Law note · Cambodia

Draft Law on Personal Data Protection, final draft

cite Draft Law on Personal Data Protection (Final Draft, 23 June 2025), Ministry of Post and Telecommunications, Kingdom of Cambodia stage PROPOSED draft date not recorded kind Comprehensive regime binds public and private bodies reviewed 2026-08-29

What it requires

  • Cambodia's Draft Law on Personal Data Protection has not been enacted and creates no binding duty as of this document's as_of_date; the Ministry of Post and Telecommunications confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage. If enacted as currently drafted, an app processing the personal data of a person in Cambodia, including a facial image, voiceprint, or other biometric identifier, would need explicit consent or another of the draft's nine listed exceptions before processing it as sensitive personal data, would need to notify the Ministry within 72 hours of a qualifying breach, and would need Ministry permission or a documented safeguards assessment before transferring personal data abroad.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
Excludes recording-derived identifiers
No

What we found

This draft, if enacted as currently written, would create a General Data Protection Regulation (GDPR)-shaped comprehensive personal-data regime: Articles 7 to 13 set lawful-basis requirements, and Article 14 prohibits processing sensitive personal data, defined to include biometric data (itself defined as personal data from technical processing of physical, physiological, or behavioural characteristics, for example a facial image or fingerprints), subject to nine listed exceptions including explicit consent.

Chapter 6 (Articles 27 to 35) would grant access, rectification, erasure, restriction, portability, objection, and a right to request human involvement in an automated decision with legal or similarly significant effect.

Article 23 would condition any transfer of personal data outside Cambodia on Ministry permission, a documented safeguards assessment, or one of six listed circumstances, and Articles 21 and 22 would require notification to the Ministry within 72 hours of a breach posing a risk to a data subject and notification to the data subject where the risk is high.

The draft's own final page carries an unsigned, undated National Assembly signature block, and the Ministry of Post and Telecommunications' own website confirmed, three weeks before this research, that the draft remained at a pre-legislative validation-workshop stage; it does not currently bind anyone.

Primary source

official draft text
Ministry of Post and Telecommunications (published via Open Development Cambodia), via an Internet Archive capture since the origin host returned no response

← Back to the example  ·  Lint your app →