Cambodia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Cambodia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Cambodia has no general privacy law. A draft law went to a public review meeting in August 2026. It is not law yet, and there is no privacy regulator to complain to. For most businesses, data can leave the country freely, with no paperwork. Banks and other lenders are the big exception. Their main data centre must sit inside Cambodia.
Data governance in Cambodia
The eight things that decide how you handle data about people in Cambodia. Same eight on every country page, so you can compare.
Who has to follow these rules
There is no general data protection law in Cambodia, so there is nothing for a foreign company to be caught by. No size threshold, no revenue threshold, no registration, and no need to appoint someone in Cambodia to answer for your data. That changes the moment you need a local licence. Banks, lenders and telecoms operators are licensed here, and their licence conditions do reach their overseas systems. A draft privacy law was put to a validation workshop on 5 August 2026 and will now go through the formal law-making process. So this answer has a shelf life.
Cambodia's data rules are scattered across separate industry rules rather than one law. The Law on Electronic Commerce (adopted late 2019) applies to electronic transactions and puts a security duty on service providers. Financial firms are caught through the National Bank of Cambodia's supervisory guidelines. Those apply to the licensed firm wherever its technology sits. The Ministry of Commerce, the Ministry of Post and Telecommunications and the Ministry of Interior each handle data questions inside their own area. None of them is a general data protection authority.
Sources
- Official sourceMinistry of Post and TelecommunicationsValidation Workshop on the Draft Law on Personal Data Protection, 5 August 2026
mptc.gov.kh
“The workshop brought together representatives from government ministries and institutions, the private sector, development partners, educational institutions, civil society organizations, and experts to review, validate, and gather feedback on the draft law before it proceeds through the formal legislative process.”
Link checked 18 August 2026
- Official sourceMinistry of Post and TelecommunicationsTraining Workshop on 'Establishing a Personal Data Protection Authority', 13-14 November 2025
mptc.gov.kh
“These practical insights will serve as an important foundation for establishing Cambodia's personal data protection authority.”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Cambodia (law, transfer and enforcement chapters)
dlapiperdataprotection.com
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, and with nothing to sign. Cambodia has no rule stopping ordinary personal data from leaving the country. Finance is the one strict exception we could verify. A bank or lender supervised by the central bank must have at least one main data centre in Cambodia. It may only use a foreign data centre as a backup. And it needs the central bank's approval before customer personal data is hosted abroad. Telecoms is the sector to watch. A 2021 order that would route all internet traffic through a single national gateway was never switched on, but was never cancelled either.
Sector by sector, checked on 18 August 2026. Banking, lending and payments. The central bank's Technology and Cyber Risk Management Guidelines, issued January 2026, require at least one primary data centre inside Cambodia. A data centre outside Cambodia needs central bank approval. It may only be a secondary or disaster-recovery site, and you need a written plan for moving back. Separately, moving or hosting customer personal data abroad needs a risk assessment of the destination and prior approval from the central bank. This is a mirror rule. Telecoms. We found no rule in force about where data is stored. The National Internet Gateway sub-decree of February 2021 would concentrate all international traffic through a state-controlled gateway, but it has never been put into operation. Open today, with a switch the government could still flip. Government and public sector. We found no binding rule requiring data to stay in Cambodia. The government's own Digital Government Policy admits that only about 30 percent of ministries use local data centres. The rest rely on overseas cloud. It sets building national data centres as a goal, not a duty. Open. Insurance and securities. The insurance regulator and the securities regulator publish laws, sub-decrees and prakas. Their document libraries load dynamically and we could not read them. We found no rule about where data must be kept. Treat that as unconfirmed rather than as an absence. Health, education, gaming, mapping and defence. We found no Cambodian government source imposing a rule about storing or sending data. Again, treat that as not found rather than absent.
Sources
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, paragraph 3.13.1
nbc.gov.kh
“The BFI shall have at least one primary data center in Cambodia to host their IT environment.”
