GDPR
APAC Privacy Laws: A Country-by-Country Guide
APAC privacy laws are frequently discussed as if they were a single regime with local variations. They are not. The region contains statutes drafted decades apart, enforced by bodies with very different powers, using vocabulary that does not translate cleanly between jurisdictions. Some are closely modelled on the GDPR. Some predate it. At least one is not fully operative yet.
This guide sets out what is actually in force across the region, country by country, with the dates and the regulator for each. It is written for people who need to scope work across several markets rather than comply with one.
Last reviewed: September 2026.
Why “APAC privacy laws” is not one thing
Three structural differences do most of the damage when organisations treat the region as a block.
The naming is inconsistent. Singapore, Malaysia, Thailand, Taiwan and Sri Lanka call their law a Personal Data Protection Act. Vietnam calls its law a Personal Data Protection Law. China has a Personal Information Protection Law. India has a Digital Personal Data Protection Act. Korea has a Personal Information Protection Act. Japan has an Act on the Protection of Personal Information. The Philippines has a Data Privacy Act. Seven names for broadly the same category of statute.
The maturity varies enormously. Japan’s law dates from 2003 and has been through two major overhauls. India’s substantive obligations do not bite until 2027. Comparing them as peers produces bad planning.
The regulators differ in kind, not just in name. Some are independent commissions publishing reasoned enforcement decisions. Some sit inside a ministry. Vietnam’s sits inside the Ministry of Public Security. That shapes how enforcement actually works, and it is not something a compliance matrix captures.
The regional picture
| Country | Statute | Key date | Regulator |
|---|---|---|---|
| China | Personal Information Protection Law (PIPL) | In force 1 November 2021 | Cyberspace Administration of China |
| India | Digital Personal Data Protection Act, 2023 | Rules notified November 2025; substantive obligations from 14 May 2027 | Data Protection Board of India |
| Indonesia | Law No. 27 of 2022 on Personal Data Protection | Transition ended 17 October 2024; agency still being established | PDP Agency (pending) |
| Japan | Act on the Protection of Personal Information (APPI) | 2020 amendments in force 1 April 2022 | Personal Information Protection Commission (PPC) |
| Malaysia | Personal Data Protection Act 2010 (Act 709) | Amendments phased in during 2025 | Personal Data Protection Commissioner |
| Philippines | Data Privacy Act of 2012 (RA 10173) | In force since 2012 | National Privacy Commission |
| Singapore | Personal Data Protection Act 2012 | Main obligations from 2 July 2014 | Personal Data Protection Commission |
| South Korea | Personal Information Protection Act (PIPA) | Major amendment in force 15 September 2023 | Personal Information Protection Commission |
| Sri Lanka | Personal Data Protection Act, No. 9 of 2022 | Phased; Authority established August 2023 | Data Protection Authority |
| Taiwan | Personal Data Protection Act | Amended 2023 and October 2025 | Personal Data Protection Commission (in transition) |
| Thailand | Personal Data Protection Act B.E. 2562 (2019) | Fully in force 1 June 2022 | Personal Data Protection Committee |
| Vietnam | Law No. 91/2025/QH15 | In force 1 January 2026 | Ministry of Public Security |
Country by country
China
The Personal Information Protection Law was adopted on 20 August 2021 and took effect on 1 November 2021. It does not stand alone. PIPL sits on top of the Cybersecurity Law and the Data Security Law, and any serious analysis has to consider all three together.
PIPL has extraterritorial reach and a strict cross-border transfer regime. Its terminology is distinct: it regulates “personal information handlers,” defined as organisations or individuals that independently determine the purposes and means of processing. That definition is functionally close to a GDPR controller, but the surrounding architecture is not.
India
The Digital Personal Data Protection Act, 2023 was passed in 2023 but sat without operative rules for two years. The Digital Personal Data Protection Rules, 2025 were notified in mid-November 2025, and the government set a staggered commencement.
The provisions establishing the Data Protection Board took effect immediately. The consent manager provisions take effect twelve months later. The substantive obligations, including the core processing duties and the rights of data principals, take effect eighteen months after notification, on 14 May 2027.
For planning purposes: India has a law, it is real, and the compliance deadline for the parts that will affect your operations is in 2027. The vocabulary is its own, using “data fiduciary” for the controller equivalent and “data principal” for the data subject.
Indonesia
Law No. 27 of 2022 was enacted on 17 October 2022 with a two-year transition period that ended on 17 October 2024. In principle, controllers and processors have had to comply since that date.
In practice the regime is incomplete. The implementing government regulation and the supervisory agency have both been in preparation, with the agency expected to become operational during 2026. This creates a familiar awkward position: obligations exist, but the body that would enforce them and the regulation that would clarify them are not yet fully in place. The prudent approach is to treat the law as binding and build to it.
Japan
The Act on the Protection of Personal Information is the oldest comprehensive law in the region. It was substantially overhauled in 2017 and again in 2020, with the 2020 amendments taking effect on 1 April 2022.
