EngageMedia DRONEDRONE
Digital Rights Oversight& Network Evaluator
Data & AI Governance
Digital Trade Agreements
Platform Accountability
Observatory
EngageMediaEngageMedia

DRONE — Digital Rights Oversight & Network Evaluator is an independent policy intelligence platform developed by EngageMedia. It monitors ASEAN digital trade frameworks, legal scrubbing, cross-border data transfer laws, and algorithmic governance threats.

Maintained by: EngageMedia Research Team

Research Modules

  • Data & AI Governance
  • Digital Trade Agreements
  • Platform Accountability
  • Jurisdiction Observatory
  • Verified Policy Ledger
  • Curated Knowledge Hub
  • Encrypted Leaks Portal

EngageMedia Network

  • EngageMedia Official Site

    Open and secure digital technologies, media, and human rights across Asia-Pacific

  • DRAPAC Network

    Digital Rights Asia-Pacific Assembly & Regional Movement Building

© 2026 EngageMedia • DRONE Project • Released under CC BY 4.0 Human Rights License.
EngageMedia DRONEDRONE
Digital Rights Oversight& Network Evaluator
Data & AI Governance
Digital Trade Agreements
Platform Accountability
Observatory
OverviewAI Ethics & AccountabilityCross-Border Data FlowsEncryption & PrivacyTech Sovereignty & Compute

Encryption & Privacy Safeguards

Can citizens freely encrypt their communications? This observatory tracks government efforts to weaken, restrict, or ban encryption across Southeast Asia — from VPN criminalization and backdoor mandates to positive capacity building. Red events signal high-impact restrictions (severity ≥ 70); green events signal capacity building and cooperative developments.
High Severity7 Events
Countries8 Tracked
Core Concepts & Regulatory Dimensions
VPN BanGovernment criminalizes or restricts VPN usage for citizens.
Backdoor MandateCompanies forced to build decryption access for authorities.
Key EscrowEncryption keys must be deposited with the government.
Intercept ExpansionLawful intercept powers expanded to cover more services.
E2EE RestrictionEnd-to-end encryption limited or weakened by regulation.
Capacity BuildingPositive: training, standards, and cooperative security efforts.
Reading Guidance: Each event is scored from 0–100 severity. Red dots (≥70) represent severe restrictions; orange dots (40–69) represent moderate concern; green dots (<40) represent positive or low-impact developments. The summary stats above the event list show per-country averages.
MM
94
Myanmar
3 events
VN
80
Vietnam
3 events
KH
75
Cambodia
1 event
TH
60
Thailand
1 event
ID
58
Indonesia
2 events
PH
25
Philippines
1 event
MY
10
Malaysia
1 event
SG
5
Singapore
1 event

Encryption Regulation & Interventions Timeline

Chronological vertical log of encryption policies, VPN restrictions, backdoor requirements, lawful intercept expansions, and cybersecurity capacity building across ASEAN.

Country:
Event Type:
Vietnam (VN)End-to-End Encryption Restriction
Nov 28, 2025

Draft AI Law Proposes Algorithmic Audit Mandates

Proposed AI governance framework would require foreign AI and encryption service providers to submit algorithms for government review and audit, potentially weakening end-to-end encryption implementations.

Risk Meter
75/100
Official Document
Malaysia (MY)Cybersecurity Capacity Building
Jun 15, 2025

NACSA Launches National Encryption Standards Framework

National Cyber Security Agency publishes voluntary encryption standards for critical infrastructure sectors, emphasizing AES-256 and post-quantum readiness without backdoor requirements.

Risk Meter
10/100
Official Document
Philippines (PH)Cybersecurity Capacity Building
Feb 14, 2025

CICC Partners with Interpol on Cybercrime Capacity Building

Cybercrime Investigation and Coordinating Center partners with Interpol to enhance cyber forensics and encryption analysis capabilities for law enforcement.

