You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 9, 2025

Myanmar Issues Cybersecurity Law

On January 1, 2025, Myanmar’s State Administration Council enacted Cybersecurity Law No. 1/2025, which aims to regulate various aspects of digital security and online activities. The law has not yet been implemented and will come into force on a date specified by the Myanmar president, who will also provide an official adoption and compliance timeline for individuals and organizations impacted by the new regulations.

Below are some of the key provisions, implications, and penalties under the Cybersecurity Law.

  • Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders.
  • VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers.
  • Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated.
  • Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws.
  • Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with over 100,000 users are required to apply for the latter license. Noncompliance with this requirement will be subject to a fine of at least MMK 100 million (approx. USD 47,600), and any proceeds resulting from the violation will be confiscated.
  • Penalties for unsolicited communications. Individuals who transmit unwanted and unsolicited messages, emails, or data via a network will be subject to imprisonment for 1–2 years, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both.
  • Penalties for cyber misuse. Engaging in cyber misuse—including the alteration, deletion, or sale of computer programs or data, as well as the unauthorized control and execution of computer systems, programs, or electronic data—will be subject to imprisonment from 6 months to 3 years, a fine of MMK 1–20 million (approx. USD 476–9,530), or both.
  • Penalties for online theft or mischief. Committing or inciting others to commit online theft or mischief using cyber resources will be subject to imprisonment for 2–7 years and the possibility of additional fines.
  • Penalties for unapproved online gambling. Operating an online gambling system without proper authorization may result in imprisonment for 6 months to 1 year, a fine of MMK 5–20 million (approx. USD 2,380–9,530), or both, with the proceeds from such activities being confiscated. If the offender is a corporation or organization, the minimum fine is MMK 20 million, and the illicit proceeds will also be confiscated. The law does not address how online gambling platforms can obtain official approval.

Myanmar’s Cybersecurity Law represents a significant step in the country’s regulation and oversight of digital security and online activities. Businesses, digital platform providers, cybersecurity service providers, and VPN providers need to understand these requirements and ensure compliance to prevent substantial penalties.

For more details on the Cybersecurity Law, or on any aspect of digital security and internet regulations in Myanmar, please contact Tilleke & Gibbins at [email protected].

RELATED INSIGHTS​ 

March 10, 2025
Thailand’s Securities and Exchange Commission (SEC) will officially add USD Coin (USDC) and Tether (USDT) to its list of approved cryptocurrencies for use in digital asset transactions on March 16, 2025. The addition is a significant move that expands Thailand’s digital asset market, aiming to enhance market flexibility and provide more payment options for investors and traders in Thailand’s digital asset ecosystem. Under the SEC regulations, digital asset operators, including digital token issuers, ICO portals, and digital asset exchanges, are only permitted to accept, conduct transactions with, and use “approved cryptocurrencies” as trading pairs. After the addition of USDC and USDT, the full list of approved cryptocurrencies will include: Bitcoin (BTC) Ethereum (ETH) Ripple (XRP) Stellar (XLM) Tether (USDT) USD Coin (USDC) Other cryptocurrencies used for testing programmable payments under the enhanced regulatory sandbox in accordance with the Bank of Thailand’s rules and conditions. For more information on these new additions, or on any aspect of digital assets and cryptocurrency in Thailand, please contact Kobkit Thienpreecha at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].
February 28, 2025
Vietnam’s Decree No. 163/2024/ND-CP (Decree 163), which has been in full effect since January 1, 2025, provides crucial guidance on the implementation of Vietnam’s 2023 Telecom Law. Decree 163 replaced Decree No. 25/2011/ND-CP dated April 6, 2011 (Decree 25), which guided the implementation of the previous 2009 Telecom Law, and introduces many notable changes to the regulations on telecom service provision. Some key changes that will impact businesses engaged in the telecom sector in Vietnam are detailed below. 1. Classification of Telecom Services The classification of telecom services into “basic telecom services” and “value-added telecom services” has been retained, in alignment with Vietnam’s WTO commitments in the telecom sector. However, Decree 163 expands the scope of both categories, as follows: Basic telecom services: “Transmission services for machine-to-machine (M2M) communication” and “leasing services of all or part of the telecom network” are added. “Image transmission services” is changed to “transmission services for radio and television.” Value-added telecom services: “Data center services,” “cloud computing services,” and “basic telecom services over the internet” (also known as over-the-top (OTT) telecom services) are added. 2. M2M Communication Services Since M2M communication services are classified as basic telecom services, without exception, they are subject to the same regulatory framework. Specifically: Cross-border provision: M2M communication services provided across borders must be conducted through a commercial agreement with a Vietnamese telecom enterprise licensed to provide telecom services with an international communication scope. Onshore provision: Onshore M2M communication services will require a telecom license. 3. New Telecom Services (Data Center, Cloud, and OTT Telecom Services) The 2023 Telecom Law adopted a light-touch management approach for data center, cloud, and OTT telecom services by not requiring the same licensing as previously regulated value-added telecom services, but instead mandating registration or notification before service provision. Decree 163 offers clearer guidance
February 26, 2025
Tilleke & Gibbins has contributed the Vietnam chapter to Data Protection 2025, a comprehensive comparative guide in the Law Over Borders series from Global Legal Post. This Q&A-style resource offers detailed insights into data protection regulations across multiple jurisdictions, serving as an essential reference for organizations managing personal data in today’s global business environment. The Vietnam chapter examines the evolving data protection landscape in Vietnam, including analysis of relevant provisions in the Cybersecurity Law, the Law on Information Technology, and the upcoming Personal Data Protection Decree. The chapter addresses key aspects of data protection through the following topics: Regulatory framework: Analysis of national laws regulating personal data, jurisdictional scope, application to different entities, and regulated data processing activities. Data categories and processing: Overview of regulated personal data types, special categories requiring enhanced protection, and lawful processing requirements. Compliance requirements: Explanation of controller and processor obligations, technical and organizational measures, and data subject rights. Commercial communications and international transfers: Rules governing direct marketing and cross-border data flows. Regulatory oversight: Details on enforcement powers, investigation procedures, sanctions, and remedies for noncompliance. Tilleke & Gibbins also contributed the Thailand chapter to Data Protection 2025. Readers can access the complete Data Protection 2025 guide through Global Legal Post’s Law Over Borders platform.
February 26, 2025
Tilleke & Gibbins has contributed the Thailand chapter to Data Protection 2025, a newly published comparative guide from Global Legal Post’s Law Over Borders series. This comprehensive Q&A-style resource provides insights into data protection regulations across multiple jurisdictions worldwide, offering valuable guidance for businesses navigating the complex landscape of global data privacy requirements. The Thailand chapter offers a detailed analysis of the country’s data protection framework, with particular focus on the Personal Data Protection Act (PDPA) that came into full effect in 2022. The chapter addresses key aspects of data protection in Thailand through the following topics: Regulatory framework: National laws governing personal data, scope of application, territorial reach, and regulated operations. Data categories and protection: Types of personal data covered, special categories subject to enhanced protection, and processing requirements. Compliance obligations: Requirements for lawful processing, organizational responsibilities, and data subject rights. Marketing and cross-border considerations: Rules for commercial communications and international data transfers. Enforcement mechanisms: Regulatory powers, investigation procedures, sanctions, and remedies for noncompliance. Tilleke & Gibbins also contributed the Vietnam chapter to Data Protection 2025. Readers can access the complete Data Protection 2025 guide through Global Legal Post’s Law Over Borders platform.