What Is Personal Data Protection Order, 2025?
Brunei has an omnibus private-sector framework: the Personal Data Protection Order, 2025, made on 8 January 2025. The official commencement notification appointed 1 January 2026 for Parts 3–9, section 42, and Schedules 1–5, and the official AGC index records that commencement. AITI describes the Order as comprehensive and states that it administers and enforces the framework. The Order provides purpose and consent controls, withdrawal of consent, access, correction, accuracy, security, retention, overseas-transfer protections, and direct-marketing opt-out rules. Access and correction rights are subject to detailed exceptions involving evaluative opinions, examinations, trusts, arbitration or mediation, prosecutions, privilege, confidential commercial information, investigations, safety, national interest, and other listed circumstances. No standalone right to erasure, data portability, general objection, restriction of processing, or protection against solely automated decisions was located. The retention and destruction duty is an organisational obligation, not a general subject-initiated erasure right. No dedicated data-broker or public-record route was located, although AITI’s general complaint process can address unauthorised collection, use, disclosure, or refusal of access or correction.
At a glance
- Full name
- Personal Data Protection Order, 2025
- Short code
- PDPO 2025
- Jurisdiction
- Brunei Darussalam
- Enacted
- 2025
- Last major update
- Parts 3–9, section 42, and Schedules 1–5 commenced on 1 January 2026; no official amendment was located in the materials checked in the 28 August 2026 review
- Regulator
- Authority for Info-communications Technology Industry (AITI)
- Private right of action
- Limited
- Statutory citation
- Personal Data Protection Order, 2025
Scope, who PDPO 2025 covers
Protected data
Data subject rights
Right to purpose-specific and reasonably necessary consent controls, without deceptive or unnecessary bundling
Right to withdraw consent on reasonable notice, with an explanation of likely consequences
Right of access to personal data in an organisation’s possession or control
Right to information about use or disclosure during the preceding year
Right to correction of errors or omissions as soon as practicable
Right to use a valid representative for consent, withdrawal, access, and correction functions where permitted
Right to reasonable accuracy and security efforts
Right to organisational cessation of retention when the purpose is no longer served, subject to legal or operational justification
Right to complain to AITI about unauthorised collection, use, disclosure or sharing, or refusal to provide access or correction
Direct-marketing opt-out protection for marketing to a Brunei telephone number
No standalone right to erasure, portability, general objection, restriction of processing, or protection against solely automated decisions was located
Notable features
The PDPO 2025 cleared Brunei’s current-law and commencement blocker: the operative private-sector framework commenced on 1 January 2026. Its distinctive limits are the absence of a standalone erasure or portability right located in the reviewed materials, detailed access and correction exceptions, and a transfer rule requiring a comparable level of protection for data sent outside Brunei.
Enforcement & penalties
Regulator: Authority for Info-communications Technology Industry (AITI)
Penalties: An administrative financial penalty against an organisation may be up to 10% of annual turnover in Brunei where annual turnover exceeds $10 million, or otherwise up to $1 million, for intentional or negligent contraventions of Parts 3–7. Unauthorised disclosure, improper use, or unauthorised re-identification carries an individual fine up to $5,000, imprisonment up to 2 years, or both. Obstructing investigations, evading requests, destroying or falsifying records, or providing false or misleading information may carry an individual fine up to $10,000 and imprisonment up to 12 months, or in other cases a fine up to $100,000. A general offence where no specific penalty applies carries up to $10,000, imprisonment up to 3 years, or both, with continuing offences potentially attracting up to $1,000 per day after conviction.
Private right of action: AITI complaint, mediation, review, investigation, compliance, destruction, and financial-penalty routes are the identified mechanisms. A general private compensation or direct civil-action route was not identified.
Relevance to data brokers
No data-broker-specific or public-record-specific complaint, deletion, or opt-out route was located in the official AGC and AITI materials checked. The Order permits specified collection, use, and disclosure of publicly available data without consent and recognises credit-bureau reporting, but neither is a general data-broker deletion mechanism. The Authority may direct destruction of data collected in contravention of the Order, but that is an enforcement remedy rather than a general individual deletion right.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Brunei’s Personal Data Protection Order currently in force?+
Yes. The Personal Data Protection Order, 2025 was made on 8 January 2025, and the official commencement notification appointed 1 January 2026 for Parts 3–9, section 42, and Schedules 1–5.
What privacy rights does Brunei’s PDPO provide?+
The Order provides consent and withdrawal controls, access, correction, accuracy, security, retention, overseas-transfer, and direct-marketing protections, together with complaints to AITI. No standalone right to erasure, portability, general objection, restriction, or solely automated-decision protection was located.
Can I request deletion from a Brunei data broker?+
No data-broker-specific or public-record-specific complaint, deletion, or opt-out route was located. AITI’s general complaint form may address unauthorised collection, use, disclosure, or refusal of access or correction.
Official sources & citations
Other international privacy regimes
PDPO 2025 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
