Brunei Personal Data Protection Order 2022 (PDPO)
Evidence request list. 31 controls, 31 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Brunei PDPO Part 1-2: Preliminary and Administration
Interpretation. Section 2 defines the terms used in the Order (personal data, organisation, data subject/individual, processing, consent, data breach, the Authority and others).
- Mapping of statutory definitions to internal terminology
- Classification of data as personal data per s2
- Definitions not applied
- Personal data not identified
Application. Section 3 sets out to whom and what processing the Order applies, including any exclusions and the treatment of public agencies.
- Determination of organisation status and processing in scope
- Records of processing subject to the Order
- Processing wrongly scoped out
- Public-agency treatment misjudged
Administration. Section 4 designates the Authority (AITI) responsible for administering the Order.
- Recognition of AITI as the data protection authority
- Engagement records with the Authority
- Authority role not recognised
- No engagement with the Authority
Functions of the Authority. Section 5 sets out the functions and duties of the Authority, including supervision, guidance and enforcement.
- Responses to Authority guidance and requirements
- Cooperation with supervision
- Authority requirements not met
- No cooperation
Brunei PDPO Part 10-12: Offences, Enforcement and Remedies
Unauthorised disclosure. Section 31 makes it an offence for a person to knowingly or recklessly disclose personal data in contravention of the Order.
- Awareness of the s31 offence among staff
- Controls preventing unauthorised disclosure
- Staff unaware of the offence
- No controls against unauthorised disclosure
Improper use. Section 32 makes it an offence to make use of personal data to obtain a gain or cause harm in contravention of the Order.
- Awareness of the s32 offence
- Controls preventing improper use of personal data
- No controls against improper use
Re-identification. Section 33 makes it an offence to re-identify anonymised information without authorisation.
- Controls and prohibitions on re-identifying anonymised data
- Awareness of the s33 offence
- No controls against re-identification
Directions. Section 36 empowers the Authority to give directions to an organisation to ensure compliance with the Order.
- Records of any Authority directions and compliance
- Remediation of matters subject to directions
- Directions not complied with
- Remediation not tracked
Financial penalties. Section 37 empowers the Authority to impose financial penalties for non-compliance, up to the prescribed limits (including turnover-based caps).
- Awareness of financial-penalty exposure
- Controls preventing penalised conduct
- Records of any penalties and remediation
- Penalty exposure not assessed
- No controls against infractions
Appeals. Section 42 provides a right of appeal from a direction or decision of the Authority to the Data Protection Appeal Panel/Committee.
- Awareness of appeal rights and the Appeal Panel process
- Records of any appeals
- Appeal rights not understood
- Appeals not tracked
Private action. Section 59 gives an individual who suffers loss or damage from a contravention of the Order a right of private action.
- Awareness of private-action exposure
- Claim-handling records
- Legal review of contraventions
- Private-action exposure not assessed
- Claims not handled
Brunei PDPO Part 3: Accountability
Accountability. Section 7 sets the responsibilities of an organisation for personal data in its possession or control, including designating a data protection officer and developing policies and practices.
- Designation of a data protection officer with contact details
- Documented data protection policies and practices
- Responsibility retained for data transferred to processors
- No DPO designated
- No documented policies
- Responsibility for transferred data not retained
Brunei PDPO Part 4: Consent
Valid consent. Section 10 sets the conditions for consent to be valid (informed, given by the individual, not obtained through deception or as a condition beyond what is reasonable).
- Evidence consent is informed and freely given
- Records of consent scope and purpose
- Consent not valid under s10
- Consent bundled/coerced
Deemed consent. Section 11 sets the circumstances in which an individual is deemed to consent to the collection, use or disclosure of personal data.
- Documentation of reliance on deemed consent and its basis
- Assessment that deemed-consent conditions are met
- Deemed consent asserted without meeting the conditions
- No documentation
Withdrawal of consent. Section 13 gives individuals the right to withdraw consent and requires organisations to cease the relevant processing.
- Mechanism for individuals to withdraw consent
- Records of withdrawals actioned and cessation of processing
- No withdrawal mechanism
- Withdrawals not actioned
Without consent. Section 14 sets out the situations in which personal data may be collected, used or disclosed without consent.
