🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
KH · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 5 sources retrieved model claude-sonnet-5 ·

Cambodia

KH schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 21 claims · 5 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
21Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No comprehensive data protection law is currently in force; the draft LPDP is pre-enactment and provides no binding rights or obligations yet.

Primary frameworkDraft Law on Personal Data Protection (LPDP) — not yet enacted
Supervisory authorityMinistry of Post and Telecommunications (MPTC)
Traffic-light rationale — RedNo comprehensive data protection law is currently in force; the draft LPDP is pre-enactment and provides no binding rights or obligations yet.

Sub-modules (5)

Regulator And AuthorityAmber

The MPTC is the ministry drafting and administering the LPDP and is expected to appoint inspectors with judicial police status to enforce it once the law is passed; no dedicated independent DPA currently exists.

Claims: CLM-KH-a1b2c3d4

Act And InstrumentsRed

The LPDP is Cambodia's first comprehensive draft data protection framework; it remains unenacted.

Claims: CLM-KH-e5f6a7b8

Material ScopeAmber

The draft LPDP defines personal data broadly and enumerates sensitive/special categories including biometric and genetic data.

Claims: CLM-KH-c9d0e1f2

Territorial ScopeAmber

The draft LPDP is designed to apply extraterritorially to foreign entities offering goods or services to Cambodian residents, mirroring GDPR Art 3.

Claims: CLM-KH-a3b4c5d6

Regulator Registration And FilingRed

No registration or filing regime is currently operative for Cambodia; the draft law's registration/filing mechanics (if any) have not been confirmed in available secondary sources.

Absence provenance: not recorded. Searched: Cambodia data controller registration requirement, MPTC personal data controller filing.

Category narrative85 words

Cambodia has no comprehensive, enacted data protection statute in force. The Ministry of Post and Telecommunications (MPTC) unveiled a draft Law on Personal Data Protection (LPDP) that, if passed, would be Cambodia's first omnibus privacy framework, but as of the most recent reporting it remains a draft with no confirmed enactment or grace-period start date. In the interim, data-related obligations arise only incidentally from adjacent instruments such as the 2019 E-Commerce Law and the Law on Telecommunications, neither of which constitutes a GDPR-equivalent omnibus regime.

Sources and claims (4)
  1. ProbableOneTrust DataGuidanceUnder the draft LPDP, MPTC-appointed inspectors would hold judicial police status and be responsible for oversight, investigation, and suppression of data-related offenses.
  2. ConfirmedOneTrust DataGuidanceCambodia's PDP Law remains a draft, with the MPTC continuing to describe it as a 'Draft Law on Personal Data Protection' and no official enactment or grace-period start date announced.
  3. ConfirmedIAPPThe draft LPDP defines personal data broadly as information relating to an identifiable natural person, with sensitive personal data including biometric and genetic data, health status, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and sexual orientation.
  4. ConfirmedOneTrust DataGuidanceThe draft LPDP applies to data processing in Cambodia and to overseas processing related to Cambodian residents, with specific exclusions for public authorities and personal activities.

#

All lawful-basis and special-category content derives from a pre-enactment draft; nothing is currently in force.

Primary frameworkDraft LPDP — not yet enacted
Supervisory authorityMinistry of Post and Telecommunications (MPTC)
Traffic-light rationale — RedAll lawful-basis and special-category content derives from a pre-enactment draft; nothing is currently in force.

Sub-modules (4)

Lawful BasesAmber

The draft LPDP establishes lawful bases for processing including consent, contractual necessity, legal obligation, and legitimate interests.

Claims: CLM-KH-f7a8b9c0

Special CategoriesAmber

The draft LPDP enumerates an unusually broad sensitive-data category, including a genetic-data definition wider than the GDPR's.

Claims: CLM-KH-b1c2d3e4

Pseudonymisation And AnonymisationRed

No pseudonymisation or anonymisation safe-harbour provisions for Cambodia were identified in available sources.

Absence provenance: not recorded. Searched: Cambodia LPDP pseudonymisation anonymisation definition.

Category narrative40 words

The draft LPDP proposes a GDPR-style set of lawful bases and a broad definition of special/sensitive categories, but none of this is currently binding law. No enacted Cambodian statute presently codifies lawful-basis or consent standards for general personal data processing.

