#
No independent regulator; core instrument identity/number is contested across otherwise authoritative sources; World Bank explicitly characterizes the framework as non-comprehensive.
Sub-modules (5)
Regulator And AuthorityRed
MTC is the implementing ministry for electronic data protection; there is no independent DPA equivalent to GDPR-style supervisory authorities.
Claims (1):
- The Ministry of Technology and Communications is the implementing authority for Laos's electronic data protection law, and Laos has no independent data-protection authority separating rule-setting, business-facilitation and enforcement functions.
Act And InstrumentsAmber
The core instrument is the Law on Electronic Data Protection, subject to a two-number discrepancy (No. 25/NA vs No. 117/PO) plus an implementing 2018 guideline.
Claims (2):
- The Law on the Protection of Electronic Data (No. 25/NA) was enacted in 2017.
- A discrepancy exists across otherwise authoritative sources as to the instrument's reference number and date: National Assembly Law No. 25/NA dated 12 May 2017 (Lao Trade Portal, Council of Europe) versus presidential-decree No. 117/PO dated 23 June 2017 (World Bank), both apparently referring to the same underlying statute, alongside an implementing Guideline No. 2128 of 2018.
Material ScopeAmber
Scope extends to 'general' and 'specific' categories of electronic data across public and private sectors, broader than a narrow personal-data definition.
Claims (1):
- Laos's electronic data protection law is broader-than-typical in scope, covering 'general' and 'specific' electronic data rather than personal data alone.
Territorial ScopeRed
No explicit extraterritorial-application clause for non-established controllers was identified in available secondary sources.
Absence provenance: unavailable. Searched: Laos Law on Electronic Data Protection extraterritorial scope, Laos data protection territorial application non-established controllers.
Regulator Registration And FilingRed
No controller registration or filing regime with a data-protection authority was identified; MTC-administered licensing (e.g., software/internet-content-center licensing) exists for related ICT services but is not a DP filing obligation.
Absence provenance: unavailable. Searched: Laos data controller registration filing MTC, Laos personal data processing notification requirement.
Claims (1):
- Related ICT-sector licensing (e.g., Software Business and Internet Content Center licensing under Decision No. 143/MPT) requires operators to respect and protect personal data of service users, including a general prohibition on disclosure except at the request of relevant government authorities, but this is a sector licensing condition rather than a DPA filing/registration regime.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (5)
- ConfirmedWorld Bank — The Ministry of Technology and Communications is the implementing authority for Laos's electronic data protection law, and Laos has no independent data-protection authority separating rule-setting, business-facilitation and enforcement functions.observed
- ConfirmedCouncil of Europe — The Law on the Protection of Electronic Data (No. 25/NA) was enacted in 2017.observed
- UncertainLao Trade Portal — A discrepancy exists across otherwise authoritative sources as to the instrument's reference number and date: National Assembly Law No. 25/NA dated 12 May 2017 (Lao Trade Portal, Council of Europe) versus presidential-decree No. 117/PO dated 23 June 2017 (World Bank), both apparently referring to the same underlying statute, alongside an implementing Guideline No. 2128 of 2018.observed
- ProbableWorld Bank — Laos's electronic data protection law is broader-than-typical in scope, covering 'general' and 'specific' electronic data rather than personal data alone.observed
- ProbableLao Trade Portal — Related ICT-sector licensing (e.g., Software Business and Internet Content Center licensing under Decision No. 143/MPT) requires operators to respect and protect personal data of service users, including a general prohibition on disclosure except at the request of relevant government authorities, but this is a sector licensing condition rather than a DPA filing/registration regime.observed