HR holds the most sensitive data in the business. Payroll numbers, national ID details, bank accounts, medical records, disciplinary files, biometric attendance logs. Nowhere else in a business does so much personally identifiable and sensitive data sit in one system as it does in HR. Yet across ASEAN, HR teams are often the last to be looped into data protection planning, even as the regionโs regulators become the first to act on it.
In 2025 and 2026, this gap has become expensive. Thailandโs regulator has issued multi-million-baht fines1. Malaysia has raised its maximum penalty five-fold2. Bangladesh has passed its first comprehensive data protection law3. Globally, the average data breach now costs an organisation USD 4.44 million4, and customer and employee personal data remains the type of record most frequently compromised.
For HR leaders across Malaysia, Thailand, Cambodia, Bangladesh, Sri Lanka and the wider region, understanding the compliance landscape is no longer a legal department concern. It is an operational one.
A regional patchwork, not a single rulebook
ASEAN does not have a unifying data protection regulation in the way the EU has the GDPR. Instead, member states have built their own frameworks at different speeds and to different standards, loosely coordinated through the non-binding ASEAN Framework on Personal Data Protection and the ASEAN Model Contractual Clauses for cross-border transfers. For HR teams running shared services or regional payroll across several countries, this means compliance has to be assessed market by market.
Country | Core law | Status | DPO mandatory | Breach notification |
Singapore | PDPA 2012 (amended 2020/2024) | In force; processor obligations Apr 2025, mandatory DPO Jun 2025 | Yes | Mandatory, effective Jun 2025 |
Malaysia | PDPA 2010, amended by PDP(A)A 2024 | In force; breach notification & DPO duties effective 1 Jun 2025 | Yes | Mandatory since Jun 2025 |
Thailand | PDPA B.E. 2562 (2019) | Fully enforced since Jun 2022; active enforcement phase 2024-2026 | Yes, for certain entities | 72-hour rule; PDPC investigates proactively |
Bangladesh | Personal Data Protection Act, 2026 | Enacted Apr 2026; most provisions in force from Nov 2025 | Chief Data Officer for significant data fiduciaries | Mandatory, phased in |
Cambodia | Law on Personal Data Protection (LPDP) | Draft only; not yet enacted as of mid-2026 | Proposed for all controllers/processors | Proposed, 72-hour notice to MPTC |
Table: comparative snapshot of core HR-relevant data protection obligations. Fines and thresholds are indicative; always confirm current figures with local counsel or the relevant regulator before acting.
ย
Singapore: the regional benchmark
Singaporeโs Personal Data Protection Act remains the regionโs most mature framework. Its 2024 amendment introduced new obligations for data processors, a mandatory Data Protection Officer requirement from June 2025, and a formal data breach notification duty from the same date1. For HR functions, this means any regional payroll or HRIS provider processing Singapore employee data on an organisationโs behalf now carries direct statutory obligations, not just contractual ones.
Malaysia: penalties raised five-fold
The Personal Data Protection (Amendment) Act 2024 is the first substantive update to Malaysiaโs PDPA since it took effect in 2013. From 1 June 2025, organisations must appoint a Data Protection Officer and notify the Commissioner of any breach as soon as practicable5. Maximum penalties for breaching the PDPAโs core principles have risen to RM1 million and up to three yearsโ imprisonment, a five-fold increase on the previous maximum6. Biometric data, increasingly used for attendance and access control, is now explicitly classified as sensitive personal data5.
โAppointing a DPO does not transfer your compliance obligations. The organisation remains responsible for meeting PDPA requirements.โ
โ guidance commonly given to Malaysian employers on the 2024 amendment
Thailand: from warnings to real fines
Thailandโs PDPA has been fully enforced since June 2022, but 2024 and 2025 marked a decisive shift from guidance to enforcement. The Personal Data Protection Committee issued its first major fine, THB 7 million, against a retailer following a breach that exposed more than 100,000 customer records and was linked to downstream call-centre fraud7. In August 2025 the regulator issued a further eight fines across five cases totalling roughly THB 14.5 million, taking cumulative fines since enforcement began to over THB 21 million1,7. Recurring failures cited by the regulator included missing Data Protection Officers, inadequate security measures, and failure to report breaches within 72 hours, precisely the areas where HR systems handling payroll and employee records are exposed.
Bangladesh: a new law, still being phased in
Bangladesh enacted its Personal Data Protection Act, 2026 in April 2026, repealing the interim Ordinance issued in November 20253. The law establishes data subject rights, breach notification duties, and requires significant data fiduciaries to appoint a Chief Data Officer, with provisions on penalties and complaint-handling due to be activated on a later notified date8. A February 2026 amendment narrowed data localisation requirements and replaced imprisonment with monetary fines for certain offences, while making individual government officials personally accountable for their agencyโs compliance9. For HR teams, the direction of travel is clear even while some mechanisms are still being finalised: consent, security and breach-reporting obligations are now written into law.
Cambodia: a law still on the drawing board
Cambodia remains one of the few ASEAN states without a comprehensive data protection law in force. A draft Law on Personal Data Protection was circulated for consultation through 2025, proposing GDPR-style rights, mandatory breach notification to the Ministry of Post and Telecommunications, and a mandatory certified Data Protection Officer for every controller and processor regardless of scale10. As of mid-2026 the law had not been enacted11. Businesses operating in Cambodia should treat the draft as a strong signal of the direction regulation is heading, rather than a current obligation, and prepare accordingly rather than wait for the gazette notice.
