Law / Cambodia

Cambodia

privacy

Cambodia has no comprehensive personal-data-protection law in force. The Draft Law on Personal Data Protection reached a final version dated 23 June 2025 from the Ministry of Post and Telecommunications, but its own text carries an unsigned, undated National Assembly signature block, and the Ministry's own website confirmed as recently as 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage, so this document authors it as proposed, not in force.

A widely circulated report that Cambodia "passed" a data protection law was traced to Voice of Vietnam coverage of Vietnam's own Law on Personal Data Protection and is not repeated here.

If enacted as currently drafted, the law would create a General Data Protection Regulation (GDPR)-shaped comprehensive regime naming biometric data, including facial images, as a sensitive category, a full data-subject rights chapter, a permission-or-safeguards cross-border transfer standard, and 72-hour breach notification to the Ministry, none of which currently binds.

8 instruments named 1 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Draft Law on Personal Data Protection, final draft

cite Draft Law on Personal Data Protection (Final Draft, 23 June 2025), Ministry of Post and Telecommunications, Kingdom of Cambodia stage PROPOSED draft date not recorded binds public and private bodies source official draft text
What it requires

This draft, if enacted as currently written, would create a General Data Protection Regulation (GDPR)-shaped comprehensive personal-data regime: Articles 7 to 13 set lawful-basis requirements, and Article 14 prohibits processing sensitive personal data, defined to include biometric data (itself defined as personal data from technical processing of physical, physiological, or behavioural characteristics, for example a facial image or fingerprints), subject to nine listed exceptions including explicit consent.

Chapter 6 (Articles 27 to 35) would grant access, rectification, erasure, restriction, portability, objection, and a right to request human involvement in an automated decision with legal or similarly significant effect.

Article 23 would condition any transfer of personal data outside Cambodia on Ministry permission, a documented safeguards assessment, or one of six listed circumstances, and Articles 21 and 22 would require notification to the Ministry within 72 hours of a breach posing a risk to a data subject and notification to the data subject where the risk is high.

The draft's own final page carries an unsigned, undated National Assembly signature block, and the Ministry of Post and Telecommunications' own website confirmed, three weeks before this research, that the draft remained at a pre-legislative validation-workshop stage; it does not currently bind anyone.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.