Not publishable as-is. 1 of 5 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
Myanmar
MMschema gdpri-v2trajectory: not yet assessedunregulated gapoverlaps: FIM, WPM, AIC, Crypto
Last updated · 10 categories · 16
claims · 7 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
16Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Standing brief, as of 25 August 2026.
Lead Signal
Myanmar's 2017 Law Protecting the Privacy and Security of Citizens is the jurisdiction's principal privacy statute. Its core protections in Sections 5, 7 and 8, covering warrantless search, arrest and communications surveillance, were suspended by a February 2021 NDSC/SAC amendment, and this suspension was formally reinstated in August 2025. The correction was surfaced through this cycle's challenger fold process rather than the original baseline research.
Other Developments
Myanmar is understood to lack a general, omnibus data protection authority. Its personal-data scope appears to be delineated through sector-specific statutes, including the Telecommunications Law of 2013 and the Financial Institutions Law of 2016, rather than a unitary omnibus definition. The Telecommunications Law is understood to address confidentiality of personal information handled by telecommunications service providers. The Financial Institutions Law is understood to mandate that regulated financial institutions protect customer information, reported as the only concrete general security-of-processing duty identified for the jurisdiction. Myanmar is understood to impose no general-purpose DPIA, DPO-appointment, ROPA, or breach-notification obligations on controllers outside that sectoral duty. The jurisdiction is also understood to lack a general controller-registration or filing regime.
The amended Electronic Transactions Law is understood to have introduced provisions on the protection of personal data, effective 15 February 2021. A Cybersecurity Law is reported to have entered into force on 30 July 2025, introducing a licensing regime for cybersecurity-service providers and digital-platform operators alongside a requirement for Ministry approval before VPN use. That licensing regime is reported to apply to platforms and services exceeding 100,000 users, with licences valid for three to ten years. Non-compliance, including unlicensed operation or unauthorized VPN use, is reported to carry criminal penalties under the same law.
Separately, violations of Sections 7 or 8 of the Privacy Law are reported to carry imprisonment of six months to three years and a fine of MMK 300,000 to 1.5 million, with liability narrowed by a 2020 amendment to apply only to 'competent authorities.' That 2020 amendment is reported to have narrowed Section 8's prohibitions on government interference to apply only to competent authorities acting without presidential or Union Government order, permission or warrant. The same amendment is reported to have narrowed Section 10 criminal liability on the same basis. No material development in Myanmar's data-protection or cybersecurity regulation is reported within the 180 days preceding this cycle, with the most recent substantive development remaining the Cybersecurity Law's 30 July 2025 entry into force.
Confidence across nearly all of these findings is capped at a qualified register, since most rest on single-source secondary compilations without independent corroboration.
Cross-Monitor Connections
The Financial Institutions Law's customer-information duty is flagged for the financial-integrity monitor's illicit-finance and AML-CFT risk assessment of Myanmar, and for the world-payments monitor as a payments-adjacent sectoral duty. The Cybersecurity Law's VPN-approval and platform-licensing regime is flagged for the crypto monitor as a control that may affect exchanges or platforms serving Myanmar users. It is also flagged for the artificial-intelligence monitor, given the absence of any AI-specific risk-assessment or automated-decision-making transparency regime in Myanmar, against a backdrop of broader regional ASEAN AI-governance developments tracked elsewhere.
Outlook
Myanmar's regulatory trajectory is assessed as tightening, driven by the reinstated suspension of core Privacy Law protections and the newly-in-force Cybersecurity Law licensing regime. Both developments point toward an operating environment of expanding state control over communications and platform access, layered onto a jurisdiction that still lacks a general data protection statute or authority. The baseline rests entirely on secondary-compilation and challenger-supplied sources rather than official Burmese-language primary text, a gap the monitor flags for verification in future cycles.
trust tier: ai_unverified
Standing brief, as of 25 August 2026.