Sources and claims (2)
  1. ConfirmedIAPPThe draft LPDP requires establishing a lawful basis for processing — consent, contractual necessity, legal obligation, legitimate interests, among others.
  2. ConfirmedIAPPUnlike the GDPR's precise genetic-data definition limited to physiological or health contexts, Cambodia's draft LPDP covers all genetic data linked to identity or characteristics.

#

Rights framework exists only in draft form; no binding rights are currently enforceable.

Primary frameworkDraft LPDP — not yet enacted
Supervisory authorityMinistry of Post and Telecommunications (MPTC)
Traffic-light rationale — RedRights framework exists only in draft form; no binding rights are currently enforceable.

Sub-modules (5)

Access RightAmber

The draft LPDP includes an access right among the data-subject rights.

Claims: CLM-KH-d5e6f7a8

Rectification And ErasureAmber

Rectification and erasure rights are included in the draft LPDP's rights suite.

Claims: CLM-KH-d5e6f7a8

Restriction And ObjectionAmber

Restriction and objection rights are included in the draft LPDP's rights suite.

Claims: CLM-KH-d5e6f7a8

Data PortabilityAmber

A portability right is included in the draft LPDP's rights suite.

Claims: CLM-KH-d5e6f7a8

Deadlines And Response WindowsRed

Secondary sources confirm the draft prescribes specific response timelines for data-subject requests, but the exact number of days has not been confirmed in available materials.

Absence provenance: not recorded. Searched: Cambodia LPDP data subject request deadline days, Cambodia draft PDP law response timeline.

Category narrative38 words

The draft LPDP proposes a GDPR-familiar suite of data-subject rights, but these carry no current legal force since the law has not been enacted. No existing Cambodian statute grants a general subject-access or erasure right outside the draft.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceThe draft LPDP's data subject rights include access, rectification, erasure, restriction, portability, and objection, with specific timelines for responses.

#

All accountability, DPO, ROPA, security, and breach-notification content is drawn from a pre-enactment draft.

Primary frameworkDraft LPDP — not yet enacted
Supervisory authorityMinistry of Post and Telecommunications (MPTC)
Traffic-light rationale — RedAll accountability, DPO, ROPA, security, and breach-notification content is drawn from a pre-enactment draft.

Sub-modules (7)

Accountability And DpiaAmber

The draft LPDP requires DPIAs for high-risk processing operations.

Claims: CLM-KH-c1d2e3f4

Dpo RequirementsAmber

The draft LPDP mandates a certified DPO for all controllers and processors regardless of size or processing severity, a stricter approach than GDPR's threshold-based DPO trigger.

Claims: CLM-KH-a5b6c7d8

Ropa RequirementsAmber

The draft LPDP requires maintaining detailed records of processing.

Claims: CLM-KH-e9f0a1b2

Joint Controller ArrangementsRed

No provisions on joint-controller arrangements were identified in available sources on the draft LPDP.

Absence provenance: not recorded. Searched: Cambodia LPDP joint controller processor arrangement.

Security MeasuresAmber

The draft LPDP requires implementing appropriate technical and organizational measures.

Claims: CLM-KH-c3d4e5f6

Breach NotificationAmber

The draft LPDP mandates breach notifications to the regulator and affected individuals and requires DPIA submissions and appointment of overseas representatives for cross-border activity.

Claims: CLM-KH-a7b8c9d0

Retention And DisposalRed

No specific retention-limit or disposal-duty provisions for Cambodia were identified in available sources.

Absence provenance: not recorded. Searched: Cambodia LPDP data retention limit disposal.

Category narrative43 words

The draft LPDP would impose GDPR-familiar controller/processor duties — DPIAs, DPO appointment (mandatory and universal, unlike GDPR's risk-based trigger), records of processing, security measures, and breach notification — but none of these obligations are currently binding since the statute has not been enacted.

Sources and claims (5)
  1. ConfirmedIAPPThe draft LPDP requires conducting data protection impact assessments for high-risk operations.
  2. ConfirmedIAPPThe draft LPDP's mandatory appointment of a certified data protection officer applies to all controllers and processors regardless of size or severity of their processing.
  3. ConfirmedIAPPThe draft LPDP requires maintaining detailed records of processing.
  4. ConfirmedIAPPThe draft LPDP requires implementing appropriate technical and organizational measures.
  5. ConfirmedOneTrust DataGuidanceThe draft LPDP includes GDPR-familiar duties covering mandatory breach notifications, DPIA submissions, and the appointment of overseas representatives.

