Brunei
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Brunei — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Brunei got its first privacy law in January 2025. A senior official said on 17 August 2026 that it is now in force. You can send data out of Brunei. But the place you send it to must protect it about as well as Brunei does. Nothing has to be stored inside Brunei. The regulator runs training and has a breach reporting form. We found no fines or public decisions yet.
Data governance in Brunei
The eight things that decide how you handle data about people in Brunei. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law applies even if you have no office, no staff and no company registration in Brunei. It covers any person or body. It does not matter where that body was set up or where it is based. There is no revenue or headcount limit that gets you out of it. You do not need a local representative. You do have to name at least one person, anywhere in the world, as your data protection officer. You must publish their work contact details.
- What you have to do here:
- Appoint a data protection officer · Publish a complaints contact
The law is the Personal Data Protection Order, 2025. Section 2 says an organisation is any person or body, wherever it was set up and wherever it is based. Section 7 requires you to name a data protection officer and publish their work contact details. Section 3 then removes most duties for several groups. Individuals acting for themselves or at home are out. So are employees acting for their employer. So is any government body. A supplier working under a written contract gets a shorter list of duties. But it must still keep data secure, stop keeping it when the purpose is done, and follow the rules on sending it abroad. Work contact details sit outside the law. So do records that are at least 100 years old. So does data about someone who has been dead for more than 10 years.
Sources
- Official sourceAuthority for Info-communications Technology Industry of Brunei Darussalam (AITI)Personal Data Protection Order, 2025 (Government Gazette No. S 1, 8 January 2025), sections 2, 3 and 7
pdp.aiti.gov.bn
“"organisation" includes any individual, company, association or body of persons, corporate or unincorporated, whether or not — (a) formed or recognised under the law of Brunei Darussalam; or (b) resident, or having an office or a place of business, in Brunei Darussalam”
Link checked 18 August 2026
- Official sourceAITIGuide: Appointment of Data Protection Officers, Version 1.0, 4 June 2025
pdp.aiti.gov.bn
Link checked 18 August 2026
Where the data is allowed to live
Yes, with conditions. Brunei has no rule saying data must stay in the country. You may send personal data abroad only if the people receiving it protect it about as well as Brunei does. There is no list of approved countries and no list of banned ones. Four industries add their own extra steps. One of them comes close to a keep-a-copy-here rule.
- What you have to do here:
- Put a transfer safeguard in place
Checked industry by industry on 18 August 2026. BANKING. Data does not have to stay in Brunei. The central bank's outsourcing guidelines say a bank should 'in principle' only use suppliers in countries that keep information confidential. A bank must not use a country where the regulator could be blocked from getting information. A bank must also tell the regulator if a foreign authority asks to see customer information. A separate binding notice on technology risk adds a step. A bank must tell the central bank before it signs any cloud or outsourcing contract that touches a critical system. INSURANCE AND TAKAFUL (ISLAMIC INSURANCE). This is the strictest financial gate. Outsourcing anything the rules count as material needs an application to the central bank for approval. That expressly includes software, platform and infrastructure as a service, data entry, data centres and archival storage. SECURITIES AND CAPITAL MARKETS. A licence holder must tell the central bank 30 days before outsourcing an important operational function. Internal audit, risk and compliance work may only go to its own corporate group. PAYMENTS. We checked the Notice on Requirements for Payment Systems. We found no rule about where data must be stored. HEALTH. The Ministry of Health bans its contractors from moving personal data out of Brunei. The only exception is a move that meets the privacy law's terms. The overseas recipient must also be legally bound to give comparable protection. CRITICAL NATIONAL SYSTEMS. This is the closest Brunei gets to a rule about keeping data in the country. The national cyber agency's cloud policy covers systems the government has labelled critical. If the owner uses a public cloud hosted outside Brunei, it is told to keep a physical or logical 'local anchor' inside Brunei. That is guidance, not law. But it sits next to a Code of Practice that these owners must follow by law. GOVERNMENT. The privacy law does not apply to government bodies at all. Government systems are hosted inside Brunei through the E-Government National Centre's own data centre and central database service. TELECOM, EDUCATION, GAMING, MAPPING AND DEFENCE. We found no rule about where data must be stored. Checked 18 August 2026. Confidence medium.
Sources
- Official sourceAITIPersonal Data Protection Order, 2025, section 24 (transfer of personal data outside Brunei Darussalam)
pdp.aiti.gov.bn
“No organisation shall transfer any personal data to a country outside Brunei Darussalam except in accordance with the prescribed requirements to ensure that organisations provide a standard of protection to personal data so transferred that is comparable to the protection under this Order.”