Regulatory Status
The 2017 Law Protecting the Privacy and Security of Citizens nominally remains the principal statutory basis for privacy and communications-security protection, but its core provisions in Sections 5, 7 and 8 were suspended by a February 2021 NDSC/SAC amendment, and that suspension was formally reinstated in August 2025. Myanmar is understood to lack a general, omnibus data protection authority. Its personal-data scope appears to be delineated through sector-specific statutes, including the Telecommunications Law of 2013 and the Financial Institutions Law of 2016, rather than a unitary omnibus definition. The jurisdiction is also understood to lack a general controller-registration or filing regime. The Financial Institutions Law is understood to mandate that regulated financial institutions protect customer information, reported as the only concrete general security-of-processing duty identified for the jurisdiction. Myanmar is understood to impose no general-purpose DPIA, DPO-appointment, ROPA, or breach-notification obligations on controllers outside that sectoral duty. The Telecommunications Law is understood to address confidentiality of personal information handled by telecommunications service providers. The amended Electronic Transactions Law is understood to have introduced provisions on the protection of personal data, effective 15 February 2021. A Cybersecurity Law is reported to have entered into force on 30 July 2025, introducing a licensing regime for cybersecurity-service providers and digital-platform operators alongside a requirement for Ministry approval before VPN use. The 2025 Cybersecurity Law is reported to impose Ministry-approval licensing requirements on VPN use and on cybersecurity-service and digital-platform operators exceeding 100,000 users, with licences valid for three to ten years, and criminal penalties for non-compliance. A 2020 amendment to the Privacy Law is reported to have narrowed Section 8's prohibitions on government interference to apply only to competent authorities acting without presidential or Union Government order, permission or warrant. The same amendment is reported to have narrowed Section 10 criminal liability to apply only to competent authorities committing offences under Sections 7 or 8. Violations of Sections 7 or 8 of the Privacy Law are reported to carry imprisonment of six months to three years and a fine of MMK 300,000 to 1.5 million, with liability narrowed by a 2020 amendment to apply only to 'competent authorities.' The 2025 Cybersecurity Law is reported to provide criminal penalties for operating unlicensed cybersecurity services or digital platforms and for unauthorized VPN use. No material development in Myanmar's data-protection or cybersecurity regulation is reported within the 180 days preceding this cycle, with the most recent substantive development remaining the Cybersecurity Law's 30 July 2025 entry into force.
Outlook
Myanmar's overall regulatory risk posture is assessed as high and tightening, driven by the reinstated suspension of core Privacy Law protections and the newly-in-force Cybersecurity Law licensing and VPN-approval regime, against a backdrop of no dedicated data protection authority or omnibus statute. This baseline is sourced entirely from secondary-compilation and challenger-supplied sources, with no official Burmese-language gazette or regulator-portal primary text independently retrieved; military-regime jurisdictions with non-English-primary-source legal texts are flagged as a systematic under-indexing risk for this monitor.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
No comprehensive DP statute and no general supervisory authority exist; regulatory coverage is fragmented and sector-driven.
Primary frameworkNo omnibus data protection statute; operative instruments are the Law Protecting the Privacy and Security of Citizens (Union Parliament Law 5/2017, amended 2020), the amended Electronic Transactions Law (SAC Law 7/2021), and the Cybersecurity Law (2025).
Traffic-light rationale — RedNo comprehensive DP statute and no general supervisory authority exist; regulatory coverage is fragmented and sector-driven.
Sub-modules (5)
Regulator And AuthorityRed
There is no general data protection authority in Myanmar; oversight functions are dispersed across the Ministry of Transport and Communications (cybersecurity/telecoms), the Central Bank of Myanmar (financial-sector customer data), and general law-enforcement/judicial bodies for privacy-law offences.
Claims (1):
Myanmar has no general/omnibus data protection authority; regulatory oversight of personal data is fragmented across sectoral ministries and regulators.
Act And InstrumentsAmber
The principal instruments are the 2017/2020 Privacy Law, the 2021-amended Electronic Transactions Law, and the 2025 Cybersecurity Law.
