Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134)
Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Governance
Service providers operating in Cambodia must protect personal data of subscribers and users under MPTC oversight.
- Applicability memo
- Service provider register
- Subscriber inventory
- No applicability analysis
- Unclear MPTC registration status
Provide a channel for subscribers to lodge personal data complaints and respond within reasonable time.
- Complaint register
- Response templates
- No public channel
- No closure tracking
Train staff handling personal data on protection obligations and procedures.
- Training records
- Course content
- Attestation logs
- No annual refresher
- Contractors untrained
Submit reports to MPTC on personal data practices when requested.
- MPTC filings
- Audit responses
- No reporting template
- Late filings
Personal data means information identifying or relating to an identifiable natural person held by service providers.
- Data dictionary
- Classification policy
- Field-level inventory
- No formal classification
- Ambiguous identifiers
Non-compliance may result in administrative sanctions, fines or licence action by MPTC.
- Compliance attestations
- Sanction register
- No enforcement tracking
- No remediation plan
Incident Response
Notify MPTC and affected subscribers of incidents impacting personal data.
- IR plan
- Notification templates
- Regulator correspondence
- No MPTC notification process
- Untested IR plan
Privacy
Retain personal data only as long as necessary for the service purpose or as required by law.
- Retention schedule
- Deletion logs
- Indefinite retention
- No deletion automation
Do not disclose personal data to third parties without consent except under lawful authority.
- Disclosure register
- Subpoena log
- Consent records
- Undocumented disclosures
- No subpoena tracking
Cross-border transfers must maintain equivalent protection and subscriber awareness.
- Transfer impact assessment
- Contract clauses
- Hosting locations
- No transfer mapping
- Unknown processor locations
Subscribers have rights to access and correct their personal data held by providers.
- DSAR procedure
- Request log
- Response SLAs
- No formal DSAR process
- Missed SLAs
Collect personal data only for legitimate, specified service purposes with appropriate notice to data subjects.
- Privacy notice
- Collection register
- Purpose statements
- Vague purpose statements
- No notice at collection
Obtain subscriber consent before collecting or using personal data beyond service provision needs.
- Consent records
- Consent UI screenshots
- Withdrawal logs
- Implied consent assumed
- No withdrawal mechanism
Use personal data only for the purpose stated at collection unless additional consent obtained.
- Use-case register
- Secondary use approvals
- Marketing reuse without consent
- No purpose tracking
Collect only personal data necessary for the declared service purpose.
- Field justification log
- Form review records
- Excessive fields
- No field-level review
Maintain accuracy of personal data and provide subscribers means to correct inaccuracies.
- Correction request log
- Self-service portal screenshots
- No correction channel
- Stale records
Security
Destroy personal data securely when retention period ends.
- Destruction certificates
- Wipe logs
- No certificate of destruction
- Reusable media unwiped
Implement technical and organisational measures to protect personal data from unauthorised access, loss or disclosure.
- Security policy
- Access control matrix
- Encryption inventory
- No encryption at rest
- Shared admin accounts
Restrict access to personal data to authorised personnel based on role and necessity.
- RBAC matrix
- Access reviews
- Privileged access logs
- No quarterly review
- Excessive privileges
Third-Party
Service providers remain accountable for personal data processed by contractors and vendors.
- Vendor list
- DPA clauses
- Vendor audits
- No DPA terms
- No vendor risk reviews
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) framework page.