APAC regulatory landscape
File security and audit obligations across APAC
What each APAC territory requires of organisations handling untrusted files, the instruments, the regulators and the dated developments.
Covering 13 territories across Southeast Asia, Oceania, East Asia and South Asia.
Coverage
13
territories covered
29
instruments mapped
18
dated developments
28
regulators cited
Latest across the region
What changed recently
The most recent developments across the region.
-
CCoP for CII to be updated to address APT and AI-enabled threats
CSA announced that the Cybersecurity Code of Practice for CII will be updated to address advanced persistent threats and AI-enabled threats, with changes expected to take effect in the later part of 2026. The update covers board accountability with annually reviewed cyber resilience frameworks, Cyber Trust Mark Level 5 certification, oversight of interconnected systems, threat detection deployment, cybersecurity exercise planning, and network monitoring and detection management. A separate Code of Practice for Cloud Services is planned on the same timetable.
Why it matters for file security. AI-enabled threats raise the ceiling on file-borne attacks specifically: polymorphic document payloads and machine-generated lures degrade signature and heuristic detection faster than they degrade deterministic rebuild. CII owners reviewing their control set against the updated Code should expect content-inspection and known-good reconstruction to be scrutinised more closely than detection tuning.
How Glasswall addresses it
This is the development most worth acting on ahead of the Code landing. AI-generated document payloads and machine-tailored lures degrade signature and heuristic detection considerably faster than they degrade deterministic rebuild, because rebuild does not need to recognise the threat, it removes the active content regardless. CII owners revisiting their control set before the updated Code takes effect should expect content inspection and known-good reconstruction to attract more scrutiny than detection tuning. Macro intelligence covers the Office macro surface specifically, and Large Archive reaches the container formats inline scanning cannot open.
Content Disarm and ReconstructionMacro intelligenceLarge ArchiveGlasswall Halo / Glasswall Meteor
- cii
- government
- banking
- healthcare
- telco
- energy
- transport
-
IPP 3A indirect collection transparency obligation comes into force
IPP 3A took effect, requiring agencies to take reasonable steps to notify individuals when their personal information is collected indirectly from a third party. It applies only to personal information collected on or after this date.
Why it matters for file security. Organisations receiving bulk personal data from third parties, frequently as documents and spreadsheets, now have a transparency obligation attached to that intake.
- banking
- telco
- healthcare
- education
-
Cabinet approves APPI amendment introducing administrative fines
The Cabinet approved an APPI amendment bill introducing administrative fines, strengthened protections for children's personal data, and new provisions addressing the use of personal data in AI training.
Why it matters for file security. Administrative fines change the calculus on file-borne personal data loss. Controls that reduce personal data sitting in loose documents move from good practice to risk reduction with a quantifiable value.
How Glasswall addresses it
Reducing the personal data carried in documents lowers the exposure that an administrative fine would be calculated against. Find & Redact addresses documents in flight; Storage Monitor addresses the existing estate at rest.
Find & RedactStorage Monitor + SM AuditGlasswall Halo
- banking
- healthcare
- telco
- education
-
Consultation opens on SOCI Act Ministerial Directions and risk management reforms
Following the first independent review of the SOCI Act delivered on 31 January 2026, the Government opened consultation on amendments to the Ministerial Directions powers under Part 3 and to the Critical Infrastructure Risk Management Program Rules.
Why it matters for file security. Changes to the risk management program rules are the part to watch: they determine what an entity must document about how material risks, including file-borne compromise of data storage systems, are actually mitigated.
How Glasswall addresses it
Entities revisiting their risk management program during this consultation should expect to describe file-handling mitigations more explicitly than before. A deterministic rebuild control plus a per-file verdict record is materially easier to write into a program document than a detection-tuning posture.
