Skip to the content
Global Data RulesData governance rules, country by country

Cambodia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Cambodia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: LowEnforcement: Dormant

Cambodia has no general privacy law. A draft law went to a public review meeting in August 2026. It is not law yet, and there is no privacy regulator to complain to. For most businesses, data can leave the country freely, with no paperwork. Banks and other lenders are the big exception. Their main data centre must sit inside Cambodia.

Data governance in Cambodia

The eight things that decide how you handle data about people in Cambodia. Same eight on every country page, so you can compare.

Who has to follow these rules

There is no general data protection law in Cambodia, so there is nothing for a foreign company to be caught by. No size threshold, no revenue threshold, no registration, and no need to appoint someone in Cambodia to answer for your data. That changes the moment you need a local licence. Banks, lenders and telecoms operators are licensed here, and their licence conditions do reach their overseas systems. A draft privacy law was put to a validation workshop on 5 August 2026 and will now go through the formal law-making process. So this answer has a shelf life.

Where the data is allowed to live

In general, yes, and with nothing to sign. Cambodia has no rule stopping ordinary personal data from leaving the country. Finance is the one strict exception we could verify. A bank or lender supervised by the central bank must have at least one main data centre in Cambodia. It may only use a foreign data centre as a backup. And it needs the central bank's approval before customer personal data is hosted abroad. Telecoms is the sector to watch. A 2021 order that would route all internet traffic through a single national gateway was never switched on, but was never cancelled either.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

For most organisations, nothing at all. There is no list of approved countries, no list of banned countries, no standard contract to sign, and no government form to file. Those lists are not just empty. They do not exist, because no law creates them. Finance works completely differently. Each move of customer personal data out of Cambodia needs its own approval from the central bank, decided case by case. There is no published application process and no timetable.

Ways to send data out:
Nothing required · Government sign-off needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

For privacy, nobody. Cambodia has no data protection authority. The Ministry of Post and Telecommunications is writing the law. In November 2025 it ran a training workshop with Singapore's privacy regulator on how to build such an authority. That tells you plainly that one does not yet exist. Sector regulators are a different story, and they are really working. The central bank supervises financial firms against its 2026 technology guidelines. And the telecoms regulator publicly named an operator in June 2026 for selling SIM cards without properly checking customers' identity documents.

How long you must keep it — and when to delete it

There is a minimum and almost no maximum. Tax and accounting law makes businesses keep books and supporting documents for years. Financial firms must also keep system logs, and agree keeping periods with their cloud providers. In the other direction, no general rule tells anyone to delete personal data, because there is no privacy law. The only deletion duty we could verify applies to banks and lenders. They must keep customer personal data only as long as they need it.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There is no breach reporting clock in Cambodia. No law makes you tell a regulator, or the affected people, when personal data leaks. There is no national cyber incident hotline with a deadline in hours. The nearest thing is in banking. The central bank tells supervised firms to report incidents as it requires, either on a regular cycle or one-off, with no fixed number of hours. Two draft laws would change this, so treat today's silence as temporary.

What you have to do here:
Report cyber incidents · Report breaches to the regulator · Tell affected people

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things. First, the e-commerce law reportedly bans encryption that would stop evidence being used in a criminal case. That cuts across normal end-to-end encryption promises. Second, a cloud-only bank cannot operate here. The main data centre must physically be in Cambodia. Third, moving customer banking data abroad needs the central bank's permission in advance. There is no published process and no timetable, so plan it months ahead. Fourth, telecoms operators must check identity documents before activating a SIM card, and the regulator names offenders in public. Fifth, no privacy law does not mean no risk. Your foreign customers will impose their own rules by contract.

What you have to do here:
Put a transfer safeguard in place · Keep records of how you use data
Not fully verified — see “What we're not sure about” below.

What's changing next

Four drafts are moving, and none of them is law yet. The Personal Data Protection Law reached a validation workshop on 5 August 2026 and now heads into the formal law-making process. The Cybersecurity Law was still being argued over with the Ministry of Justice in July 2026. A Data Governance Policy for 2026 to 2035 was in consultation in March 2026. It is expected to cover where data may be stored and how it may cross borders. A Digital Government Law went to consultation in July 2025. No start date has been announced for any of them.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Finance data needs a copy kept in the country

Official name: Technology and Cyber Risk Management Guidelines (TCRMG) · National Bank of Cambodia, January 2026, superseding the Technology Risk Management Guidelines of July 2019 · Regulator guideline

In forceA copy must stay

Banks and other institutions supervised by Cambodia's central bank must keep at least one main data centre inside the country. A data centre abroad is allowed only as a backup. It needs the central bank's approval. And it needs a written plan for moving back to Cambodia.

