Brunei
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Brunei got its first privacy law in January 2025 and a senior official said on 17 August 2026 that it is now in force. Data may leave the country, but only if the place it goes to protects it about as well as Brunei does. Nothing has to be stored inside Brunei. The regulator is running training and has a breach form, but we found no fines or public decisions yet.
Data governance in Brunei
The eight things that decide how you handle data about people in Brunei. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company that has no office, no staff and no company registration in Brunei. It defines an 'organisation' as any person or body, whether or not it was set up under Brunei law and whether or not it lives or has a place of business in Brunei. There is no revenue or headcount threshold to fall below, and no requirement to appoint a local representative. You do have to name at least one person, anywhere, as your data protection officer, and publish their business contact details.
Personal Data Protection Order, 2025, section 2 (definition of 'organisation') and section 7(1)(c)-(d). Section 3(1) removes the duties in Parts 3 to 7 for individuals acting personally or domestically, for employees acting in the course of employment, and — importantly — for any public agency. Section 3(2) gives a data processor working under a written contract a reduced set of duties, but expressly keeps sections 22 (security), 23 (retention) and 24 (transfer) on the processor. Section 3(5) excludes business contact information. Section 3(4) excludes records that have existed for at least 100 years and data about people who have been dead for more than 10 years.
Sources
- Official sourceAuthority for Info-communications Technology Industry of Brunei Darussalam (AITI)Personal Data Protection Order, 2025 (Government Gazette No. S 1, 8 January 2025), sections 2, 3 and 7
pdp.aiti.gov.bn
“"organisation" includes any individual, company, association or body of persons, corporate or unincorporated, whether or not — (a) formed or recognised under the law of Brunei Darussalam; or (b) resident, or having an office or a place of business, in Brunei Darussalam”
Link checked 18 August 2026
- Official sourceAITIGuide: Appointment of Data Protection Officers, Version 1.0, 4 June 2025
pdp.aiti.gov.bn
Link checked 18 August 2026
Where the data is allowed to live
Yes, with conditions. Brunei has no rule saying data must stay in the country. The privacy law says you may only send personal data abroad if the people receiving it give it protection comparable to Brunei's. There is no list of approved or banned countries. Four industries add their own gates on top, and one of them comes close to a keep-a-copy-here rule.
SECTOR BY SECTOR, all checked on 18 August 2026. BANKING — no localisation. The central bank's outsourcing guidelines say a bank should 'in principle' only use suppliers in countries that uphold confidentiality, must not use countries where the regulator's access to information could be blocked, and must tell the regulator if any foreign authority asks to see customer information. Separately, the binding Technology Risk Management Notice makes a bank tell the central bank BEFORE signing any cloud or outsourcing contract that touches a critical system. INSURANCE AND TAKAFUL — the strictest financial gate. Material outsourcing, which expressly includes software-, platform- and infrastructure-as-a-service, data entry, data centres and archival storage, needs an application to the central bank for approval. SECURITIES AND CAPITAL MARKETS — a licence holder must notify the central bank 30 days before outsourcing an important operational function, and internal audit, risk and compliance may only go to its own group. PAYMENTS — checked the Notice on Requirements for Payment Systems. No storage-location rule found. HEALTH — the Ministry of Health forbids its contractors from moving personal data out of Brunei except on privacy-law terms, and requires the overseas recipient to be bound by legally enforceable comparable protection. CRITICAL NATIONAL SYSTEMS — the closest thing Brunei has to a residency rule. The national cyber agency's cloud policy for critical information infrastructure tells owners using a public cloud hosted outside Brunei to keep a physical or logical 'local anchor' inside Brunei. It is guidance, not law, but it sits alongside a Code of Practice that operators are legally required to follow. GOVERNMENT — the privacy law does not apply to public agencies at all. Government systems are hosted domestically through the E-Government National Centre's own data centre and central database service. TELECOM, EDUCATION, GAMING, MAPPING AND DEFENCE — no storage-location rule found, checked 18 August 2026, confidence medium.
Sources
- Official sourceAITIPersonal Data Protection Order, 2025, section 24 (transfer of personal data outside Brunei Darussalam)
pdp.aiti.gov.bn
“No organisation shall transfer any personal data to a country outside Brunei Darussalam except in accordance with the prescribed requirements to ensure that organisations provide a standard of protection to personal data so transferred that is comparable to the protection under this Order.”
Link checked 18 August 2026
- Official sourceCyber Security BruneiCloud Security Policy Guidelines for Critical Information Infrastructure, Version 1.0, 19 February 2026
csb.gov.bn
“When utilizing public cloud services hosted outside of Brunei (regional clouds), CII OWNER must adopt a Hybrid Cloud Architecture. This requires maintaining a physical or logical 'local anchor' within Brunei Darussalam.”
