🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
MM v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing4 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Myanmar

MM schema gdpri-v2 trajectory: not yet assessedunregulated gapoverlaps: FIM, WPM, AIC, Crypto

Last updated · 10 categories · 16 claims · 7 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
16Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 25 August 2026.

Lead Signal

Myanmar's 2017 Law Protecting the Privacy and Security of Citizens is the jurisdiction's principal privacy statute. Its core protections in Sections 5, 7 and 8, covering warrantless search, arrest and communications surveillance, were suspended by a February 2021 NDSC/SAC amendment, and this suspension was formally reinstated in August 2025. The correction was surfaced through this cycle's challenger fold process rather than the original baseline research.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No comprehensive DP statute and no general supervisory authority exist; regulatory coverage is fragmented and sector-driven.

Primary frameworkNo omnibus data protection statute; operative instruments are the Law Protecting the Privacy and Security of Citizens (Union Parliament Law 5/2017, amended 2020), the amended Electronic Transactions Law (SAC Law 7/2021), and the Cybersecurity Law (2025).
Traffic-light rationale — RedNo comprehensive DP statute and no general supervisory authority exist; regulatory coverage is fragmented and sector-driven.

Sub-modules (5)

Regulator And AuthorityRed

There is no general data protection authority in Myanmar; oversight functions are dispersed across the Ministry of Transport and Communications (cybersecurity/telecoms), the Central Bank of Myanmar (financial-sector customer data), and general law-enforcement/judicial bodies for privacy-law offences.

Claims (1):

  • Myanmar has no general/omnibus data protection authority; regulatory oversight of personal data is fragmented across sectoral ministries and regulators.

Act And InstrumentsAmber

The principal instruments are the 2017/2020 Privacy Law, the 2021-amended Electronic Transactions Law, and the 2025 Cybersecurity Law.

Claims (3):

  • The Constitution of the Republic of the Union of Myanmar 2008 and the Law Protecting the Privacy and Security of Citizens (Union Parliament Law 5/2017), as amended in 2020, provide the principal non-comprehensive statutory basis for privacy and communications-security protection in Myanmar.
  • The amended Electronic Transactions Law (State Administration Council Law 7/2021), effective 15 February 2021, introduced provisions on the protection of personal data.
  • Myanmar's Cybersecurity Law, enacted in 2025, entered into force on 30 July 2025 and introduces a licensing regime for cybersecurity-service providers and digital-platform operators, together with mandatory Ministry approval for VPN use.

Material ScopeAmber

Material scope of personal-data protection is defined sector-by-sector rather than through a unitary definition.

Claims (1):

  • In the absence of a unitary omnibus definition, the material scope of personal-data protection in Myanmar is delineated through sector-specific statutes, including the Telecommunications Law 2013 and the Financial Institutions Law 2016.

Territorial ScopeRed

No explicit extraterritorial/territorial-scope provision applicable to non-established controllers has been identified in currently available secondary sources.

Absence provenance: unavailable. Searched: unavailable.

Regulator Registration And FilingRed

No general controller registration or filing regime exists absent an omnibus statute or general regulator.

Claims (1):

  • No general controller-registration or filing regime exists in Myanmar in the absence of an omnibus data protection law or general regulator.
Category narrative105 words

Myanmar has no omnibus data protection statute and no dedicated general data protection authority. Privacy-related obligations instead arise from a patchwork of the 2008 Constitution, the Law Protecting the Privacy and Security of Citizens (2017, amended 2020), the amended Electronic Transactions Law (2021), and the newly enacted Cybersecurity Law (2025, effective 30 July 2025), overlaid with sectoral statutes (Telecommunications Law 2013, Financial Institutions Law 2016). A January 2023 draft cybersecurity bill previously circulated by the Ministry of Transport and Communications appears to have culminated in the 2025 Cybersecurity Law, though independent confirmation of textual continuity between the draft and the enacted law was not obtained.

