Laos — Not Licensed, and the Data Law Is the Constraint

Asia-Pacific Private Investigation Registry · AI9OS

Last verified: 3 September 2026 · Sources: ඥຳລັດ ວ່າດ້ວຍວິສາຫະກິດຮັກສາຄວາມປອດໄພ (Decree on Security Enterprises), No. 138/GoL, and ກົດຫມາຍ ວ່າດ້ວຍການປົກປ້ອງຂໍ້ມູນເອເລັກໂຕຮນິກ (Law on Electronic Data Protection), No. 25/NA. Both were downloaded from the Lao Official Gazette and read in full from rendered page images: every PDF on that register is a scan with no text layer, so nothing here comes from a text search. English renderings are AI9OS working translations from the Lao and are not official. Where a figure or a rule matters to a decision, check the Lao.
FieldLaos
What the state regulatesNeither. The state licenses guarding. There is no licence for the investigation profession, and unlike Vietnam there is no licence for the activity either. What constrains investigative work is a data statute, not a permit.
Is there a private investigator licence?No. There is no PI licence, no PI register and no PI regulator. Decree 138/GoL was read from end to end, all 74 articles, and contains no investigation limb in its definitions, its permitted services, its training curriculum or its prohibitions.
Governing instrument for the licensed tradeDecree on Security Enterprises No. 138/GoL, signed 2 March 2020 by the Prime Minister, gazetted 6 May 2020. 74 articles in nine parts. Administered by the Ministry of Public Security.
In forceYes. Article 74 sets commencement at 15 days after publication in the Official Gazette, and the register carries it as in force.
What the decree actually permitsArticle 42 states the permitted field: security services for persons, property, production facilities, business units, offices, residences and organisations; transport of currency and valuables; traffic order; and temporary cover for sporting events and festivals. Obtaining or furnishing information about a person is not among them.
Enterprise licenceIssued by the Minister of Public Security (Art 16), valid three years and renewable (Arts 16–17). Granted only after an investment licence and enterprise registration through the one-stop window (Art 6).
Conditions on the enterpriseRegistered capital of at least 1 billion kip plus a bank guarantee deposit of at least 100 million kip to indemnify clients; a Lao-national director; premises, staff accommodation and a training centre; an approved communications centre; and a cap of three security enterprises per province or capital (Art 7). Every licensed company's name must end with ຮັກສາຄວາມປອດໄພ, “security” (Art 6).
Individual guardsSeparately licensed. Lao nationality, aged 18 to 55, compulsory education completed, a certificate from an approved security training course, good health and no prior custodial sentence (Art 24). Licence issued by the provincial security department, valid three years (Art 28).
The training curriculum, which is the clearest evidenceArticle 33 sets the mandatory syllabus: basic law and discipline, target protection, use of batons, handcuffs and other equipment, patrol, interception, telephone manner, traffic signalling, first aid, observation and patrol inspection, and daily report writing. The advanced course adds VIP protection and short and long firearms and tear gas. Nothing on investigation, surveillance, tracing or evidence.
Foreign participationCapped at 49 percent. Article 7(2) requires a Lao person by birth to hold at least fifty-one percent of the registered capital where there is a joint venture with a foreign party, and Article 8(4) allows the foreign investor at most forty-nine percent, earmarked for vehicles, equipment, technology, personnel development and infrastructure. The two articles are the same ceiling stated from opposite sides. Article 8 also requires the foreign partner to be a legal person, to be financially sound and to have at least ten years' experience operating a security business; Article 7(3) requires the Director-General or Board Chairman to be a Lao citizen by birth. Read from the gazette scan; confirm against the Lao text with local counsel before relying on it.
Penalty for operating unlicensedArticle 70(2): a fine of 10,000,000 to 70,000,000 kip for operating a security business without Ministry of Public Security permission. Article 70(1): 1,000,000 to 5,000,000 kip for organising or hiring self-protection in the form of a security enterprise without permission. Criminal conduct goes to the Penal Code (Art 72).
Penalty for working outside the licensed objectsArticle 52(3) prohibits operating outside the objectives stated in the licence, and Article 70(3) fines it at 5,000,000 to 10,000,000 kip. This is the provision that matters most here: see below.
Data protection overlayThis is the operative constraint. Law on Electronic Data Protection No. 25/NA, 12 May 2017, adopted by National Assembly Resolution 012/NA. Personal data is “specific data” and may not be accessed, used or disclosed without the data owner's permission. Fine 15,000,000 kip where the breach is not criminal (Art 52). Detail below.

The finding: Laos licenses guarding, and the constraint on investigation is a data law

Laos has the same shape as Thailand and Indonesia on licensing. One decree licenses a security trade; investigation is not part of it; and no other instrument creates a private investigator licence. What makes Laos different is where the risk actually sits. In Thailand and Indonesia the absence of a licence leaves a comparatively open field. In Laos, a 2017 data statute closes much of it.

Decree 138/GoL is unambiguous about what a licensed security enterprise sells. Article 42 lists the field of service, and it is guarding, cash in transit, traffic order and event cover. The mandatory training syllabus in Article 33 confirms it from the other direction: batons, handcuffs, patrol routes, traffic signals, first aid, and for the advanced course, firearms and tear gas. A regime that intended to license investigators would train them to investigate. This one trains them to stand at a gate.

