Back to Frameworks

Brunei Personal Data Protection Order 2022 (PDPO)

Brunei Darussalam
v2022
7 domains
31 controls

The Personal Data Protection Order (PDPO) 2022, issued under the Emergency (Prohibition of Certain Acts) Order, establishes a comprehensive data protection framework for Brunei Darussalam. The Authority for Info-communications Technology Industry (AITI) is designated as the data protection authority responsible for enforcement and compliance. The PDPO aligns with the APEC Privacy Framework, setting out obligations for data controllers, rights for data subjects, and enforcement mechanisms.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Brunei PDPO Part 1-2: Preliminary and Administration

4 controls
Controls in the Brunei PDPO Part 1-2: Preliminary and Administration domain of Brunei Personal Data Protection Order 2022 (PDPO)4 controls
CodeTitle
BN-PDPO-s2Interpretation
BN-PDPO-s3Application of Order
BN-PDPO-s4Administration of the Order (the Authority)
BN-PDPO-s5Functions and duties of the Authority

Brunei PDPO Part 10-12: Offences, Enforcement and Remedies

7 controls
Controls in the Brunei PDPO Part 10-12: Offences, Enforcement and Remedies domain of Brunei Personal Data Protection Order 2022 (PDPO)7 controls
CodeTitle
BN-PDPO-s31Unauthorised disclosure of personal data
BN-PDPO-s32Improper use of personal data
BN-PDPO-s33Unauthorised re-identification of anonymised information
BN-PDPO-s36Directions for non-compliance
BN-PDPO-s37Financial penalties
BN-PDPO-s42Appeal from direction or decision of the Authority
BN-PDPO-s59Right of private action

Brunei PDPO Part 3: Accountability

1 controls
Controls in the Brunei PDPO Part 3: Accountability domain of Brunei Personal Data Protection Order 2022 (PDPO)1 controls
CodeTitle
BN-PDPO-s7Responsibilities of organisation (accountability)

Brunei PDPO Part 4: Consent

6 controls
Controls in the Brunei PDPO Part 4: Consent domain of Brunei Personal Data Protection Order 2022 (PDPO)6 controls
CodeTitle
BN-PDPO-s10Valid consent
BN-PDPO-s11Deemed consent
BN-PDPO-s13Withdrawal of consent
BN-PDPO-s14Collection, use and disclosure without consent
BN-PDPO-s8Consent required
BN-PDPO-s9Consent for direct marketing messages

Brunei PDPO Part 5-6: Purpose, Notification, Access and Correction

5 controls
Controls in the Brunei PDPO Part 5-6: Purpose, Notification, Access and Correction domain of Brunei Personal Data Protection Order 2022 (PDPO)5 controls
CodeTitle
BN-PDPO-s15Limitation of purpose and extent
BN-PDPO-s17Notification of purpose
BN-PDPO-s18Access to personal data
BN-PDPO-s19Correction of personal data
BN-PDPO-s20Exercise of rights on behalf of an individual

Brunei PDPO Part 7: Care of Personal Data

4 controls
Controls in the Brunei PDPO Part 7: Care of Personal Data domain of Brunei Personal Data Protection Order 2022 (PDPO)4 controls
CodeTitle
BN-PDPO-s21Accuracy of personal data
BN-PDPO-s22Protection of personal data
BN-PDPO-s23Retention of personal data
BN-PDPO-s24Transfer of personal data outside Brunei Darussalam

Brunei PDPO Part 8-9: Data Breach Notification and Public Agency Processors

4 controls
Controls in the Brunei PDPO Part 8-9: Data Breach Notification and Public Agency Processors domain of Brunei Personal Data Protection Order 2022 (PDPO)4 controls
CodeTitle
BN-PDPO-s26Notifiable data breaches
BN-PDPO-s27Duty to conduct assessment of a data breach
BN-PDPO-s28Duty to notify a notifiable data breach
BN-PDPO-s29Obligations of a data processor of a public agency

Maps to 2 other frameworks

31 total controls
GDPR
5 source controls mapped|5 target controls covered
16%
PDPA Singapore
4 source controls mapped|4 target controls covered
13%

Frequently Asked Questions

What is Brunei Personal Data Protection Order 2022 (PDPO)?

Brunei Personal Data Protection Order 2022 (PDPO) is a compliance framework from Brunei Darussalam with 7 domains and 31 controls. The Personal Data Protection Order (PDPO) 2022, issued under the Emergency (Prohibition of Certain Acts) Order, establishes a comprehensive data protection framework for Brunei Darussalam. The Authority for Info-communications Technology Industry (AITI) is designated as the data protection authority responsible for enforcement and compliance. The PDPO aligns with the APEC Privacy Framework, setting out obligations for data controllers, rights for data subjects, and enforcement mechanisms. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Brunei Personal Data Protection Order 2022 (PDPO) have?

Brunei Personal Data Protection Order 2022 (PDPO) has 31 controls organised across 7 domains. The largest domains are Brunei PDPO Part 10-12: Offences, Enforcement and Remedies (7 controls), Brunei PDPO Part 4: Consent (6 controls), Brunei PDPO Part 5-6: Purpose, Notification, Access and Correction (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Brunei Personal Data Protection Order 2022 (PDPO) map to?

Brunei Personal Data Protection Order 2022 (PDPO) maps to 2 other compliance frameworks. The top mapping partners are GDPR (16% coverage), PDPA Singapore (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Brunei Personal Data Protection Order 2022 (PDPO) compliance?

Start your Brunei Personal Data Protection Order 2022 (PDPO) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Brunei Personal Data Protection Order 2022 (PDPO) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 31 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required