🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
MM · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 4 sources retrieved model claude-sonnet-5 ·

Myanmar

MM schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 16 claims · 4 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
16Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No comprehensive DP statute and no general supervisory authority exist; regulatory coverage is fragmented and sector-driven.

Primary frameworkNo omnibus data protection statute; operative instruments are the Law Protecting the Privacy and Security of Citizens (Union Parliament Law 5/2017, amended 2020), the amended Electronic Transactions Law (SAC Law 7/2021), and the Cybersecurity Law (2025).
Traffic-light rationale — RedNo comprehensive DP statute and no general supervisory authority exist; regulatory coverage is fragmented and sector-driven.

Sub-modules (5)

Regulator And AuthorityRed

There is no general data protection authority in Myanmar; oversight functions are dispersed across the Ministry of Transport and Communications (cybersecurity/telecoms), the Central Bank of Myanmar (financial-sector customer data), and general law-enforcement/judicial bodies for privacy-law offences.

Claims: CLM-MM-1a2b3c4d

Act And InstrumentsAmber

The principal instruments are the 2017/2020 Privacy Law, the 2021-amended Electronic Transactions Law, and the 2025 Cybersecurity Law.

Claims: CLM-MM-2b3c4d5e, CLM-MM-3c4d5e6f, CLM-MM-4d5e6f7a

Material ScopeAmber

Material scope of personal-data protection is defined sector-by-sector rather than through a unitary definition.

Claims: CLM-MM-5e6f7a8b

Territorial ScopeRed

No explicit extraterritorial/territorial-scope provision applicable to non-established controllers has been identified in currently available secondary sources.

Absence provenance: not recorded. Searched: not recorded.

Regulator Registration And FilingRed

No general controller registration or filing regime exists absent an omnibus statute or general regulator.

Claims: CLM-MM-7a8b9c0d

Category narrative105 words

Myanmar has no omnibus data protection statute and no dedicated general data protection authority. Privacy-related obligations instead arise from a patchwork of the 2008 Constitution, the Law Protecting the Privacy and Security of Citizens (2017, amended 2020), the amended Electronic Transactions Law (2021), and the newly enacted Cybersecurity Law (2025, effective 30 July 2025), overlaid with sectoral statutes (Telecommunications Law 2013, Financial Institutions Law 2016). A January 2023 draft cybersecurity bill previously circulated by the Ministry of Transport and Communications appears to have culminated in the 2025 Cybersecurity Law, though independent confirmation of textual continuity between the draft and the enacted law was not obtained.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceMyanmar has no general/omnibus data protection authority; regulatory oversight of personal data is fragmented across sectoral ministries and regulators.
  2. ConfirmedOneTrust DataGuidanceThe Constitution of the Republic of the Union of Myanmar 2008 and the Law Protecting the Privacy and Security of Citizens (Union Parliament Law 5/2017), as amended in 2020, provide the principal non-comprehensive statutory basis for privacy and communications-security protection in Myanmar.
  3. ConfirmedOneTrust DataGuidanceThe amended Electronic Transactions Law (State Administration Council Law 7/2021), effective 15 February 2021, introduced provisions on the protection of personal data.
  4. ProbableIAPPMyanmar's Cybersecurity Law, enacted in 2025, entered into force on 30 July 2025 and introduces a licensing regime for cybersecurity-service providers and digital-platform operators, together with mandatory Ministry approval for VPN use.
  5. ConfirmedOneTrust DataGuidanceIn the absence of a unitary omnibus definition, the material scope of personal-data protection in Myanmar is delineated through sector-specific statutes, including the Telecommunications Law 2013 and the Financial Institutions Law 2016.
  6. ConfirmedOneTrust DataGuidanceNo general controller-registration or filing regime exists in Myanmar in the absence of an omnibus data protection law or general regulator.

#

No lawful-bases, consent, special-category, or anonymisation regime found across searched sources.

Traffic-light rationale — RedNo lawful-bases, consent, special-category, or anonymisation regime found across searched sources.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful bases regime identified.

Absence provenance: not recorded. Searched: not recorded.

Special CategoriesRed

No special/sensitive-category data regime identified.

Absence provenance: not recorded. Searched: not recorded.

Pseudonymisation And AnonymisationRed

No pseudonymisation/anonymisation definitions or safe-harbours identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative32 words

No enumerated lawful-basis framework, consent-standard regime, special/sensitive-category classification, or statutory pseudonymisation/anonymisation safe-harbour was identified for Myanmar. This module is emitted as a gap module consistent with the absence of an omnibus statute.

