Skip to content

Evidence request lists

Brunei Personal Data Protection Order 2022 (PDPO)

Evidence request list. 31 controls, 31 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Brunei PDPO Part 1-2: Preliminary and Administration

BN-PDPO-s2
Interpretation

Interpretation. Section 2 defines the terms used in the Order (personal data, organisation, data subject/individual, processing, consent, data breach, the Authority and others).

Artefacts an auditor will ask for
  • Mapping of statutory definitions to internal terminology
  • Classification of data as personal data per s2
Where this commonly fails
  • Definitions not applied
  • Personal data not identified
BN-PDPO-s3
Application of Order

Application. Section 3 sets out to whom and what processing the Order applies, including any exclusions and the treatment of public agencies.

Artefacts an auditor will ask for
  • Determination of organisation status and processing in scope
  • Records of processing subject to the Order
Where this commonly fails
  • Processing wrongly scoped out
  • Public-agency treatment misjudged
BN-PDPO-s4
Administration of the Order (the Authority)

Administration. Section 4 designates the Authority (AITI) responsible for administering the Order.

Artefacts an auditor will ask for
  • Recognition of AITI as the data protection authority
  • Engagement records with the Authority
Where this commonly fails
  • Authority role not recognised
  • No engagement with the Authority
BN-PDPO-s5
Functions and duties of the Authority

Functions of the Authority. Section 5 sets out the functions and duties of the Authority, including supervision, guidance and enforcement.

Artefacts an auditor will ask for
  • Responses to Authority guidance and requirements
  • Cooperation with supervision
Where this commonly fails
  • Authority requirements not met
  • No cooperation

Brunei PDPO Part 10-12: Offences, Enforcement and Remedies

BN-PDPO-s31
Unauthorised disclosure of personal data

Unauthorised disclosure. Section 31 makes it an offence for a person to knowingly or recklessly disclose personal data in contravention of the Order.

Artefacts an auditor will ask for
  • Awareness of the s31 offence among staff
  • Controls preventing unauthorised disclosure
Where this commonly fails
  • Staff unaware of the offence
  • No controls against unauthorised disclosure
BN-PDPO-s32
Improper use of personal data

Improper use. Section 32 makes it an offence to make use of personal data to obtain a gain or cause harm in contravention of the Order.

Artefacts an auditor will ask for
  • Awareness of the s32 offence
  • Controls preventing improper use of personal data
Where this commonly fails
  • No controls against improper use
BN-PDPO-s33
Unauthorised re-identification of anonymised information

Re-identification. Section 33 makes it an offence to re-identify anonymised information without authorisation.

Artefacts an auditor will ask for
  • Controls and prohibitions on re-identifying anonymised data
  • Awareness of the s33 offence
Where this commonly fails
  • No controls against re-identification
BN-PDPO-s36
Directions for non-compliance

Directions. Section 36 empowers the Authority to give directions to an organisation to ensure compliance with the Order.

Artefacts an auditor will ask for
  • Records of any Authority directions and compliance
  • Remediation of matters subject to directions
Where this commonly fails
  • Directions not complied with
  • Remediation not tracked
BN-PDPO-s37
Financial penalties

Financial penalties. Section 37 empowers the Authority to impose financial penalties for non-compliance, up to the prescribed limits (including turnover-based caps).

Artefacts an auditor will ask for
  • Awareness of financial-penalty exposure
  • Controls preventing penalised conduct
  • Records of any penalties and remediation
Where this commonly fails
  • Penalty exposure not assessed
  • No controls against infractions
BN-PDPO-s42
Appeal from direction or decision of the Authority

Appeals. Section 42 provides a right of appeal from a direction or decision of the Authority to the Data Protection Appeal Panel/Committee.

Artefacts an auditor will ask for
  • Awareness of appeal rights and the Appeal Panel process
  • Records of any appeals
Where this commonly fails
  • Appeal rights not understood
  • Appeals not tracked
BN-PDPO-s59
Right of private action

Private action. Section 59 gives an individual who suffers loss or damage from a contravention of the Order a right of private action.