Link checked 18 August 2026
- Official sourceCyber Security BruneiCloud Security Policy Guidelines for Critical Information Infrastructure, Version 1.0, 19 February 2026
csb.gov.bn
“When utilizing public cloud services hosted outside of Brunei (regional clouds), CII OWNER must adopt a Hybrid Cloud Architecture. This requires maintaining a physical or logical 'local anchor' within Brunei Darussalam.”
Link checked 18 August 2026
- Official sourceBrunei Darussalam Central BankGuidelines on Outsourcing Arrangement for Insurance Companies and Takaful Operators (TIU/G-1/2019/10), section 5 and Appendix 1
cms.bdcb.gov.bn
Link checked 18 August 2026
- Official sourceMinistry of Health, Brunei DarussalamMinistry of Health Data Handling and Security Guidelines for Contractors, Version 3, issued 8 November 2025, paragraph 6.7.10
moh.gov.bn
“Do not transfer personal data out of Brunei Darussalam except in accordance with PDPO requirements.”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Brunei.
Sending data out of the country
There is no list of approved countries and no list of banned ones. The burden sits with you. Before data leaves, you must be able to show the recipient will protect it about as well as Brunei's own law does. Normally you do that by writing the promise into your contract. The regulator can also give one named company a written exemption from those conditions. That exemption does not have to be published. It can be cancelled at any time.
- What you have to do here:
- Written vendor contract
- Ways to send data out:
- Standard contract clauses · Government sign-off needed
The rule is section 24 of the Personal Data Protection Order, 2025. A transfer is lawful only if it meets 'the prescribed requirements'. The Authority can exempt a named organisation by written notice. That notice 'need not be published in the Gazette and may be revoked at any time'. The Authority can also add, change or cancel conditions whenever it likes. The regulator's own plain-language summary puts the duty simply. Do not transfer data unless there is a similar or better data protection law where it is going. The alternative it gives is 'contracts with specific instruction on data protection across borders'. We could not find published regulations setting out the prescribed requirements in detail. That gap is in the unconfirmed list.
Sources
- Official sourceAITIPersonal Data Protection Order, 2025, section 24(2)-(4)
pdp.aiti.gov.bn
“An exemption under subsection (2) — (a) may be granted subject to such conditions as the Authority may specify in writing; and (b) need not be published in the Gazette and may be revoked at any time by the Authority.”
Link checked 18 August 2026
- Official sourceAITI Data Protection OfficeOverview of PDPO — Organisations: the Transfer Limitation obligation
pdp.aiti.gov.bn
“Organisations to not transfer personal data to a country or territory outside Brunei Darussalam unless there is a similar or better data protection law available. An alternative is to have contracts with specific instruction on data protection across borders.”
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
Three regulators matter. The communications regulator is the Authority for Info-communications Technology Industry of Brunei Darussalam, known as AITI. It runs the privacy law. It has a data protection office, a breach reporting form, a complaints form, published guides and training for data protection officers. It ran awareness sessions for industry in February 2026. We found no fines, orders or published decisions from it. Treat it as waking up rather than active. The central bank is active in banking, insurance and investment. The Commissioner of Cybersecurity works through Cyber Security Brunei. It handles critical systems and has published binding codes and guidelines.
- What it costs if you get it wrong:
- Percentage of global turnover · Fixed maximum fine · Criminal liability
AITI is the Authority for Info-communications Technology Industry of Brunei Darussalam. It was created in 2001 and has long been the telecoms and broadcasting regulator. It is a real, staffed body. Its data protection arm is new. Signs of activity on its own site. It runs a dedicated portal at pdp.aiti.gov.bn. It published a Guide for Appointment of Data Protection Officers and a Guide to Developing a Data Protection Management Programme. Both are dated 4 June 2025. It runs a Certified Information Privacy Manager training programme, now on its fourth cohort, held 10 to 12 February 2026. It ran awareness sessions for the event management industry on 24 February 2026. It ran another for a national foundation on 16 February 2026. Its breach-report and complaint forms work. Signs of gaps. The frequently asked questions page returns no entries. The guidance library holds only two documents. The industry-specific advisory guidelines are still missing. Those were consulted on from 27 to 29 February 2024 and were 'targeted to be published in 2025'. They were still not published on 18 August 2026. The Order also creates a Data Protection Appeal Panel and Appeal Committees. We found no evidence that either has been set up. Fines can reach 10 per cent of Brunei turnover. That applies to an organisation turning over more than 10 million Brunei dollars (about 7.8 million US dollars) in Brunei. For everyone else the cap is 1 million Brunei dollars (about 780,000 US dollars).
Sources
- Official sourceAITIAITI Data Protection Office — Public Consultations, including the February 2024 sector-specific guidelines consultation
pdp.aiti.gov.bn
“The guidelines are targeted to be published in 2025.”
