Skip to the content
Global Data RulesData governance rules, country by country

Brunei

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Brunei — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Waking up

Brunei got its first privacy law in January 2025. A senior official said on 17 August 2026 that it is now in force. You can send data out of Brunei. But the place you send it to must protect it about as well as Brunei does. Nothing has to be stored inside Brunei. The regulator runs training and has a breach reporting form. We found no fines or public decisions yet.

Data governance in Brunei

The eight things that decide how you handle data about people in Brunei. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law applies even if you have no office, no staff and no company registration in Brunei. It covers any person or body. It does not matter where that body was set up or where it is based. There is no revenue or headcount limit that gets you out of it. You do not need a local representative. You do have to name at least one person, anywhere in the world, as your data protection officer. You must publish their work contact details.

What you have to do here:
Appoint a data protection officer · Publish a complaints contact

Where the data is allowed to live

Yes, with conditions. Brunei has no rule saying data must stay in the country. You may send personal data abroad only if the people receiving it protect it about as well as Brunei does. There is no list of approved countries and no list of banned ones. Four industries add their own extra steps. One of them comes close to a keep-a-copy-here rule.

What you have to do here:
Put a transfer safeguard in place

What to do: Get the paperwork for one of the routes below signed before any data leaves Brunei.

Sending data out of the country

There is no list of approved countries and no list of banned ones. The burden sits with you. Before data leaves, you must be able to show the recipient will protect it about as well as Brunei's own law does. Normally you do that by writing the promise into your contract. The regulator can also give one named company a written exemption from those conditions. That exemption does not have to be published. It can be cancelled at any time.

What you have to do here:
Written vendor contract
Ways to send data out:
Standard contract clauses · Government sign-off needed

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

Three regulators matter. The communications regulator is the Authority for Info-communications Technology Industry of Brunei Darussalam, known as AITI. It runs the privacy law. It has a data protection office, a breach reporting form, a complaints form, published guides and training for data protection officers. It ran awareness sessions for industry in February 2026. We found no fines, orders or published decisions from it. Treat it as waking up rather than active. The central bank is active in banking, insurance and investment. The Commissioner of Cybersecurity works through Cyber Security Brunei. It handles critical systems and has published binding codes and guidelines.

What it costs if you get it wrong:
Percentage of global turnover · Fixed maximum fine · Criminal liability
Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is no fixed number of years. You must stop keeping documents that contain personal data once two things are true. The purpose is finished, and no legal or business reason to keep them remains. You can strip out what identifies people instead of deleting the documents. Brunei sets no maximum. We could not check the general tax and company record-keeping minimums against an official source. The government's own law library was unreachable on the day we looked.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Independent audit

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are four clocks and the shortest is one hour. A bank has one hour from finding a suspected cyber intrusion to tell the central bank. It then has two hours to say whether it was real. It must not say anything publicly before that. A Ministry of Health contractor has 24 hours. Under the privacy law you first work out whether the breach is serious. You then have three days from finishing that assessment to tell the regulator. You must tell the affected people too. Owners of critical national systems must report to the Commissioner of Cybersecurity within a period the government sets. We could not find that period published.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. One. The privacy law does not apply to any government body. A public hospital or ministry sits outside it, so your only protection is the contract they give you. Two. Any other Brunei law beats the privacy law where the two disagree. A banking secrecy or national security rule wins. Three. The regulator can quietly exempt one company from the transfer rules. It does not have to publish that exemption and can cancel it whenever it likes. You cannot see what your competitor has been allowed to do. Four. Individual staff can commit a crime, not just companies. Leaking personal data, misusing it for gain, or working out who anonymous data belongs to all count. Five. Texting or calling any Brunei phone number for marketing needs clear and unambiguous consent. An existing customer relationship is not enough.

