You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 26, 2026

Myanmar’s Private Security Services Law: Considerations for Foreign Businesses

Myanmar’s Private Security Services Law, enacted on February 18, 2025, together with its implementing Directive on Applications for a Private Security Services License or Permit issued on June 18, 2025, establishes the country’s first comprehensive regulatory framework for both commercial private security service providers and companies that employ in-house security personnel. The framework applies to both Myanmar and foreign entities. For foreign investors and multinational operators, the new regime introduces strict licensing requirements, local content rules, and various approvals that must be carefully considered as part of business planning and compliance processes.

Regulatory Authority and Structure

The governing authority under the Private Security Services Law is the Private Security Services Central Supervisory Committee, formed with the minister of the Ministry of Home Affairs (MOHA) as chairperson, the chief of the Myanmar Police Force as vice-chairperson, and members from other high-ranking officials from relevant ministries, such as Transport and Communications, Defense, Planning and Finance, Investment and Foreign Economic Relations, Legal Affairs, Immigration and Population, Labor, and Commerce.

This Central Committee is the highest regulatory authority and has the power to adopt policies, approve or reject applications for licenses and permits, and decide appeals against administrative actions taken by Supervisory Committees, which operate under the Central Committee at the state and regional level. They are responsible for processing applications, verifying compliance with statutory requirements, submitting applications to the Central Committee with remarks, and issuing licenses and permits once approved. Supervisory Committees also monitor compliance by license or permit holders and impose administrative penalties for noncompliance, while the Central Committee exercises final decision-making authority.

License Requirements for Security Service Providers

To apply for a private security services license, companies must be registered under the Myanmar Companies Law. Foreign companies may also operate a private security services business in Myanmar, subject to compliance with applicable legal and regulatory requirements.

Foreign companies must maintain a minimum fixed deposit equivalent to MMK 100 million (approximately USD 47,619 at the Central Bank of Myanmar’s official exchange rate of MMK 2,100 per USD 1) in foreign currency with Myanma Economic Bank and demonstrate that their operations do not adversely affect state security or the rule of law. Licenses are valid for three years and must be renewed at least three months before expiry.

Foreign-owned license applicants must also disclose:

  • The number of Myanmar and foreign security personnel
  • Qualifications of foreign personnel

Foreign companies must also comply with the rules regarding criteria for both Myanmar and foreign security staff.

Permit Requirements for In-House Security

While licenses are required for private providers of security services, businesses that employ their own in-house security teams of more than 10 personnel must instead get separate permits for doing so. Businesses operating factories, hotels, retail stores, logistics operations, oil and gas sites, and similar premises—including foreign entities—must obtain a permit if they employ more than 10 private security personnel internally.

Security personnel covered by a permit may work only on the permit holder’s own premises, preventing group companies from pooling or cross-assigning security staff. This restriction is particularly relevant to foreign operations managing multiple entities in Myanmar.

Operational and Compliance Obligations

Both license holders and permit holders must ensure the use of only approved uniforms, insignia, and equipment and must maintain strict confidentiality of all client and business information. They are also responsible for ensuring that all employed security personnel comply with applicable laws and regulations.

Furthermore, proper authorization is required for the handling of any arms or ammunition, and prior approval of training courses, trainers, and training facilities must be obtained under the supervision and monitoring of the relevant department or ministry. Noncompliance may result in warnings, administrative fines, suspension or cancellation of a license or permit, and blacklisting from future applications. Criminal penalties may also apply.

Closing Thoughts

Maintaining the security of operations is an important consideration for businesses present in the Myanmar market. The Private Security Services Law is important for both local and foreign businesses to understand, as it introduces a framework that demands careful attention to licensing, operational protocols, and compliance. Given the complexity and evolving nature of the regulations, engaging knowledgeable local counsel is invaluable for ensuring compliance and mitigating risk, allowing businesses to focus on their core operations with greater confidence.

