Law / Brunei Darussalam

Brunei Darussalam

7 of 12 named instruments researched to a stage, across three of the six areas of law we track: 7 in force. As of 18 September 2026.

When they take effect7 of 7 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 5 instruments (5 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (327 words)

Brunei's Personal Data Protection Order 2025 (Subsidiary Legislation No. S 1/2025), gazetted 8 January 2025, is a comprehensive consent-based regime structurally modelled on Singapore's PDPA.

Its own section 1(1) commences it only on a future date appointed by ministerial notification, not on gazettal, and that notification is Government Gazette No. S 11/2025, in which the Minister of Transport and Infocommunications appoints 1 January 2026 as the commencement date for Parts 3 to 9, section 42, and Schedules 1 to 5 of the Order.

This confirms the substantive duties (consent, data-subject rights, care of personal data, cross-border transfer, breach notification, offences, and the Authority's financial-penalty power under section 37) are in effect from that date. Government Gazette No. S 11/2025's own text says only that it is issued in furtherance to the Notification of commencement immediately before this new Notification, without naming which provisions that earlier notification covers.

By elimination, its Schedule (Parts 3 to 9, section 42, and Schedules 1 to 5) leaves Part 1, Part 2, Part 10 apart from section 42, Part 11, Part 12, and Schedule 6 uncovered, so those are what the earlier notification most plausibly reaches, an inference from what this Schedule omits rather than a reading of either notification's own text.

That earlier notification is not separately located, so section 59's own current commencement, like the rest of Part 12, is recorded as unconfirmed rather than assumed. The Order has a single undifferentiated personal data definition with no sensitive-category tier and no biometric-specific provision, so a voiceprint or faceprint is regulated exactly like any other personal data, and the Order carries no biometric-specific restriction.

A genuine consent-free exemption exists for publicly available personal data, a comparable-protection cross-border transfer standard applies under section 24, and the Order arms a private plaintiff for a Part 4 to 7 contravention under section 59, one of the stronger enforcement postures in this batch, though see the caveat above on section 59's own confirmed commencement date.

Breach notification

Personal Data Protection Order 2025, breach notification

Personal Data Protection Order, 2025 (S 1/2025), Part 7 (ss.25-29)official gazette text, Attorney General's Chambers of Brunei Darussalam (agc.gov.bn), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived January 9, 2026. Publisher's page: https://www.agc.gov.bn/AGC%20Images/LAWS/Gazette_PDF/2025/EN/S%201_2025%20%5BE%5D.pdf

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

Part 7 defines a data breach as notifiable where it results in, or is likely to result in, significant harm to an affected individual, or is or is likely to be of significant scale (section 26), with the specific thresholds left to regulations not read, and an internal-only breach deemed not notifiable.

Section 28 requires the organisation to notify the Authority as soon as practicable and no later than 3 days after assessing that a breach is notifiable, and to notify each affected individual, subject to exceptions where remedial measures make significant harm unlikely or a law enforcement agency or the Authority directs otherwise. This duty reaches a breach involving a voiceprint, faceprint, or other biometric identifier exactly like any other personal data.

Government Gazette No. S 11/2025 confirms the Minister appointed 1 January 2026 as the commencement date for Parts 3 to 9 (which includes Part 7) of the Order, so this duty is in effect from that date.

What it requires

Comprehensive regime

Personal Data Protection Order 2025, comprehensive regime

Personal Data Protection Order, 2025 (S 1/2025), ss.2, 3, 8official gazette text, Attorney General's Chambers of Brunei Darussalam (agc.gov.bn), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived January 9, 2026. Publisher's page: https://www.agc.gov.bn/AGC%20Images/LAWS/Gazette_PDF/2025/EN/S%201_2025%20%5BE%5D.pdf

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

Brunei's Personal Data Protection Order 2025 was made under Article 83(3) of the Constitution and gazetted 8 January 2025, but its own section 1(1) commences it only on a date appointed by ministerial notification, with different provisions able to commence on different dates.

Section 2 defines personal data as any data about an identifiable individual, with no sensitive-category tier, and section 8 (Part 4, Division 1) requires an organisation to obtain consent before collecting, using or disclosing personal data, subject to Schedule 1 and Schedule 2 consent-free bases and Schedule 3 additional bases.

Section 3(2) imposes direct duties on organisations with reduced pass-through duties on data processors, and the Authority for Info-communications Technology Industry of Brunei Darussalam (AITI) administers the Order under Part 2.

Government Gazette No. S 11/2025 confirms the Minister of Transport and Infocommunications appointed 1 January 2026 as the commencement date for Parts 3 to 9 (which includes section 8's consent duty), section 42, and Schedules 1 to 5; sections 2 and 3 sit in Part 1 (Preliminary), whose own commencement is referenced by the same notification as an earlier, separately-appointed date not independently located, though a definitional Part necessarily has practical effect once the Parts that depend on it are in force.

