Cambodia's draft data-protection law would mandate DPOs and certification, with scope set later by a ministerial rule
Cambodia is one of the last large Southeast Asian markets without a general data-protection law, and the draft that would change that is now in public view. A final version, marked on every page "Final Version 23rd June 2025," sits on the Open Development Cambodia Datahub in both Khmer and English. It is a draft, not a law, and that distinction runs through everything below. It is worth reading now because one clause is unusually aggressive: Article 24 would require data controllers and processors to appoint a personal data protection officer, though it leaves the precise scope of that duty to a future ministerial rule, and Article 25 would require that person to hold a state-issued privacy profession certificate once the law is in force. Here is a source-checked read of the English text.
What the draft LPDP would require
Article 1 says the law "establishes the principles, rules and mechanisms of processing personal data with responsibility, transparency and adherence to ethical conducts," aiming to protect data subjects and promote the investment environment and digital economy. It builds a familiar structure across twelve chapters: a competent institution, lawful bases, security duties, cross-border transfer rules, an officer mandate, data-subject rights, and penalties.
Consent sits at the center of the draft. Article 8 would require a controller to notify the data subject of the purpose and obtain explicit consent before processing, defined in the annex as "written or electronic consent that can be used as a basis for evidence." A child-data rule would catch anyone running consumer apps: where the data subject is under sixteen, parental or guardian consent would be required, verified through available technology or other feasible means. Data subjects would also gain a withdrawal right and access, correction, and objection rights modeled on the European template.
The competent authority would be the Ministry of Post and Telecommunications. Article 4 would give it power to regulate, audit, and monitor, to demand information, to receive complaints, and to "manage the cross-border transfer of personal data by monitoring and restricting or permitting" it. Article 5 would let the minister ask the Royal Government to stand up a dedicated Personal Data Protection Unit, signaling a standalone regulator is contemplated but not yet created.
The DPO mandate: broad on its face, blank on the edges
The officer requirement is the clause that makes this draft stand out. Article 24 states:
"The data controllers and the data processors shall appoint a personal data protection officer who possesses the qualifications to practice the personal data protection. The data controllers and the data processors shall notify the Ministry of Post and Telecommunications of the name and information of the personal data protection officer within 30 (thirty) working days from the date of appointment."
Read literally, the article reads as a broad duty. Both controllers and processors are named, there is no small-business carve-out on the face of the article, and each appointment would have to be registered within thirty working days, a change of officer within fifteen. On its face that is stricter than the EU GDPR, which forces a designated officer only on public bodies and organizations whose core activity is large-scale or sensitive processing. Whether the Cambodian duty ends up that broad depends on a rule that has not been written, as the next paragraph explains.
The catch is that the reach is not settled in the statute. The same article hands the real scoping decision to a future ministerial rule: "The criteria for determining the types of the data controllers and the data processors that are required to have a personal data protection officer shall be determined by a Prakas of the Minister of the Ministry of Post and Telecommunications." A Prakas is a ministerial regulation. So the draft creates a broad duty and narrows it through an instrument that has not been written. Whether a small trading company in Phnom Penh really needs a registered officer will be decided later, by the ministry, not the National Assembly.
Article 25 adds a qualification test with teeth. The officer "is responsible for monitoring the compliance of personal data processing as stipulated by this law," and any natural person practicing as an officer "shall have adequate qualifications" and "possess a personal data protection profession certificate." The glossary confirms it: entry 25 defines the officer as a natural person, employee or outside representative by mandate, who "must have a personal data protection profession certificate" once the law is in force. The conditions for that certificate are, again, left to a Prakas, and the glossary makes the certificate a requirement only once the law is in force. In practice the draft would build a licensing gate around the profession itself, a real barrier in a market with almost no trained privacy workforce today.
Who is covered
Scope would be set by Article 2, and it is deliberately wide. The law would apply to processing by automated or non-automated means that forms a filing system, reaching two groups: controllers and processors located in Cambodia "regardless of the purposes," and those located outside Cambodia where the processing supplies goods or services to, or monitors activities related to, data subjects residing in the Kingdom. That second limb is the extraterritorial hook, mirroring the reach the EU GDPR and Thailand's PDPA already claim over foreign firms serving local users.
Two exclusions sit alongside: processing by public authorities "performing functions within their jurisdiction," a carve-out that could prove significant given how much data the state holds, and natural persons acting purely for personal or household activities. Between those bookends, the draft would capture the commercial economy, from banks and telecoms to e-commerce sellers and any overseas platform with Cambodian customers.
What it does NOT do (it is still only a draft)
This is the part most secondhand summaries get wrong. The document is a draft, and treating it as enforceable law would be a mistake.
- It is not in force. The text is a "Final Version 23rd June 2025," not promulgated by the King, and until it is, none of its obligations bind anyone.
- It sets no start date. Article 54 says only that the law "shall be implemented within 2 (two) years from the date of promulgation," and there is no promulgation date, so no compliance clock is running.
- It does not define which firms need an officer. Article 24 states the duty but delegates the scoping criteria to a future Prakas that has not been issued.
