Skip to content

Evidence request lists

Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134)

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Governance

SD134-1
Scope and Application

Service providers operating in Cambodia must protect personal data of subscribers and users under MPTC oversight.

Artefacts an auditor will ask for
  • Applicability memo
  • Service provider register
  • Subscriber inventory
Where this commonly fails
  • No applicability analysis
  • Unclear MPTC registration status
SD134-16
Complaint Handling

Provide a channel for subscribers to lodge personal data complaints and respond within reasonable time.

Artefacts an auditor will ask for
  • Complaint register
  • Response templates
Where this commonly fails
  • No public channel
  • No closure tracking
SD134-18
Training and Awareness

Train staff handling personal data on protection obligations and procedures.

Artefacts an auditor will ask for
  • Training records
  • Course content
  • Attestation logs
Where this commonly fails
  • No annual refresher
  • Contractors untrained
SD134-19
MPTC Reporting

Submit reports to MPTC on personal data practices when requested.

Artefacts an auditor will ask for
  • MPTC filings
  • Audit responses
Where this commonly fails
  • No reporting template
  • Late filings
SD134-2
Definitions of Personal Data

Personal data means information identifying or relating to an identifiable natural person held by service providers.

Artefacts an auditor will ask for
  • Data dictionary
  • Classification policy
  • Field-level inventory
Where this commonly fails
  • No formal classification
  • Ambiguous identifiers
SD134-20
Penalties and Enforcement

Non-compliance may result in administrative sanctions, fines or licence action by MPTC.

Artefacts an auditor will ask for
  • Compliance attestations
  • Sanction register
Where this commonly fails
  • No enforcement tracking
  • No remediation plan

Incident Response

SD134-17
Incident Notification

Notify MPTC and affected subscribers of incidents impacting personal data.

Artefacts an auditor will ask for
  • IR plan
  • Notification templates
  • Regulator correspondence
Where this commonly fails
  • No MPTC notification process
  • Untested IR plan

Privacy

SD134-10
Retention Limitation

Retain personal data only as long as necessary for the service purpose or as required by law.

Artefacts an auditor will ask for
  • Retention schedule
  • Deletion logs
Where this commonly fails
  • Indefinite retention
  • No deletion automation
SD134-12
Third-Party Disclosure

Do not disclose personal data to third parties without consent except under lawful authority.

Artefacts an auditor will ask for
  • Disclosure register
  • Subpoena log
  • Consent records
Where this commonly fails
  • Undocumented disclosures
  • No subpoena tracking
SD134-13
Cross-Border Transfer

Cross-border transfers must maintain equivalent protection and subscriber awareness.

Artefacts an auditor will ask for
  • Transfer impact assessment
  • Contract clauses
  • Hosting locations
Where this commonly fails
  • No transfer mapping
  • Unknown processor locations
SD134-15
Subscriber Rights

Subscribers have rights to access and correct their personal data held by providers.

Artefacts an auditor will ask for
  • DSAR procedure
  • Request log
  • Response SLAs
Where this commonly fails
  • No formal DSAR process
  • Missed SLAs
SD134-3
Lawful Collection

Collect personal data only for legitimate, specified service purposes with appropriate notice to data subjects.

Artefacts an auditor will ask for
  • Privacy notice
  • Collection register
  • Purpose statements
Where this commonly fails
  • Vague purpose statements
  • No notice at collection
SD134-4
Consent Requirements

Obtain subscriber consent before collecting or using personal data beyond service provision needs.

Artefacts an auditor will ask for
  • Consent records
  • Consent UI screenshots
  • Withdrawal logs
Where this commonly fails
  • Implied consent assumed
  • No withdrawal mechanism
SD134-5
Purpose Limitation

Use personal data only for the purpose stated at collection unless additional consent obtained.

Artefacts an auditor will ask for
  • Use-case register
  • Secondary use approvals
Where this commonly fails
  • Marketing reuse without consent
  • No purpose tracking
SD134-6
Data Minimisation

Collect only personal data necessary for the declared service purpose.

Artefacts an auditor will ask for
  • Field justification log
  • Form review records
Where this commonly fails
  • Excessive fields
  • No field-level review
SD134-7
Accuracy and Quality

Maintain accuracy of personal data and provide subscribers means to correct inaccuracies.

Artefacts an auditor will ask for
  • Correction request log
  • Self-service portal screenshots
Where this commonly fails
  • No correction channel
  • Stale records

Security

SD134-11
Secure Disposal

Destroy personal data securely when retention period ends.

Artefacts an auditor will ask for
  • Destruction certificates
  • Wipe logs
Where this commonly fails
  • No certificate of destruction
  • Reusable media unwiped
SD134-8
Security Safeguards

Implement technical and organisational measures to protect personal data from unauthorised access, loss or disclosure.

Artefacts an auditor will ask for
  • Security policy
  • Access control matrix
  • Encryption inventory
Where this commonly fails
  • No encryption at rest
  • Shared admin accounts
SD134-9
Access Control

Restrict access to personal data to authorised personnel based on role and necessity.

Artefacts an auditor will ask for
  • RBAC matrix
  • Access reviews
  • Privileged access logs
Where this commonly fails
  • No quarterly review
  • Excessive privileges

Third-Party

SD134-14
Processor Oversight

Service providers remain accountable for personal data processed by contractors and vendors.

Artefacts an auditor will ask for
  • Vendor list
  • DPA clauses
  • Vendor audits
Where this commonly fails
  • No DPA terms
  • No vendor risk reviews
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) framework page.