With the Personal Data Protection Order (PDPO) 2025 coming into force under AITI, Brunei business websites must upgrade their data handling. Here is your practical compliance roadmap.
A New Regulatory Era for Digital Business in Brunei
The enforcement of the Personal Data Protection Order (PDPO 2025) by the Authority for Info-communications Technology Industry of Brunei Darussalam (AITI) marks a pivotal transition for the Sultanate's digital economy. For years, local websites operated with minimal privacy oversight, often gathering visitor phone numbers, emails, and IC information via unencrypted forms or deploying intrusive third-party tracking cookies without user knowledge. Under the PDPO, commercial entities collecting, using, or disclosing personal data must now uphold rigorous statutory standards of transparency, purpose limitation, and data security.
Step 1: Implementing Compliant Cookie Consent (Consent Mode v2)
A passive, decorative banner that simply says 'This site uses cookies' with an OK button is no longer legally sufficient. Under strict privacy frameworks, non-essential tracking cookies — such as Google Analytics marketing beacons or social tracking pixels — must remain blocked by default until the visitor actively gives affirmative consent. Websites must implement Google Consent Mode v2, ensuring that if a user declines non-essential cookies, analytics pings are anonymized and zero identifying tracking markers are stored on the user's browser.
Step 2: Securing Web Forms and Purging Unnecessary Data Fields
Every input field on your website's contact, job application, or quotation form represents legal liability. The principle of Data Minimization requires that businesses only collect personal data strictly necessary for fulfilling the specified purpose. If your inquiry form asks for National Registration Identity Card (NRIC) numbers or personal residential addresses without a clear operational requirement, remove them immediately. Furthermore, form submissions must transmit over TLS 1.3 encryption and incorporate native rate limiting to prevent automated scraping bots from harvesting user inputs.
Step 3: Server Sovereignty and Third-Party Data Leaks
Many common website plugins, themes, and external widget scripts silently siphon visitor browsing metadata to third-party ad networks without business owners realizing it. Under the PDPO, website owners are held accountable for data processors acting on their behalf. Conducting a rigorous Content Security Policy (CSP) audit and hosting all critical fonts, libraries, and assets locally eliminates unauthorized cross-site tracking and guarantees that your visitor data never leaves your verified infrastructure.
Step 4: Publishing Transparent Privacy Policies and Access Channels
Your website must host an easily accessible, plainly written Privacy Policy detailing what information is collected, how it is stored, how long it is retained, and the specific contact details of your designated Data Protection Officer (DPO). Customers have statutory rights to request access to or deletion of their personal information. Having clear internal protocols to respond to such data requests within the statutory timeline ensures your business avoids costly regulatory penalties and earns lasting client trust.