Link checked 18 August 2026
- Official sourceAITIAITI Data Protection Office — Guidance Documents (two documents only, as at 18 August 2026)
pdp.aiti.gov.bn
Link checked 18 August 2026
- Official sourceBrunei Darussalam Central BankBrunei Darussalam Central Bank — Regulatory Instruments: which instruments bind and which do not
bdcb.gov.bn
“Directions can be in the form of a Directive or a Notice ... They are quasi-statutory instruments with legal effect ... Guidelines set out principles or "best practice standards" ... contravention of guidelines is not a criminal offence”
Link checked 18 August 2026
- Official sourceCyber Security Brunei, Ministry of Transport and InfocommunicationsCyber Security Brunei — Code of Practice for Critical Information Infrastructure
csb.gov.bn
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is no fixed number of years. You must stop keeping documents that contain personal data once two things are true. The purpose is finished, and no legal or business reason to keep them remains. You can strip out what identifies people instead of deleting the documents. Brunei sets no maximum. We could not check the general tax and company record-keeping minimums against an official source. The government's own law library was unreachable on the day we looked.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Independent audit
Section 23 of the Personal Data Protection Order, 2025 sets the upper limit. Two oddities sit next to it in section 3(4). The Order does not apply at all to personal data in a record that is at least 100 years old. It applies to a dead person's data for only 10 years after death, and then only the disclosure and protection rules. Some minimum keeping periods we did confirm. Ministry of Health contractors must follow the Ministry's retention schedules. They must securely destroy personal data they no longer need. When a contract ends they must return or destroy all Ministry data and certify the destruction in writing. Financial firms must send the central bank an updated list of all technology arrangements with outside firms within three months of each financial year end. Owners of critical national systems must audit at least once every two years and run a risk assessment at least once a year. Sometimes a keep-it rule and a delete-it rule clash. Section 3(6)(b) of the Order settles it. Any other written law wins over the privacy law where the two disagree.
Sources
- Official sourceAITIPersonal Data Protection Order, 2025, sections 3(4), 3(6) and 23
pdp.aiti.gov.bn
“An organisation shall cease to retain its documents containing personal data, or remove the means by which the personal data can be associated with particular individuals, as soon as it is reasonable to assume that — (a) the purpose for which that personal data was collected is no longer being served by retention of the personal data; and (b) retention is no longer necessary for legal or business purposes.”
Link checked 18 August 2026
- Official sourceMinistry of Health, Brunei DarussalamMinistry of Health Data Handling and Security Guidelines for Contractors, paragraphs 6.7.9 and 6.13
moh.gov.bn
“Upon termination of contract, return or securely destroy all MOH data as instructed.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There are four clocks and the shortest is one hour. A bank has one hour from finding a suspected cyber intrusion to tell the central bank. It then has two hours to say whether it was real. It must not say anything publicly before that. A Ministry of Health contractor has 24 hours. Under the privacy law you first work out whether the breach is serious. You then have three days from finishing that assessment to tell the regulator. You must tell the affected people too. Owners of critical national systems must report to the Commissioner of Cybersecurity within a period the government sets. We could not find that period published.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Bank clock. Notice on Early Detection of Cyber Intrusion and Incident Reporting (TRS/N-1/2020/1), Amendment No. 1, effective 1 January 2024, paragraphs 4.1 to 4.5. One hour to tell the central bank. Two hours to classify the incident. No public statement before classifying. Updates at least twice every calendar day until it is resolved. A root cause report within 5 working days. Privacy law clock. Personal Data Protection Order, 2025, sections 26 to 28. The three-day clock does not start when you find the breach. It starts when you finish your assessment. Section 27 requires that assessment to be 'reasonable and expeditious'. You must report a breach if it causes or is likely to cause significant harm, or if it is of significant scale. A breach that stays inside one organisation is treated as not reportable. If your supplier suffers the breach, it must tell you without undue delay. You then run the assessment. Critical systems clock. Cybersecurity Act, Chapter 272, section 16. Failing to report is a crime. It carries a fine of up to 100,000 Brunei dollars (about 78,000 US dollars), up to two years in prison, or both.
Sources
- Official sourceBrunei Darussalam Central BankNotice on Early Detection of Cyber Intrusion and Incident Reporting (TRS/N-1/2020/1), Amendment No. 1, effective 1 January 2024, paragraph 4.1
cms.bdcb.gov.bn
“Banks shall notify Technology Risk of BDCB no later than one (1) hour after the discovery of a Suspected Incident either via email, telephone call or other authorised communication channel.”
Link checked 18 August 2026
- Official sourceAITIPersonal Data Protection Order, 2025, section 28(1)
pdp.aiti.gov.bn
“the organisation shall notify the Authority as soon as is practicable, but in any case no later than 3 days after the day the organisation makes that assessment.”