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. UncertainOneTrust DataGuidance — Myanmar has no general/omnibus data protection authority; regulatory oversight of personal data is fragmented across sectoral ministries and regulators.observed
  2. UncertainOneTrust DataGuidance — The Constitution of the Republic of the Union of Myanmar 2008 and the Law Protecting the Privacy and Security of Citizens (Union Parliament Law 5/2017), as amended in 2020, provide the principal non-comprehensive statutory basis for privacy and communications-security protection in Myanmar.observed
  3. UncertainOneTrust DataGuidance — The amended Electronic Transactions Law (State Administration Council Law 7/2021), effective 15 February 2021, introduced provisions on the protection of personal data.observed
  4. UncertainIAPP — Myanmar's Cybersecurity Law, enacted in 2025, entered into force on 30 July 2025 and introduces a licensing regime for cybersecurity-service providers and digital-platform operators, together with mandatory Ministry approval for VPN use.observed
  5. UncertainOneTrust DataGuidance — In the absence of a unitary omnibus definition, the material scope of personal-data protection in Myanmar is delineated through sector-specific statutes, including the Telecommunications Law 2013 and the Financial Institutions Law 2016.observed
  6. UncertainOneTrust DataGuidance — No general controller-registration or filing regime exists in Myanmar in the absence of an omnibus data protection law or general regulator.observed

#

No lawful-bases, consent, special-category, or anonymisation regime found across searched sources.

Traffic-light rationale — Not assessedNo lawful-bases, consent, special-category, or anonymisation regime found across searched sources.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful bases regime identified.

Absence provenance: unavailable. Searched: unavailable.

Special CategoriesRed

No special/sensitive-category data regime identified.

Absence provenance: unavailable. Searched: unavailable.

Pseudonymisation And AnonymisationRed

No pseudonymisation/anonymisation definitions or safe-harbours identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative32 words

No enumerated lawful-basis framework, consent-standard regime, special/sensitive-category classification, or statutory pseudonymisation/anonymisation safe-harbour was identified for Myanmar. This module is emitted as a gap module consistent with the absence of an omnibus statute.

#

No omnibus data-subject-rights regime exists; the Privacy Law addresses communications privacy but not GDPR-style subject rights.

Traffic-light rationale — Not assessedNo omnibus data-subject-rights regime exists; the Privacy Law addresses communications privacy but not GDPR-style subject rights.

Sub-modules (5)

Access RightRed

No general right of access to personal data identified.

Absence provenance: unavailable. Searched: unavailable.

Rectification And ErasureRed

No general rectification/erasure right identified.

Absence provenance: unavailable. Searched: unavailable.

Restriction And ObjectionRed

No restriction/objection right (including profiling opt-out) identified.

Absence provenance: unavailable. Searched: unavailable.

Data PortabilityRed

No portability right identified.

Absence provenance: unavailable. Searched: unavailable.

Deadlines And Response WindowsRed

No statutory controller-response deadlines identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative27 words

No general subject-access, rectification/erasure, restriction/objection, portability, or statutory response-deadline framework was identified for data subjects in Myanmar outside the narrow privacy/communications-security protections of the 2017/2020 Privacy Law.

#

Only a narrow sectoral security duty exists; no general controller/processor accountability framework is in force.

Primary frameworkFinancial Institutions Law 2016 (sectoral security-of-customer-information duty only).
Traffic-light rationale — RedOnly a narrow sectoral security duty exists; no general controller/processor accountability framework is in force.

Sub-modules (7)

Accountability And DpiaRed

No general accountability principle or DPIA trigger exists outside the sectoral financial-institution duty.

Claims (1):

  • In the absence of a general data protection statute, Myanmar imposes no general-purpose DPIA, DPO-appointment, ROPA, or breach-notification obligations on controllers outside the sectoral financial-institution security duty.

Dpo RequirementsRed

No DPO-appointment regime identified.

Absence provenance: unavailable. Searched: unavailable.

Ropa RequirementsRed

No ROPA requirement identified.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsRed

No joint-controller framework identified.

Absence provenance: unavailable. Searched: unavailable.

Security MeasuresAmber

The Financial Institutions Law 2016 imposes a sector-specific customer-information-protection duty functioning as a security-of-processing obligation for regulated financial institutions.

Claims (1):

  • Myanmar's Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific security-of-processing obligation in the absence of a general security-measures regime.

Breach NotificationRed

No general breach-notification regime (regulator or data-subject facing) identified.

Absence provenance: unavailable. Searched: unavailable.

Retention And DisposalRed

No statutory retention limits or disposal duties identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative31 words

Outside a sector-specific customer-information-protection duty under the Financial Institutions Law 2016, Myanmar has no general accountability principle, DPIA trigger, DPO-appointment threshold, ROPA requirement, joint-controller framework, breach-notification regime, or statutory retention/disposal duty.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. UncertainOneTrust DataGuidance — Myanmar's Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific security-of-processing obligation in the absence of a general security-measures regime.observed
  2. UncertainOneTrust DataGuidance — In the absence of a general data protection statute, Myanmar imposes no general-purpose DPIA, DPO-appointment, ROPA, or breach-notification obligations on controllers outside the sectoral financial-institution security duty.observed

#

No cross-border transfer mechanism, adequacy arrangement, or localisation statute identified.