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, paragraphs 3.13.5 and 3.13.6
nbc.gov.kh
“The BFI shall seek approval from NBC regarding establishing data center outside Cambodia. A data center outside Cambodia shall be used as a secondary data center.”
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, Chapter 9 (Customer Personal Data Protection), paragraph 9.0.3
nbc.gov.kh
“The BFI shall conduct a comprehensive risk assessment of the geographic location where customer personal data is to be migrated or hosted outside Cambodia and shall obtain prior approval from the NBC.”
Link checked 18 August 2026
- Official sourceRoyal Government of Cambodia / Ministry of Post and TelecommunicationsCambodia Digital Government Policy 2022-2035, situation analysis and priority actions on data centres and data governance
mptc.obsv3.kh-gov-1.mptccloud.gov.kh
“Only 30 percent of ministries and institutions use local data center services while others rely on overseas cloud technology services.”
Link checked 18 August 2026
- Official sourceMinistry of Post and TelecommunicationsPress Release on the National Internet Gateway, February 2021
mptc.gov.kh
Link checked 18 August 2026
- Official sourceInsurance Regulator of CambodiaInsurance Regulator of Cambodia - laws, sub-decrees, prakas and guidance sections (checked 18 August 2026)
irc.gov.kh
Link checked 18 August 2026
- Official sourceSecurities and Exchange Regulator of CambodiaSecurities and Exchange Regulator of Cambodia - Prakas listing (checked 18 August 2026)
serc.gov.kh
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Cambodia (law, transfer and enforcement chapters)
dlapiperdataprotection.com
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
For most organisations, nothing at all. There is no list of approved countries, no list of banned countries, no standard contract to sign, and no government form to file. Those lists are not just empty. They do not exist, because no law creates them. Finance works completely differently. Each move of customer personal data out of Cambodia needs its own approval from the central bank, decided case by case. There is no published application process and no timetable.
- Ways to send data out:
- Nothing required · Government sign-off needed
Cambodia has no rules on sending data abroad. So there is no concept of an approved country, no standard contract clauses, and no binding corporate rules. The controls that actually apply to Cambodian operations come from contracts imposed by overseas customers and parent companies, not from Cambodian law. Finance is different. Paragraph 9.0.3 of the central bank's 2026 guidelines requires a full risk assessment of the location. It also requires prior approval from the National Bank of Cambodia. Paragraph 3.13.5 requires separate approval for a data centre abroad. Paragraph 6.1.6 covers cloud contracts. They must spell out where data is stored and handled, what crosses borders, how long logs are kept, and how long data is kept.
Sources
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, Chapter 9 (Customer Personal Data Protection), paragraph 9.0.3
nbc.gov.kh
“The BFI shall conduct a comprehensive risk assessment of the geographic location where customer personal data is to be migrated or hosted outside Cambodia and shall obtain prior approval from the NBC.”
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, paragraphs 3.13.5 and 3.13.6
nbc.gov.kh
“The BFI shall seek approval from NBC regarding establishing data center outside Cambodia. A data center outside Cambodia shall be used as a secondary data center.”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Cambodia (law, transfer and enforcement chapters)
dlapiperdataprotection.com
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
For privacy, nobody. Cambodia has no data protection authority. The Ministry of Post and Telecommunications is writing the law. In November 2025 it ran a training workshop with Singapore's privacy regulator on how to build such an authority. That tells you plainly that one does not yet exist. Sector regulators are a different story, and they are really working. The central bank supervises financial firms against its 2026 technology guidelines. And the telecoms regulator publicly named an operator in June 2026 for selling SIM cards without properly checking customers' identity documents.