Link checked 18 August 2026
- Official sourceE-Government National Centre, Ministry of Transport and InfocommunicationsCybersecurity Act, Chapter 272 (Revised Edition 2024, originally S 20/2023), section 16
egnc.gov.bn
“The owner of a critical information infrastructure shall notify the Commissioner of the occurrence of any of the following ... within the prescribed period after becoming aware of such occurrence”
Link checked 18 August 2026
- Official sourceMinistry of Health, Brunei DarussalamMinistry of Health Data Handling and Security Guidelines for Contractors, paragraph 6.8.1
moh.gov.bn
“Report any suspected or confirmed data breaches to MOH's designated contact immediately, and no later than 24 hours after discovery.”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. One. The privacy law does not apply to any government body. A public hospital or ministry sits outside it, so your only protection is the contract they give you. Two. Any other Brunei law beats the privacy law where the two disagree. A banking secrecy or national security rule wins. Three. The regulator can quietly exempt one company from the transfer rules. It does not have to publish that exemption and can cancel it whenever it likes. You cannot see what your competitor has been allowed to do. Four. Individual staff can commit a crime, not just companies. Leaking personal data, misusing it for gain, or working out who anonymous data belongs to all count. Five. Texting or calling any Brunei phone number for marketing needs clear and unambiguous consent. An existing customer relationship is not enough.
- What you have to do here:
- Written vendor contract · Get consent · Put a transfer safeguard in place
- What it costs if you get it wrong:
- Criminal liability
(1) Section 3(1)(c) of the Order removes the main duties for public agencies. The Ministry of Health has filled that gap by contract instead. It puts privacy-law-style duties on its suppliers. (2) Section 3(6)(b) says any other written law wins where Parts 3, 4, 5, 6 and 7 of the Order disagree with it. (3) The private exemption power sits in section 24(2) to (4). (4) Sections 31, 32 and 33 create three crimes for individuals. Disclosing personal data without permission. Misusing it. And working out who anonymised information belongs to. Fines run up to 5,000 Brunei dollars (about 3,900 US dollars), with up to two years in prison. Section 48 adds crimes for destroying records to defeat an access request and for obstructing the regulator. (5) Section 9 is a standalone rule for Brunei telephone numbers. It overrides the normal consent routes in section 8. Two more traps are worth knowing. A supplier working under a written contract escapes most duties. It does not escape the duties on security, on how long it keeps data, or on sending data abroad. So an outsourcer cannot hide behind its customer. And a bank must not announce an incident publicly until it has classified it for the central bank. That cuts across most global incident communication plans.
Sources
- Official sourceAITIPersonal Data Protection Order, 2025, sections 3, 9, 24, 31 to 33 and 48
pdp.aiti.gov.bn
“the provisions of any other written law prevail to the extent that any provision of Parts 3, 4, 5, 6 and 7 is inconsistent with the provisions of that other written law.”
Link checked 18 August 2026
- Official sourceBrunei Darussalam Central BankNotice on Early Detection of Cyber Intrusion and Incident Reporting, paragraph 4.3 (no public announcement before classification)
cms.bdcb.gov.bn
“Banks shall not make any public announcement regarding a Suspected Incident prior to notifying BDCB of its assessment under paragraph 4.2.”
Link checked 18 August 2026
What's changing next
The big missing piece is the industry-by-industry guidance. The regulator consulted banks, insurers, telecoms operators, hospitals and schools in February 2024. It promised the guidelines for 2025. They were still not published on 18 August 2026. The national cyber agency published a cloud policy for critical systems on 19 February 2026. It introduces the local anchor idea. That idea could harden into a binding code. Brunei also has a guide on artificial intelligence ethics, now in a second edition. It is advice, not law.
Powers the government already holds. Each could change the answer with no consultation. (1) Section 1(1)-(2) of the Order lets the Minister switch on any remaining part of the law by a gazette notice. He can pick any date, and different dates for different parts. (2) Section 3(1)(d) lets the government exempt whole classes of organisations or data by regulation. (3) Section 58 lets the Authority make regulations. Those would set the transfer requirements. They would also set which kinds of data automatically make a breach serious, and how many affected people make a breach large. We could not find any of them published. So the working shape of the transfer and breach rules could be redrawn overnight. (4) Section 24(2) exemptions can be granted and cancelled in private. (5) Under the Cybersecurity Act, the Commissioner can label a computer or computer system as critical information infrastructure, by written notice. The system must be located wholly or partly in Brunei. That immediately switches on audits, annual risk assessments, incident reporting and the cloud restrictions. The Commissioner can also issue binding written directions and emergency measures.
