Brunei Personal Data Protection Order 2024 (PDPO)
Brunei Darussalam's Personal Data Protection Order 2024 (PDPO), issued under the Emergency Orders, establishes a comprehensive data protection framework for Brunei. The Authority for Info-communications Technology Industry (AITI) oversees compliance. The PDPO follows the APEC Privacy Framework and ASEAN Framework on Personal Data Protection. It establishes data protection obligations for organisations, individual rights, and cross-border transfer provisions. Applies to organisations processing personal data in Brunei.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (9)
Data Protection Framework
Constitutional and regulatory privacy protections
Part 1 — Preliminary
| Code | Title |
|---|---|
| MHR-1 | Objects and Definitions |
| MHR-2 | Application and Scope |
| OSA-1 | Objects and Definitions |
| OSA-2 | Scope of Application |
| POFMA-1.1 | Definitions and Interpretation (Sections 2-3) |
| POFMA-1.2 | Application and Scope (Section 4) |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
| Sec. 6 | Establishment of the Commission |
Part 2 — Administration
| Code | Title |
|---|---|
| Sec. 4 | Exemptions |
| Sec. 5 | Functions and Duties of Authority |
| Sec. 6 | Establishment of the Commission |
Part 3 — Accountability for Personal Data
| Code | Title |
|---|---|
| Sec. 7 | Responsibilities of Organisation |
Part 4 — Collection, Use and Disclosure of Personal Data
| Code | Title |
|---|---|
| Sec. 10 | Powers of the Commission |
| Sec. 11 | Deemed Consent |
| Sec. 12 | Independence |
| Sec. 13 | Appointment of Commissioner |
| Sec. 14 | Collection Without Consent |
| Sec. 8 | Functions of the Commission |
| Sec. 9 | Direct Marketing Consent |
Part 5 — Access to and Correction of Personal Data
| Code | Title |
|---|---|
| Sec. 17 | Certificate of Registration |
| Sec. 18 | Right to Correction |
| Sec. 19 | Lawful, Fair and Transparent Processing |
Part 7 — Notification of Data Breaches
| Code | Title |
|---|---|
| Sec. 25 | Interpretation |
| Sec. 26 | Notifiable Data Breaches |
| Sec. 27 | Duty to Conduct Assessment |
| Sec. 28 | Duty to Notify |
Part 8 — Offences Affecting Personal Data
| Code | Title |
|---|---|
| Sec. 31 | Unauthorised Disclosure |
| Sec. 32 | Right of Access |
| Sec. 33 | Unauthorised Re-identification |
Part 9 — Enforcement
| Code | Title |
|---|---|
| Sec. 34 | Right to Rectification |
| Sec. 36 | Right to Erasure |
| Sec. 37 | Financial Penalties |
| Sec. 39 | Voluntary Undertakings |
Maps to 574 other frameworks
Frequently Asked Questions
What is Brunei Personal Data Protection Order 2024 (PDPO)?
Brunei Personal Data Protection Order 2024 (PDPO) is a compliance framework from Brunei Darussalam with 9 domains and 35 controls. Brunei Darussalam's Personal Data Protection Order 2024 (PDPO), issued under the Emergency Orders, establishes a comprehensive data protection framework for Brunei. The Authority for Info-communications Technology Industry (AITI) oversees compliance. The PDPO follows the APEC Privacy Framework and ASEAN Framework on Personal Data Protection. It establishes data protection obligations for organisations, individual rights, and cross-border transfer provisions. Applies to organisations processing personal data in Brunei. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Brunei Personal Data Protection Order 2024 (PDPO) have?
Brunei Personal Data Protection Order 2024 (PDPO) has 35 controls organised across 9 domains. The largest domains are Part 1 — Preliminary (10 controls), Part 4 — Collection, Use and Disclosure of Personal Data (7 controls), Part 7 — Notification of Data Breaches (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Brunei Personal Data Protection Order 2024 (PDPO) map to?
Brunei Personal Data Protection Order 2024 (PDPO) maps to 574 other compliance frameworks. The top mapping partners are Tanzania Personal Data Protection Act (Draft) (38% coverage), Mauritius Data Protection Act 2017 (38% coverage), Trinidad and Tobago Data Protection Act 2011 (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Brunei Personal Data Protection Order 2024 (PDPO) compliance?
Start your Brunei Personal Data Protection Order 2024 (PDPO) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Brunei Personal Data Protection Order 2024 (PDPO) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required