Compliance
ASEAN regional governance
Compliance matrix for all 10 ASEAN member states. Admins edit country records; reviewers add comments and status.
| Country | Regulator | Law | Health data | Cross-border | Retention | Owner | Reviewed | Next | Risk | Status | |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Singapore (SG) | PDPC | PDPA 2012 (amended 2020) | high | Transfer Limitation Obligation | Rx: 5y, orders: 7y | R. Ng | 2025-11-10 | 2026-05-10 | low | Completed | |
| Malaysia (MY) | JPDP | PDPA 2010 (2024 amendments) | high | Transfer whitelist required | Rx: 7y, orders: 7y | R. Ng | 2025-11-05 | 2026-02-05 | medium | In Review | |
| Indonesia (ID) | Kominfo / PDP Agency | PDP Law 2022 | high | Adequacy-based | Rx: 5y minimum | S. Wijaya | 2025-10-22 | 2026-01-22 | high | Action Required | |
| Thailand (TH) | PDPC-TH | PDPA 2019 | high | Consent + adequacy | Rx: 5y | N. Pruk | 2025-09-30 | 2026-03-30 | medium | In Review | |
| Vietnam (VN) | A05 / MPS | PDPD 2023 (Decree 13) | high | Impact assessment required | Rx: 5y | L. Trang | 2025-10-11 | 2026-01-11 | high | Action Required | |
| Philippines (PH) | NPC | Data Privacy Act 2012 | high | Contractual safeguards | Rx: 5y | J. Cruz | 2025-11-01 | 2026-05-01 | medium | In Review | |
| Brunei (BN) | AITI | PDPO (in force 2025) | medium | Consent-based | Rx: 5y | Unassigned | 2025-08-14 | 2026-02-14 | medium | Not Started | |
| Cambodia (KH) | MPTC | Draft Cybersecurity/PDP | medium | No formal regime | Rx: 5y (proposed) | Unassigned | 2025-07-20 | 2026-01-20 | high | Action Required | |
| Laos (LA) | MPT | Law on Electronic Data Protection 2017 | medium | Consent-based | Rx: 5y | Unassigned | 2025-06-05 | 2026-01-05 | high | Not Started | |
| Myanmar (MM) | MoTC | Cybersecurity Law (2025 draft) | medium | Restrictive | Rx: 5y (proposed) | Unassigned | 2025-05-18 | 2026-02-18 | high | Action Required |