Skip to the content
Global Data RulesData governance rules, country by country

Brunei

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: MediumEnforcement: Waking up

Brunei got its first privacy law in January 2025 and a senior official said on 17 August 2026 that it is now in force. Data may leave the country, but only if the place it goes to protects it about as well as Brunei does. Nothing has to be stored inside Brunei. The regulator is running training and has a breach form, but we found no fines or public decisions yet.

Data governance in Brunei

The eight things that decide how you handle data about people in Brunei. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company that has no office, no staff and no company registration in Brunei. It defines an 'organisation' as any person or body, whether or not it was set up under Brunei law and whether or not it lives or has a place of business in Brunei. There is no revenue or headcount threshold to fall below, and no requirement to appoint a local representative. You do have to name at least one person, anywhere, as your data protection officer, and publish their business contact details.

High confidenceNational rulesAppoint a data protection officerPublish a complaints contact

Where the data is allowed to live

Yes, with conditions. Brunei has no rule saying data must stay in the country. The privacy law says you may only send personal data abroad if the people receiving it give it protection comparable to Brunei's. There is no list of approved or banned countries. Four industries add their own gates on top, and one of them comes close to a keep-a-copy-here rule.

High confidenceYes, with paperworkApproval each timePut a transfer safeguard in place

Sending data out of the country

There is no approved-country list and no banned-country list. Instead you carry the burden yourself: before data leaves, you must be able to show the recipient will protect it about as well as Brunei's own law does, normally by writing that promise into your contract. The regulator can also give a single company a written exemption from those conditions. That exemption does not have to be published and can be cancelled at any time.

Medium confidenceApproval each timeStandard contract clausesGovernment sign-off neededWritten vendor contract

The regulator, and whether it actually acts

Three regulators matter. The communications regulator, known as AITI, runs the privacy law: it has a data protection office, a breach reporting form, a complaints form, published guides and a training programme for data protection officers, and it ran awareness sessions for industry in February 2026. We found no fines, orders or published decisions from it, so treat it as waking up rather than active. The central bank is genuinely active in banking, insurance and investment. The Commissioner of Cybersecurity, working through Cyber Security Brunei, runs the critical systems regime and has published binding codes and guidelines.

Medium confidenceWaking upPercentage of global turnoverFixed maximum fineCriminal liability

How long you must keep it — and when to delete it

The ceiling is a judgement call, not a number. You must stop keeping documents containing personal data, or strip out what identifies people, as soon as it is reasonable to assume the purpose is finished and there is no legal or business reason to keep it. Brunei sets no maximum number of years. On the floor side we could not verify the general tax and company record-keeping minimums from an official source, because the government's own law library was unreachable on the day we checked.

Medium confidenceDelete data after a periodKeep data for a minimum periodIndependent audit

If something goes wrong

Count four clocks, and the shortest is brutal. A bank has ONE HOUR from discovering a suspected cyber intrusion to tell the central bank, then TWO HOURS to say whether it was real, and it must not make any public announcement before that. A Ministry of Health contractor has 24 hours. Under the privacy law you must first assess whether the breach is serious, then tell the regulator no later than THREE DAYS after you finish that assessment, and tell the affected people too. Owners of critical national systems must report to the Commissioner of Cybersecurity within a period the government sets, and we could not find that period published.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that are not in the summary. One: the privacy law does not apply to any government body, so a public hospital or ministry is outside it and your only protection is the contract they give you. Two: any other Brunei law beats the privacy law where the two disagree, so a banking secrecy or national security rule wins. Three: the regulator can quietly exempt one company from the transfer rules, need not publish that exemption, and can cancel it whenever it likes — so you cannot see what your competitor has been allowed to do. Four: ordinary staff, not just companies, commit a crime if they leak personal data, misuse it for gain, or work out who anonymous data belongs to. Five: texting or calling any Brunei phone number for marketing needs clear and unambiguous consent, with no soft opt-in from an existing customer relationship.

High confidenceCriminal liabilityWritten vendor contractGet consentPut a transfer safeguard in place

What's changing next

The big missing piece is the industry-by-industry guidance. The regulator consulted banks, insurers, telecoms operators, hospitals and schools in February 2024 and promised the guidelines for 2025. They were still not published on 18 August 2026. The national cyber agency published a cloud policy for critical systems on 19 February 2026 that introduces the local anchor idea, and that idea could harden into a binding code. Brunei also has a guide on artificial intelligence ethics, now in a second edition, which is advice rather than law.

