Law / Cambodia

Cambodia

10 of 14 named instruments researched to a stage, across three of the six areas of law we track: 4 in force and 6 proposed. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 proposed

Research summary (149 words)

Cambodia has no comprehensive personal-data-protection law in force. The Draft Law on Personal Data Protection reached a final version dated 23 June 2025 from the Ministry of Post and Telecommunications, but its own text carries an unsigned, undated National Assembly signature block, and the Ministry's own website confirmed as recently as 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage, so it is recorded here as proposed, not in force.

A widely circulated report that Cambodia "passed" a data protection law was traced to Voice of Vietnam coverage of Vietnam's own Law on Personal Data Protection and is not repeated here.

If enacted as currently drafted, the law would create a General Data Protection Regulation (GDPR)-shaped comprehensive regime naming biometric data, including facial images, as a sensitive category, a full data-subject rights chapter, a permission-or-safeguards cross-border transfer standard, and 72-hour breach notification to the Ministry, none of which currently binds.

Breach notification

Cambodia's Draft Law on Personal Data Protection, personal data breach notification

Draft Law on Personal Data Protection, articles 21-22 (personal data breach notification)official draft text, Ministry of Post and Telecommunications (published via Open Development Cambodia), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 5, 2025. Publisher's page: https://data.opendevelopmentcambodia.net/en/dataset/792fc94d-1a84-49cc-bad3-9b420f99b70f/resource/03e9c060-9bc8-42d5-80a6-8db777f61d1c/downl…

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Article 21 would require a data controller to notify the Ministry of Post and Telecommunications of a personal data breach that may pose a risk to a data subject or other natural person immediately, but no later than 72 hours from becoming aware of it, or to give the Ministry valid reasons where it could not meet that deadline.

Article 22 would separately require a data controller to notify the affected data subject immediately upon becoming aware of a breach that may pose a high risk to their rights and freedoms, unless the controller had already secured the affected data with measures such as encryption, had taken subsequent steps removing the high risk, or notifying each data subject individually would be disproportionately burdensome, in which case a public notice would serve instead; even then, the Ministry could still require notice to the data subject where it considered the breach a high risk.

The glossary defines a data breach as an incident in which personal data was accessed, disclosed, or stolen without authorization. The draft's own final page carries an unsigned, undated National Assembly signature block. The Ministry of Post and Telecommunications' own website confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage, so nothing in this row binds anyone today.

What it requires

Comprehensive regime

Draft Law on Personal Data Protection, final draft

Draft Law on Personal Data Protection (Final Draft, 23 June 2025) articles 1-13, 15-20, 24-25 and 37-39 (general provisions, principles and lawful basis, controller and processor obligations, security of processing, data protection officer, and guidelines)official draft text, Ministry of Post and Telecommunications (published via Open Development Cambodia), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 5, 2025. Publisher's page: https://data.opendevelopmentcambodia.net/en/dataset/792fc94d-1a84-49cc-bad3-9b420f99b70f/resource/03e9c060-9bc8-42d5-80a6-8db777f61d1c/downl…

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Article 2 would apply the draft to the processing of personal data by a data controller or processor located in Cambodia, and to one located outside Cambodia that supplies goods or services to, or monitors, a data subject residing there, excluding a public authority acting within its jurisdiction and a natural person acting only for personal or household activities.

Article 7 would require one of six legal bases, including the data subject's consent, before processing personal data, and Article 8 would require the verified consent of a parent or guardian before processing the personal data of a data subject under the age of 16.

Article 15 would require personal data protection by design and by default, Article 16 would require a controller or processor located outside Cambodia to appoint a local representative, and Article 17 would require a written contract between a controller and a processor.

Article 18 would require records of processing activities, Article 19 a personal data impact assessment where processing may pose a high risk, and Article 20 technical and organizational measures to secure personal data against unauthorized access, loss, or destruction. Article 24 would require a data protection officer, notified to the Ministry of Post and Telecommunications within 30 working days of appointment.

The draft's own final page carries an unsigned, undated National Assembly signature block. The Ministry of Post and Telecommunications' own website confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage, so nothing in this row binds anyone today.