Link checked 18 August 2026
- Official sourceBrunei Darussalam Central BankGuidelines on Outsourcing Arrangement for Insurance Companies and Takaful Operators (TIU/G-1/2019/10), section 5 and Appendix 1
cms.bdcb.gov.bn
Link checked 18 August 2026
- Official sourceMinistry of Health, Brunei DarussalamMinistry of Health Data Handling and Security Guidelines for Contractors, Version 3, issued 8 November 2025, paragraph 6.7.10
moh.gov.bn
“Do not transfer personal data out of Brunei Darussalam except in accordance with PDPO requirements.”
Link checked 18 August 2026
Sending data out of the country
There is no approved-country list and no banned-country list. Instead you carry the burden yourself: before data leaves, you must be able to show the recipient will protect it about as well as Brunei's own law does, normally by writing that promise into your contract. The regulator can also give a single company a written exemption from those conditions. That exemption does not have to be published and can be cancelled at any time.
Personal Data Protection Order, 2025, section 24. Section 24(1) makes the transfer lawful only 'in accordance with the prescribed requirements'. Section 24(2) lets the Authority exempt a named organisation by written notice; section 24(3)(b) says that notice 'need not be published in the Gazette and may be revoked at any time'; section 24(4) lets the Authority add, vary or revoke conditions at will. The regulator's own plain-language summary describes the duty as not transferring data 'unless there is a similar or better data protection law available', with the alternative of 'contracts with specific instruction on data protection across borders'. We could not locate published regulations setting out the 'prescribed requirements' in detail, which is recorded in the unconfirmed list.
Sources
- Official sourceAITIPersonal Data Protection Order, 2025, section 24(2)-(4)
pdp.aiti.gov.bn
“An exemption under subsection (2) — (a) may be granted subject to such conditions as the Authority may specify in writing; and (b) need not be published in the Gazette and may be revoked at any time by the Authority.”
Link checked 18 August 2026
- Official sourceAITI Data Protection OfficeOverview of PDPO — Organisations: the Transfer Limitation obligation
pdp.aiti.gov.bn
“Organisations to not transfer personal data to a country or territory outside Brunei Darussalam unless there is a similar or better data protection law available. An alternative is to have contracts with specific instruction on data protection across borders.”
Link checked 18 August 2026
The regulator, and whether it actually acts
Three regulators matter. The communications regulator, known as AITI, runs the privacy law: it has a data protection office, a breach reporting form, a complaints form, published guides and a training programme for data protection officers, and it ran awareness sessions for industry in February 2026. We found no fines, orders or published decisions from it, so treat it as waking up rather than active. The central bank is genuinely active in banking, insurance and investment. The Commissioner of Cybersecurity, working through Cyber Security Brunei, runs the critical systems regime and has published binding codes and guidelines.
AITI is the Authority for Info-communications Technology Industry of Brunei Darussalam, created in 2001 and long established as the telecoms and broadcasting regulator, so it is not a paper body — but its data protection arm is new. Evidence of activity found on its own site: the dedicated pdp.aiti.gov.bn portal; a Guide for Appointment of Data Protection Officers and a Guide to Developing a Data Protection Management Programme, both dated 4 June 2025; a Certified Information Privacy Manager training programme now on its fourth cohort (10 to 12 February 2026); awareness sessions for the event management industry (24 February 2026) and for a national foundation (16 February 2026); and live breach-report and complaint forms. Evidence of gaps: the frequently asked questions page returns no entries, the guidance library holds only two documents, and the sector-specific advisory guidelines consulted on from 27 to 29 February 2024 and 'targeted to be published in 2025' were still not published on 18 August 2026. The Order also creates a Data Protection Appeal Panel and Appeal Committees; we found no evidence that either has been constituted. Penalties can reach 10 per cent of Brunei turnover for an organisation turning over more than 10 million Brunei dollars (about 7.8 million US dollars) in Brunei, and 1 million Brunei dollars (about 780,000 US dollars) otherwise.
Sources
- Official sourceAITIAITI Data Protection Office — Public Consultations, including the February 2024 sector-specific guidelines consultation
pdp.aiti.gov.bn
“The guidelines are targeted to be published in 2025.”