Our rating of dormant is about privacy enforcement specifically. It is not about the Cambodian state generally. Here is what the sector regulators actually do. The National Bank of Cambodia runs a Technology Risk and Innovation Supervision Department. It publishes prakas and guidelines, and its own guidelines say that 'compliance requirements' are requirements that will be assessed for compliance. The Telecommunication Regulator of Cambodia published a public notification against Viettel (Cambodia) on 15 June 2026 over identity checks on SIM sales. It ran a public consultation on equipment standards, with the deadline extended to 25 June 2026. It issued guidelines on mobile text-message notifications in May 2026. Today, complaints about misuse of personal data go to whichever ministry supervises the business: commerce, telecommunications or interior. None of them publishes its decisions.
Sources
- Official sourceMinistry of Post and TelecommunicationsTraining Workshop on 'Establishing a Personal Data Protection Authority', 13-14 November 2025
mptc.gov.kh
“These practical insights will serve as an important foundation for establishing Cambodia's personal data protection authority.”
Link checked 18 August 2026
- Official sourceTelecommunication Regulator of CambodiaPublic Notification on the case of Viettel (Cambodia) selling mobile phone SIM cards without properly accepting the user's identification documents, 15 June 2026
trc.gov.kh
Link checked 18 August 2026
- Official sourceTelecommunication Regulator of CambodiaTelecommunication Regulator of Cambodia - announcements and public consultations, 2026
trc.gov.kh
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, Interpretation and Introduction (supersede the 2019 guidelines)
nbc.gov.kh
“For the purposes of this document, “Compliance requirements” are requirements that will be assessed for compliance under the guidelines.”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Cambodia (law, transfer and enforcement chapters)
dlapiperdataprotection.com
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum and almost no maximum. Tax and accounting law makes businesses keep books and supporting documents for years. Financial firms must also keep system logs, and agree keeping periods with their cloud providers. In the other direction, no general rule tells anyone to delete personal data, because there is no privacy law. The only deletion duty we could verify applies to banks and lenders. They must keep customer personal data only as long as they need it.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
How long you must keep data. The General Department of Taxation names two laws that set record-keeping duties. They are the Law on Taxation (16 May 2023) and the Law on Accounting and Auditing (11 April 2016). We could not read the exact number of years. The official copies published on the tax authority's site are scanned images of Khmer text that machines cannot read. So we record the period as unconfirmed rather than guess it. For financial firms, the central bank's 2026 guidelines require an inventory of assets recording how long each data set is kept. They require old-system archives to keep the same periods when data is moved. And they require cloud contracts to specify how long logs and data are kept. How long you may keep data. Paragraph 9.0.7 of the same guidelines is the only duty to delete that we found. Which one wins. We found no Cambodian rule saying which wins. So treat the record-keeping minimum in tax and accounting law as the stronger of the two.
Sources
- Official sourceGeneral Department of TaxationLaw and Provision - list of tax laws, including the Law on Taxation (NS/RKM/0523/004, 16 May 2023) and the Law on Accounting and Auditing (NS/RKM/4016/006, 11 April 2016)
tax.gov.kh
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, paragraphs 6.1.6 and 9.0.7 (retention and cloud contracts)
nbc.gov.kh
“The BFI shall retain customer personal data only as long as necessary for its purpose, as required by laws, or upon request for deletion from customers.”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Cambodia (law, transfer and enforcement chapters)
dlapiperdataprotection.com
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There is no breach reporting clock in Cambodia. No law makes you tell a regulator, or the affected people, when personal data leaks. There is no national cyber incident hotline with a deadline in hours. The nearest thing is in banking. The central bank tells supervised firms to report incidents as it requires, either on a regular cycle or one-off, with no fixed number of hours. Two draft laws would change this, so treat today's silence as temporary.
- What you have to do here:
- Report cyber incidents · Report breaches to the regulator · Tell affected people
This is unusual and worth saying plainly. Most countries in the region have at least one deadline measured in hours. Cambodia currently has none that we could verify. Financial firms must still build the machinery. The central bank's 2026 guidelines require an incident management policy. They require a tested incident response plan, reviewed at least once a year. They require an incident response team and severity classification. And they require procedures to tell affected individuals and relevant regulators 'in compliance with applicable laws and regulations'. That points to laws that do not yet exist. The draft Cybersecurity Law was still being negotiated with the Ministry of Justice in July 2026. That draft, and the draft Personal Data Protection Law, are the two that will bring in reporting duties.
