Law note · Cambodia
Draft Law on Personal Data Protection, final draft
What it requires
- Cambodia's Draft Law on Personal Data Protection has not been enacted and creates no binding duty as of this document's as_of_date; the Ministry of Post and Telecommunications confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage. If enacted as currently drafted, an app processing the personal data of a person in Cambodia, including a facial image, voiceprint, or other biometric identifier, would need explicit consent or another of the draft's nine listed exceptions before processing it as sensitive personal data, would need to notify the Ministry within 72 hours of a qualifying breach, and would need Ministry permission or a documented safeguards assessment before transferring personal data abroad.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbothigh_risk_decisionsprocesses_voiceprocesses_biometrics
- Excludes recording-derived identifiers
- No
What we found
This draft, if enacted as currently written, would create a General Data Protection Regulation (GDPR)-shaped comprehensive personal-data regime: Articles 7 to 13 set lawful-basis requirements, and Article 14 prohibits processing sensitive personal data, defined to include biometric data (itself defined as personal data from technical processing of physical, physiological, or behavioural characteristics, for example a facial image or fingerprints), subject to nine listed exceptions including explicit consent.
Chapter 6 (Articles 27 to 35) would grant access, rectification, erasure, restriction, portability, objection, and a right to request human involvement in an automated decision with legal or similarly significant effect.
Article 23 would condition any transfer of personal data outside Cambodia on Ministry permission, a documented safeguards assessment, or one of six listed circumstances, and Articles 21 and 22 would require notification to the Ministry within 72 hours of a breach posing a risk to a data subject and notification to the data subject where the risk is high.
The draft's own final page carries an unsigned, undated National Assembly signature block, and the Ministry of Post and Telecommunications' own website confirmed, three weeks before this research, that the draft remained at a pre-legislative validation-workshop stage; it does not currently bind anyone.
Primary source
official draft text
Ministry of Post and Telecommunications (published via Open Development Cambodia), via an Internet Archive capture since the origin host returned no response