The current APPI applies extraterritorially to any organisation handling the personal information of individuals in Japan in connection with supplying goods or services, and it includes mandatory breach notification. Enforcement by the Personal Information Protection Commission is guidance-first, escalating to binding orders and criminal penalties.
Malaysia
Act 709 dates from 2010 but was transformed by the Personal Data Protection (Amendment) Act 2024, phased in across the first half of 2025 with the headline obligations effective 1 June 2025.
The amendment renamed “data user” to “data controller,” made DPO appointment and breach notification mandatory, imposed direct obligations on processors, brought biometric data into the sensitive category, added a portability right, and replaced the cross-border whitelist with an adequacy-style assessment. If your knowledge of Malaysian data protection predates 2025, it is out of date.
Philippines
The Data Privacy Act of 2012, Republic Act No. 10173, is enforced by the National Privacy Commission. It requires the appointment of a Data Protection Officer and includes breach notification obligations. It is one of the older comprehensive laws in the region and remains substantively in force.
Singapore
The Personal Data Protection Act 2012 took full effect for its main obligations on 2 July 2014 and was substantially amended in 2020. The framework consists of eleven obligations, of which ten are in force; data portability has been legislated but awaits regulations.
Two features to watch: the breach notification window is three calendar days from assessing that a notifiable breach occurred, which is shorter and differently anchored than the 72-hour standard used elsewhere; and the maximum penalty is the higher of SGD 1 million or 10% of annual turnover in Singapore where that turnover exceeds SGD 10 million.
South Korea
PIPA underwent a major overhaul passed by the National Assembly on 27 February 2023, promulgated in March 2023, and in force from 15 September 2023, alongside an amended Enforcement Decree. Some provisions, including the right to object to automated decision-making, were phased in later.
The 2023 amendment added a data portability right and rights around automated decision-making, removed the separate track for online service providers, added grounds for overseas transfer beyond consent, and shifted the enforcement emphasis from criminal sanctions toward administrative penalties. Penalties can be calculated against an entity’s total revenue, with a cap of 3% of total revenue for serious security failures.
Korea’s regime is among the most demanding in the region on sensitive information, which requires explicit consent.
Sri Lanka
Sri Lanka’s Personal Data Protection Act, No. 9 of 2022 made it the first country in South Asia with comprehensive data protection legislation. It is modelled on the GDPR and reaches controllers and processors domiciled or incorporated in Sri Lanka, as well as those offering goods or services to people there.
Commencement was phased. The provisions establishing the Data Protection Authority and the interpretation section came into operation in 2023, with the Authority established in August 2023, and further parts commencing on 1 December 2023. The Act was amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025.
Taiwan
Taiwan is frequently omitted from regional summaries and is currently in the middle of the biggest change in its law’s history.
Taiwan’s Constitutional Court ruled in August 2022 that an independent supervisory mechanism for personal data protection was required. A May 2023 amendment added a provision naming a Personal Data Protection Commission as competent authority, and the Commission’s preparatory office was established in December 2023. On 17 October 2025 the Legislative Yuan passed further amendments establishing the Commission as supervisory authority, with mandatory DPOs for government agencies, new breach notification and reporting duties for non-government entities, expanded inspection powers, and a transition period for certain functions.
Until the transition completes, oversight remains distributed across sector regulators. The Act applies extraterritorially.
Thailand
The Personal Data Protection Act B.E. 2562 came fully into force on 1 June 2022 and is the most closely GDPR-modelled statute in Southeast Asia, with a comparable set of lawful bases.
Breach notification under Section 37(4) runs to 72 hours from awareness where feasible, with criteria published in the Government Gazette on 15 December 2022. DPOs are mandatory under Section 41 in specified circumstances. Enforcement began in earnest in August 2024 with a THB 7 million administrative fine covering inadequate security, late breach notification and failure to appoint a DPO.
Vietnam
Law No. 91/2025/QH15 was passed on 26 June 2025 and took effect on 1 January 2026, replacing a decree-level framework with statutory law. Decree No. 356/2025/ND-CP, promulgated 31 December 2025, supplies the implementing detail and replaced Decree No. 13/2023/ND-CP.
Vietnam is unusual in two respects. Enforcement sits with the Ministry of Public Security rather than an independent authority. And the law recognises three roles rather than two, adding a personal data controller and processor alongside the controller and the processor. That third category has no clean GDPR equivalent, and I have covered it in detail in controller and processor roles under Vietnam's PDPL.
Micro-enterprises and household businesses are exempt. Small enterprises and start-ups have a five-year grace period, subject to carve-outs for processing service providers, sensitive data and large-volume processing.
Australia and the wider Pacific
Organisations that say “APAC” often mean the Pacific too. Australia’s Privacy Act 1988 works differently from everything above: it is built on 13 Australian Privacy Principles rather than articles, and since 10 June 2025 individuals have been able to sue directly under a statutory tort for serious invasion of privacy. Automated decision-making transparency obligations follow on 10 December 2026. I have covered Australia alongside the GDPR and US state law in data protection laws around the world.
