You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 1, 2025

Myanmar Cybersecurity Law Takes Effect

On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities.

Below are some key provisions, implications, and penalties under the Cybersecurity Law.

  • Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders.
  • VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers.
  • Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated.
  • Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws.
  • Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with over 100,000 users are required to apply for the latter license. Noncompliance with this requirement will be subject to a fine of at least MMK 100 million (approx. USD 47,600), and any proceeds resulting from the violation will be confiscated.
  • Penalties for unsolicited communications. Individuals who transmit unwanted and unsolicited messages, emails, or data via a network will be subject to imprisonment for 1–2 years, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both.
  • Penalties for cyber misuse. Engaging in cyber misuse—including the alteration, deletion, or sale of computer programs or data, as well as the unauthorized control and execution of computer systems, programs, or electronic data—will be subject to imprisonment from 6 months to 3 years, a fine of MMK 1–20 million (approx. USD 476–9,530), or both.
  • Penalties for online theft or mischief. Committing or inciting others to commit online theft or mischief using cyber resources will be subject to imprisonment for 2–7 years and the possibility of additional fines.
  • Penalties for unapproved online gambling. Operating an online gambling system without proper authorization may result in imprisonment for 6 months to 1 year, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both, with the proceeds from such activities being confiscated. If the offender is a corporation or organization, the minimum fine is MMK 20 million, and the illicit proceeds will also be confiscated. The law does not address how online gambling platforms can obtain official approval.

Myanmar’s Cybersecurity Law represents a significant step in the country’s regulation and oversight of digital security and online activities. Businesses, digital platform providers, cybersecurity service providers, and VPN providers need to understand these requirements and ensure compliance to prevent substantial penalties.

Nonetheless, given that services such as VPNs are very widely used, it remains to be seen how these new far-reaching regulations will actually be enforced.

 

This article was prepared with the assistance of Tilleke & Gibbins intern Ian Michael Yam.