Risk Meter
25/100
Official Document
Singapore (SG)Cybersecurity Capacity Building
Oct 1, 2024

ASEAN-Singapore Cybersecurity Centre of Excellence Launched

Singapore commits S$30M to establish ASEAN cybersecurity capacity building centre, providing training on encryption standards, threat intelligence sharing, and incident response.

Risk Meter
5/100
Official Document
Indonesia (ID)Lawful Intercept Expansion
May 15, 2024

MR5 Mandates 24-Hour Content Removal and Access

Ministerial Regulation 5 requires private electronic system operators to provide access to systems and data within 24 hours for emergency compliance requests from Kominfo.

Risk Meter
65/100
Official Document
Myanmar (MM)VPN Ban / Criminalization
Mar 15, 2024

Draft Cybersecurity Law Criminalizes VPN Usage

Military junta proposes amendments mandating ISP packet inspection and criminalizing VPN usage without prior military administrative clearance. Penalties include imprisonment.

Risk Meter
95/100
Official Document
Myanmar (MM)Lawful Intercept Expansion
Feb 20, 2024

Warrantless Access to Telecommunication Logs Mandated

Draft law grants military authorities unrestricted warrantless access to all telecommunication logs and user data.

Risk Meter
98/100
Official Document
Indonesia (ID)Encryption Backdoor Mandate
Nov 10, 2023

BSSN National Cryptography Standards Push

National Cyber and Crypto Agency (BSSN) promotes mandatory use of national cryptographic standards (SNI cryptography) for government systems, raising concerns about potential backdoor requirements.

Risk Meter
50/100
Official Document
Thailand (TH)Lawful Intercept Expansion
Aug 30, 2023

Computer Crime Act Amendments Expand Surveillance Powers

Amendments to Computer Crime Act expand authorities' power to compel ISPs to provide user data and traffic logs without judicial warrant in 'emergency' situations.

Risk Meter
60/100
Official Document
Myanmar (MM)Encryption Backdoor Mandate
Jun 10, 2023

ISP Packet Inspection Infrastructure Deployed

State-owned MPT has deployed deep packet inspection equipment from Chinese vendors enabling real-time traffic monitoring and interception.

Risk Meter
90/100
Official Document
Vietnam (VN)Key Escrow Requirement
Oct 1, 2022

Decree 53 Mandates Data Access for Authorities

Decree 53/2022/ND-CP requires foreign tech firms to store user data locally and provide access to authorities upon request, effectively mandating key escrow for law enforcement access.

Risk Meter
80/100
Official Document
Cambodia (KH)Lawful Intercept Expansion
Feb 16, 2022

National Internet Gateway Enables Centralized Monitoring

NIG sub-decree routes all international internet traffic through state-controlled gateway, enabling centralized monitoring and potential interception of all cross-border communications.

Risk Meter
75/100
Official Document
Vietnam (VN)Encryption Backdoor Mandate
Jan 1, 2019

Cybersecurity Law Requires Decryption Capability

Law No. 24/2018/QH14 requires telecommunications and internet service providers to provide decryption capabilities to competent state agencies when requested.

Risk Meter
85/100
Official Document
EngageMediaEngageMedia

DRONE — Digital Rights Oversight & Network Evaluator is an independent policy intelligence platform developed by EngageMedia. It monitors ASEAN digital trade frameworks, legal scrubbing, cross-border data transfer laws, and algorithmic governance threats.

Maintained by: EngageMedia Research Team

Research Modules

  • Data & AI Governance
  • Digital Trade Agreements
  • Platform Accountability
  • Jurisdiction Observatory
  • Verified Policy Ledger
  • Curated Knowledge Hub
  • Encrypted Leaks Portal

EngageMedia Network

  • EngageMedia Official Site

    Open and secure digital technologies, media, and human rights across Asia-Pacific

  • DRAPAC Network

    Digital Rights Asia-Pacific Assembly & Regional Movement Building

© 2026 EngageMedia • DRONE Project • Released under CC BY 4.0 Human Rights License.