Sources
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, paragraph 3.8.9 (incident reporting)
nbc.gov.kh
“The BFI shall report the incident as required by NBC periodically or on ad hoc basis.”
Link checked 18 August 2026
- Official sourceMinistry of Post and TelecommunicationsTechnical meeting with the Ministry of Justice on the draft Cybersecurity Law, 8 July 2026
mptc.gov.kh
“the meeting agreed to further refine the draft law’s text based on today’s discussions and to schedule another meeting for July 14, 2026.”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Cambodia (law, transfer and enforcement chapters)
dlapiperdataprotection.com
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things. First, the e-commerce law reportedly bans encryption that would stop evidence being used in a criminal case. That cuts across normal end-to-end encryption promises. Second, a cloud-only bank cannot operate here. The main data centre must physically be in Cambodia. Third, moving customer banking data abroad needs the central bank's permission in advance. There is no published process and no timetable, so plan it months ahead. Fourth, telecoms operators must check identity documents before activating a SIM card, and the regulator names offenders in public. Fifth, no privacy law does not mean no risk. Your foreign customers will impose their own rules by contract.
- What you have to do here:
- Put a transfer safeguard in place · Keep records of how you use data
On encryption, the operative text is not available on a Cambodian government site. The claim rests on a law firm's summary of the Law on Electronic Commerce. We record it at medium confidence and list it under unconfirmed. On the banking data centre, the requirement is a plain sentence in the central bank's January 2026 guidelines. It comes with a duty to write a plan for moving a foreign data centre back to Cambodia. On SIM identity, look at the telecoms regulator's June 2026 notification. It described an operator's records showing a SIM sold in Phnom Penh to a person who was in another province that day. It said penalties were imposed under applicable law. A sixth point is worth knowing. There are no rules setting out when you are allowed to use personal data. So there is no legal certainty for anyone handling data here. The absence of rules is not the same as permission. And the draft law may apply to data you have already collected.
Sources
- Secondary sourceDLA PiperData Protection Laws of the World - Cambodia (electronic marketing and E-Commerce Law chapter)
dlapiperdataprotection.com
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, paragraph 3.13.1
nbc.gov.kh
“The BFI shall have at least one primary data center in Cambodia to host their IT environment.”
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, Chapter 9 (Customer Personal Data Protection), paragraph 9.0.3
nbc.gov.kh
“The BFI shall conduct a comprehensive risk assessment of the geographic location where customer personal data is to be migrated or hosted outside Cambodia and shall obtain prior approval from the NBC.”
Link checked 18 August 2026
- Official sourceTelecommunication Regulator of CambodiaPublic Notification on the case of Viettel (Cambodia) selling mobile phone SIM cards without properly accepting the user's identification documents, 15 June 2026
trc.gov.kh
Link checked 18 August 2026
What's changing next
Four drafts are moving, and none of them is law yet. The Personal Data Protection Law reached a validation workshop on 5 August 2026 and now heads into the formal law-making process. The Cybersecurity Law was still being argued over with the Ministry of Justice in July 2026. A Data Governance Policy for 2026 to 2035 was in consultation in March 2026. It is expected to cover where data may be stored and how it may cross borders. A Digital Government Law went to consultation in July 2025. No start date has been announced for any of them.