Link checked 18 August 2026
- Official sourceAITIAITI Data Protection Office — Guidance Documents (two documents only, as at 18 August 2026)
pdp.aiti.gov.bn
Link checked 18 August 2026
- Official sourceBrunei Darussalam Central BankBrunei Darussalam Central Bank — Regulatory Instruments: which instruments bind and which do not
bdcb.gov.bn
“Directions can be in the form of a Directive or a Notice ... They are quasi-statutory instruments with legal effect ... Guidelines set out principles or "best practice standards" ... contravention of guidelines is not a criminal offence”
Link checked 18 August 2026
- Official sourceCyber Security Brunei, Ministry of Transport and InfocommunicationsCyber Security Brunei — Code of Practice for Critical Information Infrastructure
csb.gov.bn
Link checked 18 August 2026
How long you must keep it — and when to delete it
The ceiling is a judgement call, not a number. You must stop keeping documents containing personal data, or strip out what identifies people, as soon as it is reasonable to assume the purpose is finished and there is no legal or business reason to keep it. Brunei sets no maximum number of years. On the floor side we could not verify the general tax and company record-keeping minimums from an official source, because the government's own law library was unreachable on the day we checked.
Personal Data Protection Order, 2025, section 23 sets the ceiling. Two quirks sit next to it in section 3(4): the Order does not apply at all to personal data in a record that has existed for at least 100 years, and applies to a dead person's data only for 10 years after death, and then only the disclosure and protection rules. Sector floors we did verify: Ministry of Health contractors must follow the Ministry's retention schedules, must securely dispose of personal data no longer needed, and on contract termination must return or destroy all Ministry data and certify the destruction in writing. Financial institutions must submit an updated list of all information-technology third party arrangements to the central bank within three months of each financial year end, and owners of critical national systems must audit at least once every two years and run a risk assessment at least once a year. Where a keep-it rule and a delete-it rule collide, section 3(6)(b) of the Order resolves it: any other written law wins over the privacy law to the extent of the inconsistency.
Sources
- Official sourceAITIPersonal Data Protection Order, 2025, sections 3(4), 3(6) and 23
pdp.aiti.gov.bn
“An organisation shall cease to retain its documents containing personal data, or remove the means by which the personal data can be associated with particular individuals, as soon as it is reasonable to assume that — (a) the purpose for which that personal data was collected is no longer being served by retention of the personal data; and (b) retention is no longer necessary for legal or business purposes.”
Link checked 18 August 2026
- Official sourceMinistry of Health, Brunei DarussalamMinistry of Health Data Handling and Security Guidelines for Contractors, paragraphs 6.7.9 and 6.13
moh.gov.bn
“Upon termination of contract, return or securely destroy all MOH data as instructed.”
Link checked 18 August 2026
If something goes wrong
Count four clocks, and the shortest is brutal. A bank has ONE HOUR from discovering a suspected cyber intrusion to tell the central bank, then TWO HOURS to say whether it was real, and it must not make any public announcement before that. A Ministry of Health contractor has 24 hours. Under the privacy law you must first assess whether the breach is serious, then tell the regulator no later than THREE DAYS after you finish that assessment, and tell the affected people too. Owners of critical national systems must report to the Commissioner of Cybersecurity within a period the government sets, and we could not find that period published.
Bank clock: Notice on Early Detection of Cyber Intrusion and Incident Reporting (TRS/N-1/2020/1), Amendment No. 1 effective 1 January 2024, paragraphs 4.1 to 4.5 — one hour to notify, two hours to classify, no public statement before classifying, updates at least twice every calendar day until resolved, and a root cause report within 5 working days. Privacy law clock: Personal Data Protection Order, 2025, sections 26 to 28. The three-day clock does not start at discovery; it starts when you conclude the assessment, and section 27 requires that assessment to be 'reasonable and expeditious'. A breach is notifiable if it causes or is likely to cause significant harm, or is of significant scale. A breach confined inside one organisation is deemed not notifiable. Where a supplier suffers the breach, the supplier must tell its customer without undue delay and the customer runs the assessment. Critical systems clock: Cybersecurity Act, Chapter 272, section 16 — failing to report is a criminal offence carrying a fine of up to 100,000 Brunei dollars (about 78,000 US dollars), up to two years in prison, or both.
Sources
- Official sourceBrunei Darussalam Central BankNotice on Early Detection of Cyber Intrusion and Incident Reporting (TRS/N-1/2020/1), Amendment No. 1, effective 1 January 2024, paragraph 4.1
cms.bdcb.gov.bn
“Banks shall notify Technology Risk of BDCB no later than one (1) hour after the discovery of a Suspected Incident either via email, telephone call or other authorised communication channel.”
Link checked 18 August 2026
- Official sourceAITIPersonal Data Protection Order, 2025, section 28(1)
pdp.aiti.gov.bn
“the organisation shall notify the Authority as soon as is practicable, but in any case no later than 3 days after the day the organisation makes that assessment.”