Why this matters specifically for HR
Data protection compliance conversations often default to marketing consent and customer databases. HR data carries a different risk profile, and in several respects a higher one:
- Sensitivity: national ID numbers, bank details, health and medical leave records, disciplinary history and, increasingly, biometric attendance data all sit within HR systems, and several of the regionโs newer laws (including Malaysiaโs amended PDPA) now explicitly classify biometric data as sensitive.
- Cross-border flows: regional employers running shared HR services or a single HRIS across several ASEAN markets must map exactly which countryโs rules apply to which employee record, since transfer restrictions and adequacy mechanisms differ by jurisdiction.
- Vendor exposure: HRIS, payroll and background-check providers are processors in their own right. Several 2024-2026 reforms extend direct statutory liability to processors, not just the controller organisations that engage them.
- Retention and access: HR records are kept for years, often well beyond an employeeโs tenure, and are accessed by a wide internal audience, from line managers to finance to IT, widening the practical attack surface.
The cost of getting it wrong
The global average cost of a data breach fell to USD 4.44 million in 2025, the first decline in five years, largely thanks to faster detection driven by AI-assisted security tools4. Personal information remains the data type compromised most often, and breach costs in the Asia-Pacific region have been trending upward even as global figures ease4.
Beyond the direct fines now being levied by regulators in Thailand and Malaysia, organisations face remediation costs, notification obligations to affected employees, and the reputational cost of a workforce that no longer trusts how its own data is handled.
Building an HR data security foundation across ASEAN
Regulatory detail will keep changing. The underlying discipline HR teams need does not:
- Map your data: know exactly what employee data you hold, where it is stored, which system processes it, and which countryโs law governs it.
- Appoint accountability: designate a Data Protection Officer or equivalent point of accountability, even ahead of a mandatory deadline, and give them real visibility into HR systems.
- Build a breach response plan before you need one: 72-hour notification windows are now standard across the regionโs newer laws, which leaves no time to design a process after an incident occurs.
- Review vendor contracts: confirm your HRIS, payroll and background-screening providers carry explicit data protection clauses, security commitments and breach-notification duties, not implied ones.
- Classify sensitive data: treat biometric, health and national ID data with the highest level of access control and encryption, in line with how regulators are now classifying it.
- Train the people closest to the data: line managers and HR administrators, not just IT and legal, since most exposure happens through everyday handling rather than sophisticated attacks.
Where MiHCM fits in
MiHCM, which is ISO/IEC 27701 certified (the international standard for privacy information management), builds Enterprise HR, payroll and workforce technology for multi-country operations across Asia, and data security sits at the centre of that design rather than as an add-on.
MiHCM Enterprise is built with role-based access control, audit trails and country-specific statutory compliance built into the platform, so HR teams are not left reconciling a single system against a dozen different national rulebooks by hand.
MiA ONE, MiHCMโs personal AI agent, and SmartAssist, its AI HR co-pilot, are designed around the same principle that runs through the regionโs newer laws: human judgement stays central to any decision involving personal data, with AI supporting HR teams rather than acting on their data unsupervised.
For businesses expanding across Malaysia, Thailand, Cambodia, Bangladesh, Sri Lanka, the Maldives and beyond, the practical question is rarely whether to take HR data security seriously. It is whether the systems, contracts and habits already in place would stand up to a regulatorโs questions today.
Every statutory figure, fine and legislative date in this article has been drawn from named regulatory, legal and industry sources current as of mid-2026. Data protection law across ASEAN is moving quickly, several of the laws discussed here (notably in Bangladesh and Cambodia) are still being phased in or finalised, and thresholds, deadlines and penalty amounts can change with little notice. Readers should verify current figures against the official regulator or a qualified local adviser before relying on them for a compliance decision.
References
- Tilleke & Gibbins, โMore Than a Warning: Eight Serious Fines Imposed in Thai Data Protection Casesโ, and Lexology coverage of PDPC enforcement, 2025-2026.
- InCorp Malaysia, โPDPA Compliance Malaysia: Complete Guideโ, 2025.
- Securiti, โAn Overview of Bangladeshโs Personal Data Protection Act, 2026โ; The Daily Star, โBangladeshโs Personal Data Protection Ordinance 2025: key takeawaysโ.
- IBM Security / Ponemon Institute, โCost of a Data Breach Report 2025โ.
- Chambers and Partners, โData Protection & Privacy 2026 โ Malaysiaโ; TSL Legal, โPersonal Data Protection Amendment Act 2024 โ Malaysia Insightsโ.
- InCorp Malaysia, โPDPA Compliance Malaysia: Complete Guideโ, 2025; TSL Legal Malaysia insights, 2026.
- Tilleke & Gibbins and Lexology, PDPC enforcement coverage, August 2025.
- DataGuidance, โBangladeshโ jurisdiction summary, 2026; Recording Law, โBangladesh Data Privacy Lawsโ.
- Recording Law, โBangladesh Data Privacy Laws: The PDPO 2025 and Complete Legal Frameworkโ, 2026.
- DataGuidance, โCambodia: Personal Data Protection Draft Law โ what multinationals need to knowโ, 2025.
- DLA Piper, โData Protection Laws of the World โ Cambodiaโ, 2026.
Sources correct as of July 2026. Verify current statutory figures with the relevant regulator or qualified local counsel before publication or compliance action.