What it requires

Cross border transfer

Cambodia's Draft Law on Personal Data Protection, cross-border data transfer

Draft Law on Personal Data Protection, article 23 (data transfer outside Cambodia)official draft text, Ministry of Post and Telecommunications (published via Open Development Cambodia), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 5, 2025. Publisher's page: https://data.opendevelopmentcambodia.net/en/dataset/792fc94d-1a84-49cc-bad3-9b420f99b70f/resource/03e9c060-9bc8-42d5-80a6-8db777f61d1c/downl…

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Article 23 would bar a data controller from transferring personal data outside Cambodia unless the Ministry of Post and Telecommunications grants permission, the controller assesses that appropriate safeguards are in place, or the transfer rests on one of six listed circumstances, including the data subject's written consent, the necessity of performing a contract with the data subject, or the protection of the data subject's or another person's life.

A controller relying on the safeguards or listed-circumstance grounds would have to be able to provide the Ministry with evidence of them. The draft's own final page carries an unsigned, undated National Assembly signature block. The Ministry of Post and Telecommunications' own website confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage, so nothing in this row binds anyone today.

What it requires

Data subject rights

Cambodia's Draft Law on Personal Data Protection, rights of data subjects

Draft Law on Personal Data Protection, articles 26-36 (rights of data subjects)official draft text, Ministry of Post and Telecommunications (published via Open Development Cambodia), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 5, 2025. Publisher's page: https://data.opendevelopmentcambodia.net/en/dataset/792fc94d-1a84-49cc-bad3-9b420f99b70f/resource/03e9c060-9bc8-42d5-80a6-8db777f61d1c/downl…

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Chapter 6 would carry the rights of data subjects: article 27 a right to information before processing, article 28 a right to access, article 29 a right to rectification, article 30 a right to erasure, article 31 a right to restriction, article 32 a right to portability, and article 33 a right to object, with an absolute right to object where processing is used entirely for direct marketing.

Article 26 would require a data controller to act on a data subject's request without undue delay and generally within one month. Article 34 would give a data subject the right to request human involvement where an automated decision, including profiling, produces a legal effect or similarly affects them, subject to exceptions for a contract's performance, a specific legal authorization, or the data subject's own explicit consent.

The draft's own final page carries an unsigned, undated National Assembly signature block. The Ministry of Post and Telecommunications' own website confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage, so nothing in this row binds anyone today.

What it requires

Enforcement supervision

Cambodia's Draft Law on Personal Data Protection, enforcement and penalties

Draft Law on Personal Data Protection, chapters 2, 8-10 (competent institution, inspection, dispute resolution and penalties)official draft text, Ministry of Post and Telecommunications (published via Open Development Cambodia), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 5, 2025. Publisher's page: https://data.opendevelopmentcambodia.net/en/dataset/792fc94d-1a84-49cc-bad3-9b420f99b70f/resource/03e9c060-9bc8-42d5-80a6-8db777f61d1c/downl…

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Article 4 would make the Ministry of Post and Telecommunications the competent institution for personal data protection, empowered to regulate, audit, and monitor compliance, instruct a controller or processor to provide personal data or information, access personal data and information it needs, and receive complaints and mediate disputes.

Article 40 would let the Ministry appoint personal data inspectors with judicial police status to investigate and suppress offenses, and article 45 would let a disputing party bring a complaint to the Ministry, which would appoint a conciliator.

Article 48 would set administrative fines of up to 60,000,000 Riels for a natural person or up to the greater of 600,000,000 Riels or 10 percent of annual turnover for a legal person for noncompliance with the draft's chapters on processing, controller and processor obligations, the data protection officer, or data subject rights.

Article 51 would additionally punish a repeat natural-person offender with imprisonment from 6 days to 2 years and a fine of up to 60,000,000 Riels, and a repeat legal-person offender with a fine of up to 100,000,000 Riels. The draft's own final page carries an unsigned, undated National Assembly signature block.

The Ministry of Post and Telecommunications' own website confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage, so nothing in this row binds anyone today.