Claims (3):
The Constitution of the Republic of the Union of Myanmar 2008 and the Law Protecting the Privacy and Security of Citizens (Union Parliament Law 5/2017), as amended in 2020, provide the principal non-comprehensive statutory basis for privacy and communications-security protection in Myanmar.
The amended Electronic Transactions Law (State Administration Council Law 7/2021), effective 15 February 2021, introduced provisions on the protection of personal data.
Myanmar's Cybersecurity Law, enacted in 2025, entered into force on 30 July 2025 and introduces a licensing regime for cybersecurity-service providers and digital-platform operators, together with mandatory Ministry approval for VPN use.
Material ScopeAmber
Material scope of personal-data protection is defined sector-by-sector rather than through a unitary definition.
Claims (1):
In the absence of a unitary omnibus definition, the material scope of personal-data protection in Myanmar is delineated through sector-specific statutes, including the Telecommunications Law 2013 and the Financial Institutions Law 2016.
Territorial ScopeRed
No explicit extraterritorial/territorial-scope provision applicable to non-established controllers has been identified in currently available secondary sources.
No general controller registration or filing regime exists absent an omnibus statute or general regulator.
Claims (1):
No general controller-registration or filing regime exists in Myanmar in the absence of an omnibus data protection law or general regulator.
Category narrative105 words
Myanmar has no omnibus data protection statute and no dedicated general data protection authority. Privacy-related obligations instead arise from a patchwork of the 2008 Constitution, the Law Protecting the Privacy and Security of Citizens (2017, amended 2020), the amended Electronic Transactions Law (2021), and the newly enacted Cybersecurity Law (2025, effective 30 July 2025), overlaid with sectoral statutes (Telecommunications Law 2013, Financial Institutions Law 2016). A January 2023 draft cybersecurity bill previously circulated by the Ministry of Transport and Communications appears to have culminated in the 2025 Cybersecurity Law, though independent confirmation of textual continuity between the draft and the enacted law was not obtained.
no periodic updates on record for this sub-brief
Sources and claims (6)
UncertainOneTrust DataGuidance — Myanmar has no general/omnibus data protection authority; regulatory oversight of personal data is fragmented across sectoral ministries and regulators.observed
UncertainOneTrust DataGuidance — The Constitution of the Republic of the Union of Myanmar 2008 and the Law Protecting the Privacy and Security of Citizens (Union Parliament Law 5/2017), as amended in 2020, provide the principal non-comprehensive statutory basis for privacy and communications-security protection in Myanmar.observed
UncertainOneTrust DataGuidance — The amended Electronic Transactions Law (State Administration Council Law 7/2021), effective 15 February 2021, introduced provisions on the protection of personal data.observed
UncertainIAPP — Myanmar's Cybersecurity Law, enacted in 2025, entered into force on 30 July 2025 and introduces a licensing regime for cybersecurity-service providers and digital-platform operators, together with mandatory Ministry approval for VPN use.observed
UncertainOneTrust DataGuidance — In the absence of a unitary omnibus definition, the material scope of personal-data protection in Myanmar is delineated through sector-specific statutes, including the Telecommunications Law 2013 and the Financial Institutions Law 2016.observed
UncertainOneTrust DataGuidance — No general controller-registration or filing regime exists in Myanmar in the absence of an omnibus data protection law or general regulator.observed
No enumerated lawful-basis framework, consent-standard regime, special/sensitive-category classification, or statutory pseudonymisation/anonymisation safe-harbour was identified for Myanmar. This module is emitted as a gap module consistent with the absence of an omnibus statute.
No omnibus data-subject-rights regime exists; the Privacy Law addresses communications privacy but not GDPR-style subject rights.
Traffic-light rationale — Not assessedNo omnibus data-subject-rights regime exists; the Privacy Law addresses communications privacy but not GDPR-style subject rights.
Sub-modules (5)
Access RightRed
No general right of access to personal data identified.