Link checked 18 August 2026
- Official sourceE-Government National Centre, Ministry of Transport and InfocommunicationsCybersecurity Act, Chapter 272 (Revised Edition 2024, originally S 20/2023), section 16
egnc.gov.bn
“The owner of a critical information infrastructure shall notify the Commissioner of the occurrence of any of the following ... within the prescribed period after becoming aware of such occurrence”
Link checked 18 August 2026
- Official sourceMinistry of Health, Brunei DarussalamMinistry of Health Data Handling and Security Guidelines for Contractors, paragraph 6.8.1
moh.gov.bn
“Report any suspected or confirmed data breaches to MOH's designated contact immediately, and no later than 24 hours after discovery.”
Link checked 18 August 2026
What catches people out
Five things that are not in the summary. One: the privacy law does not apply to any government body, so a public hospital or ministry is outside it and your only protection is the contract they give you. Two: any other Brunei law beats the privacy law where the two disagree, so a banking secrecy or national security rule wins. Three: the regulator can quietly exempt one company from the transfer rules, need not publish that exemption, and can cancel it whenever it likes — so you cannot see what your competitor has been allowed to do. Four: ordinary staff, not just companies, commit a crime if they leak personal data, misuse it for gain, or work out who anonymous data belongs to. Five: texting or calling any Brunei phone number for marketing needs clear and unambiguous consent, with no soft opt-in from an existing customer relationship.
(1) Section 3(1)(c) of the Order removes all the substantive duties for public agencies. The Ministry of Health has filled that gap by contract instead, imposing privacy-law-style duties on its suppliers. (2) Section 3(6)(b): 'the provisions of any other written law prevail to the extent that any provision of Parts 3, 4, 5, 6 and 7 is inconsistent with the provisions of that other written law'. (3) Section 24(2)-(4). (4) Sections 31, 32 and 33 make unauthorised disclosure, improper use and re-identification of anonymised information criminal offences for individuals, with fines up to 5,000 Brunei dollars (about 3,900 US dollars) and up to two years in prison. Section 48 adds offences for destroying records to defeat an access request and for obstructing the regulator. (5) Section 9 is a standalone rule for Brunei telephone numbers that overrides the normal consent routes in section 8. Two further snares worth knowing: a data processor working under a written contract is exempt from most duties but NOT from the security, retention and transfer duties, so an outsourcer cannot hide behind its customer; and a bank is forbidden from announcing an incident publicly until it has classified it for the central bank, which cuts across most global incident communication playbooks.
Sources
- Official sourceAITIPersonal Data Protection Order, 2025, sections 3, 9, 24, 31 to 33 and 48
pdp.aiti.gov.bn
“the provisions of any other written law prevail to the extent that any provision of Parts 3, 4, 5, 6 and 7 is inconsistent with the provisions of that other written law.”
Link checked 18 August 2026
- Official sourceBrunei Darussalam Central BankNotice on Early Detection of Cyber Intrusion and Incident Reporting, paragraph 4.3 (no public announcement before classification)
cms.bdcb.gov.bn
“Banks shall not make any public announcement regarding a Suspected Incident prior to notifying BDCB of its assessment under paragraph 4.2.”
Link checked 18 August 2026
What's changing next
The big missing piece is the industry-by-industry guidance. The regulator consulted banks, insurers, telecoms operators, hospitals and schools in February 2024 and promised the guidelines for 2025. They were still not published on 18 August 2026. The national cyber agency published a cloud policy for critical systems on 19 February 2026 that introduces the local anchor idea, and that idea could harden into a binding code. Brunei also has a guide on artificial intelligence ethics, now in a second edition, which is advice rather than law.
DORMANT SWITCHES — powers already held that could change the picture with no consultation. (1) Section 1(1)-(2) of the Order lets the Minister bring any remaining provision into operation on any date, and different dates for different provisions, by a gazette notice. (2) Section 3(1)(d) lets the government carve out whole classes of organisations or data by regulation. (3) Section 58 lets the Authority make regulations prescribing the transfer requirements, the categories of data that automatically make a breach serious, and the number of affected people that makes a breach large — none of which we could find published, so the practical shape of the transfer and breach rules can be redrawn overnight. (4) Section 24(2) exemptions can be granted and revoked privately. (5) Under the Cybersecurity Act, the Commissioner can designate any computer or computer system located wholly or partly in Brunei as critical information infrastructure by written notice, which immediately switches on audits, annual risk assessments, incident reporting and the cloud restrictions; the Commissioner can also issue binding written directions and emergency measures.