#

No binding transfer mechanism, adequacy status, or localisation mandate is currently in force.

Primary frameworkDraft LPDP — not yet enacted
Supervisory authorityMinistry of Post and Telecommunications (MPTC)
Traffic-light rationale — RedNo binding transfer mechanism, adequacy status, or localisation mandate is currently in force.

Sub-modules (6)

Transfer MechanismsAmber

The draft LPDP requires following strict procedures for cross-border transfers and appointing overseas representatives.

Claims: CLM-KH-e1f2a3b4

Adequacy ReceivedRed

No adequacy decision recognizing Cambodia has been identified.

Absence provenance: not recorded. Searched: Cambodia adequacy decision received GDPR EU.

Adequacy GrantedRed

Cambodia has not granted adequacy status to any other jurisdiction, as no comprehensive DP regime yet exists to issue such determinations.

Absence provenance: not recorded. Searched: Cambodia adequacy decision granted to foreign jurisdiction.

Sccs And BcrsRed

No standard contractual clauses or binding corporate rules framework specific to Cambodia was identified.

Absence provenance: not recorded. Searched: Cambodia LPDP standard contractual clauses BCR.

Transfer Impact AssessmentRed

No transfer impact assessment requirement specific to Cambodia was identified.

Absence provenance: not recorded. Searched: Cambodia transfer impact assessment requirement.

Data LocalisationRed

No confirmed data-localisation mandate for Cambodia was identified in available sources.

Absence provenance: not recorded. Searched: Cambodia data localisation requirement personal data.

Category narrative38 words

The draft LPDP proposes cross-border transfer restrictions and an overseas-representative requirement, but no enacted transfer regime, adequacy determination, or localisation mandate currently applies to Cambodia. Cambodia has neither received nor granted any adequacy decision identified in available sources.

Sources and claims (1)
  1. ProbableIAPPThe draft LPDP requires controllers to follow strict procedures for cross-border transfers of personal data and to appoint overseas representatives where applicable.

#

No sector-specific overlay content could be confirmed for KH beyond the bare existence of a Telecommunications Law.

Traffic-light rationale — RedNo sector-specific overlay content could be confirmed for KH beyond the bare existence of a Telecommunications Law.

Sub-modules (7)

Financial Sector OverlayRed

No Cambodia-specific financial-sector data-protection overlay was identified.

Absence provenance: not recorded. Searched: Cambodia banking secrecy law personal data, Cambodia financial sector data protection overlay.

Health Sector OverlayRed

No Cambodia-specific health-sector data-protection overlay was identified.

Absence provenance: not recorded. Searched: Cambodia health data protection law hospital records.

Telecoms And EprivacyAmber

Cambodia's Law on Telecommunications is referenced as an existing enacted statute in official EU documentation, but no dedicated ePrivacy/cookie-consent regime equivalent to the EU ePrivacy Directive was confirmed.

Claims: CLM-KH-f5a6b7c8

Employment DataRed

No Cambodia-specific employment-data overlay was identified.

Absence provenance: not recorded. Searched: Cambodia employment data protection labor law privacy.

Credit And ScoringRed

No Cambodia-specific credit-scoring data rules were identified.

Absence provenance: not recorded. Searched: Cambodia credit scoring data protection rules.

EducationRed

No Cambodia-specific education-sector data rules were identified.

Absence provenance: not recorded. Searched: Cambodia education sector student data protection.

InsuranceRed

No Cambodia-specific insurance-sector data rules were identified.

Absence provenance: not recorded. Searched: Cambodia insurance sector data protection rules.

Category narrative61 words

No confirmed Cambodia-specific sectoral overlay (financial, health, telecoms/ePrivacy, employment, credit, education, or insurance) displacing or supplementing a general DP regime was identified, since no general DP regime is yet in force. Cambodia's existing Law on Telecommunications is referenced in EU official documentation as part of the domestic legal framework, but its specific data-confidentiality content could not be confirmed from available sources.