Enforced by National Bank of Cambodia

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Banking

Banking rules

Official name: Technology and Cyber Risk Management Guidelines, Chapter 9 - Customer Personal Data Protection · National Bank of Cambodia, January 2026 · Regulator guideline

In forceYes, with paperwork

This is the closest thing Cambodia has to a privacy law, and it only applies to financial firms. It gives banking customers rights of consent, access, correction, deletion and portability. It also requires the central bank's permission in advance before their data is hosted abroad.

Enforced by National Bank of Cambodia

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Telecoms

Payment data rules

Official name: Requirement for mobile operators to obtain and verify identification documents before activating a SIM card · Licence condition

In forceYes — store it anywhere

Mobile operators must collect and check a customer's identity document before a SIM card works. This is enforced in public. In June 2026 the telecoms regulator named an operator. Its records showed a SIM sold in Phnom Penh to someone who was demonstrably in another province that day.

Enforced by Telecommunication Regulator of Cambodia

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Draft Law on Personal Data Protection (ច្បាប់ស្តីពីកិច្ចការពារទិន្នន័យបុគ្គល) · Draft law

ProposedNot yet established

Cambodia's general privacy law is still a draft. It reached a validation workshop on 5 August 2026 and has not been passed, so it imposes nothing today. Do not plan around it as if it were binding. And do not assume it will be permissive, because the text has not been published.

Enforced by Ministry of Post and Telecommunications

How this country controls where data goes: No restriction · Accepted routes: Nothing required

E-commerce

Secrecy duties for regulated professions

Official name: Law on Electronic Commerce (ច្បាប់ស្តីពីពាណិជ្ជកម្មតាមប្រព័ន្ធអេឡិចត្រូនិក) · Act of parliament

In forceYes — store it anywhere

Cambodia adopted an electronic commerce law in late 2019. It gives consumers a thin layer of protection during electronic transactions. That is mainly a duty on service providers to keep data reasonably secure. It sets no rules about where data is stored, and no restrictions on sending data abroad.

Enforced by Ministry of Commerce

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.
Government

Cloud and outsourcing rules

Official name: Cambodia Digital Government Policy 2022-2035 · Government policy document

In forceYes — store it anywhere

Cambodia has no rule forcing government data to stay in the country. The government's own policy admits that only about 30 percent of ministries use local data centres, and that the rest rely on overseas cloud. Building national data centres, and writing a data governance policy covering storage location and cross-border flows, are stated goals rather than duties. That is exactly where a future rule keeping data in Cambodia would come from.

In force since 1 April 2022

Enforced by Ministry of Post and Telecommunications

How this country controls where data goes: No restriction · Accepted routes: Nothing required

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Telecoms

Internet and platform rules

Official name: Sub-Decree on the Establishment of the National Internet Gateway (អនុក្រឹត្យស្តីពីការបង្កើតច្រកទ្វារអ៊ីនធឺណិតជាតិ) · Adopted February 2021; commencement never given effect · Directly binding regulation

SuspendedYes, with paperwork

A 2021 order would force all internet traffic in and out of Cambodia through one government-controlled gateway. It was adopted, never switched on, and never cancelled. Independent monitoring reported the government was still planning to implement it as recently as 2025, so it can be revived without warning.

Enforced by Ministry of Post and Telecommunications

How this country controls where data goes: Approval each time

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • General privacy law enforcement

    In November 2025 the Ministry of Post and Telecommunications ran a training workshop with Singapore's Personal Data Protection Commission. It covered models for setting up such an authority. The ministry described the sessions as a foundation for creating Cambodia's future authority. No chair, no staff, no decisions.

  • ក្រសួងប្រៃសណីយ៍និងទូរគមនាគមន៍

    Drafting the privacy, cybersecurity and digital government laws; telecoms and postal policy; digital government

    Active and visible. Ran the validation workshop on the draft privacy law on 5 August 2026 and technical meetings on the draft cybersecurity law in July 2026. It is a policy ministry, not a privacy regulator, and issues no privacy decisions.

