🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
LA v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing8 sources retrieved model claude-sonnet-5 · 2026-08-06

Laos

LA schema gdpri-v2 trajectory: not yet assessedunregulated gapoverlaps: FIM, WPM

Last updated · 10 categories · 18 claims · 11 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
18Claimsbaseline..claims[]
5Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 22 September 2026.

Lead Signal

Laos is understood to have no independent data-protection authority, with the Ministry of Technology and Communications combining rule-setting, business-facilitation and enforcement functions under the electronic data protection law. This finding is carried forward this cycle at a corrected, more conservative confidence level following an internal review of single-source claims.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No independent regulator; core instrument identity/number is contested across otherwise authoritative sources; World Bank explicitly characterizes the framework as non-comprehensive.

Primary frameworkLaw on Electronic Data Protection No. 25/NA (12 May 2017), also cited as Law on Protection of Electronic Data No. 117/PO (23 June 2017), with implementing Guideline No. 2128 (2018)
Traffic-light rationale — RedNo independent regulator; core instrument identity/number is contested across otherwise authoritative sources; World Bank explicitly characterizes the framework as non-comprehensive.

Sub-modules (5)

Regulator And AuthorityRed

MTC is the implementing ministry for electronic data protection; there is no independent DPA equivalent to GDPR-style supervisory authorities.

Claims (1):

  • The Ministry of Technology and Communications is the implementing authority for Laos's electronic data protection law, and Laos has no independent data-protection authority separating rule-setting, business-facilitation and enforcement functions.

Act And InstrumentsAmber

The core instrument is the Law on Electronic Data Protection, subject to a two-number discrepancy (No. 25/NA vs No. 117/PO) plus an implementing 2018 guideline.

Claims (2):

  • The Law on the Protection of Electronic Data (No. 25/NA) was enacted in 2017.
  • A discrepancy exists across otherwise authoritative sources as to the instrument's reference number and date: National Assembly Law No. 25/NA dated 12 May 2017 (Lao Trade Portal, Council of Europe) versus presidential-decree No. 117/PO dated 23 June 2017 (World Bank), both apparently referring to the same underlying statute, alongside an implementing Guideline No. 2128 of 2018.

Material ScopeAmber

Scope extends to 'general' and 'specific' categories of electronic data across public and private sectors, broader than a narrow personal-data definition.

Claims (1):

  • Laos's electronic data protection law is broader-than-typical in scope, covering 'general' and 'specific' electronic data rather than personal data alone.

Territorial ScopeRed

No explicit extraterritorial-application clause for non-established controllers was identified in available secondary sources.

Absence provenance: unavailable. Searched: Laos Law on Electronic Data Protection extraterritorial scope, Laos data protection territorial application non-established controllers.

Regulator Registration And FilingRed

No controller registration or filing regime with a data-protection authority was identified; MTC-administered licensing (e.g., software/internet-content-center licensing) exists for related ICT services but is not a DP filing obligation.

Absence provenance: unavailable. Searched: Laos data controller registration filing MTC, Laos personal data processing notification requirement.

Claims (1):

  • Related ICT-sector licensing (e.g., Software Business and Internet Content Center licensing under Decision No. 143/MPT) requires operators to respect and protect personal data of service users, including a general prohibition on disclosure except at the request of relevant government authorities, but this is a sector licensing condition rather than a DPA filing/registration regime.
Category narrative124 words

Laos has no independent data-protection authority. The Ministry of Technology and Communications (MTC) implements the Law on Electronic Data Protection, creating no separation between rule-setter, business-facilitator and enforcer. The primary instrument is variously cited as Law on Electronic Data Protection No. 25/NA (12 May 2017) per the Lao Trade Portal and Council of Europe, and as Law on Protection of Electronic Data No. 117/PO (23 June 2017) per the World Bank, with an implementing Guideline No. 2128 of 2018; both are treated as referring to the same underlying instrument pending clarification. The law covers both 'general' and 'specific' electronic data — a broader scope than typical personal-data statutes — but the World Bank's own assessment finds it falls short of a general-purpose, GDPR-comparable regime.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedWorld Bank — The Ministry of Technology and Communications is the implementing authority for Laos's electronic data protection law, and Laos has no independent data-protection authority separating rule-setting, business-facilitation and enforcement functions.observed
  2. ConfirmedCouncil of Europe — The Law on the Protection of Electronic Data (No. 25/NA) was enacted in 2017.observed
  3. UncertainLao Trade Portal — A discrepancy exists across otherwise authoritative sources as to the instrument's reference number and date: National Assembly Law No. 25/NA dated 12 May 2017 (Lao Trade Portal, Council of Europe) versus presidential-decree No. 117/PO dated 23 June 2017 (World Bank), both apparently referring to the same underlying statute, alongside an implementing Guideline No. 2128 of 2018.observed
  4. ProbableWorld Bank — Laos's electronic data protection law is broader-than-typical in scope, covering 'general' and 'specific' electronic data rather than personal data alone.observed
  5. ProbableLao Trade Portal — Related ICT-sector licensing (e.g., Software Business and Internet Content Center licensing under Decision No. 143/MPT) requires operators to respect and protect personal data of service users, including a general prohibition on disclosure except at the request of relevant government authorities, but this is a sector licensing condition rather than a DPA filing/registration regime.observed

