What Is Cambodia Privacy Protections: Constitutional, Criminal, E-Commerce, and Telecommunications Rules (No Enacted Comprehensive Personal Data Protection Law)?
No enacted, general or omnibus personal-data-protection statute was evidenced in the official Cambodian sources reviewed in the 28 August 2026 review. The Ministry of Post and Telecommunications continued describing a Personal Data Protection Law as under formulation in March 2026 and as a draft law under consultation in April 2026. An official November 2025 workshop also concerned establishing a future Personal Data Protection Authority. The operative framework is fragmented across constitutional privacy and correspondence protections, Criminal Code offences, the 2019 Law on E-Commerce, the 2015 Law on Telecommunications, and sector-specific consumer, domain-registration, credit-reporting, and administrative rules. These instruments provide targeted protections and remedies, not a GDPR-style data-subject rights framework. No general data-protection authority complaint procedure or statutory request-response clock was located. The reviewed official sources also located no Cambodia-wide data-broker opt-out, public-record suppression or deletion process, or broker-specific privacy complaint route. "Not located" is a bounded search result, not a confirmed statement of nonexistence.
At a glance
- Full name
- Cambodia Privacy Protections: Constitutional, Criminal, E-Commerce, and Telecommunications Rules (No Enacted Comprehensive Personal Data Protection Law)
- Short code
- Fragmented privacy framework
- Jurisdiction
- Cambodia
- Enacted
- 2019
- Last major update
- The Personal Data Protection Law remained under formulation or draft consultation in March-April 2026; no enacted general personal-data statute was evidenced in the reviewed official sources
- Regulator
- Ministry of Post and Telecommunications (MPTC); no verified operative independent personal-data regulator
- Private right of action
- Limited
Scope, who Fragmented privacy framework covers
Protected data
Data subject rights
No general statutory right of access, erasure, portability, restriction, objection, profiling protection, automated-decision protection, or universal controller/processor duties was located
Constitutional Article 40: protection of privacy of residence and secrecy of correspondence, subject to searches conducted according to law
Constitutional Article 39: right to denounce, complain, and file claims concerning legal breaches
E-Commerce Law Article 18: correction or withdrawal of an erroneous electronic input where statutory conditions are met
E-Commerce Law Article 30: easy rejection option for unsolicited commercial communications
E-Commerce Law Article 32: reasonable security safeguards and prohibition of unauthorized interference with electronic data
E-Commerce Law Article 22: prohibition on bad-faith or unauthorized use of another person’s identity, records, electronic signature or address, or secret code
Telecommunications Law Article 65(b): protection of subscribers’ privacy, security, and safety in using telecommunications services
Notable features
Cambodia remains a no-enacted-comprehensive-law case. Draft-law consultations and plans for a future Personal Data Protection Authority cannot substitute for current enacted law. The closest operative protections are sectoral and offence-based, and no fixed deadline located applies generally to access, deletion, correction, restriction, or objection requests.
Enforcement & penalties
Penalties: E-Commerce Law Article 60: violation of Article 32 security or unauthorized-data-interference obligations carries 1–2 years’ imprisonment and 2,000,000–4,000,000 Cambodian riels. Article 53 identity misuse carries 6 months–3 years’ imprisonment and 1,000,000–6,000,000 riels. Article 59 malicious code carries 6 months–3 years and 1,000,000–6,000,000 riels. Criminal Code Articles 301, 302, 317, and 318 generally carry 1 month–1 year and 100,000–2,000,000 riels for specified privacy, correspondence, or telecommunications offences. English statutory texts are translations; Khmer originals control in case of discrepancy.
Private right of action: The fragmented framework provides constitutional complaint and claim routes and criminal remedies for specified conduct. A general private right of action, compensation route, or civil-suit mechanism for ordinary personal-data disputes was not located in the reviewed sources.
Relevance to data brokers
No Cambodia-wide data-broker opt-out, public-record suppression or deletion process, or broker-specific privacy complaint route was located. Credit reporting is the closest sectoral route, but the current 2020 procedure and deadlines were not verified from the official legal text.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Cambodia have a comprehensive personal-data-protection law?+
No enacted general or omnibus personal-data-protection statute was evidenced in the reviewed official sources. The Personal Data Protection Law was still described as under formulation or draft consultation in 2026.
What privacy rights currently exist in Cambodia?+
Existing rules protect privacy of residence and correspondence, private conversations and images, subscriber privacy, electronic data security, and certain identity and marketing interests. No general catalog of access, erasure, portability, restriction, or objection rights was located.
Can I ask a Cambodian data broker to delete my information?+
A Cambodia-wide data-broker opt-out, public-record suppression or deletion process, or broker-specific privacy complaint route was not located.
Official sources & citations
Other international privacy regimes
Fragmented privacy framework sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