Sources
- Official sourceAITIAITI — Public Consultation on Proposed Sector-Specific Advisory Guidelines, 27 to 29 February 2024
pdp.aiti.gov.bn
“AITI received valuable feedback from representatives of sectors such as Telecommunications, Financial and Insurance, Healthcare, Real Estate, Social Services and Education”
Link checked 18 August 2026
- Official sourceAITIAITI — AI Governance and Ethics, including the Guide on AI Governance and Ethics for Brunei Darussalam (Second Edition)
aiti.gov.bn
Link checked 18 August 2026
- Official sourceE-Government National CentreCybersecurity Act, Chapter 272, sections 9, 13, 14 and 25 (designation, codes, directions, emergency measures)
egnc.gov.bn
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud Security Policy Guidelines for Critical Information Infrastructure (CII)
Regulator guideline · Version 1.0, read with the Code of Practice for CII v1.0 (11 March 2024), clause 3.6
The nearest thing Brunei has to a data residency rule. Operators of systems the government has designated as critical are told to keep a local anchor point inside Brunei when they use an overseas public cloud, to name permitted storage countries in the contract, and to tell the Commissioner of Cybersecurity before migrating to cloud at all.
Enforced by Cyber Security Brunei / Commissioner of Cybersecurity
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryA physical or logical 'local anchor' inside Brunei — a local management gateway, core database node or network termination point — must be kept when using a public cloud hosted abroad. This is guidance, not statute; the binding hook is the Code of Practice, which designated owners must follow under the Cybersecurity Act.
- Put a transfer safeguard in placeThe contract must name the countries in which the data may be stored.
- Report cyber incidentsThe Commissioner of Cybersecurity must be formally notified before any migration of a designated system to cloud.
- Assess high-risk projectsNo part of a designated system may be put on cloud without a risk assessment first.
Sources
- Official sourceCyber Security BruneiCloud Security Policy Guidelines for Critical Information Infrastructure, Version 1.0, 19 February 2026
csb.gov.bn
“CII OWNER SHALL formally notify the Commissioner of Cybersecurity of any intention or migrate CII to a cloud computing system prior to such adoption, in accordance with Clause 3.6.2 of the Code of Practice.”
Link checked 18 August 2026
- Official sourceCyber Security BruneiCode of Practice for Critical Information Infrastructure, Version 1.0, 11 March 2024, clause 3.6
csb.gov.bn
“The CIIO shall not implement the whole or any part of the CII on cloud computing systems unless”
Link checked 18 August 2026
Notice on Technology Risk Management
Regulator directive · Notice No. TRS/N-1/2023/2, issued under section 54 of the Brunei Darussalam Central Bank Order, 2010
A binding notice for banks and financial institutions. It does not require data to stay in Brunei, but the central bank must be told before any cloud or outsourcing contract touching a critical system is signed, and before artificial intelligence is added to one.
Enforced by Brunei Darussalam Central Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyThe central bank must be notified before signing any information-technology outsourcing, counterparty or cloud contract involving a critical system, with due diligence, risk assessment and an exit strategy supplied.
- Keep records of processingA list of all critical systems must be identified and kept current, including on migration to cloud.
- Written vendor contract — 1 yearA full list of information-technology third party arrangements must reach the central bank within three months of each financial year end.
- Check your algorithmsThe central bank must be notified before adding artificial intelligence to a critical system, with prior engagement for higher autonomy levels.
Sources
- Official sourceBrunei Darussalam Central BankNotice on Technology Risk Management (Notice No. TRS/N-1/2023/2), 30 June 2023, paragraphs 5.1 and 7.1
cms.bdcb.gov.bn
“Banks and FIs shall notify BDCB prior to signing a contract with an IT outsourcing service provider, counterpart and/or cloud service that involves critical systems.”
Link checked 18 August 2026
- Official sourceBrunei Darussalam Central BankGuidelines on Information Technology Third Party Risk Management (TRS/G-3/2022/2), paragraphs 4.5 and 7.1 to 7.4
cms.bdcb.gov.bn
“Depending on the scope of the service, cloud computing should be considered as a form of IT outsourcing with offshore service provider”
Link checked 18 August 2026
Notice on Early Detection of Cyber Intrusion and Incident Reporting
Regulator directive · Notice No. TRS/N-1/2020/1, Amendment No. 1 dated 23 November 2023, issued under section 66 of the Banking Order, 2006 and section 66 of the Islamic Banking Order, 2008
The sharpest clock in Brunei. A bank has one hour from discovering a suspected cyber intrusion to tell the central bank, two hours to say whether it was real, and must not say anything publicly before doing so.
Enforced by Brunei Darussalam Central Bank
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 1 hourOne hour from discovery to notify the central bank's Technology Risk unit; two hours to classify the incident; updates at least twice a day until resolved; root cause report within 5 working days.
- Secure the dataBanks must build detection capability for anomalous traffic across internal systems.