#

Absence of special-category protections and of purpose-limitation/minimisation principles is an explicit, sourced gap finding.

Primary frameworkLaw on Electronic Data Protection No. 25/NA (12 May 2017) / No. 117/PO (23 June 2017)
Traffic-light rationale — RedAbsence of special-category protections and of purpose-limitation/minimisation principles is an explicit, sourced gap finding.

Sub-modules (4)

Lawful BasesRed

Consent is treated as the near-exclusive lawful basis for processing under the current framework.

Claims (1):

  • Laos's electronic data protection framework relies primarily on consent as the near-exclusive lawful basis for processing, without accompanying purpose-limitation or data-minimisation principles.

Special CategoriesRed

The law lacks a special/sensitive category of personal data (health, biometric, genetic, ethnic, political, sexual, criminal).

Claims (1):

  • The current Lao electronic data protection framework lacks a defined special/sensitive category of personal data, a gap the World Bank identifies as a divergence from international good practice.

Pseudonymisation And AnonymisationRed

No pseudonymisation or anonymisation definitions or safe-harbour provisions were identified.

Absence provenance: unavailable. Searched: Laos electronic data protection pseudonymisation anonymisation safe harbour.

Category narrative51 words

The World Bank's gap analysis finds that Laos's electronic data law relies primarily on consent as the near-exclusive lawful basis for processing, without purpose-limitation or data-minimisation safeguards, and lacks a special category of sensitive personal data comparable to GDPR Art 9. No pseudonymisation/anonymisation safe-harbour provisions were identified in available secondary sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbableWorld Bank — Laos's electronic data protection framework relies primarily on consent as the near-exclusive lawful basis for processing, without accompanying purpose-limitation or data-minimisation principles.observed
  2. ProbableWorld Bank — The current Lao electronic data protection framework lacks a defined special/sensitive category of personal data, a gap the World Bank identifies as a divergence from international good practice.observed

#

No sourced evidence of an operative subject-rights regime; treated as an explicit gap rather than silently omitted.

Primary frameworkLaw on Electronic Data Protection No. 25/NA (12 May 2017) / No. 117/PO (23 June 2017)
Traffic-light rationale — Not assessedNo sourced evidence of an operative subject-rights regime; treated as an explicit gap rather than silently omitted.

Sub-modules (5)

Access RightRed

No statutory subject-access-request mechanism identified.

Absence provenance: unavailable. Searched: Laos electronic data protection right of access data subject.

Rectification And ErasureRed

No statutory right to rectification or erasure identified.

Absence provenance: unavailable. Searched: Laos data protection right to erasure rectification.

Restriction And ObjectionRed

No statutory restriction or objection right identified.

Absence provenance: unavailable. Searched: Laos data protection right to object profiling restriction.

Data PortabilityRed

No portability right identified.

Absence provenance: unavailable. Searched: Laos data protection right to data portability.

Deadlines And Response WindowsRed

No statutory controller response deadlines identified.

Absence provenance: unavailable. Searched: Laos data protection statutory response deadline controller.

Category narrative40 words

No comprehensive, GDPR-analogue data-subject-rights framework (access, rectification/erasure, restriction/objection, portability, statutory response deadlines) was identified for Laos in available Tier-1/Tier-2 secondary sources. This is consistent with the World Bank's characterization of the statute as falling short of general-application data-protection good practice.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

Explicit, sourced World Bank finding of misallocated breach responsibility and absent accountability infrastructure.

