This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
| 4 minute read

Asia TMT Bulletin– August 2026

The August 2026 edition of our Asia TMT Bulletin captures another busy month across the region, with regulators once again active across data privacy, cybersecurity, intellectual property, artificial intelligence, digital platforms and digital assets. 

I am delighted to have the opportunity to introduce myself in this edition. I joined Linklaters' Dubai office this July to lead the firm's TMT/IP practice across the Middle East, having spent the past several years advising governments, sovereign wealth-backed entities and multinational corporates through the region's rapid shift towards AI adoption, digital infrastructure investment and evolving data protection regimes. That on-the-ground experience across the UAE, KSA and the wider GCC means I understand not only the letter of the region's fast-moving TMT laws, but how they play out in practice for clients navigating them. I look forward to bringing that perspective to future editions of the Bulletin, and to getting to know many of you better in the months ahead.

There is a great deal happening across the region – please do reach out if you would like to discuss any of the developments below or anything else of interest.

As always, we hope you find this edition a useful and timely resource. 

Data Privacy

Singapore: AI-specific notifications now expected for organisations using personal data to train AI models

The Personal Data Protection Commission has issued Guidance for Organisations on Responsible Use of Personal Data in Generative AI. One key new measure is a requirement for organisations to inform consumers when they use personal data to train generative artificial intelligence models. This requirement is intended to mitigate the risk of sensitive personal data being exposed or reconstructed from generative AI models.

UAE: DIFC consults on amended Data Protection Regulations

The Dubai International Financial Centre consulted in July on proposed amendments to its Data Protection Regulations. The amendments aim to strengthen AI safeguards, clarify the Autonomous Systems Officer's role, and introduce a new power for the Commissioner to recognise accreditation and certification schemes. 

Thailand: Proposed amendment to the Thai PDPA

The House of Representatives consulted on a member-proposed draft act amending the Personal Data Protection Act B.E. 2562 (2019). The proposed amendments would exempt state anti-corruption functions, define "state agency", and replace the consent-based rules for processing with GDPR-style lawful bases. The public consultation closed on 15 August.

Thailand: New rules on data subject access requests

The Personal Data Protection Committee published a notification to reform access to, and obtaining copies of, personal data under section 30 of the Personal Data Protection Act B.E. 2562 (2019). From 14 September 2026, controllers must offer at least in-person and postal request channels, verify the identity of the requester within 15 days, and respond within 30 days (extendable by a further 30 days). The notification also provides for fees capped in accordance with a prescribed schedule.

Cybersecurity

Vietnam: Draft Law on Data Security open for public consultation

On 17 July 2026, the National Assembly released the first draft Law on Data Security for public consultation. The draft establishes a data security framework covering data classification, protection measures, and data localisation requirements for cross-border internet service providers. It proposes penalties of up to 5% of revenue in the previous fiscal year for serious violations.

Vietnam: New proposed sanctions for crimes relating to personal data

The draft Amended Criminal Codein respect of which public consultation closed on 16 July 2026, proposes three new offences relating to illegal personal data trading, infringement of personal data, and data protection obstruction. Notably, organisations infringing personal data of 15,000+ individuals or sensitive personal data of 3,000+ individuals may face up to a 5-year business suspension and maximum fines of VND10 billion (c. USD380,000).

Hong Kong: SFC mandates phishing-resistant authentication for online brokers and crypto platforms

The SFC has directed internet brokers and virtual asset trading platforms to replace one-time passwords with phishing-resistant authentication (e.g. passkeys or bound devices) for client login and device binding by 8 July 2027. Large brokers are expected to implement these measures “immediately”.

Digital Platform Services

China: Consultation on draft amendments to the E-Commerce Law

China’s State Administration for Market Regulation and Ministry of Commerce have released a draft amendment to the E-Commerce Law for public consultation, introducing tiered platform supervision, turnover-based fines up to 5% of annual revenue, extraterritorial application, and countermeasure provisions. The existing regulation captures entities that provide online business premises, transaction matching and information publication. The draft amendment proposes adding “order generation” to the scope of the regulation, which could capture livestream e-commerce and on-demand retail businesses.

Singapore: Consultation on the Digital Infrastructure Bill 

Singapore's Ministry of Digital Development and Information and the Infocomm Media Development Authority consulted on the draft Digital Infrastructure Bill. The Bill introduces licensing regimes for major data centre and cloud computing service providers, requiring them to maintain an adequate level of security and resilience. It also imposes mandatory baseline environmental sustainability standards and notification requirements in the event of cybersecurity incidents or service delivery disruptions.

Artificial Intelligence

China: Consultation on national AI application security classification and grading standard

China’s National Cybersecurity Standardisation Technical Committee (TC260) has released for public consultation a draft national standard classifying AI application security risks by scenario, task and capability, and grading each risk on a five-tier framework based on severity and likelihood.

Thailand: Consultation on draft Artificial Intelligence Act 

The Electronic Transaction Development Agency held a consultation on the draft Act on Artificial Intelligence, which would apply extraterritorially and introduce prohibited AI practices, sector-led regulation of high-risk systems, transparency and labelling duties for AI-generated content, and a local representative requirement.

Australia: Government announces National Artificial Intelligence Framework and Office of Artificial Intelligence (August 2026)

The Australian Government has established the Office of Artificial Intelligence, effective from 15 July 2026, to coordinate Australia's AI policy and standards, and announced a National Artificial Intelligence Framework. The framework will include requirements for large AI data centres relating to location, water consumption, energy efficiency and infrastructure obligations, alongside measures to streamline and fast-track approvals for data centre projects.

Digital Assets

Vietnam: Decree on administrative sanctions on crypto-assets and the crypto-asset market is officially issued

On 16 July 2026, the Government issued Decree 284/2026/ND-CP on administrative sanctions regarding crypto-assets and the crypto-asset market, effective from 1 September 2026. The Decree sets out sanctions relating to illegal offering, issuance, trading and operation of crypto-assets, including cancellation of illegal offerings and clawback of offering proceeds.

To stay up to date with the latest tech developments - subscribe now!

Tags

ai, data and cyber, ip, online safety