Sources
- Official sourceAITIAITI — Public Consultation on Proposed Sector-Specific Advisory Guidelines, 27 to 29 February 2024
pdp.aiti.gov.bn
“AITI received valuable feedback from representatives of sectors such as Telecommunications, Financial and Insurance, Healthcare, Real Estate, Social Services and Education”
Link checked 18 August 2026
- Official sourceAITIAITI — AI Governance and Ethics, including the Guide on AI Governance and Ethics for Brunei Darussalam (Second Edition)
aiti.gov.bn
Link checked 18 August 2026
- Official sourceE-Government National CentreCybersecurity Act, Chapter 272, sections 9, 13, 14 and 25 (designation, codes, directions, emergency measures)
egnc.gov.bn
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cyber security rules (Government)
Official name: Cloud Security Policy Guidelines for Critical Information Infrastructure (CII) · Version 1.0, read with the Code of Practice for CII v1.0 (11 March 2024), clause 3.6 · Regulator guideline
This is the closest Brunei gets to a rule about keeping data in the country. If the government has labelled your system critical, you are told three things. Keep a local anchor point inside Brunei when you use an overseas public cloud. Name the countries where data may be stored in your contract. Tell the Commissioner of Cybersecurity before you move to cloud at all.
Enforced by Cyber Security Brunei / Commissioner of Cybersecurity
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryIf you use a public cloud hosted abroad, keep a physical or logical 'local anchor' inside Brunei. That can be a local management gateway, a core database node or a network termination point. This is guidance, not law. What binds you is the Code of Practice, which owners of labelled systems must follow under the Cybersecurity Act.
- Put a transfer safeguard in placeThe contract must name the countries in which the data may be stored.
- Report cyber incidentsYou must formally tell the Commissioner of Cybersecurity before you move a labelled system to cloud.
- Assess high-risk projectsNo part of a designated system may be put on cloud without a risk assessment first.
Sources
- Official sourceCyber Security BruneiCloud Security Policy Guidelines for Critical Information Infrastructure, Version 1.0, 19 February 2026
csb.gov.bn
“CII OWNER SHALL formally notify the Commissioner of Cybersecurity of any intention or migrate CII to a cloud computing system prior to such adoption, in accordance with Clause 3.6.2 of the Code of Practice.”
Link checked 18 August 2026
- Official sourceCyber Security BruneiCode of Practice for Critical Information Infrastructure, Version 1.0, 11 March 2024, clause 3.6
csb.gov.bn
“The CIIO shall not implement the whole or any part of the CII on cloud computing systems unless”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Notice on Technology Risk Management · Notice No. TRS/N-1/2023/2, issued under section 54 of the Brunei Darussalam Central Bank Order, 2010 · Regulator directive
A binding notice for banks and financial firms. It does not require data to stay in Brunei. But you must tell the central bank before you sign any cloud or outsourcing contract that touches a critical system. You must also tell it before you add artificial intelligence to one.
Enforced by Brunei Darussalam Central Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyTell the central bank before you sign any technology outsourcing, counterparty or cloud contract involving a critical system. Supply your due diligence, risk assessment and exit plan.
- Keep records of how you use dataYou must identify all your critical systems and keep the list current, including when you move to cloud.
- Written vendor contract — 1 yearA full list of technology arrangements with outside firms must reach the central bank within three months of each financial year end.
- Check your algorithmsTell the central bank before you add artificial intelligence to a critical system. For higher autonomy levels, talk to it earlier.
Sources
- Official sourceBrunei Darussalam Central BankNotice on Technology Risk Management (Notice No. TRS/N-1/2023/2), 30 June 2023, paragraphs 5.1 and 7.1
cms.bdcb.gov.bn
“Banks and FIs shall notify BDCB prior to signing a contract with an IT outsourcing service provider, counterpart and/or cloud service that involves critical systems.”
Link checked 18 August 2026
- Official sourceBrunei Darussalam Central BankGuidelines on Information Technology Third Party Risk Management (TRS/G-3/2022/2), paragraphs 4.5 and 7.1 to 7.4
cms.bdcb.gov.bn
“Depending on the scope of the service, cloud computing should be considered as a form of IT outsourcing with offshore service provider”
Link checked 18 August 2026
Banking rules
Official name: Notice on Early Detection of Cyber Intrusion and Incident Reporting · Notice No. TRS/N-1/2020/1, Amendment No. 1 dated 23 November 2023, issued under section 66 of the Banking Order, 2006 and section 66 of the Islamic Banking Order, 2008 · Regulator directive
This is the shortest deadline in Brunei. A bank has one hour from finding a suspected cyber intrusion to tell the central bank. It has two hours to say whether it was real. It must not say anything publicly before that.