Primary frameworkLaw on Electronic Data Protection No. 25/NA (12 May 2017) / No. 117/PO (23 June 2017); Decision on Software and Data Center Business No. 143/MPT (2017)
Traffic-light rationale — RedExplicit, sourced World Bank finding of misallocated breach responsibility and absent accountability infrastructure.

Sub-modules (7)

Accountability And DpiaRed

No DPIA trigger or accountability-principle codification identified.

Absence provenance: unavailable. Searched: Laos data protection impact assessment DPIA requirement.

Dpo RequirementsRed

No DPO appointment threshold identified.

Absence provenance: unavailable. Searched: Laos data protection officer appointment requirement.

Ropa RequirementsRed

No records-of-processing obligation identified.

Absence provenance: unavailable. Searched: Laos records of processing activities requirement.

Joint Controller ArrangementsRed

No joint-controller framework identified; the law does not appear to draw a clear controller/processor distinction.

Claims (1):

  • Laos's electronic data protection framework does not clearly delineate controller and processor roles, contributing to the World Bank's finding that breach-type responsibilities are misallocated onto the 'data owner'.

Security MeasuresAmber

General confidentiality obligations exist for ICT-licensed service operators but no codified technical/organisational security-of-processing standard for data controllers generally.

Claims (1):

  • Operators licensed under the Decision on Software and Data Center Business must respect and protect the personal data of service users and must not disclose such data except at the request of relevant government authorities.

Breach NotificationRed

Breach-type responsibilities are misallocated to the 'data owner' rather than to a controller/processor, per the World Bank's assessment.

Claims (1):

  • The Lao electronic data law misallocates breach-type responsibilities onto the 'data owner' rather than onto the data controller or processor, per the World Bank's own gap analysis.

Retention And DisposalRed

No statutory retention-limit or disposal-duty regime identified.

Absence provenance: unavailable. Searched: Laos data retention limit disposal personal data.

Category narrative64 words

The World Bank's gap analysis specifically flags that the Lao framework misallocates breach-type responsibilities onto the 'data owner' rather than onto a controller/processor distinction, and that it lacks accountability infrastructure (DPIA triggers, DPO thresholds, ROPA) comparable to international good practice. Sector-adjacent security obligations exist in ICT licensing (e.g., confidentiality of service-user data under software/internet-content-center licensing) but do not constitute a general controller/processor accountability regime.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ProbableWorld Bank — Laos's electronic data protection framework does not clearly delineate controller and processor roles, contributing to the World Bank's finding that breach-type responsibilities are misallocated onto the 'data owner'.observed
  2. ConfirmedLao Trade Portal — Operators licensed under the Decision on Software and Data Center Business must respect and protect the personal data of service users and must not disclose such data except at the request of relevant government authorities.observed
  3. ProbableWorld Bank — The Lao electronic data law misallocates breach-type responsibilities onto the 'data owner' rather than onto the data controller or processor, per the World Bank's own gap analysis.observed

#

Sourced confirmation of absence of a clear transfer-mechanism regime, notwithstanding a general cross-border/encryption reference in the underlying law.

Primary frameworkLaw on Electronic Data Protection No. 25/NA (12 May 2017) / No. 117/PO (23 June 2017)
Traffic-light rationale — RedSourced confirmation of absence of a clear transfer-mechanism regime, notwithstanding a general cross-border/encryption reference in the underlying law.

Sub-modules (6)

Transfer MechanismsRed

No codified adequacy/SCC/BCR/derogation mechanism identified; the World Bank finds the framework lacks a clear cross-border transfer regime.

Claims (1):

  • The World Bank's assessment finds that Laos's electronic data protection framework lacks a clear cross-border-transfer regime comparable to international good practice (e.g., adequacy, SCCs, BCRs).

Adequacy ReceivedRed

No adequacy decision received by Laos from another regime was identified.

Absence provenance: unavailable. Searched: Laos adequacy decision received EU GDPR.

Adequacy GrantedRed

No adequacy decision granted by Laos to another regime was identified.

Absence provenance: unavailable. Searched: Laos adequacy decision granted to other jurisdiction.

Sccs And BcrsRed

No SCC or BCR uptake mechanism identified.

Absence provenance: unavailable. Searched: Laos standard contractual clauses binding corporate rules data transfer.

Transfer Impact AssessmentRed

No TIA requirement identified.

Absence provenance: unavailable. Searched: Laos transfer impact assessment requirement.

Data LocalisationAmber

The law governs cross-border transfer and encryption rules without imposing broad data-localisation requirements, per UNECA's digital-trade profile.

