You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 1, 2025

Myanmar Cybersecurity Law Takes Effect

On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities.

Below are some key provisions, implications, and penalties under the Cybersecurity Law.

  • Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders.
  • VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers.
  • Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated.
  • Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws.
  • Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with over 100,000 users are required to apply for the latter license. Noncompliance with this requirement will be subject to a fine of at least MMK 100 million (approx. USD 47,600), and any proceeds resulting from the violation will be confiscated.
  • Penalties for unsolicited communications. Individuals who transmit unwanted and unsolicited messages, emails, or data via a network will be subject to imprisonment for 1–2 years, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both.
  • Penalties for cyber misuse. Engaging in cyber misuse—including the alteration, deletion, or sale of computer programs or data, as well as the unauthorized control and execution of computer systems, programs, or electronic data—will be subject to imprisonment from 6 months to 3 years, a fine of MMK 1–20 million (approx. USD 476–9,530), or both.
  • Penalties for online theft or mischief. Committing or inciting others to commit online theft or mischief using cyber resources will be subject to imprisonment for 2–7 years and the possibility of additional fines.
  • Penalties for unapproved online gambling. Operating an online gambling system without proper authorization may result in imprisonment for 6 months to 1 year, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both, with the proceeds from such activities being confiscated. If the offender is a corporation or organization, the minimum fine is MMK 20 million, and the illicit proceeds will also be confiscated. The law does not address how online gambling platforms can obtain official approval.

Myanmar’s Cybersecurity Law represents a significant step in the country’s regulation and oversight of digital security and online activities. Businesses, digital platform providers, cybersecurity service providers, and VPN providers need to understand these requirements and ensure compliance to prevent substantial penalties.

Nonetheless, given that services such as VPNs are very widely used, it remains to be seen how these new far-reaching regulations will actually be enforced.

 

This article was prepared with the assistance of Tilleke & Gibbins intern Ian Michael Yam.