- It does not create the certificate it requires. The Article 25 privacy profession certificate depends on conditions to be set later by ministerial rule, so no one can yet be certified.
- It does not stand up a dedicated regulator. Article 5 only permits the minister to request one; the ministry is the interim authority.
- It does not reach government processing within an authority's jurisdiction, or purely personal and household use.
Cross-border read: how the draft sits against APAC data laws
The reason a Cambodian draft matters to a US or regional operator is the extraterritorial clause: if you sell to or track Cambodian residents, the law would claim you once enacted. The table below places it beside the regional laws already live. Cambodia is the draft; the others are enacted law, as peer context.
| Feature | Cambodia (draft LPDP, 23 Jun 2025) | Thailand PDPA B.E. 2562 (2019) | Singapore PDPA (2012) |
|---|---|---|---|
| Status | Final draft, not enacted | In force, fully effective June 2022 | In force since 2012, amended 2020 |
| Officer requirement | All controllers and processors on the face of Art 24, narrowed later by Prakas; certificate required | Officer required in specified cases (large-scale or sensitive processing, certain public bodies) | Every organization must designate at least one data protection officer |
| Extraterritorial reach | Yes, foreign firms serving or monitoring Cambodian residents (Art 2) | Yes, foreign firms offering goods or services to, or monitoring, people in Thailand | Applies to organizations processing personal data in Singapore, with cross-border transfer duties |
| Headline penalty | Up to 600,000,000 riel or 10% of turnover for a legal person; criminal liability for repeat offenders (Arts 48, 51) | Administrative fines up to 5,000,000 baht, plus criminal and civil liability | Financial penalties up to 10% of annual turnover in Singapore or 1,000,000 dollars, whichever is higher |
| Regulator | Ministry of Post and Telecommunications, with an optional dedicated Unit | Personal Data Protection Committee (PDPC) | Personal Data Protection Commission (PDPC) |
The pattern is clear. Cambodia is not inventing anything; it is adopting the same extraterritorial, consent-first, officer-and-penalty architecture its neighbors run. What is distinctive is the choice to make the officer duty universal on paper and gate the profession behind a certificate, stricter than Thailand and, at the entry level, than the EU. Whether that survives the Prakas that scopes it is the open question.
Key facts
- Instrument
- Draft Law on Personal Data Protection (LPDP), Khmer and English, marked "Final Version 23rd June 2025." Twelve chapters plus an annexed glossary.
- Issuer and source
- Prepared under the Ministry of Post and Telecommunications as competent authority; the final draft is published on the Open Development Cambodia Datahub, a government-affiliated open-data repository.
- DPO mandate
- Article 24 would require data controllers and data processors to appoint a personal data protection officer and register it with the ministry within 30 working days, with the criteria for which of them are covered left to a future Prakas; Article 25 would require a privacy profession certificate once the law is in force.
- Who is covered
- Controllers and processors in Cambodia regardless of purpose, plus foreign controllers and processors serving or monitoring residents of Cambodia (Article 2). Government processing within jurisdiction and personal or household use are excluded.
- Penalty proposed
- Administrative fines up to 60,000,000 riel (natural person) and up to 600,000,000 riel or 10% of annual turnover (legal person); criminal liability, including imprisonment of 6 days to 2 years for repeat offenders (Articles 48, 51).
- Status
- Draft only. Not promulgated. Article 54: implemented within 2 years of the date of promulgation. No effective date exists yet.
Primary sources and further reading
- Open Development Cambodia Datahub, dataset record for the draft law: Draft law on personal data protection
- Draft Law on Personal Data Protection, English text, final version 23 June 2025 (PDF): 20250623_final-draft-pdp-law_eng.pdf
- Draft Law on Personal Data Protection, Khmer text (PDF): 20250623_final-draft-pdp-law_kh.pdf
- Related tracker: our AI Regulation News hub with the full by-jurisdiction index.
- Regional context: the Asia-Pacific section for the Thailand and Singapore entries.
- By jurisdiction: browse the jurisdiction matrix.
FAQ
Is Cambodia's Law on Personal Data Protection in force yet?
No. It is a final draft dated 23 June 2025, not promulgated. Its own text says the law would be implemented within two years of promulgation, so none of its obligations apply yet.
Who would have to appoint a data protection officer under the draft?
Article 24 says data controllers and processors shall appoint one, but leaves the criteria for which of them fall under the requirement to a Prakas of the Minister of Post and Telecommunications, a rule that does not exist yet.
Does the draft reach companies outside Cambodia?
Yes, on its face. Article 2 extends the law to controllers and processors outside Cambodia that supply goods or services to, or monitor activities related to, data subjects residing in the Kingdom, the same extraterritorial hook the EU GDPR and Thailand's PDPA use.
What penalties does the draft propose?
Administrative fines up to 60,000,000 riel for a natural person and up to 600,000,000 riel or 10 percent of annual turnover for a legal person, plus criminal liability for repeat offenders. They would only bite if the law is enacted.