No general subject-access, rectification/erasure, restriction/objection, portability, or statutory response-deadline framework was identified for data subjects in Myanmar outside the narrow privacy/communications-security protections of the 2017/2020 Privacy Law.
Only a narrow sectoral security duty exists; no general controller/processor accountability framework is in force.
Primary frameworkFinancial Institutions Law 2016 (sectoral security-of-customer-information duty only).
Traffic-light rationale — RedOnly a narrow sectoral security duty exists; no general controller/processor accountability framework is in force.
Sub-modules (7)
Accountability And DpiaRed
No general accountability principle or DPIA trigger exists outside the sectoral financial-institution duty.
Claims (1):
In the absence of a general data protection statute, Myanmar imposes no general-purpose DPIA, DPO-appointment, ROPA, or breach-notification obligations on controllers outside the sectoral financial-institution security duty.
The Financial Institutions Law 2016 imposes a sector-specific customer-information-protection duty functioning as a security-of-processing obligation for regulated financial institutions.
Claims (1):
Myanmar's Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific security-of-processing obligation in the absence of a general security-measures regime.
Breach NotificationRed
No general breach-notification regime (regulator or data-subject facing) identified.
Outside a sector-specific customer-information-protection duty under the Financial Institutions Law 2016, Myanmar has no general accountability principle, DPIA trigger, DPO-appointment threshold, ROPA requirement, joint-controller framework, breach-notification regime, or statutory retention/disposal duty.
no periodic updates on record for this sub-brief
Sources and claims (2)
UncertainOneTrust DataGuidance — Myanmar's Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific security-of-processing obligation in the absence of a general security-measures regime.observed
UncertainOneTrust DataGuidance — In the absence of a general data protection statute, Myanmar imposes no general-purpose DPIA, DPO-appointment, ROPA, or breach-notification obligations on controllers outside the sectoral financial-institution security duty.observed
No adequacy decisions have been received from or granted to other regimes, no SCC/BCR framework is codified, no transfer-impact-assessment obligation exists, and no explicit data-localisation mandate was identified for Myanmar. The 2025 Cybersecurity Law's VPN-approval and platform-licensing requirements function as digital-sovereignty-adjacent controls but do not constitute a formal data-transfer or localisation regime.
Meaningful sectoral coverage exists for financial and telecoms/cyber, but health, employment, credit-scoring, education, and insurance sub-modules are unpopulated.
Primary frameworkTelecommunications Law 2013; Financial Institutions Law 2016; Cybersecurity Law 2025.
Supervisory authorityMinistry of Transport and Communications
Traffic-light rationale — AmberMeaningful sectoral coverage exists for financial and telecoms/cyber, but health, employment, credit-scoring, education, and insurance sub-modules are unpopulated.
Sub-modules (7)
Financial Sector OverlayAmber
The Financial Institutions Law 2016 mandates protection of customer information by banks and financial institutions; supervisory function rests with the Central Bank of Myanmar (not independently confirmed in this run).
Claims (1):
The Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific overlay in the absence of an omnibus data protection statute.
The Telecommunications Law 2013 addresses confidentiality of subscriber/personal information; the 2025 Cybersecurity Law adds licensing and VPN-approval requirements for cybersecurity-service and digital-platform operators.
Claims (2):
The Telecommunications Law 2013 addresses the confidentiality of personal information handled by telecommunications service providers.
Myanmar's 2025 Cybersecurity Law imposes Ministry-approval licensing requirements on VPN use and on cybersecurity-service and digital-platform operators exceeding 100,000 users, with licenses valid for three to ten years and criminal penalties for non-compliance.
