Safeware Glasswall APAC Partner
Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Control alignmentAPAC regulatory landscape
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongolia

More

Trust & certificationsInsightsPartnersAboutDocumentation Book a demo

Language

EnglishBahasa Indonesia日本語한국어Bahasa MelayuไทยTiếng Việt简体中文繁體中文

APAC Compliance Monthly

APAC Compliance Digest: the regulatory year to July 2026

The inaugural edition of our monthly digest of file-security and data-protection regulation across Asia-Pacific. This catch-up issue covers the fourteen developments we tracked and verified across nine territories between January 2025 and July 2026; from August onwards the digest runs monthly.

Reviewed August 2026

Every territory in Asia-Pacific is tightening the rules that govern what happens when a malicious or mishandled file reaches an organisation. The obligations arrive under different names, critical infrastructure codes, privacy amendments, breach-notification regimes, but they share a direction: regulators increasingly expect organisations to show how file-borne risk is controlled, not merely to respond when it is realised.

This inaugural edition catches up on the developments we have tracked, verified against primary sources and published to our country compliance guides since the start of 2025. From next month the digest covers one calendar month at a time.

The headlines

  • Singapore is updating the Cybersecurity Code of Practice for critical information infrastructure to address advanced persistent threats and AI-enabled threats, with changes expected in the later part of 2026.
  • South Korea promulgated a PIPA amendment authorising administrative fines of up to 10% of total revenue in high-severity breach cases, with most provisions taking effect in September 2026.
  • India notified the DPDP Rules 2025, starting a phased 12 to 18 month compliance rollout that includes a 72-hour detailed breach report and at least one year of log retention.

Australia

Consultation opens on SOCI Act reforms (March 2026, consultation). Following the first independent review of the SOCI Act, delivered to Government in January 2026, the Government opened consultation on amendments to the Ministerial Directions powers under Part 3 and to the Critical Infrastructure Risk Management Program Rules. The risk management program rules are the part to watch: they determine what an entity must document about how material risks, including file-borne compromise of data storage systems, are actually mitigated. Source: Minister for Home Affairs.

Ransomware payment reporting in force (May 2025, in force). Ransomware payment reporting rules under the Cyber Security Act 2024 commenced, requiring in-scope entities to report ransomware payments to Government. Ransomware overwhelmingly enters through file-borne delivery, and a reporting obligation raises the cost of a successful document-delivered intrusion from an incident to a disclosure event. Source: ACSC.

Smart device security standards commence (March 2026, in force). Security standards for smart devices supplied to critical infrastructure operators commenced under the Cyber Security Act 2024. Indirect for file security, but relevant to supply-chain assurance: device firmware and configuration bundles are files, and their provenance is increasingly expected to be verifiable. Source: ACSC.

More detail on all three: Australia compliance guide.

India

DPDP Rules 2025 notified (November 2025, in force). The Digital Personal Data Protection Rules 2025 were notified, setting a phased 12 to 18 month compliance rollout including a 72-hour detailed breach report and at least one year of traffic and processing log retention. The explicit retention period tied to breach investigation is a requirement that structured per-file processing records satisfy more cleanly than application logs alone. See the India compliance guide. Source: MeitY.

Japan

Cabinet approves APPI amendment with administrative fines (April 2026, amendment). The Cabinet approved an APPI amendment bill introducing administrative fines, strengthened protections for children's personal data, and new provisions addressing the use of personal data in AI training. Fines change the calculus on file-borne personal data loss: controls that reduce personal data sitting in loose documents move from good practice to risk reduction with a quantifiable value. Source: PPC.

Active Cyber Defense Act passes the Diet (May 2025, comes into effect during 2026). The legislation enables active cyber defence measures structured around public-private collaboration, communications monitoring for threat detection, and government counter-access authority. It signals a shift from guidance-led to statutory cybersecurity obligations in Japan, raising expectations on operators of significant systems to detect and characterise intrusions, including file-borne ones. See the Japan compliance guide. Source: Nippon.com.

Malaysia

PDPA amendments take effect (June 2025, in force). Amendments to Malaysia's Personal Data Protection Act introduced mandatory data protection officer appointments for certain processing activities, mandatory data breach notification, and data portability rights. Breach notification creates an external consequence for personal data lost through documents, which raises the value of reducing what those documents carry. See the Malaysia compliance guide. Source: JPDP.