Claims (1):

  • The Law on Electronic Data Protection No. 25/NA governs cross-border transfer and encryption rules without imposing broad data localisation on service providers.
Category narrative56 words

Available secondary analysis indicates the Lao electronic data protection framework touches on cross-border transfer and encryption rules without imposing broad data-localisation mandates, but the World Bank assessment separately finds the framework lacks a clear cross-border-transfer regime comparable to GDPR-style mechanisms (adequacy, SCCs, BCRs, TIA). No adequacy decisions received from or granted to other regimes were identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbableWorld Bank — The World Bank's assessment finds that Laos's electronic data protection framework lacks a clear cross-border-transfer regime comparable to international good practice (e.g., adequacy, SCCs, BCRs).observed
  2. ProbableUNECA — The Law on Electronic Data Protection No. 25/NA governs cross-border transfer and encryption rules without imposing broad data localisation on service providers.observed

#

Financial and telecoms sectoral instruments are sourced; health/employment/credit/education/insurance overlays are an explicit, sourced gap.

Primary frameworkLaw on Anti-Money Laundering and Counter-Financing of Terrorism No. 50/NA; Law on Payment Systems (2017); Law on Telecommunications (Amended) No. 09/NA (2021)
Supervisory authorityBank of Lao PDR (BoL) / Telecommunications Regulatory Authority (TRA)
Traffic-light rationale — AmberFinancial and telecoms sectoral instruments are sourced; health/employment/credit/education/insurance overlays are an explicit, sourced gap.

Sub-modules (7)

Financial Sector OverlayAmber

AML/CFT Law No. 50/NA and the 2017 Law on Payment Systems (BoL oversight) govern financial-sector data handling relevant to AML data-sharing.

Claims (2):

  • Laos's Law on Anti-Money Laundering and Counter-Financing of Terrorism (No. 50/NA) governs financial-sector data-sharing obligations relevant to AML compliance.
  • The Bank of Lao PDR has oversight of the national payment system, and the Law on Payment Systems adopted in 2017 set a strategic approach to payment-system reform including increased adoption of non-cash payment instruments.

Health Sector OverlayRed

No health-sector-specific data protection overlay identified.

Absence provenance: unavailable. Searched: Laos health data protection law hospital patient records.

Telecoms And EprivacyAmber

The 2021-amended Telecommunications Law No. 09/NA and TRA governance intersect with telecom subscriber data, though no ePrivacy-style cookie/communications-confidentiality regime distinct from the general electronic data law was identified.

Claims (1):

  • Laos updated its telecommunications legal framework via the Law on Information and Communications Technology (December 2016) and revised the 2011 Telecommunications Law in 2021, with the Telecommunications Regulatory Authority structured to be independent of telecom operators.

Employment DataRed

No employment-specific data protection code identified.

Absence provenance: unavailable. Searched: Laos employment data protection code employee monitoring.

Credit And ScoringRed

No credit-scoring-specific data rules identified.

Absence provenance: unavailable. Searched: Laos credit scoring data protection rules.

EducationRed

No education-sector-specific data protection rules identified.

Absence provenance: unavailable. Searched: Laos education sector student data protection rules.

InsuranceRed

No insurance-sector-specific data protection rules identified.

Absence provenance: unavailable. Searched: Laos insurance sector data protection rules.

Category narrative65 words

Laos has sector-specific instruments that intersect with data flows: an Anti-Money-Laundering and Counter-Financing of Terrorism law governing financial-sector data sharing, a 2017 Law on Payment Systems under Bank of Lao PDR (BoL) oversight, and a 2021-amended Telecommunications Law with import/technical controls administered by an ostensibly independent Telecommunications Regulatory Authority (TRA). No health-sector, employment-data, credit-scoring, education-sector, or insurance-sector data-protection overlays were identified in available secondary sources.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedCouncil of Europe — Laos's Law on Anti-Money Laundering and Counter-Financing of Terrorism (No. 50/NA) governs financial-sector data-sharing obligations relevant to AML compliance.observed
  2. ConfirmedWorld Bank — The Bank of Lao PDR has oversight of the national payment system, and the Law on Payment Systems adopted in 2017 set a strategic approach to payment-system reform including increased adoption of non-cash payment instruments.observed
  3. ConfirmedWorld Bank — Laos updated its telecommunications legal framework via the Law on Information and Communications Technology (December 2016) and revised the 2011 Telecommunications Law in 2021, with the Telecommunications Regulatory Authority structured to be independent of telecom operators.observed

#

Comprehensive absence of an adtech/commercial-privacy regime; explicit gap finding rather than silent omission.