#

No omnibus data-subject-rights regime exists; the Privacy Law addresses communications privacy but not GDPR-style subject rights.

Traffic-light rationale — RedNo omnibus data-subject-rights regime exists; the Privacy Law addresses communications privacy but not GDPR-style subject rights.

Sub-modules (5)

Access RightRed

No general right of access to personal data identified.

Absence provenance: not recorded. Searched: not recorded.

Rectification And ErasureRed

No general rectification/erasure right identified.

Absence provenance: not recorded. Searched: not recorded.

Restriction And ObjectionRed

No restriction/objection right (including profiling opt-out) identified.

Absence provenance: not recorded. Searched: not recorded.

Data PortabilityRed

No portability right identified.

Absence provenance: not recorded. Searched: not recorded.

Deadlines And Response WindowsRed

No statutory controller-response deadlines identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative27 words

No general subject-access, rectification/erasure, restriction/objection, portability, or statutory response-deadline framework was identified for data subjects in Myanmar outside the narrow privacy/communications-security protections of the 2017/2020 Privacy Law.

#

Only a narrow sectoral security duty exists; no general controller/processor accountability framework is in force.

Primary frameworkFinancial Institutions Law 2016 (sectoral security-of-customer-information duty only).
Traffic-light rationale — RedOnly a narrow sectoral security duty exists; no general controller/processor accountability framework is in force.

Sub-modules (7)

Accountability And DpiaRed

No general accountability principle or DPIA trigger exists outside the sectoral financial-institution duty.

Claims: CLM-MM-9c0d1e2f

Dpo RequirementsRed

No DPO-appointment regime identified.

Absence provenance: not recorded. Searched: not recorded.

Ropa RequirementsRed

No ROPA requirement identified.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsRed

No joint-controller framework identified.

Absence provenance: not recorded. Searched: not recorded.

Security MeasuresAmber

The Financial Institutions Law 2016 imposes a sector-specific customer-information-protection duty functioning as a security-of-processing obligation for regulated financial institutions.

Claims: CLM-MM-8b9c0d1e

Breach NotificationRed

No general breach-notification regime (regulator or data-subject facing) identified.

Absence provenance: not recorded. Searched: not recorded.

Retention And DisposalRed

No statutory retention limits or disposal duties identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative31 words

Outside a sector-specific customer-information-protection duty under the Financial Institutions Law 2016, Myanmar has no general accountability principle, DPIA trigger, DPO-appointment threshold, ROPA requirement, joint-controller framework, breach-notification regime, or statutory retention/disposal duty.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceMyanmar's Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific security-of-processing obligation in the absence of a general security-measures regime.
  2. ConfirmedOneTrust DataGuidanceIn the absence of a general data protection statute, Myanmar imposes no general-purpose DPIA, DPO-appointment, ROPA, or breach-notification obligations on controllers outside the sectoral financial-institution security duty.

#

No cross-border transfer mechanism, adequacy arrangement, or localisation statute identified.

Traffic-light rationale — RedNo cross-border transfer mechanism, adequacy arrangement, or localisation statute identified.

Sub-modules (6)

Transfer MechanismsRed

No codified transfer mechanism (adequacy, SCCs, BCRs, derogations) identified.

Absence provenance: not recorded. Searched: not recorded.

Adequacy ReceivedRed

No adequacy decision received from another regime identified.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

No adequacy decision granted to another regime identified.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsRed

No SCC or BCR uptake/forms identified.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No TIA requirement identified.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

No absolute or partial data-localisation mandate identified beyond VPN/platform-licensing controls under the 2025 Cybersecurity Law.

Absence provenance: not recorded. Searched: not recorded.

Category narrative52 words

No adequacy decisions have been received from or granted to other regimes, no SCC/BCR framework is codified, no transfer-impact-assessment obligation exists, and no explicit data-localisation mandate was identified for Myanmar. The 2025 Cybersecurity Law's VPN-approval and platform-licensing requirements function as digital-sovereignty-adjacent controls but do not constitute a formal data-transfer or localisation regime.

#

Meaningful sectoral coverage exists for financial and telecoms/cyber, but health, employment, credit-scoring, education, and insurance sub-modules are unpopulated.

