Skip to the content
Global Data RulesData governance rules, country by country

Cambodia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: LowEnforcement: Dormant

Cambodia has no general privacy law. A bill exists and went to a public review meeting in August 2026, but it is not law and there is no privacy regulator to complain to. For most businesses data can leave the country freely, with no paperwork. Banks and other lenders are the big exception: their main data centre must sit inside Cambodia.

Eight questions about Cambodia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Cambodia's rules apply to my company?

There is no general data protection law in Cambodia, so there is nothing for a foreign company to be caught by. No size threshold, no revenue threshold, no registration, and no requirement to appoint someone in Cambodia to answer for your data. That changes the moment you need a local licence: banks, lenders and telecoms operators are licensed here and their licence conditions do reach their overseas systems. A draft privacy law was put to a validation workshop on 5 August 2026 and will proceed through the formal law-making process, so this answer has a shelf life.

High confidenceNational rulesIndustry rules

Can I store my users' data outside Cambodia?

In general, yes, and with nothing to sign. Cambodia has no rule that stops ordinary personal data leaving the country. Finance is the one hard wall we could verify: a bank or lender supervised by the central bank must have at least one main data centre in Cambodia, may only use a foreign data centre as a backup, and needs the central bank's approval before customer personal data is hosted abroad. Telecoms is the sector to watch, because a 2021 order that would route all internet traffic through a single national gateway was never switched on but was never cancelled either.

Medium confidenceDepends on your industryNo restriction

What do I need in place before data leaves Cambodia?

For most organisations, nothing at all. There is no approved-countries list, no banned-countries list, no standard contract to sign and no government form to file. The lists are not just empty, they do not exist, because there is no law that creates them. In finance the model is completely different: each move of customer personal data out of Cambodia needs its own approval from the central bank, decided case by case, and there is no published application process or timetable.

Medium confidenceNo restrictionNothing requiredGovernment sign-off needed

Who enforces the rules in Cambodia, and what can they do?

For privacy, nobody. Cambodia has no data protection authority. The Ministry of Post and Telecommunications is writing the law and, in November 2025, ran a training workshop with Singapore's privacy regulator on how to build such an authority, which tells you plainly that one does not yet exist. Sector regulators are a different story and are genuinely working: the central bank supervises financial firms against its 2026 technology guidelines, and the telecoms regulator publicly named an operator in June 2026 for selling SIM cards without properly checking customers' identity documents.

High confidenceDormant

How long do I have to keep the data?

There is a floor and almost no ceiling. Tax and accounting law forces businesses to keep books and supporting documents for years, and financial firms must keep system logs and agree retention periods with their cloud providers. In the other direction there is no general rule telling anyone to delete personal data, because there is no privacy law. The only deletion duty we could verify applies to banks and lenders, who must keep customer personal data only as long as it is needed.

Medium confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

There is no breach reporting clock in Cambodia. No law requires you to tell a regulator or the affected people when personal data leaks, and there is no national cyber incident hotline with a deadline in hours. The nearest thing is in banking: the central bank tells supervised firms to report incidents as it requires, either on a regular cycle or one-off, with no fixed number of hours. Two draft laws would change this, so treat today's silence as temporary.

Medium confidenceReport cyber incidentsReport breaches to the regulatorTell affected people

What trips people up in Cambodia?

Five things that are not in the summary. First, the e-commerce law reportedly bans encryption that would stop evidence being used in a criminal case, which cuts across normal end-to-end encryption promises. Second, a cloud-only bank cannot operate here: the main data centre must physically be in Cambodia. Third, moving customer banking data abroad needs the central bank's permission in advance, and there is no published process or timetable, so it must be planned months ahead. Fourth, telecoms operators must check identity documents before activating a SIM card, and the regulator names offenders in public. Fifth, no privacy law does not mean no risk, because your foreign customers will impose their own rules by contract.

Medium confidenceKeep the data in the countryPut a transfer safeguard in placeKeep records of processingContract-imposed rule

What is changing soon in Cambodia?