Traffic-light rationale — Not assessedComprehensive absence of an adtech/commercial-privacy regime; explicit gap finding rather than silent omission.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent regime identified.

Absence provenance: unavailable. Searched: Laos cookie consent law website tracking.

Dark PatternsRed

No dark-pattern prohibition identified.

Absence provenance: unavailable. Searched: Laos dark pattern prohibition consumer law.

Opt Out SignalsRed

No recognised opt-out signal mechanism identified.

Absence provenance: unavailable. Searched: Laos Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule identified.

Absence provenance: unavailable. Searched: Laos data clean room collaboration rules.

Cross Context AdvertisingRed

No cross-context advertising ('sale'/'share') rule identified.

Absence provenance: unavailable. Searched: Laos cross-context advertising data sale rules.

Direct MarketingRed

No direct-marketing consent/suppression regime identified.

Absence provenance: unavailable. Searched: Laos direct marketing consent suppression list law.

Category narrative27 words

No cookie/tracker consent regime, dark-pattern prohibition, recognised opt-out signal (GPC/DAA-equivalent), clean-room rule, cross-context-advertising rule, or direct-marketing consent/suppression regime specific to Laos was identified in available Tier-1/Tier-2 sources.

#

No profiling/ADM/biometric/genetic regime found; only a narrow, sourced state-surveillance carve-out exists, without independent oversight limits.

Primary frameworkLaw on Prevention and Combating Cyber Crime No. 61/NA (2015)
Supervisory authorityMinistry of Public Security / LaoCERT
Traffic-light rationale — RedNo profiling/ADM/biometric/genetic regime found; only a narrow, sourced state-surveillance carve-out exists, without independent oversight limits.

Sub-modules (6)

Profiling RestrictionsRed

No profiling restriction identified.

Absence provenance: unavailable. Searched: Laos profiling restriction automated decision.

Automated Decision Making TransparencyRed

No ADM transparency or explanation right identified.

Absence provenance: unavailable. Searched: Laos automated decision making transparency right.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime identified.

Absence provenance: unavailable. Searched: Laos artificial intelligence law risk assessment.

Biometric RegimeRed

No biometric-data-specific regime identified.

Absence provenance: unavailable. Searched: Laos biometric data facial recognition law.

Genetic DataRed

No genetic-data-specific regime identified.

Absence provenance: unavailable. Searched: Laos genetic data protection law.

State Surveillance CarveoutsAmber

ICT service licensing conditions and the Cyber Crime Law create investigatory access to user/subscriber data by government authorities, without an identified independent oversight or judicial-authorisation limit in available sources.

Claims (2):

  • Software and Internet Content Center licensees must not disclose users' data except when requested by related government authorities, and must cooperate with monitoring and inspection activities affecting national defence and public security.
  • Law No. 61/NA on Prevention and Combating Cyber Crime (2015) establishes LaoCERT as the national CSIRT and contains procedural rules and international-cooperation measures relevant to state investigatory access to electronic data.
Category narrative66 words

No profiling restriction, automated-decision-making transparency right, AI-specific risk-assessment regime, biometric-data regime, or genetic-data regime was identified for Laos. A state-surveillance carve-out is evidenced indirectly: ICT-licensed operators must not disclose users' data except at the request of relevant government authorities, and the Law on Prevention and Combating Cyber Crime (No. 61/NA, 2015) grants investigatory powers including subscriber and traffic data access, without an identified independent oversight limit.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ConfirmedLao Trade Portal — Software and Internet Content Center licensees must not disclose users' data except when requested by related government authorities, and must cooperate with monitoring and inspection activities affecting national defence and public security.observed
  2. ConfirmedCouncil of Europe — Law No. 61/NA on Prevention and Combating Cyber Crime (2015) establishes LaoCERT as the national CSIRT and contains procedural rules and international-cooperation measures relevant to state investigatory access to electronic data.observed

#

Comprehensive absence of a children/vulnerable-groups data protection regime; explicit gap finding.

Traffic-light rationale — Not assessedComprehensive absence of a children/vulnerable-groups data protection regime; explicit gap finding.

Sub-modules (5)

Age VerificationRed

No age-verification requirement identified.

Absence provenance: unavailable. Searched: Laos age verification online data processing minors.

Minor Profiling BansRed

No minor-profiling ban identified.