Enforced by Brunei Darussalam Central Bank
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 1 hourOne hour from discovery to tell the central bank's Technology Risk unit. Two hours to classify the incident. Updates at least twice a day until it is resolved. A root cause report within 5 working days.
- Secure the dataBanks must build detection capability for anomalous traffic across internal systems.
Sources
- Official sourceBrunei Darussalam Central BankNotice on Early Detection of Cyber Intrusion and Incident Reporting (TRS/N-1/2020/1), Amendment No. 1, effective 1 January 2024
cms.bdcb.gov.bn
“Banks shall notify Technology Risk of BDCB no later than one (1) hour after the discovery of a Suspected Incident”
Link checked 18 August 2026
Cloud and outsourcing rules (Insurance)
Official name: Notice on Application for Approval of Outsourcing Arrangement for Insurance Companies and Takaful Operators, with Guidelines on Outsourcing Arrangement · Notice No. TIU/N-1/2019/11 and Guidelines No. TIU/G-1/2019/10, issued under section 88 of the Insurance Order, 2006 and section 90 of the Takaful Order, 2008 · Regulator directive
Insurers and takaful operators need the central bank's approval before handing out material operations. Cloud hosting counts. They must also warn the central bank if a foreign authority asks to see customer information.
Enforced by Brunei Darussalam Central Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyMaterial outsourcing needs an application to the central bank for approval. Your board must endorse it first. Software, platform and infrastructure as a service all count. So do data centres, data entry and handling, and archival storage of records.
- Do not hand data to foreign authorities on demandTell the central bank if an overseas authority seeks access to your customer information. Tell it too if your own access rights, or the regulator's, are restricted or denied.
- Written vendor contractUse only countries that generally keep confidentiality duties. Do not use a country where the regulator could be blocked from getting information quickly.
Sources
- Official sourceBrunei Darussalam Central BankGuidelines on Outsourcing Arrangement for Insurance Companies and Takaful Operators (TIU/G-1/2019/10), 21 August 2019, paragraphs 4.9 and 5 and Appendix 1
cms.bdcb.gov.bn
“the insurer should notify AMBD if any overseas authority were to seek access to its customer information or if a situation were to arise where the rights of access of the insurer and AMBD set out in paragraph 4.8, have been restricted or denied.”
Link checked 18 August 2026
- Official sourceBrunei Darussalam Central BankNotice on Technology Risk Management, paragraph 1.5.1 confirming the insurance outsourcing approval notice remains in force
cms.bdcb.gov.bn
Link checked 18 August 2026
Cloud and outsourcing rules (Securities)
Official name: Notice on Outsourcing for Capital Markets Services Licence Holders · Notice No. CMA/N-1/2020/15, issued under the Securities Markets Order, 2013 · Regulator directive
Investment and capital markets licence holders must give the central bank 30 days' notice before outsourcing an important function. Internal audit, risk and compliance work may only go to their own corporate group.
Enforced by Brunei Darussalam Central Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notify — within 720 hoursThirty days' notice to the central bank before outsourcing an important operational function.
- Written vendor contractThe supplier and any subcontractor must agree that the regulator may see and copy records about the work. Put it in the contract or in a letter of undertaking.
- Keep records of how you use dataYou must file an outsourcing register covering every planned and renewed arrangement.
Sources
- Official sourceBrunei Darussalam Central BankNotice on Outsourcing for Capital Markets Services Licence Holders (CMA/N-1/2020/15), effective 14 April 2020, paragraphs 4.1 to 4.5
cms.bdcb.gov.bn
“Any CMSL holder that intends to outsource any important operational function shall notify the Authority 30 days prior to the outsourcing of such important operational function.”
Link checked 18 August 2026
Health data rules
Official name: Ministry of Health Data Handling and Security Guidelines for Contractors · DPP/CDGG/V.3/06/2025, Version 3, next review 8 November 2028 · Regulator guideline
The Ministry of Health is a public agency, so the privacy law does not apply to it. It puts privacy-law-style duties on its suppliers by contract instead. Health data may leave Brunei only if the recipient is legally bound to give comparable protection. A breach must reach the Ministry within 24 hours.
Enforced by Ministry of Health
How this country controls where data goes: Approval each time · Accepted routes: Standard contract clauses
What you have to do
- Put a transfer safeguard in placeNo moving data out of Brunei except on the privacy law's terms. The overseas recipient must be legally bound to give comparable protection.
- Report breaches to the regulator — within 24 hoursTell the Ministry's named contact immediately, and in any case within 24 hours of finding the breach.
- Secure the dataRestricted health data must be encrypted when stored and when sent. Only authorised healthcare professionals may see it.
- Delete data after a periodFollow the Ministry's retention schedules. When the contract ends, return or destroy all Ministry data and certify the destruction in writing.