RELATED INSIGHTS​ 

May 22, 2026
On May 8, 2026, the Thai government held a press conference to announce a coordinated, multiagency initiative to strengthen oversight and enforcement over products sold on online platforms. The initiative involves the Office of the Consumer Protection Board, the Thai Industrial Standards Institute, the Electronic Transactions Development Agency, the Thailand Consumers Council, the Consumer Protection Police Division, and major online platform operators. With this appointment, the government has signaled a deliberate shift from a predominantly reactive enforcement framework toward a more proactive regulatory and monitoring approach for online commerce and digital platform services. Legal and Regulatory Reform The government is accelerating a proposed Product Liability Law that would introduce new statutory frameworks for defective or substandard products, along with amendments to food safety and consumer protection legislation. The draft law has already been approved by the cabinet; the Council of State and relevant authorities will further draft the law and subsequently issue it for public hearings prior to enactment. Authorities also plan to expand enforcement measures against noncompliant businesses and distributors. In particular: The implementation of stricter “know your merchant” (KYM) identity verification requirements for online sellers. Expanded mandatory standards and regulatory oversight for high-risk products, such as power banks, electrical appliances, food products, and household goods. Increased monitoring of online product listings, and coordination with platform operators to remove unsafe, counterfeit, misleading, or otherwise noncompliant products. Additional monitoring and enforcement measures targeting online scams and illegal goods distributed through digital platforms, including e-cigarettes, which authorities identified as a growing concern due to increasing online distribution channels and potential health impact on young consumers. Strengthening Consumer Complaint Mechanisms The government announced increased cooperation with the Thailand Consumers Council and other agencies to facilitate complaint handling, market monitoring, and policy recommendations. Enhanced interagency coordination will aim to ensure that consumer
May 19, 2026
Thailand’s telecommunications regulator has introduced a range of new compliance obligations for telecom licensees aimed at preventing and suppressing technology crime. On May 15, 2026, the National Broadcasting and Telecommunications Commission (NBTC) published in the Government Gazette Notification on Measures for Prevention and Suppression of Technology Crime No. 2, which amends the original NBTC notification dated August 24, 2025. The amendment derives its authority from the Emergency Decree on Measures for Prevention and Suppression of Technology Crime B.E. 2566 (2023), as amended in 2025, and took effect on May 16, 2026. SIM Card Registration Cap for Non-Thai Nationals Persons without Thai nationality are now limited to a maximum of three SIM cards per person per service provider. Identity verification must be done primarily via passport. For those without a passport, acceptable alternatives include travel documents or certificates of identity issued by foreign governments, accompanied by additional Thai government-issued documents, as well as pink ID cards (for persons without Thai nationality) and white ID cards (for persons without registration status). Registration must be done in person at a branch or authorized dealer. Service providers must develop their identity verification systems and obtain NBTC approval before deployment. SIM Activation Deadline and SIM Box Prohibition Both Thai and non-Thai service users must activate their registered SIM within 60 days of registration. If they fail to do so, they must re-verify their identity in person before activation, confirming they are the same person who originally registered. Service providers must prohibit SIM box and gateway devices capable of supporting four or more SIMs from connecting to their mobile networks unless the device has received a license under the Radio Communications Act. Blacklist Enforcement Service providers must refuse registration of additional mobile numbers for persons listed on a technology crime-related database maintained by the Royal
May 6, 2026
Thailand has introduced new requirements for online social media platforms to verify the identity of paying advertisers before publishing their advertisements. On May 5, 2026, the Electronic Transactions Commission published the Notification on Measures for Prevention of Technology Crime for Online Social Media (No. 2) in the Government Gazette. The notification, which aims to prevent technology crimes such as fraud and scams, takes effect 180 days after publication (i.e., on November 1, 2026). Mandatory Advertiser Identity Verification Online social media service providers must verify the identity of every advertiser before publishing an advertisement. Verification remains valid for up to one year from the most recent verification date. The notification requires social media providers to use either of the following methods when verifying advertisers: Document-based verification: Examine government-issued identity documents (e.g., national ID, passport, or juristic person registration certificate), cross-check the connection between the advertiser and the identity documents (e.g., facial comparison with photo ID), and ensure that the identity documents are verifiable against reliable sources. Digital identity verification: Use an identity verification system with a level of assurance no lower than that prescribed by the Electronic Transactions Commission. Advertiser Data Collection and Retention Service providers must collect and retain certain data—including name, identification number, and contact details—from the start of the advertising service and for a minimum of 90 days after the end of the advertising service relationship. The same requirements apply where there is a third-party payer, such as an ad agency. Implications for Affected Businesses The notification raises two key areas of concern for affected businesses: Social media platforms must implement know-your-advertiser (KYA) onboarding as described above, including document upload and identity matching processes. The 180-day implementation window requires immediate technical and operational planning. The collection and retention of national ID cards, passport copies, and other personal
April 30, 2026
Vietnam’s Decree No. 134/2026/ND‑CP, which took effect on 9 April 2026, plays an important role in detailing and implementing Vietnam’s Intellectual Property (IP) Law in the context of rapid digital transformation and the growing application of artificial intelligence (AI). The new decree provides comprehensive guidance on the application of copyright and related‑rights regulations, addressing key issues such as authorship, ownership, statutory exceptions and limitations, registration procedures, and enforcement mechanisms. Through these measures, Decree 134 seeks to achieve an appropriate balance between safeguarding the legitimate interests of rightsholders and fostering innovation, research, and technological advancement, thereby strengthening the state’s framework for the effective management, protection, and exploitation of intellectual property in the digital and AI‑driven environment. Some notable aspects of Decree 134 are discussed below. Copyright for AI-Created Works Decree 134 provides important guidance on the determination of copyright and related rights in works created with the assistance of AI. Article 5a reaffirms the principle that human creativity remains central to copyright protection, clarifying that copyright or related rights arise only where a human makes a substantial and decisive intellectual contribution, exercises effective control over the creative outcome, and assumes responsibility for the content and its legality. At the same time, the provision confirms that AI is regarded solely as a technological tool rather than a rights‑holding subject, thus ensuring consistency with the fundamental concepts of authorship and ownership under the IP Law. By introducing requirements on transparency, proof of human contribution, and compliance with AI‑specific labelling and technical marking obligations, Decree 134 establishes a clear and enforceable legal framework for the responsible use of AI in creative activities. Lawful Use of Copyrighted Texts and Data Article 37a of Decree 134 sets out the specific conditions under which copyrighted texts and data may be lawfully used for scientific research, experimentation,