Absence provenance: unavailable. Searched: Laos minors profiling ban advertising.

Education SettingsRed

No education-settings-specific data rule identified.

Absence provenance: unavailable. Searched: Laos student data education settings privacy rule.

Dependent AdultsRed

No dependent-adults data protection provision identified.

Absence provenance: unavailable. Searched: Laos dependent adults elderly incapacitated data protection.

Category narrative25 words

No age-of-consent threshold, parental-consent mechanism, minor-profiling ban, education-settings-specific rule, or dependent-adults protection specific to electronic/personal data processing was identified for Laos in available secondary sources.

#

No independent enforcement body, no sourced penalty/redress framework, and no recent developments identified — an explicit, sourced gap.

Primary frameworkLaw on Electronic Data Protection No. 25/NA (12 May 2017) / No. 117/PO (23 June 2017)
Traffic-light rationale — RedNo independent enforcement body, no sourced penalty/redress framework, and no recent developments identified — an explicit, sourced gap.

Sub-modules (6)

Regulator Powers And PenaltiesRed

MTC combines implementation and enforcement functions with no independent DPA; no detailed penalty schedule was located.

Claims (1):

  • MTC itself implements and coordinates enforcement of the electronic data law, per the World Bank's assessment, creating no separation between rule-setter, business-facilitator and enforcer, and Laos has no independent data-protection authority.

Enforcement Activity IndexRed

No documented enforcement actions (fines/decisions) under the electronic data law were identified.

Absence provenance: unavailable. Searched: Laos data protection enforcement action fine decision.

Regulator Funding And CapacityRed

No funding/headcount data for a dedicated DP enforcement function was identified, consistent with the absence of an independent DPA.

Absence provenance: unavailable. Searched: Laos MTC data protection budget staffing capacity.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism for data-protection claims was identified.

Absence provenance: unavailable. Searched: Laos collective redress class action data protection.

Private Right Of ActionRed

No private right of direct court access for data-protection claims was identified.

Absence provenance: unavailable. Searched: Laos private right of action data protection court.

Recent Developments 180DRed

No Laos-specific data-protection legislative, case-law, guidance, or adequacy developments within the last 180 days were identified.

Absence provenance: unavailable. Searched: Laos data protection 2026 amendment personal data law update, Laos data protection news 2025 2026 ASEAN digital economy.

Category narrative69 words

Laos has no independent DPA; MTC both implements and coordinates enforcement of the electronic data law, which the World Bank characterizes as creating no separation between rule-setter, business-facilitator and enforcer. No detailed statutory penalty schedule, collective-redress mechanism, or private right of action specific to data protection was identified. No recent (180-day) legislative, case-law, guidance, or adequacy developments specific to Laos data protection were identified as of the research date.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ConfirmedWorld Bank — MTC itself implements and coordinates enforcement of the electronic data law, per the World Bank's assessment, creating no separation between rule-setter, business-facilitator and enforcer, and Laos has no independent data-protection authority.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct100.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Laos
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 18 claim(s) (18 category placement(s)), 11 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (43 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, cross_border_and_adequacy, sectoral_watch, and algorithmic_biometric_and_surveillance_governance (state_surveillance_carveouts sub-module) rest on T1 (World Bank, Lao Trade Portal, Council of Europe) and T2 (ILO NATLEX, UNECA, Lao Trade Portal sectoral decisions) anchors. data_subject_rights, adtech_and_commercial_privacy, children_and_vulnerable_groups, and most of enforcement_and_redress carry no T1-T3 findings at all and are populated solely with absent_field_provenance narratives, reflecting a genuine, sourced absence of a comprehensive regime rather than a research shortfall. One T3 source (Japan PPC secondary report) was used only as corroborating context, not as the basis for any binding claim.

Unresolved questions (4):

  • Is the core instrument correctly cited as Law No. 25/NA (12 May 2017) or as Law/Decree No. 117/PO (23 June 2017), or are these formally distinct instruments (National Assembly law number vs. presidential promulgation decree number)?
  • Is there an authoritative, gazetted English translation of the Law on Electronic Data Protection and its 2018 implementing Guideline No. 2128 available for direct primary-source verification?
  • Does the 2021 amendment to the Telecommunications Law or any post-2022 instrument materially update the data-protection gaps identified in the World Bank's 2022 assessment?
  • Has Laos taken any steps toward adopting the World Bank's recommended 'data protection law of general application' since 2022?

Escalate to primary-source review: yes