Powers the government already holds. These matter more than the drafts. One. The National Internet Gateway sub-decree of February 2021 was adopted. It was never brought into operation, and never cancelled. Independent monitoring reported that the government was still developing plans to put it in place as recently as 2025. The Ministry of Post and Telecommunications and Cambodia Telecom are named as responsible. It can be revived by an administrative act. Two. The central bank can change the rules for financial firms by issuing a prakas or a new guideline, with no public consultation. It did exactly that in January 2026, when the Technology and Cyber Risk Management Guidelines replaced the 2019 version. Three. The coming Data Governance Policy is the most likely route for a general rule requiring data to stay in Cambodia. The 2022 Digital Government Policy already lists where data is stored, and cross-border data flows, as things that policy must settle.
Sources
- Official sourceMinistry of Post and TelecommunicationsValidation Workshop on the Draft Law on Personal Data Protection, 5 August 2026
mptc.gov.kh
“The workshop brought together representatives from government ministries and institutions, the private sector, development partners, educational institutions, civil society organizations, and experts to review, validate, and gather feedback on the draft law before it proceeds through the formal legislative process.”
Link checked 18 August 2026
- Official sourceMinistry of Post and TelecommunicationsTechnical meeting with the Ministry of Justice on the draft Cybersecurity Law, 8 July 2026
mptc.gov.kh
“the meeting agreed to further refine the draft law’s text based on today’s discussions and to schedule another meeting for July 14, 2026.”
Link checked 18 August 2026
- Official sourceMinistry of Post and TelecommunicationsConsultation on the draft Data Governance Policy 2026-2035, 9 March 2026
mptc.gov.kh
Link checked 18 August 2026
- Official sourceMinistry of Post and TelecommunicationsConsultative Workshop on the Draft Law on Digital Government of the Kingdom of Cambodia, July 2025
mptc.gov.kh
Link checked 18 August 2026
- Official sourceMinistry of Post and TelecommunicationsPress Release on the National Internet Gateway, February 2021
mptc.gov.kh
Link checked 18 August 2026
- Official sourceRoyal Government of Cambodia / Ministry of Post and TelecommunicationsCambodia Digital Government Policy 2022-2035, situation analysis and priority actions on data centres and data governance
mptc.obsv3.kh-gov-1.mptccloud.gov.kh
“Only 30 percent of ministries and institutions use local data center services while others rely on overseas cloud technology services.”
Link checked 18 August 2026
- Secondary sourceFreedom HouseFreedom on the Net 2025 - Cambodia (reports that the government developed plans to implement the 2021 gateway sub-decree)
freedomhouse.org
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Finance data needs a copy kept in the country
Official name: Technology and Cyber Risk Management Guidelines (TCRMG) · National Bank of Cambodia, January 2026, superseding the Technology Risk Management Guidelines of July 2019 · Regulator guideline
Banks and other institutions supervised by Cambodia's central bank must keep at least one main data centre inside the country. A data centre abroad is allowed only as a backup. It needs the central bank's approval. And it needs a written plan for moving back to Cambodia.
Enforced by National Bank of Cambodia
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryAt least one primary data centre must be in Cambodia and host the firm's technology environment.
- Put a transfer safeguard in placeA data centre outside Cambodia needs central-bank approval. It may only be a secondary or disaster-recovery site. It also needs a risk assessment covering political and geographical risk.
- Written vendor contractCloud contracts must state where data is stored and handled, and what crosses borders. They must also state how long logs are kept, how long data is kept, and audit trails.
- Secure the data
- Independent auditPhysical and environmental controls for data centres tested at least annually; outsourcing of significant functions reported to the central bank at least annually.
Sources
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, paragraph 3.13.1
nbc.gov.kh
“The BFI shall have at least one primary data center in Cambodia to host their IT environment.”
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, paragraphs 3.13.5 and 3.13.6
nbc.gov.kh
“The BFI shall seek approval from NBC regarding establishing data center outside Cambodia. A data center outside Cambodia shall be used as a secondary data center.”
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, Interpretation and Introduction (supersede the 2019 guidelines)
nbc.gov.kh
“For the purposes of this document, “Compliance requirements” are requirements that will be assessed for compliance under the guidelines.”