What it requires

Cross border transfer

Personal Data Protection Order 2025, cross-border transfer

Personal Data Protection Order, 2025 (S 1/2025), s.24official gazette text, Attorney General's Chambers of Brunei Darussalam (agc.gov.bn), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived January 9, 2026. Publisher's page: https://www.agc.gov.bn/AGC%20Images/LAWS/Gazette_PDF/2025/EN/S%201_2025%20%5BE%5D.pdf

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

Section 24 bars an organisation from transferring personal data outside Brunei Darussalam except in accordance with prescribed requirements ensuring the receiving country provides protection comparable to the Order's own standard, with the Authority empowered to grant an organisation a case-by-case exemption from any prescribed requirement.

This is a comparable-protection standard structurally identical to Singapore PDPA section 26, not a flat prohibition or a data-localization mandate; the specific prescribed requirements sit in subsidiary regulations not read. This duty reaches any personal data leaving Brunei, including a voiceprint, faceprint, or other biometric identifier processed by a service, since the Order draws no sensitive-category distinction.

Government Gazette No. S 11/2025 confirms the Minister appointed 1 January 2026 as the commencement date for Parts 3 to 9 (which includes Part 6, where section 24 sits) of the Order, so this duty is in effect from that date.

What it requires

Data subject rights

Personal Data Protection Order 2025, data-subject rights

Personal Data Protection Order, 2025 (S 1/2025), ss.18-20official gazette text, Attorney General's Chambers of Brunei Darussalam (agc.gov.bn), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived January 9, 2026. Publisher's page: https://www.agc.gov.bn/AGC%20Images/LAWS/Gazette_PDF/2025/EN/S%201_2025%20%5BE%5D.pdf

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

Part 5 of the Order grants an individual a right of access to personal data an organisation holds about them (section 18) and a right to have inaccurate personal data corrected (section 19), with section 20 allowing either right to be exercised on the individual's behalf, for example by a legal representative.

As with Singapore's PDPA, the Order names no distinct deletion or erasure right and no data-portability provision; access and correction, subject to exceptions listed in Schedules 4 and 5, are the only named statutory rights. These rights reach a voiceprint or faceprint exactly like any other personal data the Order covers, since it draws no sensitive-category or biometric-specific distinction.

Government Gazette No. S 11/2025 confirms the Minister appointed 1 January 2026 as the commencement date for Parts 3 to 9 (which includes Part 5) of the Order, so this Part's rights are in effect from that date.

What it requires

Enforcement supervision

Personal Data Protection Order 2025, enforcement and penalties

Personal Data Protection Order, 2025 (S 1/2025), ss.37, 59official gazette text, Attorney General's Chambers of Brunei Darussalam (agc.gov.bn), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived January 9, 2026. Publisher's page: https://www.agc.gov.bn/AGC%20Images/LAWS/Gazette_PDF/2025/EN/S%201_2025%20%5BE%5D.pdf

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

The Authority for Info-communications Technology Industry of Brunei Darussalam (AITI) is the Order's supervisory authority under Part 2, and section 37 (Part 9) sets financial penalties of up to 10 percent of Brunei annual turnover for an organisation with turnover exceeding 10,000,000 Brunei dollars, or up to 1,000,000 Brunei dollars otherwise, numerically identical to Singapore PDPA section 48J's organisation-tier caps.

Section 59(1) (Part 12, General) gives a person who suffers loss or damage directly from a contravention of Part 4, 5, 6, or 7 a right of action for relief, including injunction, declaration, and damages, in civil proceedings; this does not extend to Part 3 (Accountability).

Separately, Part 8 creates individual criminal offences for unauthorised disclosure, improper use, and unauthorised re-identification of personal data, each carrying fines up to 5,000 Brunei dollars or up to 2 years' imprisonment.

Government Gazette No. S 11/2025 confirms the Minister appointed 1 January 2026 as the commencement date for Parts 3 to 9 of the Order (which includes Part 9's section 37 penalty power) and Schedules 1 to 5; that notification's own text lists only Parts 3 to 9, section 42, and Schedules 1 to 5, and does not name Part 12, so section 59's own private right of action may have commenced on a separate, earlier date under a prior notification that is not located, or may remain pending.

This instrument is recorded as in force on the strength of section 37's confirmed commencement, with section 59's own commencement flagged as unconfirmed rather than assumed.

What it requires

Scraping law1 instrument, 1 in force

Research summary (262 words)

Brunei has no scraping-specific statute, so general law governs each dimension separately.