- Extra vendor secrecy termsThis applies to every outside party that handles Ministry data. It fills the gap left by the privacy law not covering public agencies.
Sources
- Official sourceMinistry of Health, Brunei DarussalamMinistry of Health Data Handling and Security Guidelines for Contractors, Version 3, issued 8 November 2025
moh.gov.bn
“Ensure that the overseas recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPO.”
Link checked 18 August 2026
Telecoms rules
Official name: Code of Practice for the Registration of Mobile Prepaid Subscriber Identity Module (SIM) Cards · Mobile Prepaid SIM Cards Registration Code · Statutory code of practice
Every prepaid mobile subscriber in Brunei must be identified against an original identity document. The operator must keep those records accurate. There is no rule about where the data must be stored. But the identity dataset this creates is unusually complete.
Enforced by Authority for Info-communications Technology Industry of Brunei Darussalam
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep records of how you use dataMobile providers and their resellers must keep accurate identity records for every prepaid subscriber. That means name, identity card number and address. Records must be updated whenever ownership changes.
- Get a parent's consent for children — applies at: under 12A prepaid card for a child under 12 must be registered in a parent's or guardian's name. The child is listed only as the user. Brunei's age limit of 12 is far below the global norm of 13 to 16.
Sources
- Official sourceAITIAITI — Code of Practice for the Registration of Mobile Prepaid SIM Cards, effective 4 September 2024
aiti.gov.bn
“For subscribers under twelve (12) years old ("minor"), the parent or legal guardian of the minor shall register the mobile prepaid SIM card under the parent or legal guardian and list the minor as the user.”
Link checked 18 August 2026
- Official sourceAITICode of Practice for the Registration of Mobile Prepaid SIM Cards (full text), paragraph 2.1
aiti.gov.bn
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: Personal Data Protection Order, 2025 / Perintah Perlindungan Data Peribadi, 2025 · Government Gazette No. S 1 of 2025, made under Article 83(3) of the Constitution · Directly binding regulation
Brunei's first general privacy law. It closely follows Singapore's. It is built on consent. It gives people the right to see and correct their data. You must name a data protection officer. You must report a serious breach within three days. You may send data abroad only if it gets comparable protection there. Government bodies sit entirely outside the law, and any other Brunei law overrides it.
Enforced by Authority for Info-communications Technology Industry of Brunei Darussalam
How this country controls where data goes: Approval each time · Accepted routes: Standard contract clauses, Government sign-off needed
What you have to do
- Get consentConsent is the default. The alternatives are deemed consent, deemed consent by notification, and a list of exceptions in Schedules 1 to 3 of the law.
- Tell people what you do
- Let people see their dataIncludes the right to be told how the data was used or disclosed in the year before the request.
- Let people correct their data
- Let people objectExpressed as a right to withdraw consent on reasonable notice.
- Secure the data
- Delete data after a periodNo fixed period. Stop retaining once the purpose is served and no legal or business need remains.
- Put a transfer safeguard in placeThe recipient must give a comparable standard of protection. We found no published detail on what that requires, as at 18 August 2026.
- Report breaches to the regulator — within 72 hoursThree days, counted from the completion of the organisation's own assessment, not from discovery.
- Tell affected peopleYou need not tell people if your fix, or technology you already had, makes significant harm unlikely.
- Appoint a data protection officerAt least one designated individual. No requirement that the person be in Brunei.
- Publish a complaints contactYou must publish that person's work contact details and set up a complaints process.
- Keep records of how you use dataYou must write policies, put them into use, tell staff about them, and hand them over on request.
What it costs if you get it wrong
- Percentage of global turnover: 10% of annual turnover in Brunei DarussalamIntentional or negligent breach of Parts 3 to 7 by an organisation whose Brunei turnover exceeds B$10,000,000
- Fixed maximum fine: B$1,000,000 — about $780 thousandIntentional or negligent breach of Parts 3 to 7 in any other case
- Criminal liability: B$5,000 and/or 2 years' imprisonment — about $4 thousandUnauthorised disclosure, improper use, or re-identification of anonymised information by an individual
- Order to stopDirections for non-compliance under section 36, including orders to stop collecting, using or disclosing personal data
Sources
- Official sourceAITIPersonal Data Protection Order, 2025 (Government Gazette No. S 1, 8 January 2025)
pdp.aiti.gov.bn
Link checked 18 August 2026
- Official sourcePelita Brunei, Government of Brunei DarussalamKerjasama strategik pemangkin kejayaan transformasi digital NBD, 17 August 2026 — official statement that the Personal Data Protection Order is now in force
pelitabrunei.gov.bn
“Ini termasuk pelaksanaan Perintah Perlindungan Data Peribadi, yang kini berkuat kuasa.”