What it requires

Sensitive categories

Cambodia's Draft Law on Personal Data Protection, sensitive personal data

Draft Law on Personal Data Protection, article 14 (sensitive personal data)official draft text, Ministry of Post and Telecommunications (published via Open Development Cambodia), Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 5, 2025. Publisher's page: https://data.opendevelopmentcambodia.net/en/dataset/792fc94d-1a84-49cc-bad3-9b420f99b70f/resource/03e9c060-9bc8-42d5-80a6-8db777f61d1c/downl…

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Article 14 would prohibit the processing of sensitive personal data unless a data controller both has a legal basis under article 7 and meets one of nine additional listed conditions, beginning with the data subject's explicit consent.

The glossary defines sensitive personal data as personal data revealing racial origin, political opinions, religious or philosophical beliefs, or trade union membership, biometric data, genetic data, health data, and data concerning a natural person's sex life or sexual orientation.

It defines biometric data as personal data resulting from technical processing relating to an individual's physical, physiological, or behavioural characteristics from which they can be identified, giving a facial image or fingerprints as examples. The draft's own final page carries an unsigned, undated National Assembly signature block.

The Ministry of Post and Telecommunications' own website confirmed on 5 August 2026 that the draft remained at a pre-legislative validation-workshop stage, so nothing in this row binds anyone today.

What it requires

Scraping law3 instruments, 3 in force

Research summary (252 words)

Cambodia has no scraping-specific statute, so general law governs each dimension separately. The Criminal Code of the Kingdom of Cambodia (2009) criminalizes fraudulently accessing or maintaining access to an automated data processing system at Articles 427 to 430, without a security-measure-infringement threshold comparable to Kenya's or Indonesia's computer-misuse statutes, and no reported case addresses whether reading a public, unauthenticated page satisfies the "fraudulent access" standard.

No Cambodian court has ruled on the enforceability of a browsewrap or clickwrap terms of service against a scraper. The Law on Copyright and Related Rights (2003) protects a compilation of data in a database as a derivative work and expressly excludes a substantial part of a digital database from the personal-use copying exception that otherwise covers a published work, so Cambodia protects a database only through ordinary compilation copyright, with no sui generis database right.

The same Act's citation provision permits quoting a legitimately published work without authorization or payment, conditioned on attribution and a proportionality limit, but no provision creates a text-and-data-mining exception, so training a model on scraped copyrighted Cambodian text rests, if at all, on that citation ground rather than a dedicated exception.

Cambodia's Draft Law on Personal Data Protection, still at a pre-legislative stage as of August 2026, would reach personal data collected by scraping if enacted as drafted, but currently binds nobody. No statute or reported case establishes a Cambodia-specific unfair-competition, misappropriation, or trespass doctrine reaching scraping, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Criminal Code, offences in the information technology sector

Criminal Code of the Kingdom of Cambodia (2009), Arts. 427-432Official English translation of the Criminal Code of the Kingdom of Cambodia (2009)

In force. Binds public and private bodies.

What this law does

Article 427 punishes fraudulently accessing or maintaining access to a system of automated data processing with imprisonment of one month to one year and a fine of KHR 100,000 to KHR 2,000,000. Where the access results in deleting or modifying the system's data or altering how the system functions, the same article raises the penalty to imprisonment of one to two years and a fine of KHR 2,000,000 to KHR 4,000,000.

Article 428 punishes obstructing the operations of an automated data processing system, and Article 429 punishes fraudulently introducing, deleting, or modifying data in such a system, each at the same one-to-two-year, KHR 2,000,000-to-4,000,000 tier. Article 430 extends that same tier to participating in a group or agreement formed to prepare an offence under the Chapter. Article 431 applies the same penalties to an attempt.

None of these articles conditions liability on infringing a security measure, and no reported Cambodian case addresses whether reading a public, unauthenticated page satisfies the "fraudulent" access standard.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (123 words)

Cambodia has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, and no reported hot-news, linking, or framing case law.

The Law on Copyright and Related Rights (2003) permits citing a legitimately published work in another work without the author's authorization or payment, conditioned on attribution and a proportionality limit, and separately lets an author's short quotations, justified by a critical, polemical, pedagogical, scientific, or informative purpose, and the broadcasting of press commentary go unprohibited where the author's name and the work's source are clearly indicated.

Neither provision distinguishes a text-and-data-mining use from any other reproduction, and no provision in the Act creates a machine-readable opt-out mechanism, so the Act draws no line between an aggregator's indexing and an ordinary human reader's citation.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.