Primary frameworkTelecommunications Law 2013; Financial Institutions Law 2016; Cybersecurity Law 2025.
Supervisory authorityMinistry of Transport and Communications
Traffic-light rationale — AmberMeaningful sectoral coverage exists for financial and telecoms/cyber, but health, employment, credit-scoring, education, and insurance sub-modules are unpopulated.

Sub-modules (7)

Financial Sector OverlayAmber

The Financial Institutions Law 2016 mandates protection of customer information by banks and financial institutions; supervisory function rests with the Central Bank of Myanmar (not independently confirmed in this run).

Claims: CLM-MM-aa11bb22

Health Sector OverlayRed

No health-sector-specific data rules identified.

Absence provenance: not recorded. Searched: not recorded.

Telecoms And EprivacyAmber

The Telecommunications Law 2013 addresses confidentiality of subscriber/personal information; the 2025 Cybersecurity Law adds licensing and VPN-approval requirements for cybersecurity-service and digital-platform operators.

Claims: CLM-MM-bb22cc33, CLM-MM-cc33dd44

Employment DataRed

No employment-specific data rules identified.

Absence provenance: not recorded. Searched: not recorded.

Credit And ScoringRed

No credit-scoring-specific rules identified.

Absence provenance: not recorded. Searched: not recorded.

EducationRed

No education-sector-specific data rules identified.

Absence provenance: not recorded. Searched: not recorded.

InsuranceRed

No insurance-sector-specific data rules identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative48 words

Sectoral overlays are the primary source of enforceable data-protection-adjacent duties in Myanmar: the Financial Institutions Law 2016 for banking customer information, the Telecommunications Law 2013 for subscriber confidentiality, and the 2025 Cybersecurity Law for digital-platform/VPN licensing. No dedicated health, employment, credit-scoring, education, or insurance data rules were identified.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceThe Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific overlay in the absence of an omnibus data protection statute.
  2. ConfirmedOneTrust DataGuidanceThe Telecommunications Law 2013 addresses the confidentiality of personal information handled by telecommunications service providers.
  3. ProbableIAPPMyanmar's 2025 Cybersecurity Law imposes Ministry-approval licensing requirements on VPN use and on cybersecurity-service and digital-platform operators exceeding 100,000 users, with licenses valid for three to ten years and criminal penalties for non-compliance.

#

No adtech/commercial-privacy regulation identified in any searched source.

Traffic-light rationale — RedNo adtech/commercial-privacy regulation identified in any searched source.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent law identified.

Absence provenance: not recorded. Searched: not recorded.

Dark PatternsRed

No dark-pattern prohibition identified.

Absence provenance: not recorded. Searched: not recorded.

Opt Out SignalsRed

No opt-out-signal (GPC/DAA-equivalent) recognition identified.

Absence provenance: not recorded. Searched: not recorded.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules identified.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingRed

No cross-context-advertising ('sale'/'share') regime identified.

Absence provenance: not recorded. Searched: not recorded.

Direct MarketingRed

No direct-marketing consent/suppression framework identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative20 words

No cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rule, cross-context-advertising regime, or direct-marketing consent/suppression framework was identified for Myanmar.

#

The only substantive content in this module concerns broadened state-surveillance carve-outs; ADM, biometric, genetic, and AI-risk-assessment sub-modules are unpopulated.

Primary frameworkLaw Protecting the Privacy and Security of Citizens (2017, as amended 2020).
Traffic-light rationale — RedThe only substantive content in this module concerns broadened state-surveillance carve-outs; ADM, biometric, genetic, and AI-risk-assessment sub-modules are unpopulated.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction regime identified.

Absence provenance: not recorded. Searched: not recorded.

Automated Decision Making TransparencyRed

No ADM-transparency right identified.

Absence provenance: not recorded. Searched: not recorded.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime identified.

Absence provenance: not recorded. Searched: not recorded.

Biometric RegimeRed

No biometric-data regime identified.

Absence provenance: not recorded. Searched: not recorded.

Genetic DataRed

No genetic-data regime identified.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsAmber

The 2020 amendment narrowed privacy protections against government interference to apply specifically to 'competent authorities,' and the NDSC separately expanded authority to restrict constitutional rights during martial law.