Sectoral overlays are the primary source of enforceable data-protection-adjacent duties in Myanmar: the Financial Institutions Law 2016 for banking customer information, the Telecommunications Law 2013 for subscriber confidentiality, and the 2025 Cybersecurity Law for digital-platform/VPN licensing. No dedicated health, employment, credit-scoring, education, or insurance data rules were identified.
no periodic updates on record for this sub-brief
Sources and claims (3)
UncertainOneTrust DataGuidance — The Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific overlay in the absence of an omnibus data protection statute.observed
UncertainOneTrust DataGuidance — The Telecommunications Law 2013 addresses the confidentiality of personal information handled by telecommunications service providers.observed
UncertainIAPP — Myanmar's 2025 Cybersecurity Law imposes Ministry-approval licensing requirements on VPN use and on cybersecurity-service and digital-platform operators exceeding 100,000 users, with licenses valid for three to ten years and criminal penalties for non-compliance.observed
No cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rule, cross-context-advertising regime, or direct-marketing consent/suppression framework was identified for Myanmar.
The only substantive content in this module concerns broadened state-surveillance carve-outs; ADM, biometric, genetic, and AI-risk-assessment sub-modules are unpopulated.
Primary frameworkLaw Protecting the Privacy and Security of Citizens (2017, as amended 2020).
Traffic-light rationale — RedThe only substantive content in this module concerns broadened state-surveillance carve-outs; ADM, biometric, genetic, and AI-risk-assessment sub-modules are unpopulated.
The 2020 amendment narrowed privacy protections against government interference to apply specifically to 'competent authorities,' and the NDSC separately expanded authority to restrict constitutional rights during martial law.
Claims (2):
The 2020 amendment to the Law Protecting the Privacy and Security of Citizens narrowed Section 8 so that its prohibitions on government interference apply specifically to 'competent authorities' acting without an order, permission, or warrant from the President or Union Government, rather than to persons generally.
The 2020 amendment narrowed criminal liability under Section 10 of the Privacy Law so that it applies specifically to 'competent authorities' who commit offences under Sections 7 or 8, rather than to persons generally.
Category narrative78 words
No profiling restriction, ADM-transparency right, AI-specific risk-assessment regime, biometric-data regime, or genetic-data regime was identified. State-surveillance carve-outs are, however, evidenced: the 2020 amendment to the Privacy Law narrowed the scope of protection against government interference by confining Section 8 obligations and Section 10 criminal liability to 'competent authorities' acting under presidential/Union Government order, permission, or warrant, and the National Defence and Security Council (NDSC) separately issued an amendment law expanding authority to restrict constitutional rights during martial law.
no periodic updates on record for this sub-brief
Sources and claims (2)
UncertainOneTrust DataGuidance — The 2020 amendment to the Law Protecting the Privacy and Security of Citizens narrowed Section 8 so that its prohibitions on government interference apply specifically to 'competent authorities' acting without an order, permission, or warrant from the President or Union Government, rather than to persons generally.observed
UncertainOneTrust DataGuidance — The 2020 amendment narrowed criminal liability under Section 10 of the Privacy Law so that it applies specifically to 'competent authorities' who commit offences under Sections 7 or 8, rather than to persons generally.observed
No age-of-consent, parental-consent mechanism, minor-profiling ban, education-settings-specific rule, or dependent-adults protection was identified for Myanmar in any reviewed source.
Enforcement powers are narrow, sector/criminal-law based, and there is no dedicated DP regulator, enforcement-activity index, or private right of action.
Primary frameworkLaw Protecting the Privacy and Security of Citizens (2017, amended 2020); Cybersecurity Law (2025).
Traffic-light rationale — RedEnforcement powers are narrow, sector/criminal-law based, and there is no dedicated DP regulator, enforcement-activity index, or private right of action.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
Criminal penalties exist under both the Privacy Law and the 2025 Cybersecurity Law, but are administered through general courts/ministries rather than a dedicated DP regulator.
Claims (2):
Under the Law Protecting the Privacy and Security of Citizens, violations of Sections 7 or 8 are punishable by imprisonment of between six months and three years and a fine of between MMK 300,000 and MMK 1.5 million, with liability narrowed by the 2020 amendment to 'competent authorities' who commit such violations.
Myanmar's 2025 Cybersecurity Law provides criminal penalties for operating unlicensed cybersecurity services or digital platforms and for unauthorized VPN use.
