Enforcement supervision
Cybersecurity Law, digital platform data retention and disclosure duty
Cybersecurity Law, State Administration Council Law No. 1/2025, ss.33-34official text
Commencement not set. Binds public and private bodies.
What this law does
Myanmar's Cybersecurity Law (State Administration Council Law No. 1/2025) contains no data-protection framework: its Chapter II definitions define cybersecurity-related terms but no "personal data" or "biometric data" term at all, and the sole use of "personal information" in the entire law is at section 33, which requires a digital platform service provider to retain personal information of a user, usage records, and any data the Department specifies for 3 years, disclosed to an authorised individual or organisation on written request under section 34.
This is a retention and state-access duty, not a protective one: it carries no consent standard, no purpose limitation, no retention ceiling beyond the 3-year floor, and no individual notice or objection right, and it runs toward government access to personal data rather than away from it, reaching a voiceprint or faceprint a covered platform stores exactly like any other user data.
The law's own section 2 commences it only on a date the president appoints by notification; independent trackers converge on State Administration Council Notification No. 113/2025 bringing it into force 30 July 2025, but that notification is not cited here, so this instrument is recorded as enacted rather than in effect.
Enforcement runs through a Central Committee and a Steering Committee on Cybersecurity and a Department with licensing and investigation powers (Chapter III); no private civil right of action exists anywhere in the law's text.
What it requires