Law / Cambodia

Cambodia's Draft Law on Personal Data Protection, personal data breach notification

Draft Law on Personal Data Protection, articles 21-22 (personal data breach notification)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Proposed: draft date not recorded.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Cambodia's Draft Law on Personal Data Protection has not been enacted and creates no binding duty as of the date shown; the Ministry of Post and Telecommunications confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage.
  • If enacted as drafted, a data controller would have to notify the Ministry of Post and Telecommunications immediately, but no later than 72 hours of becoming aware of a personal data breach that may pose a risk to the data subject or another natural person, or give the Ministry valid reasons for any delay.
  • If enacted as drafted, a data controller would have to notify the affected data subject immediately upon becoming aware of a personal data breach that may pose a high risk to their rights and freedoms, unless the controller had already secured the data, had taken steps removing the high risk, or individual notice would be disproportionately burdensome, in which case a public notice would serve instead.
  • If enacted as drafted, the Ministry of Post and Telecommunications could still require the data controller to notify the data subject even where an exception applied, if it considered the breach presented a high risk to the data subject's rights and freedoms.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 21 would require a data controller to notify the Ministry of Post and Telecommunications of a personal data breach that may pose a risk to a data subject or other natural person immediately, but no later than 72 hours from becoming aware of it, or to give the Ministry valid reasons where it could not meet that deadline.

Article 22 would separately require a data controller to notify the affected data subject immediately upon becoming aware of a breach that may pose a high risk to their rights and freedoms, unless the controller had already secured the affected data with measures such as encryption, had taken subsequent steps removing the high risk, or notifying each data subject individually would be disproportionately burdensome, in which case a public notice would serve instead; even then, the Ministry could still require notice to the data subject where it considered the breach a high risk.

The glossary defines a data breach as an incident in which personal data was accessed, disclosed, or stolen without authorization. The draft's own final page carries an unsigned, undated National Assembly signature block. The Ministry of Post and Telecommunications' own website confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage, so nothing in this row binds anyone today.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

official draft text, Ministry of Post and Telecommunications (published via Open Development Cambodia), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 5, 2025. Publisher's page: https://data.opendevelopmentcambodia.net/en/dataset/792fc94d-1a84-49cc-bad3-9b420f99b70f/resource/03e9c060-9bc8-42d5-80a6-8db777f61d1c/downl…

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app