{
 "jurisdiction_id": "MM",
 "jurisdiction": "Myanmar",
 "url": "https://dataprotection.gi/jurisdictions/myanmar/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 16,
  "sub_modules": 57,
  "source_register": 4
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "red",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/myanmar/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "No comprehensive DP statute and no general supervisory authority exist; regulatory coverage is fragmented and sector-driven.",
   "claims": [
    {
     "statement": "Myanmar has no general/omnibus data protection authority; regulatory oversight of personal data is fragmented across sectoral ministries and regulators.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/myanmar?article_type=news_post",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Constitution of the Republic of the Union of Myanmar 2008 and the Law Protecting the Privacy and Security of Citizens (Union Parliament Law 5/2017), as amended in 2020, provide the principal non-comprehensive statutory basis for privacy and communications-security protection in Myanmar.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/myanmar?article_type=news_post",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The amended Electronic Transactions Law (State Administration Council Law 7/2021), effective 15 February 2021, introduced provisions on the protection of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/myanmar?article_type=news_post",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Myanmar's Cybersecurity Law, enacted in 2025, entered into force on 30 July 2025 and introduces a licensing regime for cybersecurity-service providers and digital-platform operators, together with mandatory Ministry approval for VPN use.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-check-up-reveals-new-prescriptions-for-compliance",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In the absence of a unitary omnibus definition, the material scope of personal-data protection in Myanmar is delineated through sector-specific statutes, including the Telecommunications Law 2013 and the Financial Institutions Law 2016.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/myanmar?article_type=news_post",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No general controller-registration or filing regime exists in Myanmar in the absence of an omnibus data protection law or general regulator.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/myanmar?article_type=news_post",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/myanmar/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No lawful-bases, consent, special-category, or anonymisation regime found across searched sources.",
   "claims": []
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/myanmar/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No omnibus data-subject-rights regime exists; the Privacy Law addresses communications privacy but not GDPR-style subject rights.",
   "claims": []
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "red",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/myanmar/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Only a narrow sectoral security duty exists; no general controller/processor accountability framework is in force.",
   "claims": [
    {
     "statement": "Myanmar's Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific security-of-processing obligation in the absence of a general security-measures regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/myanmar?article_type=news_post",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In the absence of a general data protection statute, Myanmar imposes no general-purpose DPIA, DPO-appointment, ROPA, or breach-notification obligations on controllers outside the sectoral financial-institution security duty.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/myanmar?article_type=news_post",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/myanmar/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No cross-border transfer mechanism, adequacy arrangement, or localisation statute identified.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/myanmar/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Meaningful sectoral coverage exists for financial and telecoms/cyber, but health, employment, credit-scoring, education, and insurance sub-modules are unpopulated.",
   "claims": [
    {
     "statement": "The Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific overlay in the absence of an omnibus data protection statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/myanmar?article_type=news_post",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Telecommunications Law 2013 addresses the confidentiality of personal information handled by telecommunications service providers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/myanmar?article_type=news_post",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Myanmar's 2025 Cybersecurity Law imposes Ministry-approval licensing requirements on VPN use and on cybersecurity-service and digital-platform operators exceeding 100,000 users, with licenses valid for three to ten years and criminal penalties for non-compliance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-check-up-reveals-new-prescriptions-for-compliance",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/myanmar/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No adtech/commercial-privacy regulation identified in any searched source.",
   "claims": []
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/myanmar/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "The only substantive content in this module concerns broadened state-surveillance carve-outs; ADM, biometric, genetic, and AI-risk-assessment sub-modules are unpopulated.",
   "claims": [
    {
     "statement": "The 2020 amendment to the Law Protecting the Privacy and Security of Citizens narrowed Section 8 so that its prohibitions on government interference apply specifically to 'competent authorities' acting without an order, permission, or warrant from the President or Union Government, rather than to persons generally.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/myanmar-parliament-amends-privacy-law-narrows-prosecutions-under-article-10",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The 2020 amendment narrowed criminal liability under Section 10 of the Privacy Law so that it applies specifically to 'competent authorities' who commit offences under Sections 7 or 8, rather than to persons generally.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/myanmar-parliament-amends-privacy-law-narrows-prosecutions-under-article-10",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/myanmar/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "No children/vulnerable-groups data protection regime identified.",
   "claims": []
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "red",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/myanmar/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers are narrow, sector/criminal-law based, and there is no dedicated DP regulator, enforcement-activity index, or private right of action.",
   "claims": [
    {
     "statement": "Under the Law Protecting the Privacy and Security of Citizens, violations of Sections 7 or 8 are punishable by imprisonment of between six months and three years and a fine of between MMK 300,000 and MMK 1.5 million, with liability narrowed by the 2020 amendment to 'competent authorities' who commit such violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/myanmar-parliament-amends-privacy-law-narrows-prosecutions-under-article-10",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Myanmar's 2025 Cybersecurity Law provides criminal penalties for operating unlicensed cybersecurity services or digital platforms and for unauthorized VPN use.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-check-up-reveals-new-prescriptions-for-compliance",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No material Myanmar data-protection or cybersecurity regulatory development has been identified within the 180 days preceding this run; the most recent substantive development remains the 30 July 2025 entry into force of the Cybersecurity Law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-check-up-reveals-new-prescriptions-for-compliance",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}