Law note · Myanmar

Cybersecurity Law, digital platform data retention and disclosure duty

cite Cybersecurity Law, State Administration Council Law No. 1/2025, ss.33-34 stage IMMINENT commencement not set kind Enforcement supervision binds public and private bodies reviewed 2026-08-29

What it requires

  • Myanmar's Cybersecurity Law creates no data-protection right; it is a state-access duty, not a rights regime. A digital platform service with 100,000 or more Myanmar users must retain personal information of a user, including a voiceprint or faceprint the platform stores, for 3 years and disclose it to an authorised individual or organisation on written request, with no consent, purpose-limitation, or individual-notice duty running the other way. Whether this duty currently binds turns on a presidential commencement notification that has not been independently confirmed, though independent reporting places it in force since 30 July 2025.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web
  • trains_models
  • deploys_chatbot
Private right of action
No

What we found

Myanmar's Cybersecurity Law (State Administration Council Law No. 1/2025) contains no data-protection framework: its Chapter II definitions define cybersecurity-related terms but no "personal data" or "biometric data" term at all, and the sole use of "personal information" in the entire law is at section 33, which requires a digital platform service provider to retain personal information of a user, usage records, and any data the Department specifies for 3 years, disclosed to an authorised individual or organisation on written request under section 34.

This is a retention and state-access duty, not a protective one: it carries no consent standard, no purpose limitation, no retention ceiling beyond the 3-year floor, and no individual notice or objection right, and it runs toward government access to personal data rather than away from it, reaching a voiceprint or faceprint a covered platform stores exactly like any other user data.

The law's own section 2 commences it only on a date the president appoints by notification; independent trackers converge on State Administration Council Notification No. 113/2025 bringing it into force 30 July 2025, but that notification was not independently read this pass, so this instrument is recorded as enacted rather than in effect.

Enforcement runs through a Central Committee and a Steering Committee on Cybersecurity and a Department with licensing and investigation powers (Chapter III); no private civil right of action exists anywhere in the law's text.

Primary source

official text
Ministry of Information of Myanmar (moi.gov.mm), which reproduces Chapters I-III (through section 10) of the law verbatim and stops mid-article with "To be continued" sections 33-34 (Chapter 9) are not on this page. Cross-checked against a Yangon law firm's full-text reproduction (lincolnmyanmar.com), which matches the official copy exactly on every section both cover, for confidence in sections 33-34's own text

← Back to the example  ·  Lint your app →