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaIT Guidelines page listing the Technology and Cyber Risk Management Guideline (2026) and the superseded 2019 guidelines
nbc.gov.kh
Link checked 18 August 2026
Banking rules
Official name: Technology and Cyber Risk Management Guidelines, Chapter 9 - Customer Personal Data Protection · National Bank of Cambodia, January 2026 · Regulator guideline
This is the closest thing Cambodia has to a privacy law, and it only applies to financial firms. It gives banking customers rights of consent, access, correction, deletion and portability. It also requires the central bank's permission in advance before their data is hosted abroad.
Enforced by National Bank of Cambodia
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Put a transfer safeguard in placeRisk assessment of the destination country plus prior approval from the central bank before customer personal data is moved or hosted abroad.
- Get consentConsent must be freely given, informed, specific and unambiguous.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Delete data after a periodKeep customer personal data only as long as needed, as required by law, or until the customer asks for deletion.
- Assess high-risk projects — 3 yearsPrivacy or data protection impact assessment reviewed after a critical incident or at least every three years.
- Appoint a data protection officerA data protection function must be established inside the firm; the guideline does not require a named officer or set qualifications.
- Written vendor contractContracts with suppliers who handle data for you must carry explicit clauses protecting customer personal data.
- Tell affected peopleProcedures must exist to notify affected individuals and relevant regulators, but no deadline is set.
Sources
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, Chapter 9 (Customer Personal Data Protection), paragraph 9.0.3
nbc.gov.kh
“The BFI shall conduct a comprehensive risk assessment of the geographic location where customer personal data is to be migrated or hosted outside Cambodia and shall obtain prior approval from the NBC.”
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, paragraphs 6.1.6 and 9.0.7 (retention and cloud contracts)
nbc.gov.kh
“The BFI shall retain customer personal data only as long as necessary for its purpose, as required by laws, or upon request for deletion from customers.”
Link checked 18 August 2026
- Official sourceNational Bank of CambodiaTechnology and Cyber Risk Management Guidelines, January 2026, Interpretation and Introduction (supersede the 2019 guidelines)
nbc.gov.kh
“For the purposes of this document, “Compliance requirements” are requirements that will be assessed for compliance under the guidelines.”
Link checked 18 August 2026
Payment data rules
Official name: Requirement for mobile operators to obtain and verify identification documents before activating a SIM card · Licence condition
Mobile operators must collect and check a customer's identity document before a SIM card works. This is enforced in public. In June 2026 the telecoms regulator named an operator. Its records showed a SIM sold in Phnom Penh to someone who was demonstrably in another province that day.
Enforced by Telecommunication Regulator of Cambodia
What you have to do
- Keep records of how you use dataOperators must collect and verify a customer's identity document before service is activated, and their records must stand up to checking by the regulator.
What it costs if you get it wrong
- Loss of your licenceSelling or distributing SIM cards without proper identification documents. The regulator states penalties were imposed under applicable law but does not publish the amount.
Sources
- Official sourceTelecommunication Regulator of CambodiaPublic Notification on the case of Viettel (Cambodia) selling mobile phone SIM cards without properly accepting the user's identification documents, 15 June 2026
trc.gov.kh
Link checked 18 August 2026
- Official sourceTelecommunication Regulator of CambodiaTelecommunication Regulator of Cambodia - announcements and public consultations, 2026
trc.gov.kh
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Draft Law on Personal Data Protection (ច្បាប់ស្តីពីកិច្ចការពារទិន្នន័យបុគ្គល) · Draft law
Cambodia's general privacy law is still a draft. It reached a validation workshop on 5 August 2026 and has not been passed, so it imposes nothing today. Do not plan around it as if it were binding. And do not assume it will be permissive, because the text has not been published.