- Record of any non-consent ground relied on
- Necessity assessment for the ground
- Reliance on a non-consent ground that does not apply
- Ground not documented
Consent required. Section 8 requires consent for the collection, use or disclosure of personal data unless otherwise permitted by the Order.
- Consent capture and records
- Identification of permitted non-consent grounds where relied on
- Processing without consent or a permitted ground
- Consent not demonstrable
Direct marketing. Section 9 sets the consent requirements for sending direct marketing messages to recipients in Brunei Darussalam.
- Consent/opt-out records for direct marketing
- Mechanism to honour do-not-contact requests
- Marketing without a valid basis
- No opt-out mechanism
Brunei PDPO Part 5-6: Purpose, Notification, Access and Correction
Purpose limitation. Section 15 limits the collection, use and disclosure of personal data to purposes a reasonable person would consider appropriate and to the extent necessary.
- Documented purposes for processing
- Assessment that processing is limited to what is necessary
- Processing beyond appropriate purposes
- No purpose documentation
Notification. Section 17 requires organisations to notify the individual of the purposes for collection, use or disclosure on or before collection.
- Notices stating the purposes at/before collection
- Process to provide notification
- No purpose notification
- Notice incomplete
Right of access. Section 18 gives individuals the right to request access to their personal data and information about its use and disclosure.
- Procedure for handling access requests within statutory timeframes
- Records of access requests and responses
- Identity verification
- Access requests not handled
- No procedure
- Timeframes missed
Right of correction. Section 19 gives individuals the right to request correction of an error or omission in their personal data.
- Procedure for correction requests
- Records of corrections and propagation to recipients
- Correction requests not actioned
- No procedure
Representation. Section 20 sets out how rights under the Order may be exercised on behalf of an individual (e.g. by a person with authority).
- Procedure to verify and handle requests made on behalf of individuals
- Authorised-representative requests not handled
- No verification of authority
Brunei PDPO Part 7: Care of Personal Data
Accuracy. Section 21 requires organisations to make a reasonable effort to ensure personal data collected is accurate and complete, where it may be used to make a decision affecting the individual or disclosed.
- Accuracy verification processes
- Correction of inaccurate data
- Accuracy not verified
- Inaccurate data used for decisions
Protection. Section 22 requires organisations to protect personal data by making reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal.
- Reasonable technical and organisational security arrangements
- Access controls and protection against unauthorised processing
- Security proportionate to the data and risk
- Inadequate security arrangements
- No access controls
- Security not documented
Retention. Section 23 requires organisations to cease retention of personal data when the purpose is no longer served and retention is no longer necessary for legal or business purposes.
- Retention schedule and disposal records
- Periodic review of data holdings
- Anonymisation/disposal when purpose served
- Data retained beyond need
- No retention schedule
Cross-border transfer. Section 24 requires that personal data transferred outside Brunei Darussalam receive a standard of protection comparable to that under the Order.
- Inventory of overseas transfers and recipients
- Comparable-protection measures (contracts, due diligence) for transfers
- Assessment of the destination's protection
- Transfers without comparable protection
- Transfers not inventoried
Brunei PDPO Part 8-9: Data Breach Notification and Public Agency Processors
Notifiable data breaches. Section 26 defines the data breaches that are notifiable (those resulting in or likely to result in significant harm, or of a significant scale).
- Breach assessment criteria for notifiability
- Breach register
- Notifiability criteria not defined
- No breach register
Breach assessment. Section 27 requires organisations to conduct a prompt assessment to determine whether a data breach is notifiable.
- Documented breach-assessment procedure and timelines
- Records of breach assessments
- No breach-assessment procedure
- Assessments not timely
Breach notification. Section 28 requires organisations to notify the Authority (and affected individuals where required) of a notifiable data breach within the prescribed time.
- Records of breach notifications to the Authority and affected individuals within required timeframes
- Notification templates and escalation
- Notifiable breaches not reported
- Timeframes missed
- Affected individuals not notified where required
Public-agency processors. Section 29 sets the obligations of organisations acting as data processors for public agencies.
- Contracts governing public-agency processing
- Compliance with public-agency processor obligations
- Public-agency processing without compliant arrangements
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Brunei Personal Data Protection Order 2022 (PDPO) framework page.