What you have to do here:
Written vendor contract · Get consent · Put a transfer safeguard in place
What it costs if you get it wrong:
Criminal liability

What's changing next

The big missing piece is the industry-by-industry guidance. The regulator consulted banks, insurers, telecoms operators, hospitals and schools in February 2024. It promised the guidelines for 2025. They were still not published on 18 August 2026. The national cyber agency published a cloud policy for critical systems on 19 February 2026. It introduces the local anchor idea. That idea could harden into a binding code. Brunei also has a guide on artificial intelligence ethics, now in a second edition. It is advice, not law.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Cyber security rules (Government)

Official name: Cloud Security Policy Guidelines for Critical Information Infrastructure (CII) · Version 1.0, read with the Code of Practice for CII v1.0 (11 March 2024), clause 3.6 · Regulator guideline

In forceA copy must stay

This is the closest Brunei gets to a rule about keeping data in the country. If the government has labelled your system critical, you are told three things. Keep a local anchor point inside Brunei when you use an overseas public cloud. Name the countries where data may be stored in your contract. Tell the Commissioner of Cybersecurity before you move to cloud at all.

In force since 19 February 2026

Enforced by Cyber Security Brunei / Commissioner of Cybersecurity

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Finance

Cloud and outsourcing rules

Official name: Notice on Technology Risk Management · Notice No. TRS/N-1/2023/2, issued under section 54 of the Brunei Darussalam Central Bank Order, 2010 · Regulator directive

In forceYes, with paperwork

A binding notice for banks and financial firms. It does not require data to stay in Brunei. But you must tell the central bank before you sign any cloud or outsourcing contract that touches a critical system. You must also tell it before you add artificial intelligence to one.

In force since 30 June 2023

Enforced by Brunei Darussalam Central Bank

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Banking

Banking rules

Official name: Notice on Early Detection of Cyber Intrusion and Incident Reporting · Notice No. TRS/N-1/2020/1, Amendment No. 1 dated 23 November 2023, issued under section 66 of the Banking Order, 2006 and section 66 of the Islamic Banking Order, 2008 · Regulator directive

In forceYes — store it anywhere

This is the shortest deadline in Brunei. A bank has one hour from finding a suspected cyber intrusion to tell the central bank. It has two hours to say whether it was real. It must not say anything publicly before that.

In force since 1 January 2024

Enforced by Brunei Darussalam Central Bank

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: Personal Data Protection Order, 2025 / Perintah Perlindungan Data Peribadi, 2025 · Government Gazette No. S 1 of 2025, made under Article 83(3) of the Constitution · Directly binding regulation

Partly in forceYes, with paperwork

Brunei's first general privacy law. It closely follows Singapore's. It is built on consent. It gives people the right to see and correct their data. You must name a data protection officer. You must report a serious breach within three days. You may send data abroad only if it gets comparable protection there. Government bodies sit entirely outside the law, and any other Brunei law overrides it.

In force since 1 January 2026

Enforced by Authority for Info-communications Technology Industry of Brunei Darussalam

How this country controls where data goes: Approval each time · Accepted routes: Standard contract clauses, Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Cyber security rules

Official name: Cybersecurity Act, Chapter 272 (Perintah Keselamatan Siber, 2023) · S 20/2023, Revised Edition 2024 · Act of parliament

In forceYes — store it anywhere

Brunei's cybersecurity law. It has been in force since 20 May 2023 and binds the Government itself. The Commissioner of Cybersecurity can label any computer system located wholly or partly in Brunei as critical. That label brings compulsory incident reporting, audits every two years, annual risk assessments, and a duty to follow the published codes of practice.

In force since 20 May 2023

Enforced by Cyber Security Brunei / Commissioner of Cybersecurity

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Pihak Berkuasa Industri Teknologi Info-komunikasi Negara Brunei Darussalam (AITI)

    Privacy law, telecoms, broadcasting, postal, artificial intelligence guidance

    It has been the telecoms regulator since 2003 and is clearly staffed. Its data protection arm is new. It has a dedicated portal at pdp.aiti.gov.bn and two guidance documents dated 4 June 2025. It ran a fourth cohort of privacy manager training in February 2026, plus industry awareness sessions the same month. Its breach and complaint forms work. We found no fines, orders or published enforcement decisions under the privacy law as at 18 August 2026. The industry-specific guidelines promised for 2025 are still unpublished.