Medium confidencePartly in forceRegulator guideline

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Cloud Security Policy Guidelines for Critical Information Infrastructure (CII)

Regulator guideline · Version 1.0, read with the Code of Practice for CII v1.0 (11 March 2024), clause 3.6

In forceA copy must stay

The nearest thing Brunei has to a data residency rule. Operators of systems the government has designated as critical are told to keep a local anchor point inside Brunei when they use an overseas public cloud, to name permitted storage countries in the contract, and to tell the Commissioner of Cybersecurity before migrating to cloud at all.

In force since 19 February 2026

Enforced by Cyber Security Brunei / Commissioner of Cybersecurity

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence
Finance

Notice on Technology Risk Management

Regulator directive · Notice No. TRS/N-1/2023/2, issued under section 54 of the Brunei Darussalam Central Bank Order, 2010

In forceYes, with paperwork

A binding notice for banks and financial institutions. It does not require data to stay in Brunei, but the central bank must be told before any cloud or outsourcing contract touching a critical system is signed, and before artificial intelligence is added to one.

In force since 30 June 2023

Enforced by Brunei Darussalam Central Bank

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Banking

Notice on Early Detection of Cyber Intrusion and Incident Reporting

Regulator directive · Notice No. TRS/N-1/2020/1, Amendment No. 1 dated 23 November 2023, issued under section 66 of the Banking Order, 2006 and section 66 of the Islamic Banking Order, 2008

In forceYes — store it anywhere

The sharpest clock in Brunei. A bank has one hour from discovering a suspected cyber intrusion to tell the central bank, two hours to say whether it was real, and must not say anything publicly before doing so.

In force since 1 January 2024

Enforced by Brunei Darussalam Central Bank

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Personal Data Protection Order, 2025 / Perintah Perlindungan Data Peribadi, 2025

Directly binding regulation · Government Gazette No. S 1 of 2025, made under Article 83(3) of the Constitution

Partly in forceYes, with paperwork

Brunei's first general privacy law, closely modelled on Singapore's. Consent-based, with access and correction rights, a designated data protection officer, a three-day breach notification clock and a comparable-protection test for sending data abroad. Government bodies are entirely outside it, and any other Brunei law overrides it.

In force since 1 January 2026

Enforced by Authority for Info-communications Technology Industry of Brunei Darussalam

Transfer model: Approval each time · Accepted routes: Standard contract clauses, Government sign-off needed

Medium confidence

Cybersecurity Act, Chapter 272 (Perintah Keselamatan Siber, 2023)

Act of parliament · S 20/2023, Revised Edition 2024

In forceYes — store it anywhere

Brunei's cybersecurity law, in force since 20 May 2023 and binding on the Government itself. It lets the Commissioner of Cybersecurity designate any computer system located wholly or partly in Brunei as critical, which then triggers mandatory incident reporting, two-yearly audits, annual risk assessments and mandatory compliance with published codes of practice.

In force since 20 May 2023

Enforced by Cyber Security Brunei / Commissioner of Cybersecurity

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Pihak Berkuasa Industri Teknologi Info-komunikasi Negara Brunei Darussalam (AITI)

    Privacy law, telecoms, broadcasting, postal, artificial intelligence guidance

    Long-established as the telecoms regulator since 2003 and unquestionably staffed. Its data protection arm is new: dedicated portal at pdp.aiti.gov.bn, two guidance documents dated 4 June 2025, a fourth cohort of privacy manager training in February 2026, live breach and complaint forms, and industry awareness sessions in February 2026. No fines, orders or published enforcement decisions under the privacy law were found as at 18 August 2026, and the sector-specific guidelines promised for 2025 remain unpublished.

  • Bank Pusat Brunei Darussalam (BDCB), formerly Autoriti Monetari Brunei Darussalam (AMBD)

    Banking, Islamic banking, insurance and takaful, capital markets, payments, money services

    Fully active. Publishes a searchable register of over 340 binding notices, guidelines and codes, has an enforcement function and an alert list, and issued new instruments as recently as February 2026. Its own published taxonomy distinguishes Notices (legally binding) from Guidelines (best practice), which matters when reading its outsourcing rules.