Sources and claims (1)
  1. UncertainEUR-LexCambodia's Law on Telecommunications is identified in official EU documentation as one of Cambodia's enacted statutes forming part of the domestic legal framework, though its specific data-confidentiality obligations were not confirmed in available sources.

#

No adtech/commercial-privacy content specific to KH was located.

Traffic-light rationale — RedNo adtech/commercial-privacy content specific to KH was located.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent regime for Cambodia was identified.

Absence provenance: not recorded. Searched: Cambodia cookie consent law, Cambodia LPDP cookies trackers.

Dark PatternsRed

No dark-pattern prohibition for Cambodia was identified.

Absence provenance: not recorded. Searched: Cambodia dark patterns consumer protection law.

Opt Out SignalsRed

No recognition of Global Privacy Control or similar opt-out signals for Cambodia was identified.

Absence provenance: not recorded. Searched: Cambodia Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No clean-room / data-collaboration-room rules for Cambodia were identified.

Absence provenance: not recorded. Searched: Cambodia data clean room regulation.

Cross Context AdvertisingRed

No cross-context-advertising (sale/share) rules for Cambodia were identified.

Absence provenance: not recorded. Searched: Cambodia cross context advertising data sale share.

Direct MarketingRed

No direct-marketing consent/suppression regime specific to Cambodia was identified.

Absence provenance: not recorded. Searched: Cambodia direct marketing consent suppression rules.

Category narrative49 words

No Cambodia-specific cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rules, cross-context advertising rules, or direct-marketing consent/suppression regime was identified in available sources. Sectoral prescriptions for advertising referenced in regional trade-press coverage relate to other ASEAN jurisdictions (e.g., Vietnam), not Cambodia, and are excluded here to avoid JID misattribution.

#

Biometric/genetic classification exists only in draft form; the surveillance-related sub-decree is unimplemented, and ADM/AI-specific governance is absent.

Primary frameworkDraft LPDP — not yet enacted
Supervisory authorityMinistry of Post and Telecommunications (MPTC)
Traffic-light rationale — AmberBiometric/genetic classification exists only in draft form; the surveillance-related sub-decree is unimplemented, and ADM/AI-specific governance is absent.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction provisions specific to Cambodia were identified.

Absence provenance: not recorded. Searched: Cambodia LPDP profiling restriction Article 22 analogue.

Automated Decision Making TransparencyRed

No ADM-transparency or explanation-right provisions specific to Cambodia were identified.

Absence provenance: not recorded. Searched: Cambodia automated decision making transparency law.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime for Cambodia was identified.

Absence provenance: not recorded. Searched: Cambodia AI risk assessment law regulation.

Biometric RegimeAmber

The draft LPDP classifies biometric data as a sensitive personal data category requiring heightened protection.

Claims: CLM-KH-b9c0d1e2

Genetic DataAmber

The draft LPDP's genetic-data definition covers all genetic data linked to identity or characteristics, broader than GDPR's health-context-limited definition.

Claims: CLM-KH-d3e4f5a6

State Surveillance CarveoutsAmber

The draft LPDP exempts public authorities performing official duties from its scope; separately, a National Internet Gateway sub-decree approved in February 2021 raised online-surveillance/censorship risks but had not been implemented as of the most recent official reporting reviewed.

Claims: CLM-KH-a9b0c1d2, CLM-KH-e3f4a5b6

Category narrative65 words

The draft LPDP would classify biometric and genetic data as sensitive personal data, with the latter defined more broadly than under GDPR. Public authorities performing official duties are exempted from the draft's scope. A National Internet Gateway sub-decree approved in February 2021 raises surveillance concerns but has not been implemented, per official EU reporting. No profiling-restriction, ADM-transparency, or AI-risk-assessment regime specific to Cambodia was identified.

Sources and claims (4)
  1. ConfirmedIAPPThe draft LPDP's sensitive personal data category includes biometric and genetic data alongside health status, racial/ethnic origin, political opinions, religious beliefs, trade union membership, and sexual orientation.
  2. ConfirmedIAPPCambodia's draft LPDP covers all genetic data linked to identity or characteristics, unlike the GDPR's more precise genetic-data definition limited to specific physiological or health contexts.
  3. ConfirmedIAPPThe draft LPDP exempts natural persons acting in a personal capacity and public authorities performing official duties from its scope.
  4. ProbableEUR-LexA Cambodian government sub-decree on a National Internet Gateway, approved in February 2021, increased the risk for online censorship and surveillance but had not been implemented as of the most recent official EU reporting reviewed.

