The September 2026 edition of our Asia TMT Bulletin reflects another active month across the region, with developments spanning data privacy, cybersecurity, intellectual property, artificial intelligence, and digital assets.
Australia has released an exposure draft of significant Privacy Act reforms for public consultation, whilst Vietnam has issued a raft of new decrees overhauling its cybersecurity and personal data protection framework. China has proposed draft data protection rules targeting large-scale personal information handlers processing data on more than 10 million individuals and has also published its first AI large model trade secret case, recognising prompt templates and annotation standards as protectable technology secrets. In the AI space, Singapore has amended its Penal Code to criminalise the production of AI-generated intimate images without consent, Hong Kong's PCPD has issued formal guidelines on agentic AI, and Hong Kong's financial regulators have selected their first cohort of agentic AI use cases for the GenAI Sandbox++.
Data Privacy
Australia: Proposed reforms to the Privacy Act released for consultation
The Australian Government has released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (Cth) for public consultation, with submissions due by 18 September 2026. The Bill proposes significant reforms to the Privacy Act 1988 (Cth), including the introduction of a new fair and reasonable handling test, strengthened consent and data security requirements, revised direct marketing rules, updated definitions, and a limited right to erasure applicable to large digital platforms.
Vietnam: Decree on administrative sanctions on cybersecurity and personal data protection is officially issued
On 19 August 2026, the Government issued Decree 330/2026/ND-CP on administrative sanctions on cybersecurity and personal data protection, effective immediately. The Decree completes the Vietnamese personal data protection framework with the sanctioning mechanism. While the maximum cybersecurity fine is VND200 million (approx. USD7,720), serious cross-border personal data transfer violations may attract fines of up to 5% of the violator's preceding year's revenue.
China: Draft data protection rules for large personal information handlers
The Cyberspace Administration of China has released for public consultation draft rules for processors of personal information of over 10 million individuals, imposing requirements such as data localisation, appointment of a management-level protection officer and establishment of a supervisory committee. The consultation closed 7 September 2026.
Cybersecurity
KSA: NCA consults on draft AI Cybersecurity Guidelines
Saudi Arabia's National Cybersecurity Authority consulted on the draft AI Cybersecurity Guidelines, proposing governance, defensive control, resilience and third-party risk requirements for AI systems within its mandate. The consultation closed 5 August 2026.
Vietnam: Decree on preventing infringement of national security, public order, and social safety in cyberspace officially issued
On 19 August 2026, the Government issued Decree 327/2026/ND-CP, effective immediately. The Decree outlines measures for preventing and handling unlawful dissemination of information and conduct in cyberspace, detailing the responsibilities of service providers and information system managers, including implementing electronic identification, cybersecurity warnings, and reporting cyberattacks within 24 hours, among others.
Vietnam: New decree on preventing and combating fake news and false information
On 19 August 2026, the Government issued Decree 328/2026/ND-CP on preventing and combating fake news and false information, effective from 5 October 2026. The Decree classifies types of fake news and false information, and sets out prevention mechanisms and the relevant responsibilities of local and foreign entities in Vietnam.
Vietnam: New framework for licensing of businesses dealing in cybersecurity products and services
On 19 August 2026, the Government issued Decree 332/2026/ND-CP on business activities related to cybersecurity products and services, effective immediately. The Decree regulates the conditions attached to issuance and maintenance of business licenses regarding the trading, import, and export of cybersecurity products and cybersecurity services, such as network security inspection, consulting, and data recovery, among others.
Vietnam: Cybersecurity law implementation measures officially issued
On 19 August 2026, the Government issued Decree 333/2026/ND-CP detailing implementation measures of the Law on Cybersecurity, effective immediately. The Decree prescribes procedures and authority for key cybersecurity measures, including assessment, inspection, monitoring, incident response, removal of illegal content, electronic data collection, and suspension or revocation of information systems and domain names.
Intellectual Property
China: First trade secret case involving an AI vertical large model
China's State Administration for Market Regulation has published the first AI large model trade secret case, recognising prompt templates, review rules and annotation standards as an integrated technology trade secret, thus extending trade secret protections beyond just protecting the source code.
Digital Platform Services
Australia: eSafety accepts court-enforceable undertaking from Roblox
Australia's eSafety Commissioner has accepted a court-enforceable undertaking from Roblox, the U.S. gaming platform, following concerns it was not meeting obligations under the Online Safety Act's codes and standards, including allegedly failing to prevent contact between adults and children under 16. Roblox has three months to make under-16 accounts private by default, restrict adult contact without parental consent, and appoint an independent auditor.
Artificial Intelligence
Singapore: Penal Code amended to criminalise AI-generated intimate images without consent
From 17 August, Singapore's Penal Code was amended to, among other amendments, criminalise the production of intimate images without consent. Prohibited images include synthetic AI-generated material that depict a person without altering an original image or recording. The crime is punishable by up to two years' imprisonment and/or a fine. Where the material depicts a minor below 14 years of age, mandatory imprisonment of up to two years applies, with the offender also liable to a fine or caning.
Singapore: MinLaw and IPOS are consulting on AI’s impact on Singapore’s IP regime
The Ministry of Law Singapore and the Intellectual Property Office of Singapore are consulting (until 22 October 2026) on AI’s impact on Singapore’s intellectual property regime, covering copyright questions around greater certainty and accountability in AI training, copyright risk management in AI deployment and use and the nature of human creativity in AI-assisted works, and patent questions around how inventorship principles should apply to human-AI interactions in the inventive process and how the large-scale publication of AI-generated technical disclosures may affect prior art.
Hong Kong: PCPD issues agentic AI guidelines
On 25 August 2026, the PCPD published formal guidelines on protecting personal data privacy in the use of agentic AI, setting out 9 recommendations covering data minimisation, transparency, accuracy, retention, purpose limitation, security, data subject rights, risk assessment and governance. Read more.
Hong Kong: Regulators select first cohort for GenAI Sandbox++
Hong Kong's financial regulators have selected 36 agentic AI use cases for the first cohort of the GenAI Sandbox++, spanning customer onboarding, payments, insurance claims and customer interactions. Participating institutions will receive supervisory guidance and technical support to test and develop their solutions in the controlled sandbox environment.
Digital Assets
Thailand: SEC consults on draft regulations for crypto ETFs
Thailand's Securities and Exchange Commission is consulting (until 20 September 2026) on 11 draft notifications permitting crypto exchange traded funds. These would apply to passive funds, initially limited to Bitcoin and Ethereum, with assets generally held by a Thai-licensed digital asset custodian.
Thailand: SEC issues notification on risk management for digital asset transfers
The SEC has issued Notification No. Sor Thor. 9/2569, effective 27 February 2027, requiring licensed digital asset operators to adopt board-approved transfer controls, transmit prescribed originator and beneficiary information, screen wallets and sanctions lists, and retain records for five years.

/Passle/5c4b4157989b6f1634166cf2/MediaLibrary/Images/2026-07-01-10-05-52-711-6a44e6804d141be5967eb61e.jpg)


/Passle/5c4b4157989b6f1634166cf2/MediaLibrary/Images/2026-02-10-09-26-10-525-698af9b2b876970f0dcaea7f.jpg)