Artefacts an auditor will ask for
  • Awareness of private-action exposure
  • Claim-handling records
  • Legal review of contraventions
Where this commonly fails
  • Private-action exposure not assessed
  • Claims not handled

Brunei PDPO Part 3: Accountability

BN-PDPO-s7
Responsibilities of organisation (accountability)

Accountability. Section 7 sets the responsibilities of an organisation for personal data in its possession or control, including designating a data protection officer and developing policies and practices.

Artefacts an auditor will ask for
  • Designation of a data protection officer with contact details
  • Documented data protection policies and practices
  • Responsibility retained for data transferred to processors
Where this commonly fails
  • No DPO designated
  • No documented policies
  • Responsibility for transferred data not retained

Brunei PDPO Part 4: Consent

BN-PDPO-s10
Valid consent

Valid consent. Section 10 sets the conditions for consent to be valid (informed, given by the individual, not obtained through deception or as a condition beyond what is reasonable).

Artefacts an auditor will ask for
  • Evidence consent is informed and freely given
  • Records of consent scope and purpose
Where this commonly fails
  • Consent not valid under s10
  • Consent bundled/coerced
BN-PDPO-s11
Deemed consent

Deemed consent. Section 11 sets the circumstances in which an individual is deemed to consent to the collection, use or disclosure of personal data.

Artefacts an auditor will ask for
  • Documentation of reliance on deemed consent and its basis
  • Assessment that deemed-consent conditions are met
Where this commonly fails
  • Deemed consent asserted without meeting the conditions
  • No documentation
BN-PDPO-s13
Withdrawal of consent

Withdrawal of consent. Section 13 gives individuals the right to withdraw consent and requires organisations to cease the relevant processing.

Artefacts an auditor will ask for
  • Mechanism for individuals to withdraw consent
  • Records of withdrawals actioned and cessation of processing
Where this commonly fails
  • No withdrawal mechanism
  • Withdrawals not actioned
BN-PDPO-s14
Collection, use and disclosure without consent

Without consent. Section 14 sets out the situations in which personal data may be collected, used or disclosed without consent.

Artefacts an auditor will ask for
  • Record of any non-consent ground relied on
  • Necessity assessment for the ground
Where this commonly fails
  • Reliance on a non-consent ground that does not apply
  • Ground not documented
BN-PDPO-s8
Consent required

Consent required. Section 8 requires consent for the collection, use or disclosure of personal data unless otherwise permitted by the Order.

Artefacts an auditor will ask for
  • Consent capture and records
  • Identification of permitted non-consent grounds where relied on
Where this commonly fails
  • Processing without consent or a permitted ground
  • Consent not demonstrable
BN-PDPO-s9
Consent for direct marketing messages

Direct marketing. Section 9 sets the consent requirements for sending direct marketing messages to recipients in Brunei Darussalam.

Artefacts an auditor will ask for
  • Consent/opt-out records for direct marketing
  • Mechanism to honour do-not-contact requests
Where this commonly fails
  • Marketing without a valid basis
  • No opt-out mechanism

Brunei PDPO Part 5-6: Purpose, Notification, Access and Correction

BN-PDPO-s15
Limitation of purpose and extent

Purpose limitation. Section 15 limits the collection, use and disclosure of personal data to purposes a reasonable person would consider appropriate and to the extent necessary.

Artefacts an auditor will ask for
  • Documented purposes for processing
  • Assessment that processing is limited to what is necessary
Where this commonly fails
  • Processing beyond appropriate purposes
  • No purpose documentation
BN-PDPO-s17
Notification of purpose

Notification. Section 17 requires organisations to notify the individual of the purposes for collection, use or disclosure on or before collection.

Artefacts an auditor will ask for
  • Notices stating the purposes at/before collection
  • Process to provide notification
Where this commonly fails
  • No purpose notification
  • Notice incomplete
BN-PDPO-s18
Access to personal data

Right of access. Section 18 gives individuals the right to request access to their personal data and information about its use and disclosure.

Artefacts an auditor will ask for
  • Procedure for handling access requests within statutory timeframes
  • Records of access requests and responses
  • Identity verification
Where this commonly fails
  • Access requests not handled
  • No procedure
  • Timeframes missed
BN-PDPO-s19
Correction of personal data

Right of correction. Section 19 gives individuals the right to request correction of an error or omission in their personal data.