Link checked 18 August 2026
- Official sourceLink may be brokenAttorney General's Chambers, Brunei DarussalamAttorney General's Chambers — Personal Data Protection Order, 2025 (amendment page)
agc.gov.bn
Link checked 18 August 2026
Cyber security rules
Official name: Cybersecurity Act, Chapter 272 (Perintah Keselamatan Siber, 2023) · S 20/2023, Revised Edition 2024 · Act of parliament
Brunei's cybersecurity law. It has been in force since 20 May 2023 and binds the Government itself. The Commissioner of Cybersecurity can label any computer system located wholly or partly in Brunei as critical. That label brings compulsory incident reporting, audits every two years, annual risk assessments, and a duty to follow the published codes of practice.
Enforced by Cyber Security Brunei / Commissioner of Cybersecurity
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidentsYou must report within a period the government sets. We could not find that period published, as at 18 August 2026.
- Independent audit — 2 yearsThe auditor must be approved or appointed by the Commissioner. The report is due within 30 days of the audit finishing.
- Assess high-risk projects — 1 yearAnnual cybersecurity risk assessment of the designated system.
- Hold a security certificateIf your system is labelled critical, you must follow the codes of practice and standards of performance the Commissioner issues.
What it costs if you get it wrong
- Criminal liability: B$100,000 and/or 2 years' imprisonment — about $78 thousandFailing without reasonable excuse to report a cybersecurity incident affecting a designated system
Sources
- Official sourceE-Government National Centre, Ministry of Transport and InfocommunicationsCybersecurity Act, Chapter 272, Revised Edition 2024 (originally S 20/2023, commencement 20 May 2023)
egnc.gov.bn
“Subject to subsections (4) and (7), every owner of a critical information infrastructure shall comply with the codes of practice and standards of performance that apply to the critical information infrastructure.”
Link checked 18 August 2026
- Official sourcePelita Brunei, Government of Brunei DarussalamMTIC perkukuh keterhubungan, transformasi digital pacu Wawasan Brunei 2035, 6 August 2026 — the Cybersecurity Order 2023 and Personal Data Protection Order 2025 described as the regulatory framework
pelitabrunei.gov.bn
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact commencement date of the Personal Data Protection Order, 2025, and which provisions have and have not been brought into operation
We could not confirm the start date against the official gazette notice. The Attorney General's Chambers website has an expired security certificate. We rely on two other sources instead. An official government newspaper reported on 17 August 2026 that a senior speaker said the Order 'is now in force'. A well-known international law firm survey says most of the main rules started on 1 January 2026. This record uses 1 January 2026 and the status 'partly in force'. Treat the date as indicative.
Whether regulations have been made prescribing the transfer requirements under section 24, the categories of data that make a breach automatically serious, and the number of affected people that makes a breach large
The regulator's own legislation page lists only the Order itself, with nothing underneath it. Its guidance library holds just two documents. Until these requirements are written down, the real content of the transfer rule and the breach thresholds is uncertain. This is the biggest open question in this record.
The identity of gazette notice S 11 of 2025, described by the Attorney General's Chambers as relating to an amendment to the Personal Data Protection Order, 2025
We could not retrieve the gazette notice or the Attorney General's Chambers page. Both sit on a site with an expired security certificate. The amendment may or may not change the transfer, breach or penalty rules used here. Check it before you rely on them.
The period within which an owner of critical information infrastructure must report a cybersecurity incident to the Commissioner of Cybersecurity
The Cybersecurity Act says 'within the prescribed period'. We could not find the regulations that set it. No figure appears in the Code of Practice or the published guidelines either. Assume it is short.
General minimum record-keeping periods under Brunei's tax, company and anti-money-laundering law
These rules sit in statutes held by the Attorney General's Chambers, which we could not reach. The central bank's anti-money-laundering pages returned no readable text, and its electronic know-your-customer notice is a scanned image. The minimum keeping periods in this record are therefore incomplete. Check them before you design a deletion schedule.
Whether the ASEAN Model Contractual Clauses are formally endorsed by the Brunei regulator as a transfer mechanism
A law firm survey reports this. We could not find the endorsement on the regulator's own site, so we do not record it as an official route. Check with the regulator before you rely on it.
Whether any organisation has been granted a written exemption from the transfer requirements
The Order expressly says these exemptions need not be published. By design there is no way to check.
Whether any storage-location or localisation rule exists in education, gaming, mapping and geospatial, or defence
We found no such rule, checked on 18 August 2026, and our confidence is medium. Brunei publishes little industry regulation outside finance and telecoms, and the main statute repository was unreachable. If you work in one of these industries, check before you rely on this.
Whether the Data Protection Appeal Panel has been constituted
We found no appointment notice or membership list on any government site. That shows nothing has been published. It does not show that no appointment has been made.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.