Myanmar Cybersecurity Law (2023)
Myanmar's Cybersecurity Law (2023) establishes a cybersecurity and data protection framework. The law covers cybersecurity obligations for digital platform service providers, critical information infrastructure protection, personal data processing requirements, and cybersecurity incident reporting. Administered by the Ministry of Transport and Communications. The law has been criticised for its surveillance provisions and broad scope.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (21)
Assurance
| Code | Title |
|---|---|
| MCL.14 | Security Audit and Independent Review |
Content Governance
| Code | Title |
|---|---|
| MCL.03 | Content Restriction and Blocking Compliance |
Critical Infrastructure
| Code | Title |
|---|---|
| MCL.06 | Critical Information Infrastructure Designation |
Cybercrime Offences
| Code | Title |
|---|---|
| Art. 28 | Notifying Authorities |
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 30 | Privacy Policy |
| Art. 31 | Designation of Chief Privacy Officer |
| MMCL-Ch9-1 | Unauthorized Access |
| MMCL-Ch9-2 | Data Interference |
| MMCL-Ch9-3 | System Interference |
Data Residency
| Code | Title |
|---|---|
| MCL.04 | Personal Data Localization |
Data Subject Rights
| Code | Title |
|---|---|
| MCL.10 | Data Subject Rights Handling |
Enforcement
| Code | Title |
|---|---|
| CTDPA-13 | AG Enforcement Authority |
| CTDPA-14 | Cure Period |
| FDBR-720 | Enforcement and Penalties (§501.72) |
| MCL.16 | Penalties and Enforcement Awareness |
| MMCL-Ch13-1 | Penalties |
| MMCL-Ch14-1 | Appeal Procedures |
| PY-11 | Supervisory Authority |
| PY-12 | Penalties |
| TIPA-12 | Profiling with Significant Effects |
| TIPA-13 | Children's and Teen Data Considerations |
Enforcement
| Code | Title |
|---|---|
| CTDPA-13 | AG Enforcement Authority |
| CTDPA-14 | Cure Period |
| FDBR-720 | Enforcement and Penalties (§501.72) |
| MCL.16 | Penalties and Enforcement Awareness |
| MMCL-Ch13-1 | Penalties |
| MMCL-Ch14-1 | Appeal Procedures |
| PY-11 | Supervisory Authority |
| PY-12 | Penalties |
| TIPA-12 | Profiling with Significant Effects |
| TIPA-13 | Children's and Teen Data Considerations |
Identity and Access
| Code | Title |
|---|---|
| MCL.08 | User Identity Verification |
Incident Reporting
| Code | Title |
|---|---|
| MCL.07 | Cyber Incident Notification |
Institutional Framework
| Code | Title |
|---|---|
| MMCL-Ch4-1 | Central Cybersecurity Committee |
| MMCL-Ch4-2 | Committee Duties and Powers |
International Transfers
| Code | Title |
|---|---|
| MCL.12 | Cross Border Data Transfer Authorization |
Lawful Intercept
| Code | Title |
|---|---|
| MCL.05 | Lawful Surveillance Assistance |
Licensing
| Code | Title |
|---|---|
| MMCL-Ch6-1 | Cybersecurity Service License |
| MMCL-Ch6-2 | Digital Platform License |
| MMCL-Ch6-3 | VPN Regulation |
Licensing and Authorization
| Code | Title |
|---|---|
| MCL.01 | Licensing of Digital Platform Service Providers |
| MCL.02 | Internet Service Provider Authorization |
Network Controls
| Code | Title |
|---|---|
| MCL.09 | Prohibition on Unlicensed Virtual Private Networks |
People and Training
| Code | Title |
|---|---|
| MCL.13 | Cybersecurity Workforce Competence |
Platform Obligations
Video-sharing platform and enforcement requirements
Records Management
| Code | Title |
|---|---|
| MCL.15 | Records Retention and Disclosure Logs |
Risk Management
| Code | Title |
|---|---|
| MCL.11 | Cybersecurity Risk Management Programme |
Third Party Risk
| Code | Title |
|---|---|
| MCL.17 | Third Party and Outsourcing Oversight |
Your Compliance Coverage
If you comply with Myanmar Cybersecurity Law (2023), you already cover:
Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011)
13%
5 controls mapped
Compare →UK GDPR (UK General Data Protection Regulation)
13%
5 controls mapped
Compare →Pakistan Personal Data Protection Bill 2023
13%
5 controls mapped
Compare →+ 468 more: Kenya Data Protection Act 2019 (13%), Ghana Data Protection Act 2012 (Act 843) (13%)
See all 471 mapped frameworks ↓Maps to 471 other frameworks
Frequently Asked Questions
What is Myanmar Cybersecurity Law (2023)?
Myanmar Cybersecurity Law (2023) is a compliance framework from Myanmar with 21 domains and 38 controls. Myanmar's Cybersecurity Law (2023) establishes a cybersecurity and data protection framework. The law covers cybersecurity obligations for digital platform service providers, critical information infrastructure protection, personal data processing requirements, and cybersecurity incident reporting. Administered by the Ministry of Transport and Communications. The law has been criticised for its surveillance provisions and broad scope. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Myanmar Cybersecurity Law (2023) have?
Myanmar Cybersecurity Law (2023) has 38 controls organised across 21 domains. The largest domains are Enforcement (9 controls), Cybercrime Offences (7 controls), Licensing (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Myanmar Cybersecurity Law (2023) map to?
Myanmar Cybersecurity Law (2023) maps to 471 other compliance frameworks. The top mapping partners are Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) (13% coverage), UK GDPR (UK General Data Protection Regulation) (13% coverage), Pakistan Personal Data Protection Bill 2023 (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Myanmar Cybersecurity Law (2023) compliance?
Start your Myanmar Cybersecurity Law (2023) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Myanmar Cybersecurity Law (2023) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 38 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required