Traffic-light rationale — Not assessedNo cross-border transfer mechanism, adequacy arrangement, or localisation statute identified.

Sub-modules (6)

Transfer MechanismsRed

No codified transfer mechanism (adequacy, SCCs, BCRs, derogations) identified.

Absence provenance: unavailable. Searched: unavailable.

Adequacy ReceivedRed

No adequacy decision received from another regime identified.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedRed

No adequacy decision granted to another regime identified.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsRed

No SCC or BCR uptake/forms identified.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentRed

No TIA requirement identified.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationRed

No absolute or partial data-localisation mandate identified beyond VPN/platform-licensing controls under the 2025 Cybersecurity Law.

Absence provenance: unavailable. Searched: unavailable.

Category narrative52 words

No adequacy decisions have been received from or granted to other regimes, no SCC/BCR framework is codified, no transfer-impact-assessment obligation exists, and no explicit data-localisation mandate was identified for Myanmar. The 2025 Cybersecurity Law's VPN-approval and platform-licensing requirements function as digital-sovereignty-adjacent controls but do not constitute a formal data-transfer or localisation regime.

#

Meaningful sectoral coverage exists for financial and telecoms/cyber, but health, employment, credit-scoring, education, and insurance sub-modules are unpopulated.

Primary frameworkTelecommunications Law 2013; Financial Institutions Law 2016; Cybersecurity Law 2025.
Supervisory authorityMinistry of Transport and Communications
Traffic-light rationale — AmberMeaningful sectoral coverage exists for financial and telecoms/cyber, but health, employment, credit-scoring, education, and insurance sub-modules are unpopulated.

Sub-modules (7)

Financial Sector OverlayAmber

The Financial Institutions Law 2016 mandates protection of customer information by banks and financial institutions; supervisory function rests with the Central Bank of Myanmar (not independently confirmed in this run).

Claims (1):

  • The Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific overlay in the absence of an omnibus data protection statute.

Health Sector OverlayRed

No health-sector-specific data rules identified.

Absence provenance: unavailable. Searched: unavailable.

Telecoms And EprivacyAmber

The Telecommunications Law 2013 addresses confidentiality of subscriber/personal information; the 2025 Cybersecurity Law adds licensing and VPN-approval requirements for cybersecurity-service and digital-platform operators.

Claims (2):

  • The Telecommunications Law 2013 addresses the confidentiality of personal information handled by telecommunications service providers.
  • Myanmar's 2025 Cybersecurity Law imposes Ministry-approval licensing requirements on VPN use and on cybersecurity-service and digital-platform operators exceeding 100,000 users, with licenses valid for three to ten years and criminal penalties for non-compliance.

Employment DataRed

No employment-specific data rules identified.

Absence provenance: unavailable. Searched: unavailable.

Credit And ScoringRed

No credit-scoring-specific rules identified.

Absence provenance: unavailable. Searched: unavailable.

EducationRed

No education-sector-specific data rules identified.

Absence provenance: unavailable. Searched: unavailable.

InsuranceRed

No insurance-sector-specific data rules identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative48 words

Sectoral overlays are the primary source of enforceable data-protection-adjacent duties in Myanmar: the Financial Institutions Law 2016 for banking customer information, the Telecommunications Law 2013 for subscriber confidentiality, and the 2025 Cybersecurity Law for digital-platform/VPN licensing. No dedicated health, employment, credit-scoring, education, or insurance data rules were identified.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — The Financial Institutions Law 2016 mandates that regulated financial institutions protect customer information, operating as a sector-specific overlay in the absence of an omnibus data protection statute.observed
  2. UncertainOneTrust DataGuidance — The Telecommunications Law 2013 addresses the confidentiality of personal information handled by telecommunications service providers.observed
  3. UncertainIAPP — Myanmar's 2025 Cybersecurity Law imposes Ministry-approval licensing requirements on VPN use and on cybersecurity-service and digital-platform operators exceeding 100,000 users, with licenses valid for three to ten years and criminal penalties for non-compliance.observed

#

No adtech/commercial-privacy regulation identified in any searched source.

Traffic-light rationale — Not assessedNo adtech/commercial-privacy regulation identified in any searched source.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent law identified.

Absence provenance: unavailable. Searched: unavailable.

Dark PatternsRed

No dark-pattern prohibition identified.

Absence provenance: unavailable. Searched: unavailable.

Opt Out SignalsRed

No opt-out-signal (GPC/DAA-equivalent) recognition identified.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules identified.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingRed

No cross-context-advertising ('sale'/'share') regime identified.

Absence provenance: unavailable. Searched: unavailable.

Direct MarketingRed

No direct-marketing consent/suppression framework identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative20 words

No cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rule, cross-context-advertising regime, or direct-marketing consent/suppression framework was identified for Myanmar.

#

The only substantive content in this module concerns broadened state-surveillance carve-outs; ADM, biometric, genetic, and AI-risk-assessment sub-modules are unpopulated.

Primary frameworkLaw Protecting the Privacy and Security of Citizens (2017, as amended 2020).
Traffic-light rationale — RedThe only substantive content in this module concerns broadened state-surveillance carve-outs; ADM, biometric, genetic, and AI-risk-assessment sub-modules are unpopulated.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction regime identified.

Absence provenance: unavailable. Searched: unavailable.

Automated Decision Making TransparencyRed

No ADM-transparency right identified.

Absence provenance: unavailable. Searched: unavailable.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime identified.

Absence provenance: unavailable. Searched: unavailable.

Biometric RegimeRed

No biometric-data regime identified.

Absence provenance: unavailable. Searched: unavailable.

Genetic DataRed

No genetic-data regime identified.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsAmber

The 2020 amendment narrowed privacy protections against government interference to apply specifically to 'competent authorities,' and the NDSC separately expanded authority to restrict constitutional rights during martial law.

Claims (2):

  • The 2020 amendment to the Law Protecting the Privacy and Security of Citizens narrowed Section 8 so that its prohibitions on government interference apply specifically to 'competent authorities' acting without an order, permission, or warrant from the President or Union Government, rather than to persons generally.
  • The 2020 amendment narrowed criminal liability under Section 10 of the Privacy Law so that it applies specifically to 'competent authorities' who commit offences under Sections 7 or 8, rather than to persons generally.
Category narrative78 words

No profiling restriction, ADM-transparency right, AI-specific risk-assessment regime, biometric-data regime, or genetic-data regime was identified. State-surveillance carve-outs are, however, evidenced: the 2020 amendment to the Privacy Law narrowed the scope of protection against government interference by confining Section 8 obligations and Section 10 criminal liability to 'competent authorities' acting under presidential/Union Government order, permission, or warrant, and the National Defence and Security Council (NDSC) separately issued an amendment law expanding authority to restrict constitutional rights during martial law.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. UncertainOneTrust DataGuidance — The 2020 amendment to the Law Protecting the Privacy and Security of Citizens narrowed Section 8 so that its prohibitions on government interference apply specifically to 'competent authorities' acting without an order, permission, or warrant from the President or Union Government, rather than to persons generally.observed
  2. UncertainOneTrust DataGuidance — The 2020 amendment narrowed criminal liability under Section 10 of the Privacy Law so that it applies specifically to 'competent authorities' who commit offences under Sections 7 or 8, rather than to persons generally.observed

#

No children/vulnerable-groups data protection regime identified.

Traffic-light rationale — Not assessedNo children/vulnerable-groups data protection regime identified.

Sub-modules (5)

Age VerificationRed

No age-verification requirement identified.

Absence provenance: unavailable. Searched: unavailable.

Minor Profiling BansRed

No minor-profiling ban identified.

Absence provenance: unavailable. Searched: unavailable.

Education SettingsRed

No education-settings-specific rule identified.

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsRed

No dependent-adults protection identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative19 words

No age-of-consent, parental-consent mechanism, minor-profiling ban, education-settings-specific rule, or dependent-adults protection was identified for Myanmar in any reviewed source.

#

Enforcement powers are narrow, sector/criminal-law based, and there is no dedicated DP regulator, enforcement-activity index, or private right of action.

Primary frameworkLaw Protecting the Privacy and Security of Citizens (2017, amended 2020); Cybersecurity Law (2025).
Traffic-light rationale — RedEnforcement powers are narrow, sector/criminal-law based, and there is no dedicated DP regulator, enforcement-activity index, or private right of action.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Criminal penalties exist under both the Privacy Law and the 2025 Cybersecurity Law, but are administered through general courts/ministries rather than a dedicated DP regulator.

Claims (2):

  • Under the Law Protecting the Privacy and Security of Citizens, violations of Sections 7 or 8 are punishable by imprisonment of between six months and three years and a fine of between MMK 300,000 and MMK 1.5 million, with liability narrowed by the 2020 amendment to 'competent authorities' who commit such violations.
  • Myanmar's 2025 Cybersecurity Law provides criminal penalties for operating unlicensed cybersecurity services or digital platforms and for unauthorized VPN use.