Artefacts an auditor will ask for
  • Procedure for correction requests
  • Records of corrections and propagation to recipients
Where this commonly fails
  • Correction requests not actioned
  • No procedure
BN-PDPO-s20
Exercise of rights on behalf of an individual

Representation. Section 20 sets out how rights under the Order may be exercised on behalf of an individual (e.g. by a person with authority).

Artefacts an auditor will ask for
  • Procedure to verify and handle requests made on behalf of individuals
Where this commonly fails
  • Authorised-representative requests not handled
  • No verification of authority

Brunei PDPO Part 7: Care of Personal Data

BN-PDPO-s21
Accuracy of personal data

Accuracy. Section 21 requires organisations to make a reasonable effort to ensure personal data collected is accurate and complete, where it may be used to make a decision affecting the individual or disclosed.

Artefacts an auditor will ask for
  • Accuracy verification processes
  • Correction of inaccurate data
Where this commonly fails
  • Accuracy not verified
  • Inaccurate data used for decisions
BN-PDPO-s22
Protection of personal data

Protection. Section 22 requires organisations to protect personal data by making reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal.

Artefacts an auditor will ask for
  • Reasonable technical and organisational security arrangements
  • Access controls and protection against unauthorised processing
  • Security proportionate to the data and risk
Where this commonly fails
  • Inadequate security arrangements
  • No access controls
  • Security not documented
BN-PDPO-s23
Retention of personal data

Retention. Section 23 requires organisations to cease retention of personal data when the purpose is no longer served and retention is no longer necessary for legal or business purposes.

Artefacts an auditor will ask for
  • Retention schedule and disposal records
  • Periodic review of data holdings
  • Anonymisation/disposal when purpose served
Where this commonly fails
  • Data retained beyond need
  • No retention schedule
BN-PDPO-s24
Transfer of personal data outside Brunei Darussalam

Cross-border transfer. Section 24 requires that personal data transferred outside Brunei Darussalam receive a standard of protection comparable to that under the Order.

Artefacts an auditor will ask for
  • Inventory of overseas transfers and recipients
  • Comparable-protection measures (contracts, due diligence) for transfers
  • Assessment of the destination's protection
Where this commonly fails
  • Transfers without comparable protection
  • Transfers not inventoried

Brunei PDPO Part 8-9: Data Breach Notification and Public Agency Processors

BN-PDPO-s26
Notifiable data breaches

Notifiable data breaches. Section 26 defines the data breaches that are notifiable (those resulting in or likely to result in significant harm, or of a significant scale).

Artefacts an auditor will ask for
  • Breach assessment criteria for notifiability
  • Breach register
Where this commonly fails
  • Notifiability criteria not defined
  • No breach register
BN-PDPO-s27
Duty to conduct assessment of a data breach

Breach assessment. Section 27 requires organisations to conduct a prompt assessment to determine whether a data breach is notifiable.

Artefacts an auditor will ask for
  • Documented breach-assessment procedure and timelines
  • Records of breach assessments
Where this commonly fails
  • No breach-assessment procedure
  • Assessments not timely
BN-PDPO-s28
Duty to notify a notifiable data breach

Breach notification. Section 28 requires organisations to notify the Authority (and affected individuals where required) of a notifiable data breach within the prescribed time.

Artefacts an auditor will ask for
  • Records of breach notifications to the Authority and affected individuals within required timeframes
  • Notification templates and escalation
Where this commonly fails
  • Notifiable breaches not reported
  • Timeframes missed
  • Affected individuals not notified where required
BN-PDPO-s29
Obligations of a data processor of a public agency

Public-agency processors. Section 29 sets the obligations of organisations acting as data processors for public agencies.

Artefacts an auditor will ask for
  • Contracts governing public-agency processing
  • Compliance with public-agency processor obligations
Where this commonly fails
  • Public-agency processing without compliant arrangements
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Brunei Personal Data Protection Order 2022 (PDPO) framework page.