You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 1, 2025

Myanmar Cybersecurity Law Takes Effect

On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities.

Below are some key provisions, implications, and penalties under the Cybersecurity Law.

  • Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders.
  • VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers.
  • Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated.
  • Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws.
  • Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with over 100,000 users are required to apply for the latter license. Noncompliance with this requirement will be subject to a fine of at least MMK 100 million (approx. USD 47,600), and any proceeds resulting from the violation will be confiscated.
  • Penalties for unsolicited communications. Individuals who transmit unwanted and unsolicited messages, emails, or data via a network will be subject to imprisonment for 1–2 years, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both.
  • Penalties for cyber misuse. Engaging in cyber misuse—including the alteration, deletion, or sale of computer programs or data, as well as the unauthorized control and execution of computer systems, programs, or electronic data—will be subject to imprisonment from 6 months to 3 years, a fine of MMK 1–20 million (approx. USD 476–9,530), or both.
  • Penalties for online theft or mischief. Committing or inciting others to commit online theft or mischief using cyber resources will be subject to imprisonment for 2–7 years and the possibility of additional fines.
  • Penalties for unapproved online gambling. Operating an online gambling system without proper authorization may result in imprisonment for 6 months to 1 year, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both, with the proceeds from such activities being confiscated. If the offender is a corporation or organization, the minimum fine is MMK 20 million, and the illicit proceeds will also be confiscated. The law does not address how online gambling platforms can obtain official approval.

Myanmar’s Cybersecurity Law represents a significant step in the country’s regulation and oversight of digital security and online activities. Businesses, digital platform providers, cybersecurity service providers, and VPN providers need to understand these requirements and ensure compliance to prevent substantial penalties.

Nonetheless, given that services such as VPNs are very widely used, it remains to be seen how these new far-reaching regulations will actually be enforced.

 

This article was prepared with the assistance of Tilleke & Gibbins intern Ian Michael Yam.

