Brunei Personal Data Protection Order 2022 (PDPO)
The Personal Data Protection Order (PDPO) 2022, issued under the Emergency (Prohibition of Certain Acts) Order, establishes a comprehensive data protection framework for Brunei Darussalam. The Authority for Info-communications Technology Industry (AITI) is designated as the data protection authority responsible for enforcement and compliance. The PDPO aligns with the APEC Privacy Framework, setting out obligations for data controllers, rights for data subjects, and enforcement mechanisms.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (32)
Awareness
| Code | Title |
|---|---|
| BN-PDPO-19 | Training and Awareness |
Complaints
| Code | Title |
|---|---|
| BN-PDPO-20 | Complaints Handling |
Consent
| Code | Title |
|---|---|
| BN-PDPO-3 | Consent Obligation |
| BN-PDPO-4 | Deemed and Implied Consent Boundaries |
Cross-Border
| Code | Title |
|---|---|
| BN-PDPO-12 | Transfer Limitation Obligation |
Data Protection Framework
Constitutional and regulatory privacy protections
Data Quality
| Code | Title |
|---|---|
| BN-PDPO-9 | Accuracy Obligation |
Documentation
| Code | Title |
|---|---|
| BN-PDPO-21 | Records of Compliance Activities |
Governance
| Code | Title |
|---|---|
| BN-PDPO-2 | Data Protection Officer Appointment |
Improvement
| Code | Title |
|---|---|
| BN-PDPO-25 | Continuous Improvement |
Incident
| Code | Title |
|---|---|
| BN-PDPO-14 | Data Breach Notification |
Individual Rights
| Code | Title |
|---|---|
| BN-PDPO-7 | Access Obligation |
| BN-PDPO-8 | Correction Obligation |
Inventory
| Code | Title |
|---|---|
| BN-PDPO-17 | Inventory and ROPA |
Marketing
| Code | Title |
|---|---|
| BN-PDPO-16 | Do Not Call (if Applicable) |
Notice
| Code | Title |
|---|---|
| BN-PDPO-6 | Notification Obligation |
Part 1 - Preliminary
| Code | Title |
|---|---|
| MHR-1 | Objects and Definitions |
| MHR-2 | Application and Scope |
| OSA-1 | Objects and Definitions |
| OSA-2 | Scope of Application |
| POFMA-1.1 | Definitions and Interpretation (Sections 2-3) |
| POFMA-1.2 | Application and Scope (Section 4) |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
| Sec. 6 | Establishment of the Commission |
Part 2 - Administration
| Code | Title |
|---|---|
| Sec. 4 | Exemptions |
| Sec. 5 | Functions and Duties of Authority |
| Sec. 6 | Establishment of the Commission |
Part 3 - Accountability for Personal Data
| Code | Title |
|---|---|
| Sec. 7 | Responsibilities of Organisation |
Part 4 - Collection, Use and Disclosure of Personal Data
| Code | Title |
|---|---|
| Sec. 10 | Powers of the Commission |
| Sec. 11 | Deemed Consent |
| Sec. 12 | Independence |
| Sec. 13 | Appointment of Commissioner |
| Sec. 14 | Collection Without Consent |
| Sec. 8 | Functions of the Commission |
| Sec. 9 | Direct Marketing Consent |
Part 5 - Access to and Correction of Personal Data
| Code | Title |
|---|---|
| Sec. 17 | Certificate of Registration |
| Sec. 18 | Right to Correction |
| Sec. 19 | Lawful, Fair and Transparent Processing |
Part 7 - Notification of Data Breaches
| Code | Title |
|---|---|
| Sec. 25 | Interpretation |
| Sec. 26 | Notifiable Data Breaches |
| Sec. 27 | Duty to Conduct Assessment |
| Sec. 28 | Duty to Notify |
Part 8 - Offences Affecting Personal Data
| Code | Title |
|---|---|
| Sec. 31 | Unauthorised Disclosure |
| Sec. 32 | Right of Access |
| Sec. 33 | Unauthorised Re-identification |
Part 9 - Enforcement
| Code | Title |
|---|---|
| Sec. 34 | Right to Rectification |
| Sec. 36 | Right to Erasure |
| Sec. 37 | Financial Penalties |
| Sec. 39 | Voluntary Undertakings |
Public Sector
| Code | Title |
|---|---|
| BN-PDPO-23 | Public Sector Coordination |
Purpose
| Code | Title |
|---|---|
| BN-PDPO-5 | Purpose Limitation Obligation |
Regulator
| Code | Title |
|---|---|
| BN-PDPO-24 | Enforcement Cooperation |
Retention
| Code | Title |
|---|---|
| BN-PDPO-11 | Retention Limitation Obligation |
Risk
| Code | Title |
|---|---|
| BN-PDPO-18 | Risk and Impact Assessments |
Scope
| Code | Title |
|---|---|
| BN-PDPO-1 | Applicability and Scope Determination |
Security
| Code | Title |
|---|---|
| BN-PDPO-10 | Protection Obligation |
Third Party
| Code | Title |
|---|---|
| BN-PDPO-15 | Data Intermediary Contracts |
Transparency
| Code | Title |
|---|---|
| BN-PDPO-13 | Openness Obligation |
Vulnerable
| Code | Title |
|---|---|
| BN-PDPO-22 | Children's Data |
Your Compliance Coverage
If you comply with Brunei Personal Data Protection Order 2022 (PDPO), you already cover:
Tanzania Personal Data Protection Act (Draft)
22%
13 controls mapped
Compare →Mauritius Data Protection Act 2017
22%
13 controls mapped
Compare →Trinidad and Tobago Data Protection Act 2011
22%
13 controls mapped
Compare →+ 594 more: Botswana Data Protection Act (2024) (22%), Egypt Personal Data Protection Law (Law No. 151 of 2020) (22%)
See all 597 mapped frameworks ↓Maps to 597 other frameworks
Frequently Asked Questions
What is Brunei Personal Data Protection Order 2022 (PDPO)?
Brunei Personal Data Protection Order 2022 (PDPO) is a compliance framework from Brunei Darussalam with 32 domains and 60 controls. The Personal Data Protection Order (PDPO) 2022, issued under the Emergency (Prohibition of Certain Acts) Order, establishes a comprehensive data protection framework for Brunei Darussalam. The Authority for Info-communications Technology Industry (AITI) is designated as the data protection authority responsible for enforcement and compliance. The PDPO aligns with the APEC Privacy Framework, setting out obligations for data controllers, rights for data subjects, and enforcement mechanisms. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Brunei Personal Data Protection Order 2022 (PDPO) have?
Brunei Personal Data Protection Order 2022 (PDPO) has 60 controls organised across 32 domains. The largest domains are Part 1 - Preliminary (10 controls), Part 4 - Collection, Use and Disclosure of Personal Data (7 controls), Part 7 - Notification of Data Breaches (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Brunei Personal Data Protection Order 2022 (PDPO) map to?
Brunei Personal Data Protection Order 2022 (PDPO) maps to 597 other compliance frameworks. The top mapping partners are Tanzania Personal Data Protection Act (Draft) (22% coverage), Mauritius Data Protection Act 2017 (22% coverage), Trinidad and Tobago Data Protection Act 2011 (22% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Brunei Personal Data Protection Order 2022 (PDPO) compliance?
Start your Brunei Personal Data Protection Order 2022 (PDPO) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Brunei Personal Data Protection Order 2022 (PDPO) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 60 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required