RELATED INSIGHTS​ 

November 4, 2022
Lawyers from Tilleke & Gibbins in Cambodia, Laos, Myanmar, Thailand, and Vietnam have contributed to the new Multilaw Global Checklist for Monitoring Staff Data, which compiles essential information on regulations related to collection of data on employees. Such collection of data is an increasingly important concern for employers and entrepreneurs as the world pays closer attention to diversity, equality, and antidiscrimination in the workplace. The checklist contains fundamental information for each jurisdiction on legal considerations pertaining to employment diversity surveys and what can and cannot be asked. The table-style list is global in scope, with a separate line for each jurisdiction. The jurisdictional entries are grouped by region, allowing the reader to quickly compare how various countries treat different issues in each part of the world. In each column is a common question about how employers can monitor staff data in full compliance with the law, covering issues such as: Requesting data from employees; Type and format of data captured; Data storage and access; Retention of data; Intra-group cross-border data transfers; and Specific considerations for each jurisdiction. Multilaw, of which Tilleke & Gibbins is a member, is a global network of carefully selected, independent law firms consisting of over 10,000 commercial lawyers in more than 100 countries, able to provide expert legal advice in complex environments around the globe. The full checklist is available for free on the Multilaw website.
November 1, 2022
Background Thailand’s Personal Data Protection Act 2019 (‘PDPA’) is the country’s first unified data privacy legislation for personal data protection. Coming at a time when people around the world are increasingly aware of the risks and negative consequences of their personal data being compromised, the PDPA seeks to align with international standards, such as the General Data Protection Regulation (Regulation (EU) 2016/679) (‘GDPR’). Prior to the enactment of the PDPA, privacy rights were recognised in the Constitution of the Kingdom of Thailand. Beyond this, the handling of personal data was governed by specific regulations for a handful of sectors, such as telecommunications, financial institutions, securities, and life sciences. The PDPA was announced in the Royal Gazette of the Kingdom of Thailand on 27 May 2019, with an exemption for the enforcement of its requirements in relation to the collection, use, disclosure, and transfer (‘process’ or ‘processing’) of personal data, as well as its provisions on data subjects rights. After some delays caused by the impact of the COVID-19 pandemic over the past two years, the PDPA finally came fully into force on 1 June 2022. Unlike most legislation in Thailand, the PDPA has an extraterritorial aspect whereby data controllers and data processors outside Thailand may be subject to the PDPA if the processing activities they undertake fall under the criteria prescribed in the PDPA. The basics The PDPA defines personal data as any data pertaining to a living natural person that enables the identification of that person, whether directly or indirectly, such as phone number, address, email address, or anything else that might enable the data subject’s identification. The PDPA applies to personal data in any form, whether digital or otherwise. The PDPA introduces two main roles relating to the handling of others’ personal data: the data controller and the
October 21, 2022
On September 21, 2022, the Electronic Transactions Development Agency (ETDA) held another public hearing on the draft Royal Decree on Digital Platforms and its sub-regulations. This updated draft Royal Decree on Digital Platforms (which is subsequent to a previous round of updates last year) is anticipated to be the final draft before it is proposed to the king for endorsement. Thereafter, it will be published in the Government Gazette and will become effective 240 days after the publication date. The key issues under the latest draft royal decree are as follows: Exemption for certain regulated businesses. The current draft royal decree exempts business operators that are regulated by the Bank of Thailand or the Securities and Exchange Commission, as well as digital platforms operated by government agencies for noncommercial purposes, from the application of the royal decree. Nevertheless, these business operators must ensure that their digital platform has transparency, fairness, and standards which are not less than those required under the Royal Decree. Definition of digital platform. According to the public hearing, the definition of a digital platform has been amended to exclude digital platforms that are used to offer the goods or services of a digital platform provider or its affiliate acting on its behalf, regardless of whether the offering of such goods or services is made to a third party or the affiliate. Appointment of a local contact. Instead of appointing a local representative with no limit of liability, the current draft royal decree only requires offshore digital platform providers to appoint a local contact to coordinate with the ETDA. The local contact must not operate any business in Thailand under the Foreign Business Act. Notification of the ETDA. Digital platforms as defined under the royal decree must notify the ETDA of certain information—such as the name
October 20, 2022
On October 1, 2022, the Vietnamese government promulgated Decree No. 71/2022/ND-CP (“Decree 71”) amending and supplementing Decree No. 06/2016/ND-CP (“Decree 06”) on the Management, Provision, and Use of Radio and Television Services. Decree 71 will take effect on January 1, 2023, at the same time as the new Cinema Law. Decree 71 is the result of the government’s long-time attempt to regulate the cross-border provision of “over-the-top” (OTT) television services, which deliver TV content to viewers over the internet, bypassing the traditional broadcast, cable, and satellite platforms, as well as to reinforce the requirements for content on demand. The key issues of Decree 71 are set out below. 1. Expanded Scope of Application Decree 71 expands the scope of Decree 06 to clearly cover OTT video-on-demand (VOD) services by amending some definitions: “Radio and TV services” is redefined to mean “services which provide intact domestic program channels and foreign program channels, on-demand radio and TV content [newly added], and value-added service content to users over radio and TV transmission and broadcasting infrastructure. Radio and TV services can be provided directly to service users without the use of storage or delay devices (online radio and TV services), or upon the specific request of subscribers (on-demand radio and TV services).” “On-demand radio and TV content” is newly defined to include “films, domestic programs, and foreign programs.” Films (phim in Vietnamese) follow the definition under the Cinema Law, and in this context include movies/feature films as well as what would be considered “TV shows” or “TV series” (e.g., scripted comedies and dramas) in other countries. Domestic and foreign “programs,” on the other hand, follow the definition of radio and TV programs under Article 3.10 of the Press Law: “a collection of news and articles in spoken or visual press about a topic