You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 1, 2025

Myanmar Cybersecurity Law Takes Effect

On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities.

Below are some key provisions, implications, and penalties under the Cybersecurity Law.

  • Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders.
  • VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers.
  • Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated.
  • Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws.
  • Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with over 100,000 users are required to apply for the latter license. Noncompliance with this requirement will be subject to a fine of at least MMK 100 million (approx. USD 47,600), and any proceeds resulting from the violation will be confiscated.
  • Penalties for unsolicited communications. Individuals who transmit unwanted and unsolicited messages, emails, or data via a network will be subject to imprisonment for 1–2 years, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both.
  • Penalties for cyber misuse. Engaging in cyber misuse—including the alteration, deletion, or sale of computer programs or data, as well as the unauthorized control and execution of computer systems, programs, or electronic data—will be subject to imprisonment from 6 months to 3 years, a fine of MMK 1–20 million (approx. USD 476–9,530), or both.
  • Penalties for online theft or mischief. Committing or inciting others to commit online theft or mischief using cyber resources will be subject to imprisonment for 2–7 years and the possibility of additional fines.
  • Penalties for unapproved online gambling. Operating an online gambling system without proper authorization may result in imprisonment for 6 months to 1 year, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both, with the proceeds from such activities being confiscated. If the offender is a corporation or organization, the minimum fine is MMK 20 million, and the illicit proceeds will also be confiscated. The law does not address how online gambling platforms can obtain official approval.

Myanmar’s Cybersecurity Law represents a significant step in the country’s regulation and oversight of digital security and online activities. Businesses, digital platform providers, cybersecurity service providers, and VPN providers need to understand these requirements and ensure compliance to prevent substantial penalties.

Nonetheless, given that services such as VPNs are very widely used, it remains to be seen how these new far-reaching regulations will actually be enforced.

 

This article was prepared with the assistance of Tilleke & Gibbins intern Ian Michael Yam.