Content Disarm and ReconstructionPer-file verdict recordGlasswall Halo / Glasswall Meteor
- cii
- energy
- telco
- transport
- banking
- healthcare
-
Amended PIPA promulgated with revenue-based fines and mandatory ISMS-P
The PIPA amendment was promulgated as Act No. 21445, authorising administrative fines of up to 10% of total revenue in high-severity breach cases. Most provisions take effect 11 September 2026; mandatory ISMS-P certification provisions take effect 1 July 2027.
Why it matters for file security. Revenue-based penalties materially change the business case for reducing personal data held in documents, and the ISMS-P mandate creates a dated deadline for evidencing technical safeguards.
How Glasswall addresses it
Two dated deadlines to plan against: September 2026 for the penalty regime and July 2027 for ISMS-P certification. Reducing personal data in documents addresses the first; documented deterministic file handling with a per-file verdict record addresses the second.
Find & RedactContent Disarm and ReconstructionPer-file verdict recordGlasswall Halo
- banking
- healthcare
- telco
- education
-
Mandatory smart device security standards take effect
Security standards for smart devices supplied to critical infrastructure operators commenced under the Cyber Security Act 2024.
Why it matters for file security. Indirect for file security, but relevant to supply-chain assurance: device firmware and configuration bundles are files, and their provenance is increasingly expected to be verifiable.
How Glasswall addresses it
Signature Verify checks file signatures against a managed site list on a any-deny-wins basis, which is the relevant control where firmware or configuration bundles arrive from a supplier and provenance has to be established before use.
Signature VerifyGlasswall Halo
- cii
- manufacturing
- energy
-
First independent review of the SOCI Act delivered
The first independent review of the Security of Critical Infrastructure Act was delivered to Government, forming the basis for the reform consultation opened in March 2026.
Why it matters for file security. Sets the direction for the next round of obligations on critical infrastructure entities, including how prescriptively risk management programs must describe technical controls.
- cii
-
DPDP Rules 2025 notified with phased compliance rollout
The Digital Personal Data Protection Rules 2025 were notified, setting a phased 12- to 18-month compliance rollout including a 72-hour detailed breach report and at least one year of traffic and processing log retention.
Why it matters for file security. Establishes dated compliance milestones and, importantly, an explicit log retention period tied to breach investigation, a requirement that structured per-file processing records satisfy more cleanly than application logs alone.
How Glasswall addresses it
Organisations mapping their DPDP log-retention obligation should account for file-processing evidence, not just application and network logs. The per-file verdict record is exportable to whatever retention tier the Rules require.
Per-file verdict recordFind & RedactGlasswall Halo
- banking
- telco
- healthcare
- education
Southeast Asia
Southeast Asia territories
5 instruments · 3 developments
Singapore
Sector-designated CII regime under a statutory code of practice
1 instrument · 1 development
Indonesia
Comprehensive data protection statute; supervisory authority not yet established
2 instruments · 2 developments
Malaysia
Licensed NCII regime under the Cyber Security Act 2024
1 instrument · 1 development
Philippines
Data Privacy Act with an active regulator issuing binding circulars
1 instrument · 0 developments
Thailand
GDPR-modelled data protection statute with an established regulator
2 instruments · 0 developments
Vietnam
Cybersecurity Law with localisation expectations plus a personal data protection decree
East Asia
East Asia territories
3 instruments · 2 developments
Japan
Economic security statute for ~250 critical operators, plus new active cyber defence law
2 instruments · 1 development
South Korea
Prescriptive privacy statute with mandatory security certification (ISMS-P)
1 instrument · 0 developments
Mongolia
Cyber security and personal data protection laws enacted 2021
1 instrument · 1 development
Taiwan
Cybersecurity Management Act for public sector plus a newly operational privacy regulator
South Asia
South Asia territories
Scope
About these pages
These pages are a working reference, not legal advice, obligations depend on designation, sector and architecture, so take local advice before relying on them for a compliance decision. Where a page describes how Glasswall relates to an obligation, it describes a control, not a certification.