Sources
- Official sourceBrunei Darussalam Central BankNotice on Early Detection of Cyber Intrusion and Incident Reporting (TRS/N-1/2020/1), Amendment No. 1, effective 1 January 2024
cms.bdcb.gov.bn
“Banks shall notify Technology Risk of BDCB no later than one (1) hour after the discovery of a Suspected Incident”
Link checked 18 August 2026
Notice on Application for Approval of Outsourcing Arrangement for Insurance Companies and Takaful Operators, with Guidelines on Outsourcing Arrangement
Regulator directive · Notice No. TIU/N-1/2019/11 and Guidelines No. TIU/G-1/2019/10, issued under section 88 of the Insurance Order, 2006 and section 90 of the Takaful Order, 2008
Insurers and takaful operators need the central bank's approval before handing out material operations, and cloud hosting counts. They must also warn the central bank if any foreign authority asks to see customer information.
Enforced by Brunei Darussalam Central Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyMaterial outsourcing needs an application to the central bank for approval, with board endorsement first. Software-, platform- and infrastructure-as-a-service, data centres, data entry and processing, and archival storage of records all count as material outsourcing.
- Do not hand data to foreign authorities on demandThe insurer must tell the central bank if any overseas authority seeks access to its customer information, or if the insurer's or the regulator's rights of access are restricted or denied.
- Written vendor contractOnly jurisdictions that generally uphold confidentiality obligations should be used, and none where the regulator's prompt access to information could be blocked.
Sources
- Official sourceBrunei Darussalam Central BankGuidelines on Outsourcing Arrangement for Insurance Companies and Takaful Operators (TIU/G-1/2019/10), 21 August 2019, paragraphs 4.9 and 5 and Appendix 1
cms.bdcb.gov.bn
“the insurer should notify AMBD if any overseas authority were to seek access to its customer information or if a situation were to arise where the rights of access of the insurer and AMBD set out in paragraph 4.8, have been restricted or denied.”
Link checked 18 August 2026
- Official sourceBrunei Darussalam Central BankNotice on Technology Risk Management, paragraph 1.5.1 confirming the insurance outsourcing approval notice remains in force
cms.bdcb.gov.bn
Link checked 18 August 2026
Notice on Outsourcing for Capital Markets Services Licence Holders
Regulator directive · Notice No. CMA/N-1/2020/15, issued under the Securities Markets Order, 2013
Investment and capital markets licence holders must give the central bank 30 days' notice before outsourcing an important function, and may only send internal audit, risk and compliance work to their own corporate group.
Enforced by Brunei Darussalam Central Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notify — within 720 hoursThirty days' notice to the central bank before outsourcing an important operational function.
- Written vendor contractThe supplier and any subcontractor must agree in the contract or a letter of undertaking that the regulator may access and copy records relating to the function.
- Keep records of processingAn outsourcing register must be submitted covering all planned and renewed arrangements.
Sources
- Official sourceBrunei Darussalam Central BankNotice on Outsourcing for Capital Markets Services Licence Holders (CMA/N-1/2020/15), effective 14 April 2020, paragraphs 4.1 to 4.5
cms.bdcb.gov.bn
“Any CMSL holder that intends to outsource any important operational function shall notify the Authority 30 days prior to the outsourcing of such important operational function.”
Link checked 18 August 2026
Ministry of Health Data Handling and Security Guidelines for Contractors
Regulator guideline · DPP/CDGG/V.3/06/2025, Version 3, next review 8 November 2028
The Ministry of Health is exempt from the privacy law as a public agency, so it imposes privacy-law-style duties on its suppliers by contract instead. Health data may leave Brunei only if the recipient is legally bound to comparable protection, and breaches must reach the Ministry within 24 hours.
Enforced by Ministry of Health
Transfer model: Approval each time · Accepted routes: Standard contract clauses
What it makes you do
- Put a transfer safeguard in placeNo transfer out of Brunei except on privacy-law terms, and the overseas recipient must be bound by legally enforceable obligations giving comparable protection.
- Report breaches to the regulator — within 24 hoursTo the Ministry's designated contact, immediately and in any event within 24 hours of discovery.
- Secure the dataRestricted health data must be encrypted at rest and in transit and limited to authorised healthcare professionals.
- Delete data after a periodFollow the Ministry's retention schedules; on contract end, return or destroy all Ministry data and certify destruction in writing.
- Extra vendor secrecy termsApplies to every external party handling Ministry data, filling the gap left by the privacy law's exclusion of public agencies.
Sources
- Official sourceMinistry of Health, Brunei DarussalamMinistry of Health Data Handling and Security Guidelines for Contractors, Version 3, issued 8 November 2025
moh.gov.bn
“Ensure that the overseas recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPO.”