The Computer Misuse Act (Cap. 194) criminalises securing access to a computer, program, or data ‘without authority’, defined as lacking both the entitlement to control access and the consent of a person who holds that entitlement, a broader authorisation test than one that turns on infringing a technical security measure; no reported Brunei decision addresses whether reading a public, unauthenticated page fits that definition.

No Brunei court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Emergency (Copyright) Order, 1999 permits fair dealing for research and private study, criticism, review, and reporting current events with a sufficient acknowledgement, but its closed list of permitted acts contains no text-and-data-mining or computational-analysis exception, so training a model on scraped Brunei-hosted copyrighted text finds no statutory carve-out distinct from that list.

The Order confers no sui generis database right; its related rights cover sound recordings, films, broadcasts, cable programmes, and published editions, not compilations of data as such.

The Personal Data Protection Order 2025 (researched under the privacy topic) exempts publicly available personal data from its consent duty and holds cross-border transfers to a comparable-protection standard once its Parts 3 to 9 duties took effect on 1 January 2026, so scraping a person's already-public personal data from a Brunei source is not, on that basis alone, a consent violation.

No Brunei statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Computer Misuse Act, unauthorised access to computer material

Computer Misuse Act (Cap. 194, Revised Edition 2007), s. 3 (Unauthorised Access to Computer Material)official consolidated Act text, Attorney General's Chambers of Brunei Darussalam (agc.gov.bn), an Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived January 9, 2026. Publisher's page: https://www.agc.gov.bn/AGC%20Images/LOB/pdf/Computer%20Misuse.pdf

In force since 21 June 2000. Binds public and private bodies.

What this law does

Section 3 prohibits knowingly causing a computer to perform a function for the purpose of securing access, without authority, to a program or data held in any computer, with access being without authority where the person is not entitled to control access of that kind and has no consent from someone who is.

A first conviction carries a fine of up to $5,000 and imprisonment of up to 2 years, or both, rising to $10,000 and 3 years for a second or subsequent conviction, and to $50,000 and 7 years where the offence causes damage (s. 3(2)); where access to a protected computer, one used for defence, a confidential law-enforcement source, essential infrastructure, or public safety, is obtained in the course of this or certain other offences, section 9 substitutes an enhanced penalty of up to $100,000 and 20 years.

The Act's authorisation test turns on entitlement to control access rather than on infringing a technical security measure, and no reported Brunei decision has tested whether reading a public, unauthenticated page fits it.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (209 words)

Brunei has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Emergency (Copyright) Order, 1999's fair dealing exception for criticism, review, and reporting current events (s. 34) is the primary copyright-side answer to an aggregator's reproduction of headlines and snippets, subject to a sufficient-acknowledgement requirement, with no headline-length or short-extract cap and no reported decision testing it against a systematic aggregator.

Neighbouring rights under the Order cover sound recordings, films, broadcasts, and cable programmes, not a print or online publisher's own news reporting, so no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates exists.

The Electronic Transactions Act's section 10 shields a network service provider that merely provides access to third-party electronic records from liability founded on the material's publication or on an infringement of rights in it, though no reported decision has applied it to an aggregator's own reproduction, framing, or linking, as opposed to a conventional access provider, and no statute or case addresses whether a hyperlink is itself a communication to the public.

No hot-news or misappropriation doctrine distinct from ordinary copyright law has been identified, and Brunei's copyright statute predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

Linking and framing

Electronic Transactions Act, liability of network service providers for third-party material

Electronic Transactions Act (Cap. 196, Revised Edition 2008), s. 10 (Liability of Network Service Providers)Electronic Transactions Act (Cap. 196, Revised Edition 2008)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2020. Publisher's page: http://www.agc.gov.bn/AGC%20Images/LOB/PDF/Electronic%20Transactions%20(chp.196).pdf

In force since 1 May 2001. Binds public and private bodies.

What this law does

Section 10(1) shields a network service provider from civil or criminal liability under any rule of law for third-party material in the form of electronic records to which it merely provides access, where that liability is founded on the making, publication, dissemination, or distribution of the material or a statement in it, or on an infringement of rights subsisting in the material.

Section 10(3) defines 'providing access' to mean supplying the necessary technical means by which the material may be accessed, including automatic and temporary storage for that purpose, and defines a 'third party' as a person over whom the provider has no effective control. Section 10(2) preserves any liability founded on contract, on a licensing or regulatory regime, or on a court or statutory order to remove, block, or deny access to material.

No reported Brunei decision has applied section 10 to a news aggregator that reproduces, frames, or links to a publisher's headlines and snippets rather than to a conventional access provider, and no Brunei statute or case addresses whether a hyperlink is itself a communication to the public or whether framing or inline display changes that answer.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.