Myanmar Cybersecurity Law (2023)
Myanmar's Cybersecurity Law (2023) establishes a cybersecurity and data protection framework. The law covers cybersecurity obligations for digital platform service providers, critical information infrastructure protection, personal data processing requirements, and cybersecurity incident reporting. Administered by the Ministry of Transport and Communications. The law has been criticised for its surveillance provisions and broad scope.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Cybercrime Offences
| Code | Title |
|---|---|
| Art. 28 | Administrative Measures |
| Art. 29 | Safety Measures |
| Art. 30 | Privacy Policy |
| Art. 31 | Designation of Chief Privacy Officer |
| MMCL-Ch9-1 | Unauthorized Access |
| MMCL-Ch9-2 | Data Interference |
| MMCL-Ch9-3 | System Interference |
Enforcement
| Code | Title |
|---|---|
| CTDPA-13 | AG Enforcement Authority |
| CTDPA-14 | Cure Period |
| FDBR-720 | Enforcement and Penalties (§501.72) |
| MMCL-Ch13-1 | Penalties |
| MMCL-Ch14-1 | Appeal Procedures |
| PY-11 | Supervisory Authority |
| PY-12 | Penalties |
| TIPA-12 | AG Enforcement |
| TIPA-13 | 60-Day Cure Period |
Institutional Framework
| Code | Title |
|---|---|
| MMCL-Ch4-1 | Central Cybersecurity Committee |
| MMCL-Ch4-2 | Committee Duties and Powers |
Licensing
| Code | Title |
|---|---|
| MMCL-Ch6-1 | Cybersecurity Service License |
| MMCL-Ch6-2 | Digital Platform License |
| MMCL-Ch6-3 | VPN Regulation |
Platform Obligations
Video-sharing platform and enforcement requirements
Maps to 464 other frameworks
Frequently Asked Questions
What is Myanmar Cybersecurity Law (2023)?
Myanmar Cybersecurity Law (2023) is a compliance framework from Myanmar with 5 domains and 21 controls. Myanmar's Cybersecurity Law (2023) establishes a cybersecurity and data protection framework. The law covers cybersecurity obligations for digital platform service providers, critical information infrastructure protection, personal data processing requirements, and cybersecurity incident reporting. Administered by the Ministry of Transport and Communications. The law has been criticised for its surveillance provisions and broad scope. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Myanmar Cybersecurity Law (2023) have?
Myanmar Cybersecurity Law (2023) has 21 controls organised across 5 domains. The largest domains are Enforcement (9 controls), Cybercrime Offences (7 controls), Licensing (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Myanmar Cybersecurity Law (2023) map to?
Myanmar Cybersecurity Law (2023) maps to 464 other compliance frameworks. The top mapping partners are Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) (24% coverage), UK GDPR (UK General Data Protection Regulation) (24% coverage), Pakistan Personal Data Protection Bill 2023 (24% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Myanmar Cybersecurity Law (2023) compliance?
Start your Myanmar Cybersecurity Law (2023) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Myanmar Cybersecurity Law (2023) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 21 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required