RELATED INSIGHTS​ 

January 24, 2024
Thailand’s Personal Data Protection Act came into full effect on 1 June 2022 and various subordinate regulations have since been issued by the Personal Data Protection Committee. These include regulations on security measures to be implemented by data controllers, data breach notification requirements, a mandatory obligation to appoint a data protection officer when the processing activity requires regular monitoring of personal data or a system due to the large scale of personal data, administrative measures and data processors’ record of processing activities. As some areas under the PDPA still require further clarifications, a series of public consultations for the remaining draft subordinate regulations is anticipated in 2024. Potential areas include data protection impact assessments and cross-border transfers of personal data, which are crucial for organizations and particularly for entities with establishments in other jurisdictions. PDPA enforcement by Thai regulators was silent until the last quarter of 2023, when the PDPC published details about complaints that have been lodged to the Expert Committee. The committee is designated by virtue of the PDPA and has the power to make determinations related to imposing administrative fines and other penalties. Enforcement in 2024 is expected to become more active and potentially more serious, which means organizations should pay closer attention to ensure compliance with the PDPA. Similar to the GDPR, the PDPA also has extraterritorial effect. Once the subordinate regulation on international cooperation has been issued by the PDPC, this should clarify how PDPA enforcement against organizations located outside of Thailand will be conducted by Thai regulators. With respect to sector-specific data protection legislation, in September 2023, Thailand’s National Broadcasting and Telecommunications Commission issued the Notification of the NBTC Re: Measures to Protect Telecommunications Service Users’ Rights in regard to Personal Data, Privacy Rights, and Freedom of Telecommunications, which replaces the previous notification.
January 19, 2024
On November 24, 2023, the National Assembly of the Socialist Republic of Vietnam adopted Law No. 24/2023/QH15 on Telecommunications (“Telecom Law 2023”) after a lengthy period of extensive discussions and revisions. The Telecom Law 2023 is set to take effect on July 1, 2024, except for the requirements relating to basic telecom services on the internet (otherwise known as over-the-top services, or “OTT”), data center services, and cloud computing services, which will take effect on January 1, 2025. Some important highlights of the Telecom Law 2023 are discussed below. Updates on Telecom License Requirements With a few exceptions and save for certain types of telecom services, enterprises in Vietnam are required to obtain Telecom Licenses in order to provide telecom services. There are two types of Telecom Licenses: licenses for the provision of telecom services, and licenses for telecom operations. Telecom Licenses can be granted in two forms. The first is separate licensing, which is for telecom services with network infrastructures that use radio frequencies or operate in areas with special requirements set by the government. The second is group licensing, which covers telecom services with network infrastructure (except in certain cases), telecom services without network infrastructure (except in certain cases), and telecom operations. New Regulations for OTT, Data Center, and Cloud Computing Services The Telecom Law 2023 provides the definitions for OTT services, data center services, and cloud computing services, recognizing them as different types of telecom services. It also outlines the rights and obligations of service providers in these fields. Regarding market-entry conditions, foreign direct investments in OTT services, data center services, and cloud computing services are subject to no restrictions on share ownership ratio or capital contribution. Foreign investors can establish 100% foreign-owned enterprises in Vietnam to offer these services. Enterprises offering these services are not
January 12, 2024
Thailand’s Revenue Department (RD) has issued a notification requiring electronic platforms to report their revenue from business operators on their platform. With this information, the RD intends to track business operators’ income from the sale of goods and services through electronic platforms in order to facilitate accurate and efficient tax collection. The notification, which was enacted on December 27, 2023, took effect on January 1, 2024. Under the notification, electronic platforms are required to compile a “special account” containing information on the revenue received from each business operator on their platform and submit it to the RD through the department’s electronic reporting system within 150 days of the end of the fiscal year. The notification defines “electronic platforms” as entities that intermediate between business operators (i.e., sellers of goods or providers of services via the electronic platform) and consumers for the purpose of enabling electronic transactions between the parties. This covers online marketplace operators, ride-hailing operators, food delivery operators, and so on. This reporting requirement applies to electronic platforms registered in Thailand that have (or previously had, starting from the notification’s effective date) annual revenue exceeding THB 1 billion (approx. USD 28.5 million), except for electronic platforms under the supervision of the Bank of Thailand or the Office of the Securities and Exchange Commission, such as payment service providers and cryptocurrency exchanges. Electronic platforms can appoint a third party to prepare and submit the required special account information to the RD on their behalf. Compliance Steps As the requirements established by this notification mean that the RD will now have direct access to information on the income earned by vendors and merchants on electronic platforms, these business operators—whether corporate or individual—should ensure that they faithfully disclose their earnings, submit tax payments correctly, and file income tax returns in a
January 9, 2024
As of January 1, 2024, all films distributed in cyberspace in Vietnam must display ratings and warnings (if required) for viewers, following the phased-in effectiveness of Decree No. 131/2022/ND-CP of the Government dated December 31, 2022, guiding the implementation of the Law on Cinematography (Decree 131). While Decree 131 took effect on January 1, 2023 (the same date as the Law on Cinematography), it provided a grace period of one year for films to be distributed in cyberspace without the display of ratings or warnings. Now, for continued distribution in cyberspace of such films, distributors must add ratings and warnings in compliance with regulations issued under Circular No. 05/2023/TT-BVHTTDL of the Ministry of Culture, Sports and Tourism (MOCST) dated April 5, 2023 (Circular 05). Film Rating Film distributors can either carry out the film rating by themselves or request the MOCST to provide the rating. In the former case, the distributor must request the MOCST to recognize its eligibility for self-rating. (Based on our experience successfully obtaining this recognition for a client, this procedure may take about two to three months for completion, depending on the availability of required information and materials.) If a distributor cannot obtain recognition for film self-rating eligibility, it must request the MOCST to provide the film rating for each and every film it distributes in cyberspace. Display of Ratings and Warnings Circular 05 requires that the film rating must be displayed clearly and prominently in the introduction of a film in order for a user to make an informed decision to access that film or not. Moreover, the rating must be displayed on the left or right corner of the screen during the entire distribution time. Warning contents must be in words or sound which must be displayed three seconds after the beginning of