Link checked 18 August 2026
Code of Practice for the Registration of Mobile Prepaid Subscriber Identity Module (SIM) Cards
Statutory code of practice · Mobile Prepaid SIM Cards Registration Code
Every prepaid mobile subscriber in Brunei must be identified against an original identity document, and the operator must keep those records accurate. There is no storage-location rule, but the identity dataset it creates is unusually complete.
Enforced by Authority for Info-communications Technology Industry of Brunei Darussalam
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep records of processingMobile service providers and their resellers must keep accurate identity records for every prepaid subscriber, including name, identity card number and address, and update them on any change of ownership.
- Get a parent's consent for children — applies at: under 12A prepaid card for a child under 12 must be registered in a parent's or guardian's name, with the child listed only as the user. Brunei's threshold is 12, far below the global norm of 13 to 16.
Sources
- Official sourceAITIAITI — Code of Practice for the Registration of Mobile Prepaid SIM Cards, effective 4 September 2024
aiti.gov.bn
“For subscribers under twelve (12) years old ("minor"), the parent or legal guardian of the minor shall register the mobile prepaid SIM card under the parent or legal guardian and list the minor as the user.”
Link checked 18 August 2026
- Official sourceAITICode of Practice for the Registration of Mobile Prepaid SIM Cards (full text), paragraph 2.1
aiti.gov.bn
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Personal Data Protection Order, 2025 / Perintah Perlindungan Data Peribadi, 2025
Directly binding regulation · Government Gazette No. S 1 of 2025, made under Article 83(3) of the Constitution
Brunei's first general privacy law, closely modelled on Singapore's. Consent-based, with access and correction rights, a designated data protection officer, a three-day breach notification clock and a comparable-protection test for sending data abroad. Government bodies are entirely outside it, and any other Brunei law overrides it.
Enforced by Authority for Info-communications Technology Industry of Brunei Darussalam
Transfer model: Approval each time · Accepted routes: Standard contract clauses, Government sign-off needed
What it makes you do
- Get consentConsent is the default. Deemed consent, deemed consent by notification, and a list of statutory exceptions in Schedules 1 to 3 provide the alternatives.
- Tell people what you do
- Let people see their dataIncludes the right to be told how the data was used or disclosed in the year before the request.
- Let people correct their data
- Let people objectExpressed as a right to withdraw consent on reasonable notice.
- Secure the data
- Delete data after a periodNo fixed period. Stop retaining once the purpose is served and no legal or business need remains.
- Put a transfer safeguard in placeComparable standard of protection required. The detailed prescribed requirements were not found published as at 18 August 2026.
- Report breaches to the regulator — within 72 hoursThree days, counted from the completion of the organisation's own assessment, not from discovery.
- Tell affected peopleNot required where remedial action or pre-existing technology makes significant harm unlikely.
- Appoint a data protection officerAt least one designated individual. No requirement that the person be in Brunei.
- Publish a complaints contactBusiness contact information of the designated individual must be made public, and a complaints process developed.
- Keep records of processingPolicies and practices must be developed, implemented and communicated to staff, and made available on request.
What it costs if you get it wrong
- Percentage of global turnover: 10% of annual turnover in Brunei DarussalamIntentional or negligent breach of Parts 3 to 7 by an organisation whose Brunei turnover exceeds B$10,000,000
- Fixed maximum fine: B$1,000,000 — about $780 thousandIntentional or negligent breach of Parts 3 to 7 in any other case
- Criminal liability: B$5,000 and/or 2 years' imprisonment — about $4 thousandUnauthorised disclosure, improper use, or re-identification of anonymised information by an individual
- Order to stopDirections for non-compliance under section 36, including orders to stop collecting, using or disclosing personal data
Sources
- Official sourceAITIPersonal Data Protection Order, 2025 (Government Gazette No. S 1, 8 January 2025)
pdp.aiti.gov.bn
Link checked 18 August 2026
- Official sourcePelita Brunei, Government of Brunei DarussalamKerjasama strategik pemangkin kejayaan transformasi digital NBD, 17 August 2026 — official statement that the Personal Data Protection Order is now in force
pelitabrunei.gov.bn
“Ini termasuk pelaksanaan Perintah Perlindungan Data Peribadi, yang kini berkuat kuasa.”
Link checked 18 August 2026
- Official sourceLink may be brokenAttorney General's Chambers, Brunei DarussalamAttorney General's Chambers — Personal Data Protection Order, 2025 (amendment page)
agc.gov.bn
Link checked 18 August 2026
Cybersecurity Act, Chapter 272 (Perintah Keselamatan Siber, 2023)
Act of parliament · S 20/2023, Revised Edition 2024
Brunei's cybersecurity law, in force since 20 May 2023 and binding on the Government itself. It lets the Commissioner of Cybersecurity designate any computer system located wholly or partly in Brunei as critical, which then triggers mandatory incident reporting, two-yearly audits, annual risk assessments and mandatory compliance with published codes of practice.