Four drafts are moving and none of them is law yet. The Personal Data Protection Law reached a validation workshop on 5 August 2026 and now heads into the formal law-making process. The Cybersecurity Law was still being argued over with the Ministry of Justice in July 2026. A Data Governance Policy for 2026 to 2035 was in consultation in March 2026 and is expected to cover where data may be stored and how it may cross borders. A Digital Government Law went to consultation in July 2025. No commencement date has been announced for any of them.

High confidenceProposedSuspended

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    4 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules3 rules

Draft Law on Personal Data Protection (ច្បាប់ស្តីពីកិច្ចការពារទិន្នន័យបុគ្គល)

Draft law

ProposedNot yet established

Cambodia's general privacy law is still a draft. It reached a validation workshop on 5 August 2026 and has not been passed, so it imposes nothing today. Do not plan around it as if it were binding, and do not assume it will be permissive - the text has not been published.

Enforced by Ministry of Post and Telecommunications

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Law on Electronic Commerce (ច្បាប់ស្តីពីពាណិជ្ជកម្មតាមប្រព័ន្ធអេឡិចត្រូនិក)

Act of parliament · E-commerce

In forceYes — store it anywhere

Cambodia adopted an electronic commerce law in late 2019. It gives consumers a thin layer of protection during electronic transactions - mainly a duty on service providers to keep data reasonably secure - but it sets no storage location rules and no restrictions on sending data abroad.

Enforced by Ministry of Commerce

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Cambodia Digital Government Policy 2022-2035

Government policy document · Government

In forceYes — store it anywhere

Cambodia has no rule forcing government data to stay in the country. The government's own policy admits that only about 30 percent of ministries use local data centres and the rest rely on overseas cloud. Building national data centres and writing a data governance policy that will cover storage location and cross-border flows are stated goals, not duties - which is exactly where a future localisation rule would come from.

In force since 1 April 2022

Enforced by Ministry of Post and Telecommunications

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules4 rules

Technology and Cyber Risk Management Guidelines (TCRMG)

Regulator guideline · National Bank of Cambodia, January 2026, superseding the Technology Risk Management Guidelines of July 2019 · Finance

In forceA copy must stay

Banks and other institutions supervised by Cambodia's central bank must keep at least one main data centre inside the country. A data centre abroad is allowed only as a backup, only with the central bank's approval, and only with a written plan for moving back to Cambodia.

Enforced by National Bank of Cambodia

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Technology and Cyber Risk Management Guidelines, Chapter 9 - Customer Personal Data Protection

Regulator guideline · National Bank of Cambodia, January 2026 · Banking

In forceYes, with paperwork

This is the closest thing Cambodia has to a privacy law, and it only applies to financial firms. It gives banking customers consent, access, correction, deletion and portability rights, and it requires the central bank's permission in advance before their data is hosted abroad.

Enforced by National Bank of Cambodia

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Sub-Decree on the Establishment of the National Internet Gateway (អនុក្រឹត្យស្តីពីការបង្កើតច្រកទ្វារអ៊ីនធឺណិតជាតិ)

Directly binding regulation · Adopted February 2021; commencement never given effect · Telecoms

SuspendedYes, with paperwork

A 2021 order would force all internet traffic in and out of Cambodia through one government-controlled gateway. It was adopted, never switched on, and never cancelled. Independent monitoring reported the government was still planning to implement it as recently as 2025, so it can be revived without warning.

Enforced by Ministry of Post and Telecommunications

Transfer model: Approval each time

Low confidence

Who you would hear from

  • General privacy law enforcement

    Does not exist. In November 2025 the Ministry of Post and Telecommunications ran a training workshop with Singapore's Personal Data Protection Commission on models for establishing such an authority, describing the sessions as a foundation for creating Cambodia's future authority. No chair, no staff, no decisions.

  • ក្រសួងប្រៃសណីយ៍និងទូរគមនាគមន៍

    Drafting the privacy, cybersecurity and digital government laws; telecoms and postal policy; digital government

    Active and visible. Ran the validation workshop on the draft privacy law on 5 August 2026 and technical meetings on the draft cybersecurity law in July 2026. It is a policy ministry, not a privacy regulator, and issues no privacy decisions.

