Cambodia's Draft Law on Personal Data Protection, enforcement and penalties
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Proposed: draft date not recorded.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Cambodia's Draft Law on Personal Data Protection has not been enacted and creates no binding duty as of the date shown; the Ministry of Post and Telecommunications confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage.
- If enacted as drafted, the Ministry of Post and Telecommunications would regulate, audit, and monitor compliance with the draft, could instruct a data controller or processor to provide personal data or information, and could access all personal data and information it needs to perform its functions.
- If enacted as drafted, Ministry-appointed personal data inspectors would hold judicial police status to oversee, investigate, and suppress offenses under the draft, and seize evidence and prepare case files.
- If enacted as drafted, an administrative fine of up to 60,000,000 Riels for a natural person, or up to the greater of 600,000,000 Riels or 10 percent of annual turnover for a legal person, would apply to noncompliance with the draft's processing, controller and processor, data protection officer, or data subject rights provisions.
- If enacted as drafted, a natural person who commits the same offense again would face imprisonment from 6 days to 2 years and a fine of up to 60,000,000 Riels, and a legal person who commits the same offense again would face a fine of up to 100,000,000 Riels.
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 4 would make the Ministry of Post and Telecommunications the competent institution for personal data protection, empowered to regulate, audit, and monitor compliance, instruct a controller or processor to provide personal data or information, access personal data and information it needs, and receive complaints and mediate disputes.
Article 40 would let the Ministry appoint personal data inspectors with judicial police status to investigate and suppress offenses, and article 45 would let a disputing party bring a complaint to the Ministry, which would appoint a conciliator.
Article 48 would set administrative fines of up to 60,000,000 Riels for a natural person or up to the greater of 600,000,000 Riels or 10 percent of annual turnover for a legal person for noncompliance with the draft's chapters on processing, controller and processor obligations, the data protection officer, or data subject rights.
Article 51 would additionally punish a repeat natural-person offender with imprisonment from 6 days to 2 years and a fine of up to 60,000,000 Riels, and a repeat legal-person offender with a fine of up to 100,000,000 Riels. The draft's own final page carries an unsigned, undated National Assembly signature block.
The Ministry of Post and Telecommunications' own website confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage, so nothing in this row binds anyone today.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisions
Read the law
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 5, 2025. Publisher's page: https://data.opendevelopmentcambodia.net/en/dataset/792fc94d-1a84-49cc-bad3-9b420f99b70f/resource/03e9c060-9bc8-42d5-80a6-8db777f61d1c/downl…Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.