Enforcement Activity IndexRed
No enforcement-activity data (fines, decisions) for the last 12 months was identified.
No material Myanmar data-protection or cybersecurity regulatory development was identified within the 180 days preceding this run (February-August 2026).
Claims (1):
No material Myanmar data-protection or cybersecurity regulatory development has been identified within the 180 days preceding this run; the most recent substantive development remains the 30 July 2025 entry into force of the Cybersecurity Law.
Category narrative100 words
Enforcement is criminal/administrative and sector-specific rather than centralised in a data protection authority. The Privacy Law imposes imprisonment and fines for violations of its confidentiality/interference provisions (as narrowed to 'competent authorities' by the 2020 amendment), and the 2025 Cybersecurity Law imposes criminal penalties for unlicensed cybersecurity-service/digital-platform operation and unauthorized VPN use. No enforcement-activity index, dedicated regulator funding/capacity data, collective-redress mechanism, or private right of action was identified. No material Myanmar DP/cybersecurity development was confirmed within the 180 days preceding this run (February-August 2026); the most recent substantive development remains the 30 July 2025 entry into force of the Cybersecurity Law.
no periodic updates on record for this sub-brief
Sources and claims (3)
UncertainOneTrust DataGuidance — Under the Law Protecting the Privacy and Security of Citizens, violations of Sections 7 or 8 are punishable by imprisonment of between six months and three years and a fine of between MMK 300,000 and MMK 1.5 million, with liability narrowed by the 2020 amendment to 'competent authorities' who commit such violations.observed
UncertainIAPP — Myanmar's 2025 Cybersecurity Law provides criminal penalties for operating unlicensed cybersecurity services or digital platforms and for unauthorized VPN use.observed
UncertainIAPP — No material Myanmar data-protection or cybersecurity regulatory development has been identified within the 180 days preceding this run; the most recent substantive development remains the 30 July 2025 entry into force of the Cybersecurity Law.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 1 failing check(s).
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
28.57
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Myanmar
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 16 claim(s) (16 category placement(s)), 7 source(s) in the cumulative register.
Coverage for regulator_and_framework, algorithmic_biometric_and_surveillance_governance (state-surveillance sub-module), sectoral_watch, and enforcement_and_redress rests on T3 legal-intelligence secondary sources (OneTrust DataGuidance, IAPP) rather than direct T1 primary-statute or regulator-portal text, since no official English-language gazette or regulator URL was locatable for Myanmar's instruments (several primary texts are Burmese-only and were not independently retrieved). lawful_processing_and_special_data, data_subject_rights, adtech_and_commercial_privacy, and children_and_vulnerable_groups modules are populated entirely via absent_field_provenance, consistent with the unregulated_gap jurisdiction status, since no comprehensive statute exists to source affirmative claims. cross_border_and_adequacy and most controller_processor_duties sub-modules are likewise gap-populated. The single most material and least-corroborated finding is the 2025 Cybersecurity Law (entry into force 30 July 2025), sourced only from a single IAPP secondary analysis piece; this was marked Probable confidence rather than Confirmed.
Unresolved questions (5):
Whether the January 2023 Ministry of Transport and Communications draft cybersecurity bill is textually continuous with the enacted 2025 Cybersecurity Law, or represents a materially amended successor instrument, is unconfirmed.
The official Burmese-language text and any implementing notifications/rules issued under the 2025 Cybersecurity Law have not been independently verified beyond secondary (IAPP) reporting.
Whether the amended Electronic Transactions Law (2021) has been repealed or superseded by the 2025 Cybersecurity Law, as earlier drafts contemplated, is unconfirmed.
No sub-regulations, notifications, or directives issued under Section 14 of the amended Privacy Law (2020) empowering ministries to implement the law were located or reviewed.
Whether any Myanmar regulator (e.g., Central Bank of Myanmar, Ministry of Transport and Communications) has issued enforcement decisions or sanctions under the sectoral instruments in the past 12 months is unconfirmed.