Draft Law on Personal Data Protection, final draft
This draft, if enacted as currently written, would create a General Data Protection Regulation (GDPR)-shaped comprehensive personal-data regime: Articles 7 to 13 set lawful-basis requirements, and Article 14 prohibits processing sensitive personal data, defined to include biometric data (itself defined as personal data from technical processing of physical, physiological, or behavioural characteristics, for example a facial image or fingerprints), subject to nine listed exceptions including explicit consent.
Chapter 6 (Articles 27 to 35) would grant access, rectification, erasure, restriction, portability, objection, and a right to request human involvement in an automated decision with legal or similarly significant effect.
Article 23 would condition any transfer of personal data outside Cambodia on Ministry permission, a documented safeguards assessment, or one of six listed circumstances, and Articles 21 and 22 would require notification to the Ministry within 72 hours of a breach posing a risk to a data subject and notification to the data subject where the risk is high.
The draft's own final page carries an unsigned, undated National Assembly signature block, and the Ministry of Post and Telecommunications' own website confirmed, three weeks before this research, that the draft remained at a pre-legislative validation-workshop stage; it does not currently bind anyone.