RELATED INSIGHTS​ 

July 11, 2023
Can computer programs resolve legal disputes? For decades, the answer from much of the legal community has been no. However, developments in artificial intelligence (AI), and in particular natural language processing and machine learning, have led to renewed discussions of this possibility. Increasingly, tools are being developed to assist parties with litigation outcome prediction and judges with litigation outcome determination. However, while some argue that the use of AI in legal disputes can reduce the length of proceedings, cut costs, and improve access to justice, others raise concerns that “black box” AI systems could reduce transparency, entrench bias, and harm the development of the law. Litigation Outcome Prediction The use of computers to predict the outcome of legal cases is not new. As early as the 1980s, researchers developed outcome prediction tools, often in the form of decision-tree algorithms. However, developments in AI have allowed the creation of more sophisticated prediction models. In 2017, a model built by Katz et al. predicted US Supreme Court decisions with an accuracy of 70.2%, while in 2019, a model built by Medvedeva et al. predicted decisions of the European Court of Human Rights with an accuracy of 75%. In various studies, AI tools have been able to predict case outcomes more accurately than expert lawyers. Companies such as Solomonic and Lex Machina, owned by LexisNexis, now provide commercial litigation prediction and analytics tools. Outcome prediction tools can be used by parties and their legal representatives to craft arguments and facilitate settlement negotiations, or by third-party litigation financers to assess the risk of providing funding. More broadly, outcome prediction may be used by the likes of insurance companies to help calculate claim payouts. However, those using such tools must take care to ensure that they do not breach any professional or legal obligations.
July 10, 2023
One of the more positive outcomes of the COVID-19 pandemic is that telemedicine has become remarkably important as an interactive system between patients and healthcare professionals. Thailand, which ranks near the top as a world medical hub, is a highly favored destination in Asia for expat workers. Currently, the Thai market has both Thai-based and foreign-based platforms with information about healthcare providers and telemedicine readily available. “Doctor Locator,” “Weed Map,” and “Find a Teeth Aligner Dentist” are examples of online platforms connecting patients with medical and telemedicine services. These digital platforms provide information about the location of specialized clinics, cannabis dispensaries, pharmacy stores, and orthodontic practitioners in Thailand. These platforms act as intermediaries between medical care businesses and consumers. As actual medical services are not offered or provided, these digital platforms do not have to be regulated under the Medical Facility Act of Thailand. However, healthcare digital platform services that act as an intermediary or conduit managing information used to connect medical clinics or cannabis dispensaries with patients or customers via a computer network are now regulated under the soon-to-be-implemented Royal Decree on Digital Platforms, regardless of whether payment is actually made via the platform. The regulatory authority for this is the Electronic Transactions Development Agency (ETDA). Under this royal decree, digital platform providers that intend to operate a digital platform service must notify the ETDA prior to initiating operations. The extent of the details to be included in the notification to the ETDA will be more comprehensive if the digital platform: has annual revenue (before expenses) for digital platform services within Thailand exceeding THB 1.8 million (approx. USD 51,200) for an individual operator or THB 50 million (approx. USD 1.42 million) for a corporate or entity operator; or has more than 5,000 users (on average) per month. Apart
June 26, 2023
Vietnam’s Ministry of Information and Communications (MIC) organized a workshop with industry representatives on June 19, 2023, to discuss its future policy direction for over-the-top (OTT) telecom services and internet data center (IDC) and cloud computing services. OTT telecom services, in the MIC’s interpretation, are communication services such as text messages or voice calls provided over the internet—for example, the services of Zalo, WhatsApp, WeChat, etc. The workshop, the first in an expected series, focused only on the discussion of policy on how to regulate these services. Light-Touch Management Approach A very positive signal of the MIC in the workshop was its clear intention to apply a “light-touch” approach to management. For cross-border provision of OTT telecom services and IDC/cloud computing services, the MIC intends to require notification and a post-check mechanism, instead of a heavy licensing or commercial arrangement regime like the one applicable to traditional telecom services. In addition, there is no limitation on foreign investment if foreigners would like to provide these services in Vietnam. With regard to domestic service providers, the MIC proposes a registration regime with a similar post-check mechanism. The MIC’s reason for registration instead of notification is because the provision of these services by domestic companies may involve setting up data center/cloud systems which require consideration of various issues including location, electricity sources, and connection with telecom infrastructure such as marine cable. However, the MIC is also hoping to make the registration process as light as possible for enterprises (for example, using online registration) to provide a favorable environment and conditions to facilitate development of the industry without obstacles or cumbersome administrative procedures for companies’ operations. For providers of these services, the MIC is also considering an exemption from the responsibility to pay fees for telecommunications activities rights, and from payment to
June 8, 2023
At a conference organized by Vietnam’s Ministry of Public Security (MPS) on June 7, 2023, government officials provided more guidance on the recently issued Personal Data Protection Decree (PDPD), which is set to take effect on July 1, 2023. Key takeaways included the following: A national portal on personal data protection for online submission of notifications and registrations will be launched before July 1, 2023. The MPS also plans to issue templates for data processing impact assessments (DPIAs) and transfer impact assessments (TIAs) in the near future. The PDPD requires data controllers, data processors, and data controller-processors to prepare a DPIA at the start of personal data processing. The MPS clarified that the DPIA is expected to be prepared and submitted once. Only changes to its content would require submission of an updated DPIA. Both DPIAs and TIAs (which are for cross-border data transfers) must be prepared in Vietnamese. Since the sale and purchase of personal data is strictly prohibited unless explicitly permitted by law, the MPS has handled approximately 14 cases involving unlawful trading of personal data, including sensitive data. Under the PDPD, sensitive data has a broader definition than under the GDPR (the European Union’s General Data Protection Regulation), and also includes location data, creditworthiness, and personal financial data. Consent is not a legal basis for the trading of personal data, including sensitive data. The 72-hour timeline for responding to a data subject’s request does not mean 72 working or business hours. Rather, it means 72 actual consecutive hours. Any organization transferring the personal data of Vietnamese citizens outside of Vietnam must comply with the PDPD, regardless of the organization’s location. For organizations incorporated overseas that must comply with the PDPD, there is no requirement to appoint a local representative (unlike the GDPR)—but appointment of a data