New Zealand

IPP 3A in force (May 2026, in force). IPP 3A requires agencies to take reasonable steps to notify individuals when their personal information is collected indirectly from a third party, applying to personal information collected on or after 1 May 2026. Organisations receiving bulk personal data from third parties, frequently as documents and spreadsheets, now have a transparency obligation attached to that intake. The Privacy Amendment Act 2025 that introduced it received royal assent in September 2025. See the New Zealand compliance guide. Sources: Bell Gully, New Zealand Legislation.

Singapore

CCoP update to address APT and AI-enabled threats (July 2026, consultation). CSA announced that the Cybersecurity Code of Practice for CII will be updated to address advanced persistent threats and AI-enabled threats, with changes expected to take effect in the later part of 2026. The update covers board accountability with annually reviewed cyber resilience frameworks, Cyber Trust Mark Level 5 certification, oversight of interconnected systems, threat detection deployment, cybersecurity exercise planning, and network monitoring and detection management. A separate Code of Practice for Cloud Services is planned on the same timetable. AI-enabled threats raise the ceiling on file-borne attacks specifically: polymorphic document payloads and machine-generated lures degrade signature and heuristic detection faster than they degrade deterministic rebuild. Source: CSA.

Cybersecurity (Amendment) Act provisions commence (October 2025, in force). Key provisions introduced Part 3A to regulate providers of essential services that do not own the CII they rely on, and extended CSA oversight to cloud service providers and data centre operators. The practical consequence is scope: organisations that assumed the CII control set did not apply because they rent rather than own infrastructure are now potentially in scope, and inherit the Code's content-inspection and retention expectations for files entering the essential-service environment. See the Singapore compliance guide. Source: CSA.

South Korea

Amended PIPA promulgated with revenue-based fines (March 2026, amendment). The PIPA amendment was promulgated as Act No. 21445, authorising administrative fines of up to 10% of total revenue in high-severity breach cases. Most provisions take effect 11 September 2026; mandatory ISMS-P certification provisions take effect 1 July 2027. Revenue-based penalties materially change the business case for reducing personal data held in documents, and the ISMS-P mandate creates a dated deadline for evidencing technical safeguards. See the South Korea compliance guide. Source: Hunton Andrews Kurth.

Taiwan

Personal Data Protection Commission begins operations (August 2025, guidance). Taiwan's PDPC began operations as the sole data protection authority, enforcing and interpreting the Personal Data Protection Act. Consolidated enforcement under a dedicated regulator is expected to raise supervisory consistency, including over technical safeguards for personal data held in documents. See the Taiwan compliance guide. Source: Law.asia.

No published change in the period

Indonesia, Mongolia, the Philippines, Thailand and Vietnam recorded no development that passed our review in this window. Absence of change is itself worth recording: it means the obligations described in each country guide remain current. (Vietnam's Decree 330/2026/ND-CP, published in August 2026, falls in next month's edition.)

What this means for file handling

This closing section is where we map the developments above to the platform we represent; everything before it is regulatory reporting.

Three patterns run through the year. First, regulators are converging on evidence: India's log-retention rule, South Korea's ISMS-P mandate and Australia's risk management program reforms all ask organisations to show, with records, how file-borne risk is handled. A deterministic rebuild control with a per-file verdict record is materially easier to write into a program document, and to evidence at audit, than a detection-tuning posture. Second, AI-enabled threats are now named in regulation, most explicitly in Singapore's CCoP update. AI-generated document payloads and machine-tailored lures degrade signature and heuristic detection considerably faster than they degrade deterministic rebuild, because rebuild does not need to recognise the threat: it removes active content regardless. Third, penalties are moving from fixed to proportional, in Japan and South Korea especially, which changes the business case for reducing the personal data that sits in loose documents in flight and at rest.

How Glasswall CDR addresses each obligation, control by control, is mapped territory by territory in our compliance guides, and our team in Singapore can walk your control set against the codes that apply to you: talk to us.

This digest is assembled from primary regulator and legislative sources; every entry links the source it is drawn from, and regulatory statements follow the cited source rather than our interpretation. It is general information, not legal advice; confirm obligations for your organisation with counsel in the relevant territory. Territory pages with fuller control mappings are linked throughout.

See it against your own files

We will bring the engine, you bring the documents that matter. Contracted, deployed and supported in-region by Safeware.

Talk to us