermediary service providers and online platform operators—both Thai and foreign—to appoint a point of contact to liaise with the Electronic Transactions Development Agency (ETDA) if they have any users in Thailand. However, the draft PEA does not mandate establishment of a local entity in Thailand. Types of Intermediary Services The draft PEA sets out a three-tiered classification system for different types of service providers, ordered from fewest obligations to most: Intermediary services. Intermediary services are further divided into three subcategories: mere conduit, caching, and hosting. Each type of intermediary service has different safe harbor provisions, which define their scope and limitations. Online platform services. Online platform services are defined as involving “the provision of intermediary services in the hosting category that involve facilitating the matching of various types of users to enable transactions or interactions, whether or not a fee is charged. Additionally, such services may include other provisions to facilitate these transactions or interactions.” Key obligations for online platform providers include: Informing users of their rights and duties under relevant laws Implementing a notice-and-action mechanism Disclosing advertising information Publishing T&Cs, including details such as service fees, algorithms, and complaint management mechanisms. Very large online platform services. Very large online platform services (VLOPs) have extra duties beyond regular online platform services,
January 16, 2025
On January 13, 2025, Thailand’s cabinet approved in principle the draft Entertainment Complex Act, as proposed by the Ministry of Finance. This landmark legislative proposal, which would allow casinos as part of larger “entertainment complexes,” will now proceed through further parliamentary review and approval. Key provisions of the draft act are described below. Corporate structure: Entertainment complexes must be operated by Thai-registered limited companies or public limited companies with a minimum paid-up capital of THB 10 billion. Directors of the licensed entity must be individuals and have the qualifications and none of the prohibited characteristics specified in the draft act. The draft act does not impose restrictions on foreign-majority ownership structures; however, it is worth monitoring whether any amendments addressing this matter are introduced during the legislative process. Operating conditions: Each entertainment complex must be located in an area designated under a royal decree. It must also include at least four types of entertainment businesses listed in the annex to the draft act (e.g., shopping mall, hotel, sports stadium, amusement park), along with a casino. The allocation of casino space must comply with regulations to be specified at a later date. Licensing conditions: Licenses will be valid for 30 years, renewable in increments of up to 10 years. The license issuance fee is THB 5 billion, the annual fee is THB 1 billion, and the renewal fee is THB 5 billion. The Entertainment Complex Policy Committee, chaired by the prime minister, will review and approve applications. Online gambling restrictions: Licensees are prohibited from offering gambling through internet-connected systems or electronic devices that allow access from outside the casino premises. Labor requirements: Thai and foreign employee ratios must adhere to prescribed regulations. Land privileges: Lease agreements for land use are limited to 50 years. Renewal is permitted for up to
January 13, 2025
The State Bank of Vietnam’s Circular No. 50/2024/TT-NHNN regulating safety and security for the provision of online services in the banking sector (“Circular 50”), issued on October 31, 2024, took effect on January 1, 2025, with delayed effectiveness for certain provisions on (i) network, communication, and security systems, online banking application software, and mobile banking application software (July 1, 2025); (ii) transaction confirmation for payment transactions conducted via the straight-through processing method (January 1, 2026); and (iii) authentication forms and reporting obligations (July 1, 2026). The cybersecurity situation in Vietnam is complicated, and the banking and finance sector has been one of the top targets of high-tech criminals. Circular 50 seeks to enhance user protection by expanding the technical requirements to more services in the banking sector as well as standardizing how transactions are authenticated. Expanded Scope of Services Covered Previous regulations on safety and security of online services in the banking sector only covered banking services and intermediary payment services. Circular 50 expands the scope to include other services of credit institutions and foreign bank branches such as credit information services, foreign exchange services, securities depository services, and services related to factoring and letters of credit, which now need to comply with technical requirements and standards for online services such as firewalls and DMZ network barriers. Risk-Based Approach to Authentication Circular 50 sets out standards for payment transactions and card transactions by: Classifying various online transactions based on the type of client, the purpose of the transfer, the value of the specific transaction, and the total value of certain transactions during the day; and Applying various types of authentication for the corresponding types of online transactions, e.g., using passwords or PINs for small-value online transactions, and using OTPs (through SMS, voice, or email), biometric matching, or e-signatures for