Enforced by Ministry of Post and Telecommunications
How this country controls where data goes: No restriction · Accepted routes: Nothing required
Sources
- Official sourceMinistry of Post and TelecommunicationsValidation Workshop on the Draft Law on Personal Data Protection, 5 August 2026
mptc.gov.kh
“The workshop brought together representatives from government ministries and institutions, the private sector, development partners, educational institutions, civil society organizations, and experts to review, validate, and gather feedback on the draft law before it proceeds through the formal legislative process.”
Link checked 18 August 2026
- Official sourceMinistry of Post and TelecommunicationsTraining Workshop on 'Establishing a Personal Data Protection Authority', 13-14 November 2025
mptc.gov.kh
“These practical insights will serve as an important foundation for establishing Cambodia's personal data protection authority.”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Cambodia (law, transfer and enforcement chapters)
dlapiperdataprotection.com
Link checked 18 August 2026
Secrecy duties for regulated professions
Official name: Law on Electronic Commerce (ច្បាប់ស្តីពីពាណិជ្ជកម្មតាមប្រព័ន្ធអេឡិចត្រូនិក) · Act of parliament
Cambodia adopted an electronic commerce law in late 2019. It gives consumers a thin layer of protection during electronic transactions. That is mainly a duty on service providers to keep data reasonably secure. It sets no rules about where data is stored, and no restrictions on sending data abroad.
Enforced by Ministry of Commerce
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataService providers must take reasonable security measures against loss, alteration, leakage and unauthorised disclosure of consumer data.
- Extra vendor secrecy termsReported to prohibit encryption that would obstruct the use of evidence in a criminal case. Operative text not verified against an official Cambodian source.
Sources
- Official sourceRoyal Government of Cambodia / Ministry of Post and TelecommunicationsCambodia Digital Government Policy 2022-2035 (official English text)
mptc.obsv3.kh-gov-1.mptccloud.gov.kh
“In late 2019, Cambodia adopted the E-Commerce Law, which determines the authenticity, accuracy, security, and reliability of electronic forms and communications, and the Consumer Protection Law to promote fair competition.”
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Cambodia (electronic marketing and E-Commerce Law chapter)
dlapiperdataprotection.com
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World - Cambodia (law, transfer and enforcement chapters)
dlapiperdataprotection.com
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Cambodia Digital Government Policy 2022-2035 · Government policy document
Cambodia has no rule forcing government data to stay in the country. The government's own policy admits that only about 30 percent of ministries use local data centres, and that the rest rely on overseas cloud. Building national data centres, and writing a data governance policy covering storage location and cross-border flows, are stated goals rather than duties. That is exactly where a future rule keeping data in Cambodia would come from.
Enforced by Ministry of Post and Telecommunications
How this country controls where data goes: No restriction · Accepted routes: Nothing required
Sources
- Official sourceRoyal Government of Cambodia / Ministry of Post and TelecommunicationsCambodia Digital Government Policy 2022-2035, situation analysis and priority actions on data centres and data governance
mptc.obsv3.kh-gov-1.mptccloud.gov.kh
“Only 30 percent of ministries and institutions use local data center services while others rely on overseas cloud technology services.”
Link checked 18 August 2026
- Official sourceRoyal Government of Cambodia / Ministry of Post and TelecommunicationsCambodia Digital Government Policy 2022-2035 (official English text)
mptc.obsv3.kh-gov-1.mptccloud.gov.kh
“In late 2019, Cambodia adopted the E-Commerce Law, which determines the authenticity, accuracy, security, and reliability of electronic forms and communications, and the Consumer Protection Law to promote fair competition.”
Link checked 18 August 2026
- Official sourceMinistry of Post and TelecommunicationsConsultation on the draft Data Governance Policy 2026-2035, 9 March 2026
mptc.gov.kh
Link checked 18 August 2026
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Internet and platform rules
Official name: Sub-Decree on the Establishment of the National Internet Gateway (អនុក្រឹត្យស្តីពីការបង្កើតច្រកទ្វារអ៊ីនធឺណិតជាតិ) · Adopted February 2021; commencement never given effect · Directly binding regulation
A 2021 order would force all internet traffic in and out of Cambodia through one government-controlled gateway. It was adopted, never switched on, and never cancelled. Independent monitoring reported the government was still planning to implement it as recently as 2025, so it can be revived without warning.