A note on the Gulf
Regional programmes described as “APAC” frequently include the Gulf states. Those are governed by a separate family of statutes using the PDPL name: Saudi Arabia, Bahrain, Oman, Jordan and the UAE. Vietnam also uses that name, which is a persistent source of confusion. I have written a separate guide to what PDPL means and which countries use it.
Equally, five jurisdictions in this guide use the PDPA name and are not the same law as each other. That family is covered in what is PDPA.
Six things that differ most
If you are building a regional programme, these are the points where a single template will break:
- Breach notification windows. Singapore is three calendar days from assessment. Thailand is 72 hours from awareness. Malaysia is as soon as practicable. They are not interchangeable, and the trigger points differ as much as the durations.
- DPO thresholds and qualifications. Some jurisdictions require appointment above a processing threshold, some require notification to the regulator, and some require accreditation on a register.
- Cross-border transfer mechanisms. Adequacy-style assessments, standard contractual clauses, consent-based transfer and regulator approval all appear across the region, in different combinations.
- Terminology. Controller, data user, data fiduciary, personal information handler and organisation all denote roughly the same role in different statutes. Mapping them is the first step in any regional gap analysis, and the underlying
controller and processor distinctionis what makes the mapping possible. - Whether consent is the default. China and Korea lean heavily on consent. Thailand offers a full set of lawful bases. Singapore sits between, having added legitimate interests in 2020.
- Regulator character. An independent commission publishing reasoned decisions behaves differently from an enforcement function inside a ministry. Plan your engagement accordingly.
What this means in practice
The productive approach across the region is not one policy applied twelve times, and not twelve separate programmes. It is a common core with jurisdiction-specific overlays.
The common core is the same everywhere: know what personal data you hold and why, document the roles you occupy in each processing activity, be able to produce a regulator notification quickly, and have contracts that reflect what your processors actually do. That work supports every statute in the table above.
The overlay is jurisdiction-specific: the exact notification deadline, the registration requirement, the DPO threshold, the transfer mechanism, and the contract clauses that particular law demands.
Building the core first is what makes the overlays cheap. Organisations that skip it end up maintaining parallel programmes that drift apart, which is expensive and produces exactly the governance gaps regulators are now fining people for. A working data governance framework does more for regional privacy compliance than a stack of country-specific policies.
Frequently asked questions
How many countries in APAC have privacy laws?
Every major economy in the region now has a comprehensive data protection statute in force or commenced. The twelve covered above account for most commercial activity, and the regional total is higher once smaller jurisdictions are included.
Which APAC privacy law is closest to GDPR?
Thailand’s PDPA is the closest structural match in Southeast Asia, with a comparable set of lawful bases. Sri Lanka’s Act is also closely modelled on the GDPR, and Korea’s PIPA moved nearer to GDPR standards with the 2023 amendment.
Does GDPR apply in Asia?
The GDPR applies to organisations in Asia where they offer goods or services to individuals in the EU or monitor their behaviour there. It does not displace local law. An organisation in Singapore serving EU customers is subject to both.
What is the difference between PDPA and PIPL?
PDPA is Personal Data Protection Act, the name used in Singapore, Malaysia, Thailand, Taiwan and Sri Lanka. PIPL is the Personal Information Protection Law, China’s statute in force since 1 November 2021. Different countries, different laws.
When does India’s data protection law take effect?
The Digital Personal Data Protection Act, 2023 was notified in stages from November 2025. The substantive obligations take effect on 14 May 2027.
Do I need a separate DPO for each country?
Not necessarily, but you need to check each jurisdiction’s requirement separately. Thresholds, notification duties and, in some jurisdictions, formal accreditation all vary.
Which was the first comprehensive privacy law in South Asia?
Sri Lanka’s Personal Data Protection Act, No. 9 of 2022.
Sources
- China Personal Information Protection Law, adopted 20 August 2021
- India Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025; commencement notifications published in the Official Gazette, November 2025
- Indonesia Law No. 27 of 2022 on Personal Data Protection
- Japan Act on the Protection of Personal Information, as amended in 2020
- Malaysia Personal Data Protection Act 2010 (Act 709) and Personal Data Protection (Amendment) Act 2024 (Act A1727)
- Philippines Data Privacy Act of 2012 (Republic Act No. 10173)
- Singapore Personal Data Protection Act 2012 and Personal Data Protection (Amendment) Act 2020
- South Korea Personal Information Protection Act, as amended 2023; Personal Information Protection Commission press release, 15 September 2023
- Sri Lanka Personal Data Protection Act, No. 9 of 2022, and Personal Data Protection (Amendment) Act, No. 22 of 2025
- Taiwan Personal Data Protection Act, as amended May 2023 and October 2025; Constitutional Court Judgment 111-Hsien-Pan-13 (2022)
- Thailand Personal Data Protection Act B.E. 2562 (2019); Personal Data Protection Committee breach notification criteria, Government Gazette, 15 December 2022
- Vietnam Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP