Cybersecurity Law, digital platform data retention and disclosure duty
Cybersecurity Law, State Administration Council Law No. 1/2025, ss.33-34
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
An enforcement supervision rule binding public and private bodies.
As of 29 August 2026.
What it requires
- Myanmar's Cybersecurity Law creates no data-protection right; it is a state-access duty, not a rights regime. A digital platform service with 100,000 or more Myanmar users must retain personal information of a user, including a voiceprint or faceprint the platform stores, for 3 years and disclose it to an authorised individual or organisation on written request, with no consent, purpose-limitation, or individual-notice duty running the other way. Whether this duty currently binds turns on a presidential commencement notification that has not been independently confirmed, though independent reporting places it in force since 30 July 2025.
If you get it wrong
Private right of actionNo
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Myanmar's Cybersecurity Law (State Administration Council Law No. 1/2025) contains no data-protection framework: its Chapter II definitions define cybersecurity-related terms but no "personal data" or "biometric data" term at all, and the sole use of "personal information" in the entire law is at section 33, which requires a digital platform service provider to retain personal information of a user, usage records, and any data the Department specifies for 3 years, disclosed to an authorised individual or organisation on written request under section 34.
This is a retention and state-access duty, not a protective one: it carries no consent standard, no purpose limitation, no retention ceiling beyond the 3-year floor, and no individual notice or objection right, and it runs toward government access to personal data rather than away from it, reaching a voiceprint or faceprint a covered platform stores exactly like any other user data.
The law's own section 2 commences it only on a date the president appoints by notification; independent trackers converge on State Administration Council Notification No. 113/2025 bringing it into force 30 July 2025, but that notification is not cited here, so this instrument is recorded as enacted rather than in effect.
Enforcement runs through a Central Committee and a Steering Committee on Cybersecurity and a Department with licensing and investigation powers (Chapter III); no private civil right of action exists anywhere in the law's text.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_webtrains_modelsdeploys_chatbot
Read the law
official text
Ministry of Information of Myanmar (moi.gov.mm), which reproduces Chapters I-III (through section 10) of the law verbatim and stops mid-article with "To be continued" sections 33-34 (Chapter 9) are not included in that reproduction. Cross-checked against a Yangon law firm's full-text reproduction (lincolnmyanmar.com), which matches the official copy exactly on every section both cover, for confidence in sections 33-34's own text
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.