  • ធនាគារជាតិនៃកម្ពុជា

    Banks, lenders, payment institutions and third-party processors, including their technology and customer data

    Working, and in reality the data regulator for finance. It runs a Technology Risk and Innovation Supervision Department. It replaced its 2019 technology guidelines with new ones in January 2026. It says the compliance requirements in those guidelines will be assessed for compliance.

  • និយ័តករទូរគមនាគមន៍កម្ពុជា

    Telecoms operators, SIM registration and identity checks, equipment standards

    Active. It published a public notification naming Viettel (Cambodia) on 15 June 2026, over SIM sales without proper identity documents. It ran a public consultation on equipment standards to 25 June 2026. And it issued guidelines on mobile text-message notifications in May 2026.

  • Electronic commerce and consumer protection, including consumer data in electronic transactions

    Working as a ministry. We found no published data protection decisions, and we could not read its online legal library.

  • និយ័តករធានារ៉ាប់រងកម្ពុជា

    Insurance companies, brokers and agents

    Working as an insurance supervisor. We found no insurance rule about storing or sending data. We could not read its document library, so that is not proof that no rule exists.

  • Securities markets, market operators and intermediaries

    Working as a securities supervisor. We found no securities rule about storing or sending data. We could not read its list of prakas, so treat this as not found rather than absent.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The operative text of the Law on Electronic Commerce, including its security duty and the reported ban on encryption that would obstruct criminal evidence

    We could not find an official copy of the law on any Cambodian government website. The government link we use confirms only that the law was adopted in late 2019, and what it broadly covers. The substance rests on a law firm's summary, so we mark this rule medium confidence. Check the official text before you rely on the encryption point.

  • The sub-decree number and exact date of the National Internet Gateway sub-decree, its article-level requirements, and whether it has been formally suspended, extended or repealed

    We could not confirm the current status of this order. The ministry's February 2021 press release is published as an image, and we found no later official notice. The status rests on independent monitoring, so we mark it low confidence and record it as suspended rather than repealed.

  • The exact minimum record retention periods under the Law on Taxation (2023) and the Law on Accounting and Auditing (2016)

    We could not confirm the number of years. The official copies published by the General Department of Taxation are scanned images of Khmer text that machines cannot read. We can show the laws exist and are current, but not the periods. Ask the tax authority before you delete any records.

  • Whether the Insurance Regulator of Cambodia or the Securities and Exchange Regulator of Cambodia imposes any data storage location, outsourcing or cross-border transfer rule

    We found no rule, but we could not confirm that. Both regulators publish their laws and prakas through pages we could not read. Not finding a rule here is not evidence that none exists. If you work in insurance or securities, check with your regulator.

  • Whether any health, education, online gaming, mapping or defence sector rule in Cambodia restricts where data may be stored

    We found no Cambodian government source imposing such a rule on 18 August 2026. The commercial gambling regulator's website did not work at all, so that industry in particular is a real gap. Check with your regulator before you rely on this.

  • Whether the central bank's Technology and Cyber Risk Management Guidelines bind payment service institutions and third-party processors as well as banks

    We could not confirm who is covered. The guidelines address 'banks and financial institutions' and publish no list of who that means. The central bank supervises payment service institutions and third-party processors as separate kinds of regulated firm, which suggests they are covered. But we could not verify it in the text. Ask the central bank if this affects you.

  • Whether a new Law on Banking and Financial Institutions has replaced the 1999 law

    We could not confirm that a newer law exists. The central bank's English legislation page still lists the 1999 Law on Banking and Financial Institutions as current. We saw nothing newer there.

  • What the draft Personal Data Protection Law will require, in particular whether it will restrict transfers abroad or create a localisation duty

    We could not confirm what the draft will require, because the text has not been published. Only the fact and date of the validation workshop are on the record.

  • The exact publication date of the Technology and Cyber Risk Management Guidelines and whether the central bank treats them as binding or as supervisory expectation

    We could not confirm the exact date or the legal status. The document is dated January 2026 with no day. It calls itself a guideline, but says its compliance requirements will be assessed for compliance. We have recorded it as in force and enforced through supervision, rather than as a law.

  • Coverage completeness of this record

    Our coverage of Cambodia is thinner than usual. We built these findings by going to Cambodian government websites directly, plus two professional sources and one media source. We could not reach sources that a general search would normally turn up, especially recent prakas in insurance, securities and gambling. Treat this record as a starting point, not as complete.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.