Law / Myanmar

Myanmar

privacy

Myanmar has no comprehensive personal-data-protection law. Its Cybersecurity Law (State Administration Council Law No. 1/2025), read directly in full via two overlapping copies, defines no "personal data" or "biometric data" term anywhere in its text; its only individual-data provision, section 33, is a mandatory 3-year retention and state-disclosure duty running toward government access rather than a data-protection right.

The law's own section 2 commences it only on a date the president appoints by notification, and while independent trackers converge on State Administration Council Notification No. 113/2025 bringing it into force 30 July 2025, that notification itself was not independently read this pass, so this document records the law as enacted rather than in effect.

A separate 2017 law protecting citizens' privacy against government intrusion reportedly had its operative sections suspended by a 2021 order, per commentary this pass could not independently verify against the order's own text, so it is not authored as an instrument here.

5 instruments named 1 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Enforcement supervision

Cybersecurity Law, digital platform data retention and disclosure duty

cite Cybersecurity Law, State Administration Council Law No. 1/2025, ss.33-34 stage IMMINENT commencement not set binds public and private bodies source official text
What it requires

Myanmar's Cybersecurity Law (State Administration Council Law No. 1/2025) contains no data-protection framework: its Chapter II definitions define cybersecurity-related terms but no "personal data" or "biometric data" term at all, and the sole use of "personal information" in the entire law is at section 33, which requires a digital platform service provider to retain personal information of a user, usage records, and any data the Department specifies for 3 years, disclosed to an authorised individual or organisation on written request under section 34.

This is a retention and state-access duty, not a protective one: it carries no consent standard, no purpose limitation, no retention ceiling beyond the 3-year floor, and no individual notice or objection right, and it runs toward government access to personal data rather than away from it, reaching a voiceprint or faceprint a covered platform stores exactly like any other user data.

The law's own section 2 commences it only on a date the president appoints by notification; independent trackers converge on State Administration Council Notification No. 113/2025 bringing it into force 30 July 2025, but that notification was not independently read this pass, so this instrument is recorded as enacted rather than in effect.

Enforcement runs through a Central Committee and a Steering Committee on Cybersecurity and a Department with licensing and investigation powers (Chapter III); no private civil right of action exists anywhere in the law's text.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.