  • Cyber Security Brunei (CSB)

    Critical information infrastructure, national incident response through BruCERT

    Operating under the Ministry of Transport and Infocommunications. Has issued a Code of Practice for critical information infrastructure (version 1.0, 11 March 2024) and a set of guidelines including the Cloud Security Policy dated 19 February 2026, runs an incident reporting channel through BruCERT, and was publicly active through 2026. We found no published list of designated critical systems and no published prescribed reporting period.

  • Kementerian Kesihatan

    Health data handled by ministry contractors and suppliers

    Issues and revises its own contractor data handling standard; version 3 dated 8 November 2025 with a review date of 8 November 2028.

  • Appeals against directions and decisions under the privacy law

    Established by section 41 of the Personal Data Protection Order, 2025. We found no evidence that the Panel has been appointed or that any Appeal Committee has been constituted, and no published appeal decisions, as at 18 August 2026.

  • Pusat Kerajaan Elektronik Kebangsaan (EGNC)

    Government hosting, government cloud, ministry ICT policies

    Runs the government's own co-location data centre and the National Centralised Database service, available only to government ministries and departments. Publishes government computer use, internet use and email policies.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact commencement date of the Personal Data Protection Order, 2025, and which provisions have and have not been brought into operation

    The Order commences on dates appointed by the Minister by gazette notice, and different dates may be set for different provisions. The commencement notice itself sits with the Attorney General's Chambers, whose website could not be opened on 18 August 2026 because its security certificate has expired. We rely on two other pieces of evidence: an official government newspaper report of 17 August 2026 quoting a senior speaker saying the Order 'is now in force', and a well-known international law firm survey stating most substantive provisions commenced on 1 January 2026. Because the primary notice is missing, the record uses 1 January 2026 and the status 'partly in force'. Treat the date as indicative.

  • Whether regulations have been made prescribing the transfer requirements under section 24, the categories of data that make a breach automatically serious, and the number of affected people that makes a breach large

    The regulator's own legislation page lists only the Order itself, with no subsidiary instruments, and its guidance library holds just two documents. Until those requirements are prescribed, the practical content of the transfer rule and of the breach thresholds is uncertain. This is the single biggest open question in the record.

  • The identity of gazette notice S 11 of 2025, described by the Attorney General's Chambers as relating to an amendment to the Personal Data Protection Order, 2025

    Both the gazette PDF and the Attorney General's Chambers page are hosted on a site whose security certificate has expired, so neither could be retrieved. The amendment may or may not alter the transfer, breach or penalty provisions relied on here.

  • The period within which an owner of critical information infrastructure must report a cybersecurity incident to the Commissioner of Cybersecurity

    The Cybersecurity Act says 'within the prescribed period' but we could not find the regulations prescribing it, nor a figure in the Code of Practice or the published guidelines. Assume it is short.

  • General minimum record-keeping periods under Brunei's tax, company and anti-money-laundering law

    These sit in statutes hosted by the Attorney General's Chambers, which was unreachable. The central bank's anti-money-laundering pages returned no readable content and its electronic know-your-customer notice is a scanned image. The retention floor in this record is therefore incomplete.

  • Whether the ASEAN Model Contractual Clauses are formally endorsed by the Brunei regulator as a transfer mechanism

    Reported by a law firm survey. We could not find the endorsement on the regulator's own site, so it is not recorded as an official mechanism.

  • Whether any organisation has been granted a written exemption from the transfer requirements

    The Order expressly says such exemptions need not be published. By design there is no way to check.

  • Whether any storage-location or localisation rule exists in education, gaming, mapping and geospatial, or defence

    No rule found, checked 18 August 2026, confidence medium. Brunei publishes little sector regulation outside finance and telecoms, and the central statute repository was unreachable.

  • Whether the Data Protection Appeal Panel has been constituted

    No appointment notice or membership list found on any government site. We can evidence absence of publication, not absence of appointment.

60-day cadence. Two things move fast here: the regulations that will fill in the transfer and breach rules could appear at any time, and the sector-specific advisory guidelines are already a year overdue. The Minister can also commence further provisions, and the Commissioner of Cybersecurity can designate new critical systems, by notice with no consultation.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Brunei versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.