Enforced by Cyber Security Brunei / Commissioner of Cybersecurity
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidentsReportable within a period the government prescribes. We could not find that period published as at 18 August 2026.
- Independent audit — 2 yearsBy an auditor approved or appointed by the Commissioner; report due within 30 days of completion.
- Assess high-risk projects — 1 yearAnnual cybersecurity risk assessment of the designated system.
- Hold a security certificateCompliance with codes of practice and standards of performance issued by the Commissioner is mandatory for designated owners.
What it costs if you get it wrong
- Criminal liability: B$100,000 and/or 2 years' imprisonment — about $78 thousandFailing without reasonable excuse to report a cybersecurity incident affecting a designated system
Sources
- Official sourceE-Government National Centre, Ministry of Transport and InfocommunicationsCybersecurity Act, Chapter 272, Revised Edition 2024 (originally S 20/2023, commencement 20 May 2023)
egnc.gov.bn
“Subject to subsections (4) and (7), every owner of a critical information infrastructure shall comply with the codes of practice and standards of performance that apply to the critical information infrastructure.”
Link checked 18 August 2026
- Official sourcePelita Brunei, Government of Brunei DarussalamMTIC perkukuh keterhubungan, transformasi digital pacu Wawasan Brunei 2035, 6 August 2026 — the Cybersecurity Order 2023 and Personal Data Protection Order 2025 described as the regulatory framework
pelitabrunei.gov.bn
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact commencement date of the Personal Data Protection Order, 2025, and which provisions have and have not been brought into operation
The Order commences on dates appointed by the Minister by gazette notice, and different dates may be set for different provisions. The commencement notice itself sits with the Attorney General's Chambers, whose website could not be opened on 18 August 2026 because its security certificate has expired. We rely on two other pieces of evidence: an official government newspaper report of 17 August 2026 quoting a senior speaker saying the Order 'is now in force', and a well-known international law firm survey stating most substantive provisions commenced on 1 January 2026. Because the primary notice is missing, the record uses 1 January 2026 and the status 'partly in force'. Treat the date as indicative.
Whether regulations have been made prescribing the transfer requirements under section 24, the categories of data that make a breach automatically serious, and the number of affected people that makes a breach large
The regulator's own legislation page lists only the Order itself, with no subsidiary instruments, and its guidance library holds just two documents. Until those requirements are prescribed, the practical content of the transfer rule and of the breach thresholds is uncertain. This is the single biggest open question in the record.
The identity of gazette notice S 11 of 2025, described by the Attorney General's Chambers as relating to an amendment to the Personal Data Protection Order, 2025
Both the gazette PDF and the Attorney General's Chambers page are hosted on a site whose security certificate has expired, so neither could be retrieved. The amendment may or may not alter the transfer, breach or penalty provisions relied on here.
The period within which an owner of critical information infrastructure must report a cybersecurity incident to the Commissioner of Cybersecurity
The Cybersecurity Act says 'within the prescribed period' but we could not find the regulations prescribing it, nor a figure in the Code of Practice or the published guidelines. Assume it is short.
General minimum record-keeping periods under Brunei's tax, company and anti-money-laundering law
These sit in statutes hosted by the Attorney General's Chambers, which was unreachable. The central bank's anti-money-laundering pages returned no readable content and its electronic know-your-customer notice is a scanned image. The retention floor in this record is therefore incomplete.
Whether the ASEAN Model Contractual Clauses are formally endorsed by the Brunei regulator as a transfer mechanism
Reported by a law firm survey. We could not find the endorsement on the regulator's own site, so it is not recorded as an official mechanism.
Whether any organisation has been granted a written exemption from the transfer requirements
The Order expressly says such exemptions need not be published. By design there is no way to check.
Whether any storage-location or localisation rule exists in education, gaming, mapping and geospatial, or defence
No rule found, checked 18 August 2026, confidence medium. Brunei publishes little sector regulation outside finance and telecoms, and the central statute repository was unreachable.
Whether the Data Protection Appeal Panel has been constituted
No appointment notice or membership list found on any government site. We can evidence absence of publication, not absence of appointment.
60-day cadence. Two things move fast here: the regulations that will fill in the transfer and breach rules could appear at any time, and the sector-specific advisory guidelines are already a year overdue. The Minister can also commence further provisions, and the Commissioner of Cybersecurity can designate new critical systems, by notice with no consultation.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Brunei versus
Compare