  • ធនាគារជាតិនៃកម្ពុជា

    Banks, lenders, payment institutions and third-party processors, including their technology and customer data

    Fully operational and the effective data regulator for finance. Runs a Technology Risk and Innovation Supervision Department, replaced its 2019 technology guidelines with new ones in January 2026, and states that the compliance requirements in those guidelines will be assessed for compliance.

  • និយ័តករទូរគមនាគមន៍កម្ពុជា

    Telecoms operators, SIM registration and identity checks, equipment standards

    Active. Published a public notification naming Viettel (Cambodia) on 15 June 2026 over SIM sales without proper identity documents, ran a public consultation on equipment standards to 25 June 2026, and issued guidelines on mobile text-message notifications in May 2026.

  • Electronic commerce and consumer protection, including consumer data in electronic transactions

    Operational as a ministry. No published data protection decisions were located, and its online legal library could not be read by automated tools.

  • និយ័តករធានារ៉ាប់រងកម្ពុជា

    Insurance companies, brokers and agents

    Operational as an insurance supervisor. We found no insurance-specific data storage or transfer rule, but its document library loads dynamically and could not be read, so this is not proof that none exists.

  • Securities markets, market operators and intermediaries

    Operational as a securities supervisor. No securities-specific data storage or transfer rule was found; its prakas listing did not render to automated fetching, so this is recorded as not found rather than absent.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The operative text of the Law on Electronic Commerce, including its security duty and the reported ban on encryption that would obstruct criminal evidence

    No official copy of the law could be located on any Cambodian government domain. The government backlink used confirms only that the law was adopted in late 2019 and what it broadly covers. The substance rests on a law-firm summary, so the rule is marked medium confidence.

  • The sub-decree number and exact date of the National Internet Gateway sub-decree, its article-level requirements, and whether it has been formally suspended, extended or repealed

    The ministry's February 2021 press release is published as an image and no later official notice was found. Implementation status rests on independent monitoring, so the rule is marked low confidence and its status recorded as suspended rather than repealed.

  • The exact minimum record retention periods under the Law on Taxation (2023) and the Law on Accounting and Auditing (2016)

    The official copies published by the General Department of Taxation are scanned images of Khmer text that machine reading cannot extract. We can evidence that the laws exist and are current, but not the number of years.

  • Whether the Insurance Regulator of Cambodia or the Securities and Exchange Regulator of Cambodia imposes any data storage location, outsourcing or cross-border transfer rule

    Both regulators publish their laws and prakas through dynamically loaded pages that returned no document list to automated fetching. Absence of a finding here is not evidence of absence of a rule.

  • Whether any health, education, online gaming, mapping or defence sector rule in Cambodia restricts where data may be stored

    No Cambodian government source imposing such a rule was located on 18 August 2026. The commercial gambling regulator's website did not resolve at all, so that sector in particular is a genuine gap.

  • Whether the central bank's Technology and Cyber Risk Management Guidelines bind payment service institutions and third-party processors as well as banks

    The guidelines address 'banks and financial institutions' and do not publish a scope list. The central bank supervises payment service institutions and third-party processors as separate categories of regulated entity, which suggests they are covered, but we could not verify it in the instrument.

  • Whether a new Law on Banking and Financial Institutions has replaced the 1999 law

    The central bank's English legislation page still lists the 1999 Law on Banking and Financial Institutions as current. Any newer statute was not visible there.

  • What the draft Personal Data Protection Law will require, in particular whether it will restrict transfers abroad or create a localisation duty

    The draft text has not been published. Only the fact and date of the validation workshop are on the record.

  • The exact publication date of the Technology and Cyber Risk Management Guidelines and whether the central bank treats them as binding or as supervisory expectation

    The document is dated January 2026 without a day, and calls itself a guideline while stating that its compliance requirements will be assessed for compliance. We have recorded it as in force and enforced through supervision rather than as a statute.

  • Coverage completeness of this record

    General web search was unavailable during this research run, so findings were built by fetching Cambodian government sites and their content interfaces directly, plus two professional and one media source. Avenues a search engine would normally surface, especially recent prakas in the insurance, securities and gambling sectors, were not reachable.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.