Support for the paperwork privacy law asks for.
Privacy laws across ASEAN and the EU ask similar questions: what do you collect, why, where does it go, and can you show it? Our tools and services help you answer them.
Six regimes, one approach
| Where | Law | What it asks (in short) | Where Minimo helps |
|---|---|---|---|
| Malaysia | Personal Data Protection Act 2010 (amended 2024) | Seven principles: general, notice and choice, disclosure, security, retention, data integrity, access. The 2024 amendments add duties such as breach notification and appointing a data protection officer in some cases. | On-device processing limits disclosure and transfer. Redaction reduces the personal data you keep. |
| Singapore | Personal Data Protection Act 2012 | Consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, breach notification, accountability (a designated DPO). | Redaction supports retention limitation. On-device use avoids cross-border transfer. Policy review supports notification. |
| Thailand | Personal Data Protection Act B.E. 2562 (2019) | Lawful basis or consent, data-subject rights, security measures, conditions for transferring data abroad, breach notification, and a DPO where required. | On-device use avoids overseas transfer. Policy review checks that notices are complete. |
| EU | GDPR | Data minimisation and storage limitation (Art. 5), privacy by design (Art. 25), processor contracts (Art. 28), records of processing (Art. 30), security (Art. 32), breach notification (Art. 33), transfers (Chapter V). | Privacy-by-design architecture. Sample record-keeping outputs. A processor relationship only where we host data. |
| Indonesia | Personal Data Protection Law (Law No. 27 of 2022) | Fully enforceable since October 2024. Lawful basis, data-subject rights, a DPO in certain cases, breach notification, and conditions for cross-border transfers. | On-device processing and redaction reduce exposure. Advisory for local requirements. |
| Vietnam | Decree 13/2023 and the Personal Data Protection Law | Consent, processing impact assessments, rules for sensitive data, and cross-border transfer dossiers. The new law takes effect in 2026, so check the current text. | Advisory and documentation support. Local ID formats are on our detection roadmap. |
What is available, and what is not yet.
We mark each capability honestly. “Planned” means it is not in an app today.
| Capability | Where | Status | Helps with |
|---|---|---|---|
| Keep content on the device | Our on-device products | Available | Data minimisation, security, transfer limits across all six |
| Detect and redact personal data in documents | Emails, phone numbers, addresses, US SSN-style and card-like numbers | Available | Data minimisation, retention limitation |
| Detect regional IDs (MY, SG, TH, ID, VN) | Planned for our document and keyboard tools | Planned | The same, for the IDs that matter in ASEAN |
| Redaction log export | Sample below; export not yet built | Planned | Accountability, records of processing |
| Policy scan report | Policy scanning tool; sample below | In development | Notice, transparency, transfer disclosures |
| Tamper-evident evidence (hash and timestamp) | Evidence tool | Available | Integrity, chain-of-custody evidence |
| Privacy and governance consulting | Enterprise page: GDPR-standard frameworks, audits, training | Available | All of the above; done by people |
See the output before you commit.
Both files use fictitious names and data, and show the format we are building towards. They are not the output of a released export feature.
Redaction log
Every item detected in a document, what was done to it, whether it was found automatically, and the reviewer’s decision. Masked values only.
Download CSVPolicy scan report
A privacy policy compared with common disclosure expectations under GDPR and the PDPAs, with findings and suggested actions for a person to review.
Download PDFNeed a person, not just a tool?
Our Enterprise page covers GDPR-standard governance, privacy policies, audits and staff training for operations in Asia-Pacific.