You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 1, 2025

Myanmar Cybersecurity Law Takes Effect

On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities.

Below are some key provisions, implications, and penalties under the Cybersecurity Law.

  • Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders.
  • VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers.
  • Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated.
  • Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws.
  • Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with over 100,000 users are required to apply for the latter license. Noncompliance with this requirement will be subject to a fine of at least MMK 100 million (approx. USD 47,600), and any proceeds resulting from the violation will be confiscated.
  • Penalties for unsolicited communications. Individuals who transmit unwanted and unsolicited messages, emails, or data via a network will be subject to imprisonment for 1–2 years, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both.
  • Penalties for cyber misuse. Engaging in cyber misuse—including the alteration, deletion, or sale of computer programs or data, as well as the unauthorized control and execution of computer systems, programs, or electronic data—will be subject to imprisonment from 6 months to 3 years, a fine of MMK 1–20 million (approx. USD 476–9,530), or both.
  • Penalties for online theft or mischief. Committing or inciting others to commit online theft or mischief using cyber resources will be subject to imprisonment for 2–7 years and the possibility of additional fines.
  • Penalties for unapproved online gambling. Operating an online gambling system without proper authorization may result in imprisonment for 6 months to 1 year, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both, with the proceeds from such activities being confiscated. If the offender is a corporation or organization, the minimum fine is MMK 20 million, and the illicit proceeds will also be confiscated. The law does not address how online gambling platforms can obtain official approval.

Myanmar’s Cybersecurity Law represents a significant step in the country’s regulation and oversight of digital security and online activities. Businesses, digital platform providers, cybersecurity service providers, and VPN providers need to understand these requirements and ensure compliance to prevent substantial penalties.

Nonetheless, given that services such as VPNs are very widely used, it remains to be seen how these new far-reaching regulations will actually be enforced.

 

This article was prepared with the assistance of Tilleke & Gibbins intern Ian Michael Yam.

RELATED INSIGHTS​ 

October 2, 2023
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has issued the Notification of the NBTC Re: Measures to Protect Telecommunications Service Users’ Rights Regarding Personal Data, Privacy Rights, and Freedom of Telecommunications to replace the previous 2006 notification of the same name. The replacement notification supports compliance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA), modernizes the regulations in response to technological change and the convergence of digital business, and enhances the protection of telecommunications users’ personal data, privacy rights, and freedoms. Key aspects of the replacement notification are highlighted below. User Data and Consent The notification specifies that “user’s personal data” includes name, address, ID number, mobile number, usage information, and user behavior that can identify the user. “User” does not include resellers of telecommunications services. To collect, use, or disclose users’ personal data for a purpose other than telecommunications service, service providers must obtain each user’s consent prior to or at the time of collecting the data. The consent (whether written or electronic) must be separate from the telecommunications service agreement. Service providers must clarify the purpose of collecting data, and they must honor users’ rights to opt in and opt out by providing clear and convenient channels for users to withdraw any of their information or cancel any services offered by the operator. Service providers must add an electronic channel for receiving requests from users to review, access, edit, change, or obtain a copy of their data. The electronic channel must also allow requests from users to suspend use or disclosure of their personal data and withdraw consent to collect, use, or disclose their personal data. In addition, service providers must have a system for verifying the identity of users who want to exercise the rights listed in this paragraph. Data Collection and Storage Collection
September 26, 2023
On September 14, 2023, Thailand’s Personal Data Protection Committee (PDPC) published a notification on the requirements for the appointment of a data protection officer (DPO) in the Government Gazette, taking effect on December 13, 2023. The notification on appointing a DPO lays out the criteria for what constitutes processing of personal data requiring “regular monitoring of the personal data or the system” by reason of “having large-scale personal data,” which requires data controllers and data processors to appoint a DPO under the Personal Data Protection Act B.E. 2562 (PDPA). Criteria After a hearing on the draft DPO appointment notification in July, the published version has been slightly amended while the main criteria for appointment of a DPO are still the same. These have been finalized as follows: When determining whether processing of personal data requires regular monitoring due to having large-scale personal data, only the “core activity” of the data controller or data processor is to be taken into consideration. The term “core activity” denotes an essential and integral activity directly related to the primary operations of the data controller or data processor and does not include any supplementary business activities (e.g., human resources and information technology activities). “Processing activities that require regular monitoring of personal data” refers to activities relating to tracking, monitoring, analyzing, or predicting the behavior, attitude, or profile of individuals, and generally involves the processing of personal data in a systemic manner on a usual or regular basis. Examples include membership card programs, credit scoring, insurance premium consideration, fraud prevention, processing of personal data by computer network system service providers or telecommunications operators, behavioral advertising, and so on. To determine whether processing activities constitute “large-scale processing of personal data,” various factors are considered: Volume, type, or nature of personal data processed; Duration or permanence of
September 21, 2023
Myanmar’s Ministry of Commerce has announced its E-commerce Guidelines to regulate stakeholders engaging in e-commerce. The guidelines—which were issued on September 5, 2023, and took immediate effect—are mandatory for e-commerce business operators (both entities and individuals), and failure to comply with the guidelines’ requirements may result in penalties under relevant laws. The E-commerce Guidelines come as Myanmar seeks to increase its regulation of e-commerce activities. The guidelines were preceded by a July 2023 notification requiring e-commerce business operators to register their activities with the Ministry of Commerce by January 21, 2024. Definitions “E-commerce” is defined as the sale of goods or services on the internet or other digital platforms. The term also covers sales promotions, marketing, logistics, ordering, and delivery. An “e-commerce platform entrepreneur” is a person who manages an e-commerce platform where two or more entrepreneurs can conduct e-commerce. An “e-commerce business operator” is a person operating or authorized to operate e-commerce activities. This includes e-commerce platform entrepreneurs, entrepreneurs selling on e-commerce platforms, and sellers through social media platforms. Electronic Contracts Acceptable forms of electronic contracts, which must comply with the Electronic Transactions Law, Contract Act, and other relevant laws, include: Click-wrap, click-through, and web-wrap contracts; Browse-wrap contracts; and Agreements between seller and buyer on social media platforms, such as by accepting or rejecting an offer via direct message. Samples of contract forms are appended to the guidelines. Consumer Protection Disclosure notices for consumers must be comprehensible, correct, consistent, simple, accessible, and visible. They can be written in Myanmar language, English, or Myanmar language and another language. They must also comply with the relevant provisions of the Consumer Protection Law. The guidelines provide that if the agreed delivery date is eclipsed by more than 15 days, the consumer may terminate the contract and request a full refund of
August 31, 2023
When your company suffers a data breach, taking prudent, careful action can limit and perhaps even rectify some of the damage. First of all, it is important to document everything, starting with the time the data breach was discovered. Secure the data systems and preserve all evidence so that investigators can determine what happened, and begin following the protocol that all companies handling personal data should have in place to guide their data breach response. It is also crucial to seek timely legal assistance to ensure that every aspect of the response is planned and carried out according to the law. While applicable legal advice for each situation can only be obtained by consulting a legal advisor, this guide gives an overview of what companies in Southeast Asian jurisdictions can expect if they suffer a data breach. This guide from Tilleke & Gibbins is a quick-reference resource covering key regulatory issues regarding data breach responses in Cambodia, Laos, Myanmar, Thailand, and Vietnam. The full guide can be downloaded through the button below.