#

No children/vulnerable-groups content specific to KH was located in any reviewed source.

Traffic-light rationale — RedNo children/vulnerable-groups content specific to KH was located in any reviewed source.

Sub-modules (5)

Age VerificationRed

No age-of-consent or age-verification provisions for Cambodia were identified.

Absence provenance: not recorded. Searched: Cambodia age of consent data processing minors, Cambodia LPDP children data provisions.

Minor Profiling BansRed

No minor-profiling ban for Cambodia was identified.

Absence provenance: not recorded. Searched: Cambodia minor profiling ban children.

Education SettingsRed

No education-settings-specific data rules for Cambodia were identified.

Absence provenance: not recorded. Searched: Cambodia education settings student data rules.

Dependent AdultsRed

No dependent-adult data protections for Cambodia were identified.

Absence provenance: not recorded. Searched: Cambodia dependent adult elderly data protection.

Category narrative36 words

No Cambodia-specific provisions on age of consent for data processing, parental-consent mechanisms, minor-profiling bans, education-setting-specific rules, or dependent-adult protections were identified in available sources, whether in the draft LPDP summaries reviewed or in existing sectoral law.

#

No enforcement powers, penalties, or redress mechanisms are currently in force; all content is drawn from a pre-enactment draft.

Primary frameworkDraft LPDP — not yet enacted
Supervisory authorityMinistry of Post and Telecommunications (MPTC)
Traffic-light rationale — RedNo enforcement powers, penalties, or redress mechanisms are currently in force; all content is drawn from a pre-enactment draft.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The draft LPDP proposes MPTC-appointed inspectors with judicial police status, empowered to enforce the law including oversight, investigation, and suppression of data-related offenses, with penalties including fines and imprisonment for repeated offenses.

Claims: CLM-KH-f9a0b1c2

Enforcement Activity IndexRed

No enforcement activity exists since no comprehensive law is in force.

Absence provenance: not recorded. Searched: Cambodia data protection enforcement action fine 2025 2026.

Regulator Funding And CapacityRed

No confirmed funding or headcount data for a Cambodian DP regulator was identified, since no dedicated DPA yet exists.

Absence provenance: not recorded. Searched: Cambodia MPTC data protection office funding headcount.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism for data protection matters in Cambodia was identified.

Absence provenance: not recorded. Searched: Cambodia class action data protection collective redress.

Private Right Of ActionRed

No confirmed private right of action for data protection violations in Cambodia was identified.

Absence provenance: not recorded. Searched: Cambodia private right of action data protection court.

Recent Developments 180DAmber

As of the most recent reporting reviewed (dated late May 2026), Cambodia's LPDP remains at draft stage; a September 2025 MPTC-led seminar indicated the law would likely be passed within the following twelve months, with a two-year transition period from promulgation before full effect.

Claims: CLM-KH-c5d6e7f8, CLM-KH-e7f8a9b0

Category narrative87 words

Because no comprehensive DP statute is in force, there is currently no operative enforcement regime, penalty schedule, enforcement activity, or redress mechanism for general data protection in Cambodia. The draft LPDP proposes MPTC-appointed inspectors with judicial police status and penalties including fines and imprisonment for repeat offenses, but this is not yet binding. The most recent 180-day development is continued draft status reported as of late May 2026, with expectation (as of a September 2025 legal-industry seminar) that the law would be passed within roughly twelve months.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceMPTC-appointed inspectors under the draft LPDP would have judicial police status and be responsible for enforcing the law, including oversight, investigation, and suppression of data-related offenses, with penalties including fines and imprisonment for repeated offenses.
  2. ProbableOneTrust DataGuidanceCambodia's PDP Law was, as of a September 2025 MPTC-led seminar, expected to be passed within the next 12 months, with a two-year transition period from promulgation.
  3. UncertainIAPPAs of the most recent regional trade-press reporting reviewed, the LPDP's full effect is tentatively projected for later in the reporting year or early the following year, following a two-year rehabilitation/transition period after promulgation.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Cambodia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 21 claim(s), 5 source(s) in the cumulative register.