Enforced by Ministry of Post and Telecommunications
How this country controls where data goes: Approval each time
What you have to do
- Keep logsWould require internet traffic to pass through a single state-controlled gateway operator able to monitor, record and block it. Article-level text not verified against an official copy.
Sources
- Official sourceMinistry of Post and TelecommunicationsPress Release on the National Internet Gateway, February 2021
mptc.gov.kh
Link checked 18 August 2026
- Secondary sourceFreedom HouseFreedom on the Net 2025 - Cambodia (reports that the government developed plans to implement the 2021 gateway sub-decree)
freedomhouse.org
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The operative text of the Law on Electronic Commerce, including its security duty and the reported ban on encryption that would obstruct criminal evidence
We could not find an official copy of the law on any Cambodian government website. The government link we use confirms only that the law was adopted in late 2019, and what it broadly covers. The substance rests on a law firm's summary, so we mark this rule medium confidence. Check the official text before you rely on the encryption point.
The sub-decree number and exact date of the National Internet Gateway sub-decree, its article-level requirements, and whether it has been formally suspended, extended or repealed
We could not confirm the current status of this order. The ministry's February 2021 press release is published as an image, and we found no later official notice. The status rests on independent monitoring, so we mark it low confidence and record it as suspended rather than repealed.
The exact minimum record retention periods under the Law on Taxation (2023) and the Law on Accounting and Auditing (2016)
We could not confirm the number of years. The official copies published by the General Department of Taxation are scanned images of Khmer text that machines cannot read. We can show the laws exist and are current, but not the periods. Ask the tax authority before you delete any records.
Whether the Insurance Regulator of Cambodia or the Securities and Exchange Regulator of Cambodia imposes any data storage location, outsourcing or cross-border transfer rule
We found no rule, but we could not confirm that. Both regulators publish their laws and prakas through pages we could not read. Not finding a rule here is not evidence that none exists. If you work in insurance or securities, check with your regulator.
Whether any health, education, online gaming, mapping or defence sector rule in Cambodia restricts where data may be stored
We found no Cambodian government source imposing such a rule on 18 August 2026. The commercial gambling regulator's website did not work at all, so that industry in particular is a real gap. Check with your regulator before you rely on this.
Whether the central bank's Technology and Cyber Risk Management Guidelines bind payment service institutions and third-party processors as well as banks
We could not confirm who is covered. The guidelines address 'banks and financial institutions' and publish no list of who that means. The central bank supervises payment service institutions and third-party processors as separate kinds of regulated firm, which suggests they are covered. But we could not verify it in the text. Ask the central bank if this affects you.
Whether a new Law on Banking and Financial Institutions has replaced the 1999 law
We could not confirm that a newer law exists. The central bank's English legislation page still lists the 1999 Law on Banking and Financial Institutions as current. We saw nothing newer there.
What the draft Personal Data Protection Law will require, in particular whether it will restrict transfers abroad or create a localisation duty
We could not confirm what the draft will require, because the text has not been published. Only the fact and date of the validation workshop are on the record.
The exact publication date of the Technology and Cyber Risk Management Guidelines and whether the central bank treats them as binding or as supervisory expectation
We could not confirm the exact date or the legal status. The document is dated January 2026 with no day. It calls itself a guideline, but says its compliance requirements will be assessed for compliance. We have recorded it as in force and enforced through supervision, rather than as a law.
Coverage completeness of this record
Our coverage of Cambodia is thinner than usual. We built these findings by going to Cambodian government websites directly, plus two professional sources and one media source. We could not reach sources that a general search would normally turn up, especially recent prakas in insurance, securities and gambling. Treat this record as a starting point, not as complete.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.