
Brunei Darussalam has pursued economic diversification and broader job creation under Wawasan Brunei 2035, the national vision formulated in 2007. The country is looking at reducing reliance on oil and gas by expanding non-oil sectors, investment and exports while creating more skilled, higher-value employment opportunities for Bruneians. Nearly two decades later, its core framing still holds. Since 2024, the non-oil and gas sector has represented over half of its GDP, with non-oil and gas exports comprising approximately 60% of total export products.
Announced in 2026, the Digital Brunei 2030 serves as the primary digital-delivery plan under the Wawasan Brunei 2035. Its flagship projects envision a nation that prioritises digital engagement, allowing citizens and businesses to access reliable services, inclusive opportunities, and ongoing innovation. As digital adoption rises, it is crucial to implement effective data governance to ensure that personal data is used responsibly, thereby maintaining public trust. Brunei’s Personal Data Protection Order 2025 establishes a significant framework. It regulates how organisations collect, use, and share personal data. The core operational provisions, which encompass organisational responsibilities, individual rights, security obligations, breach notification, and enforcement, came into effect on 1 January 2026.
These developments set the context for the fourth DFCE 2026. Organised by the Authority for Infocommunications Technology Industry of Brunei Darussalam (AITI), the event was held under the theme “Together toward a Digital Brunei: Innovate, Empower, Transform”. It covered six thematic areas, one of which focused on data protection. TFGI Institute Director, Arifah Sharifuddin, participated in the panel discussion titled “Trust as an enabler: How strong data protection drives innovation”.
Moderators and Panelists
Moderator
- Hafimi Abdul Haadii, Executive Director, LYK Group of Companies, Honorary Consul of New Zealand and former ABAC Member for Brunei
Panelists
- Arifah Sharifuddin, Institute Director, Tech for Good Institute
- Shenny Tang, Head of Growth, Innov8 Labs
- Farah Zainal, Senior Manager, Data Protection Office, AITI
Key takeaways
- Fit-for-purpose regulation enables innovation to scale
Innovation often emerges in regulatory grey areas, but it scales when rules are made fit for purpose. Across Southeast Asia, TFGI’s regional research and stakeholder engagement suggest that it is not merely lighter regulation that fosters innovation. Instead, it is the presence of clear, proportionate, and adaptable rules that give organisations the confidence to invest, experiment and scale. Credible data governance can therefore serve as enabling infrastructure for digital adoption and innovation.
Singapore provides a valuable example. Its Personal Data Protection Act (PDPA) has undergone significant evolution, enhanced by legislative reforms and regulatory guidance. This includes mandatory data breach notification, expanded exceptions to consent and stronger enforcement measures. As the adoption of AI accelerated, the Personal Data Protection Commission (PDPC) issued the Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems in March 2024, instead of introducing a new AI-specific personal data statute. The guidelines provide clarity on the application of the existing PDPA regarding the collection and use of personal data by organisations. These enhancements reflect an effort to keep the framework responsive to technological and business developments while maintaining clear expectations
The broader design principle is important. An effective data protection framework can serve as a stable foundation on which regulators build more targeted guidance as technology evolves, rather than a strict set of rules. This gives organisations greater certainty without requiring the framework to be redesigned each time a new technology emerges.
- The sequencing of regulation and innovation depends on market context.
There may be no single sequence between regulation and innovation. While regulatory grey areas can foster experimentation, certain markets may require clearer regulations first to give businesses and communities the confidence to innovate. An interesting counterpoint emerged during the Brunei discussion, where a speaker described a preference for clear rules before innovation begins, rather than regulation developing alongside it.
Malaysia serves as an example of how that transition can be managed. Rather than implementing all changes to its established Personal Data Protection Act simultaneously, the 2024 amendments allowed different provisions to commence at different times, accompanied by regulatory guidance and consultations. For example, requirements on appointing Data Protection Officers took effect on 1 June 2025, alongside guidance to support implementation. This approach allows organisations the opportunity to understand new responsibilities and build the capabilities needed to comply.
The implication is that regional convergence does not require identical regulatory pathways. Clear legal baselines matter, but so do sequencing, implementation guidance and sufficient time for institutions and businesses to adapt.
- Trust has to become portable
As digital activity increasingly crosses borders, strong domestic data protection frameworks are only the starting point. The next challenge is ensuring that trust can travel with data through interoperable rules, recognised safeguards and stronger regulatory cooperation. The objective is not identical laws across ASEAN, but sufficient alignment and mutual confidence to enable trusted cross-border data flows and allow firms to participate more easily in the regional digital economy.
ASEAN has been building the foundations for this over time. The ASEAN Framework on Digital Data Governance established cross-border data flows as one of the region’s strategic priorities, alongside efforts to strengthen data governance while recognising different levels of national readiness. The ASEAN Model Contractual Clauses for Cross Border Data Flows, introduced in 2021, provide voluntary baseline safeguards that businesses can incorporate into cross-border data-transfer arrangements.
The next step is the ASEAN Digital Economy Framework Agreement (DEFA). ASEAN concluded negotiations in Manila in May 2026 on its first region-wide digital economy agreement, with signing targeted for the 49th ASEAN Summit in November 2026. DEFA therefore represents an important test of whether ASEAN can translate existing regional frameworks into more practical and interoperable arrangements for the movement of data across the region.