Enforcement Activity IndexRed

No enforcement-activity data (fines, decisions) for the last 12 months was identified.

Absence provenance: unavailable. Searched: unavailable.

Regulator Funding And CapacityRed

No dedicated DP regulator exists, so no funding/capacity signals are applicable.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism for data-protection matters identified.

Absence provenance: unavailable. Searched: unavailable.

Private Right Of ActionRed

No explicit private civil right of action for data subjects was identified; the Privacy Law's remedies appear criminal/administrative in nature.

Absence provenance: unavailable. Searched: unavailable.

Recent Developments 180DRed

No material Myanmar data-protection or cybersecurity regulatory development was identified within the 180 days preceding this run (February-August 2026).

Claims (1):

  • No material Myanmar data-protection or cybersecurity regulatory development has been identified within the 180 days preceding this run; the most recent substantive development remains the 30 July 2025 entry into force of the Cybersecurity Law.
Category narrative100 words

Enforcement is criminal/administrative and sector-specific rather than centralised in a data protection authority. The Privacy Law imposes imprisonment and fines for violations of its confidentiality/interference provisions (as narrowed to 'competent authorities' by the 2020 amendment), and the 2025 Cybersecurity Law imposes criminal penalties for unlicensed cybersecurity-service/digital-platform operation and unauthorized VPN use. No enforcement-activity index, dedicated regulator funding/capacity data, collective-redress mechanism, or private right of action was identified. No material Myanmar DP/cybersecurity development was confirmed within the 180 days preceding this run (February-August 2026); the most recent substantive development remains the 30 July 2025 entry into force of the Cybersecurity Law.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — Under the Law Protecting the Privacy and Security of Citizens, violations of Sections 7 or 8 are punishable by imprisonment of between six months and three years and a fine of between MMK 300,000 and MMK 1.5 million, with liability narrowed by the 2020 amendment to 'competent authorities' who commit such violations.observed
  2. UncertainIAPP — Myanmar's 2025 Cybersecurity Law provides criminal penalties for operating unlicensed cybersecurity services or digital platforms and for unauthorized VPN use.observed
  3. UncertainIAPP — No material Myanmar data-protection or cybersecurity regulatory development has been identified within the 180 days preceding this run; the most recent substantive development remains the 30 July 2025 entry into force of the Cybersecurity Law.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct28.57
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Myanmar
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 16 claim(s) (16 category placement(s)), 7 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (34 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Coverage for regulator_and_framework, algorithmic_biometric_and_surveillance_governance (state-surveillance sub-module), sectoral_watch, and enforcement_and_redress rests on T3 legal-intelligence secondary sources (OneTrust DataGuidance, IAPP) rather than direct T1 primary-statute or regulator-portal text, since no official English-language gazette or regulator URL was locatable for Myanmar's instruments (several primary texts are Burmese-only and were not independently retrieved). lawful_processing_and_special_data, data_subject_rights, adtech_and_commercial_privacy, and children_and_vulnerable_groups modules are populated entirely via absent_field_provenance, consistent with the unregulated_gap jurisdiction status, since no comprehensive statute exists to source affirmative claims. cross_border_and_adequacy and most controller_processor_duties sub-modules are likewise gap-populated. The single most material and least-corroborated finding is the 2025 Cybersecurity Law (entry into force 30 July 2025), sourced only from a single IAPP secondary analysis piece; this was marked Probable confidence rather than Confirmed.

Unresolved questions (5):

  • Whether the January 2023 Ministry of Transport and Communications draft cybersecurity bill is textually continuous with the enacted 2025 Cybersecurity Law, or represents a materially amended successor instrument, is unconfirmed.
  • The official Burmese-language text and any implementing notifications/rules issued under the 2025 Cybersecurity Law have not been independently verified beyond secondary (IAPP) reporting.
  • Whether the amended Electronic Transactions Law (2021) has been repealed or superseded by the 2025 Cybersecurity Law, as earlier drafts contemplated, is unconfirmed.
  • No sub-regulations, notifications, or directives issued under Section 14 of the amended Privacy Law (2020) empowering ministries to implement the law were located or reviewed.
  • Whether any Myanmar regulator (e.g., Central Bank of Myanmar, Ministry of Transport and Communications) has issued enforcement decisions or sanctions under the sectoral instruments in the past 12 months is unconfirmed.

Escalate to primary-source review: yes