Cambodia Draft PDPL
Draft Personal Data Protection Law
Cambodia's draft data protection law establishing human intervention rights for automated decisions (Article 34) and mandatory DPO requirement.
Jurisdiction
Cambodia
KH
Enacted
Unknown
Effective
Unknown
Enforcement
To be established
Expected passage 2026-2027
What It Requires
Who Must Comply
This law applies to:
- • Data controllers and processors in Cambodia (when enacted)
- • Entities processing data of Cambodian residents
- • Automated decision-making systems
Capability triggers:
Safety Provisions
- • Human intervention rights for automated decisions (Article 34)
- • Data Protection Officer mandatory
- • Consent requirements for data processing
- • Breach notification required
- • Cross-border transfer restrictions
Enforcement
Enforced by
To be established
Penalties
To be determined upon enactment
Quick Facts
- Binding
- No
- Mental Health Focus
- Yes
- Child Safety Focus
- No
- Algorithmic Scope
- Yes
Why It Matters
Cambodia's Article 34 human intervention requirement for automated decisions will directly impact AI chatbots making risk assessments when enacted. Monitor for passage.
Recent Developments
Draft under consideration, expected passage 2026-2027
Cite This
APA
Cambodia. (n.d.). Draft Personal Data Protection Law. Retrieved from https://nope.net/regs/kh-draft-pdpl
BibTeX
@misc{kh_draft_pdpl,
title = {Draft Personal Data Protection Law},
author = {Cambodia},
year = {n.d.},
url = {https://nope.net/regs/kh-draft-pdpl}
} Related Regulations
Brunei PDPO
Brunei's personal data protection order requiring DPIA and imposing penalties up to 10% Brunei turnover or $1M.
India DPDP Act
STRICTEST children's provisions in APAC. Children = under 18; verifiable parental consent MANDATORY; PROHIBITION on tracking, behavioral monitoring, targeted advertising to children.
Indonesia PP 17/2025
Indonesia's comprehensive child online protection regulation establishing age-appropriate design requirements for electronic systems accessible to children. Most granular age classification globally (5 groups). Requires risk assessments, privacy-by-default, parental consent, DPIAs, and prohibits data profiling of children. First of its kind in Asia and Global South.
Nepal AI Policy
Nepal national AI policy establishing governance framework and development priorities. Creates AI Governance Council (chaired by Minister for Communications and IT), AI Regulation Council, National AI Centre, and AI Regulatory Authority. Six pillars including ethics, human resource development, and sectoral application.
Pakistan AI Policy
Pakistan's national AI roadmap establishing six strategic pillars: AI Innovation Ecosystem, Awareness and Readiness, Research and Development, Infrastructure, Governance, and International Cooperation. Creates National AI Fund (NAIF), Centres of Excellence in 7 cities, and targets training 200,000 individuals annually.
Myanmar Cybersecurity Law
Myanmar's cybersecurity law requiring platforms with 100,000+ users to register and imposing data retention requirements. Enacted post-2021 coup with uncertain enforcement.