  • Bank Pusat Brunei Darussalam (BDCB), formerly Autoriti Monetari Brunei Darussalam (AMBD)

    Banking, Islamic banking, insurance and takaful, capital markets, payments, money services

    Fully active. It publishes a searchable register of over 340 binding notices, guidelines and codes. It has an enforcement function and an alert list. It issued new rules as recently as February 2026. Its own published labels separate Notices, which are legally binding, from Guidelines, which are best practice. That matters when you read its outsourcing rules.

  • Cyber Security Brunei (CSB)

    Critical information infrastructure, national incident response through BruCERT

    Operates under the Ministry of Transport and Infocommunications. It has issued a Code of Practice for critical information infrastructure, version 1.0, dated 11 March 2024. It has also issued guidelines including the Cloud Security Policy dated 19 February 2026. It runs an incident reporting channel through BruCERT and was publicly active through 2026. We found no published list of labelled critical systems and no published reporting deadline.

  • Kementerian Kesihatan

    Health data handled by ministry contractors and suppliers

    It writes and updates its own standard for how contractors handle data. Version 3 is dated 8 November 2025 and is due for review on 8 November 2028.

  • Appeals against directions and decisions under the privacy law

    Set up by section 41 of the Personal Data Protection Order, 2025. We found no evidence that the Panel has been appointed or that any Appeal Committee exists. We found no published appeal decisions as at 18 August 2026.

  • Pusat Kerajaan Elektronik Kebangsaan (EGNC)

    Government hosting, government cloud, ministry ICT policies

    Runs the government's own shared data centre and the National Centralised Database service. Only government ministries and departments can use them. It publishes the government's computer use, internet use and email policies.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact commencement date of the Personal Data Protection Order, 2025, and which provisions have and have not been brought into operation

    We could not confirm the start date against the official gazette notice. The Attorney General's Chambers website has an expired security certificate. We rely on two other sources instead. An official government newspaper reported on 17 August 2026 that a senior speaker said the Order 'is now in force'. A well-known international law firm survey says most of the main rules started on 1 January 2026. This record uses 1 January 2026 and the status 'partly in force'. Treat the date as indicative.

  • Whether regulations have been made prescribing the transfer requirements under section 24, the categories of data that make a breach automatically serious, and the number of affected people that makes a breach large

    The regulator's own legislation page lists only the Order itself, with nothing underneath it. Its guidance library holds just two documents. Until these requirements are written down, the real content of the transfer rule and the breach thresholds is uncertain. This is the biggest open question in this record.

  • The identity of gazette notice S 11 of 2025, described by the Attorney General's Chambers as relating to an amendment to the Personal Data Protection Order, 2025

    We could not retrieve the gazette notice or the Attorney General's Chambers page. Both sit on a site with an expired security certificate. The amendment may or may not change the transfer, breach or penalty rules used here. Check it before you rely on them.

  • The period within which an owner of critical information infrastructure must report a cybersecurity incident to the Commissioner of Cybersecurity

    The Cybersecurity Act says 'within the prescribed period'. We could not find the regulations that set it. No figure appears in the Code of Practice or the published guidelines either. Assume it is short.

  • General minimum record-keeping periods under Brunei's tax, company and anti-money-laundering law

    These rules sit in statutes held by the Attorney General's Chambers, which we could not reach. The central bank's anti-money-laundering pages returned no readable text, and its electronic know-your-customer notice is a scanned image. The minimum keeping periods in this record are therefore incomplete. Check them before you design a deletion schedule.

  • Whether the ASEAN Model Contractual Clauses are formally endorsed by the Brunei regulator as a transfer mechanism

    A law firm survey reports this. We could not find the endorsement on the regulator's own site, so we do not record it as an official route. Check with the regulator before you rely on it.

  • Whether any organisation has been granted a written exemption from the transfer requirements

    The Order expressly says these exemptions need not be published. By design there is no way to check.

  • Whether any storage-location or localisation rule exists in education, gaming, mapping and geospatial, or defence

    We found no such rule, checked on 18 August 2026, and our confidence is medium. Brunei publishes little industry regulation outside finance and telecoms, and the main statute repository was unreachable. If you work in one of these industries, check before you rely on this.

  • Whether the Data Protection Appeal Panel has been constituted

    We found no appointment notice or membership list on any government site. That shows nothing has been published. It does not show that no appointment has been made.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.