RELATED INSIGHTS​ 

March 31, 2026
Thailand’s Office of the Consumer Protection Board has opened a public hearing period on draft regulations governing the transfer of direct sales and direct marketing businesses. The draft Notification of the Direct Sales and Direct Marketing Committee: Criteria and Procedures for Business Transfer and Amendment of Registration for Direct Sales or Direct Marketing Businesses establishes a compliance-focused process with strict documentation requirements and timelines for transferring direct sales and direct marketing businesses. The proposed framework also defines the roles of transferors and transferees and establishes application procedures with the Office of the Consumer Protection Board. Applications may be submitted in person or electronically and will be examined to confirm they are complete, authentic, and compliant with legal requirements. This includes verification that: The transferee meets all required qualifications; No disqualifying factors apply; and The applicant is not subject to legal restrictions. The public hearing period is open until April 29, 2026. Direct sales and direct marketing business operators should prepare for these proposed requirements to ensure compliant implementation once the regulations are finalized.
March 27, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has publicly indicated that it is preparing a new regulatory framework for data center operators that may introduce foreign-ownership restrictions. In particular, the NBTC is considering reclassifying data center operations from a type 1 telecommunications business license to a type 3 license. If implemented, this change would subject data center operators to a significantly more stringent regulatory regime, especially in relation to foreign ownership and control. The NBTC has indicated that it intends to propose a draft framework to the NBTC board. This would be followed by a public hearing process, with a view to implementing the new rules within 2026. Under the Telecommunications Business Act B.E. 2544 (2001), as amended, telecommunications businesses operating under type 3 licenses are subject to foreign ownership restrictions, including a requirement that less than 50% of the total issued shares be held by foreign shareholders. In addition, type 3 licensees are subject to foreign dominance restrictions, which prohibit arrangements that allow foreigners to dominate the business. These foreign dominance restrictions are broad in scope and may capture various forms of direct and indirect control or influence. This includes circumstances in which a foreign national is able to influence or control the formulation of policy, management, or business operations, or the appointment of directors or senior executives. At this stage, the exact scope of the proposed rules remains unclear. Businesses with existing or planned data center operations in Thailand should therefore monitor upcoming NBTC developments in this regard and prepare for the expected public hearing process.
March 23, 2026
In March 2026, the Myanmar Investment Commission (MIC) introduced two regulatory updates affecting investors planning new investments or implementing MIC-approved projects. Minimum Investment Conditions for Tax Incentives MIC Notification No. 1/202 clarifies the minimum conditions for investments in promoted sectors to qualify for tax exemptions or relief under the Myanmar Investment Law. The notification establishes the following requirements: Investors must contribute at least 35% of the total investment amount in cash, as reflected in the relevant proposal or endorsement application. Where an investment involves a foreign loan, the investor must obtain approval from the Central Bank of Myanmar, together with a loan repayment schedule, and provide evidence that both the foreign loan proceeds and the capital contribution have been remitted in cash through an authorized dealer bank. Chinese Yuan Accepted for Investment Capital The MIC also issued Investment News Bulletin No. 1/2026, confirming that Chinese yuan (CNY) is now accepted as foreign investment capital for applications for MIC permits and endorsements, in addition to US dollars (USD). Investment funds contributed in CNY may be remitted through banks authorized to deal in foreign currency in CNY, following the same process currently applied to investments made in USD. These developments may affect how foreign investment capital is structured and remitted, as well as the availability of tax incentives for investments under the MIC framework.
March 20, 2026
Thailand’s Board of Investment (BOI) now requires data center projects to demonstrate measurable benefits for local workforce development, R&D, SME capability, and domestic supply chains to qualify for corporate income tax (CIT) exemptions. BOI Notification No. Por. 3/2569, issued on February 6, 2026, updates the requirements for projects seeking promotion under BOI category 8.2.1 (data centers). All data center projects must now submit and implement plans covering development of Thai human resources and domestic supply chain support before benefiting from any CIT exemption. Human Resources Development Plan The BOI seeks to promote local talent development beyond basic training. Plans must include the following elements: Training for data center design, construction, and operations targeting vocational students, engineering and ICT undergraduates and postgraduates, and energy and building personnel in Thailand. Joint curricula with Thai universities and technical institutes. Collaborative R&D with Thai nationals or institutions in areas including AI, resource allocation, high-performance computing, and data center hardware and systems. Thai SME upskilling in electrical and energy systems and IT services. Domestic Supply Chain Support Plan Plans must demonstrate knowledge transfer in design, construction, cooling, security, and power and water management. Projects must also include usage or installation of domestically manufactured equipment or engage specialist domestic entities. Criteria for BOI Evaluation The BOI will assess data center operators’ eligibility for CIT incentives based on two criteria: Scale requirement: Training and joint-curriculum initiatives must reach a total participants equal to at least 10 times the project headcount and run for the duration of the CIT incentive. If this threshold is not met, the applicant must also implement continuous R&D or SME skills-development plans throughout the incentive period. Substantiality test: Supply-chain plans must be substantive, meet industry standards, and show measurable development of the domestic digital and data center supply base. To ensure compliance,