Claims: CLM-MM-dd44ee55, CLM-MM-ee55ff66

Category narrative78 words

No profiling restriction, ADM-transparency right, AI-specific risk-assessment regime, biometric-data regime, or genetic-data regime was identified. State-surveillance carve-outs are, however, evidenced: the 2020 amendment to the Privacy Law narrowed the scope of protection against government interference by confining Section 8 obligations and Section 10 criminal liability to 'competent authorities' acting under presidential/Union Government order, permission, or warrant, and the National Defence and Security Council (NDSC) separately issued an amendment law expanding authority to restrict constitutional rights during martial law.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceThe 2020 amendment to the Law Protecting the Privacy and Security of Citizens narrowed Section 8 so that its prohibitions on government interference apply specifically to 'competent authorities' acting without an order, permission, or warrant from the President or Union Government, rather than to persons generally.
  2. ConfirmedOneTrust DataGuidanceThe 2020 amendment narrowed criminal liability under Section 10 of the Privacy Law so that it applies specifically to 'competent authorities' who commit offences under Sections 7 or 8, rather than to persons generally.

#

No children/vulnerable-groups data protection regime identified.

Traffic-light rationale — RedNo children/vulnerable-groups data protection regime identified.

Sub-modules (5)

Age VerificationRed

No age-verification requirement identified.

Absence provenance: not recorded. Searched: not recorded.

Minor Profiling BansRed

No minor-profiling ban identified.

Absence provenance: not recorded. Searched: not recorded.

Education SettingsRed

No education-settings-specific rule identified.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsRed

No dependent-adults protection identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative19 words

No age-of-consent, parental-consent mechanism, minor-profiling ban, education-settings-specific rule, or dependent-adults protection was identified for Myanmar in any reviewed source.

#

Enforcement powers are narrow, sector/criminal-law based, and there is no dedicated DP regulator, enforcement-activity index, or private right of action.

Primary frameworkLaw Protecting the Privacy and Security of Citizens (2017, amended 2020); Cybersecurity Law (2025).
Traffic-light rationale — RedEnforcement powers are narrow, sector/criminal-law based, and there is no dedicated DP regulator, enforcement-activity index, or private right of action.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Criminal penalties exist under both the Privacy Law and the 2025 Cybersecurity Law, but are administered through general courts/ministries rather than a dedicated DP regulator.

Claims: CLM-MM-ff66aa77, CLM-MM-aa77bb88

Enforcement Activity IndexRed

No enforcement-activity data (fines, decisions) for the last 12 months was identified.

Absence provenance: not recorded. Searched: not recorded.

Regulator Funding And CapacityRed

No dedicated DP regulator exists, so no funding/capacity signals are applicable.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism for data-protection matters identified.

Absence provenance: not recorded. Searched: not recorded.

Private Right Of ActionRed

No explicit private civil right of action for data subjects was identified; the Privacy Law's remedies appear criminal/administrative in nature.

Absence provenance: not recorded. Searched: not recorded.

Recent Developments 180DRed

No material Myanmar data-protection or cybersecurity regulatory development was identified within the 180 days preceding this run (February-August 2026).

Claims: CLM-MM-bb88cc99

Category narrative100 words

Enforcement is criminal/administrative and sector-specific rather than centralised in a data protection authority. The Privacy Law imposes imprisonment and fines for violations of its confidentiality/interference provisions (as narrowed to 'competent authorities' by the 2020 amendment), and the 2025 Cybersecurity Law imposes criminal penalties for unlicensed cybersecurity-service/digital-platform operation and unauthorized VPN use. No enforcement-activity index, dedicated regulator funding/capacity data, collective-redress mechanism, or private right of action was identified. No material Myanmar DP/cybersecurity development was confirmed within the 180 days preceding this run (February-August 2026); the most recent substantive development remains the 30 July 2025 entry into force of the Cybersecurity Law.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceUnder the Law Protecting the Privacy and Security of Citizens, violations of Sections 7 or 8 are punishable by imprisonment of between six months and three years and a fine of between MMK 300,000 and MMK 1.5 million, with liability narrowed by the 2020 amendment to 'competent authorities' who commit such violations.
  2. ProbableIAPPMyanmar's 2025 Cybersecurity Law provides criminal penalties for operating unlicensed cybersecurity services or digital platforms and for unauthorized VPN use.
  3. ConfirmedIAPPNo material Myanmar data-protection or cybersecurity regulatory development has been identified within the 180 days preceding this run; the most recent substantive development remains the 30 July 2025 entry into force of the Cybersecurity Law.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Myanmar
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 16 claim(s), 4 source(s) in the cumulative register.