The prohibitions say the same. Article 50 bans hiring a security force for intimidation, coercion or extortion, and bans operating in the form of a security enterprise without Ministry of Public Security permission. Articles 52 and 53 bind the enterprise and the individual guard: no unlicensed operation, no lending the licence, no colluding with a client's unlawful acts, no guard on duty without a licence. Not one of the prohibitions mentions investigation, surveillance, tracing or the handling of information about a person.

Why the guarding licence is not a route to investigative work

Article 52(3) prohibits a licensed security enterprise from operating outside the objectives stated in its licence, and Article 70(3) prices that at 5,000,000 to 10,000,000 kip. Since Article 42 fixes those objectives as guarding, a Lao security company that took on an investigation engagement would be outside its own licence. The guarding licence is not a broader permission that happens to include investigation; it is a narrower one that excludes it.

That is a sharper result than Thailand's. There, the guarding statute is silent on investigation and the silence leaves the question open. Here the decree states the permitted field and then penalises departure from it.

Where the exposure actually is: the Law on Electronic Data Protection

This is the part that changes how a cross-border engagement should be scoped. Law No. 25/NA divides electronic data into two classes and treats them very differently.

  • Article 9, general data (ຂໍ້ມູນທົ່ວໄປ) may be accessed, used and disclosed, but the source it was obtained from must be correctly stated. A statutory provenance obligation, and one that maps almost exactly onto how a defensible OSINT report should be built anyway.
  • Article 10, specific data (ຂໍ້ມູນສະເພາະ) may not be accessed, used or disclosed without permission from the data owner or the relevant organisation. Specific data comprises official state data and personal data (ຂໍ້ມູນສ່ວນບຸກຄົນ, defined at Article 3(12) as electronic data of an individual, legal entity or organisation).

Three further provisions matter to anyone conducting or commissioning an investigation that touches Laos.

  • Article 12 (collection). A person collecting data must tell the data owner the purpose, the details of what is being collected, who will control it and what rights the owner has. Collection requires the owner's permission, and must not use deceit or any method that causes the data owner to misunderstand the purpose or the details. Pretexting is named and prohibited, not merely implied.
  • Article 17 (transfer). Sending or transferring personal data requires the owner's permission and assurance that the recipient can protect it, and personal data and official data may not be sent out of the Lao PDR without the data owner's consent or express legal authority. A report delivered to a client outside Laos is a transfer.
  • Article 33(3). Collecting, using or disclosing data relating to race, ethnicity, political opinion, religious belief, criminal record or health record is prohibited. Criminal-record checking, a routine limb of due diligence elsewhere, is a named prohibited category.

Article 31 carries the general prohibitions, binding on everyone rather than only on data controllers: no accessing, collecting, using, disclosing, intercepting, altering, forging or supplying confidential electronic data without permission; no transferring data without the owner's permission; and no exploiting a weakness or vulnerability in a data system to access or collect data. Article 52 fines breaches of Articles 31, 32 and 33 at 15,000,000 kip where they fall short of a criminal offence, and Article 54 sends criminal conduct to the Penal Code.

The practical reading: in Laos you do not need a licence to investigate, and you may not lawfully gather a person's electronic personal data without their permission, obtain it by deception, or export it. The licensing question is the easy one. The data question decides whether the engagement can be run at all.

Why Laos is “neither” and Vietnam is “activity”

The distinction is worth stating because the two look similar and are not. Vietnam licenses the activity: from 1 July 2026 data analysis, aggregation and personal data processing are conditional business lines, so a firm doing that work needs a permit and can be refused one. Laos does not license the activity. It prohibits particular handling of personal data and fines it. There is no permit to apply for, which means there is also no permit that makes the conduct lawful. Consent from the data subject, or express legal authority, is the only gate.

What the register search proves, and what it does not

Method limit, stated because it changes the weight of the evidence. The Lao Official Gazette's search does not read scanned PDF attachments. The test was ກະແຈມື, “handcuffs”, a word read with our own eyes in Article 3(3) of Decree 138: the register returns zero rows for it, while the decree's own title phrase returns the decree. So a nil result on that register proves only that no instrument is titled for a term, or mentions it in inline text.

This is why the page does not claim that investigation appears nowhere in Lao law. The searches for ນັກສືບ, “detective”, and for investigation services do return zero, and that is worth recording, but on its own it would be a nil result from an instrument that cannot see inside the documents that matter. What supports the finding above is not the search. It is that Decree 138/GoL and Law 25/NA were both retrieved and read in full from rendered images.

The same limit caught an error of ours. An earlier working note recorded that the Lao framing is “electronic data, not personal data”, because ຂໍ້ມູນສ່ວນບຸກຄົນ returned zero on the register. The term is in fact a defined term of the statute, at Article 3(12), and a whole class of protection is built on it. The register returned zero because it cannot read the scan. A nil result is not a finding until you have proved you could have found something.

What is still open

The controlled business list has not been located. Decree No. 68/PM of 28 April 2008 approves the list of controlled business types (ບັນຊີປະເພດທຸລະກິດຄວບຄຸມ) “per attachment ka of this decree”, and the register carries the decree as in force. All four gazette pages were read: the attachment is not published with it, and no separate document for it exists on the register. Ministry of Industry and Commerce guidance of 22 December 2023 shows what turns on it: an activity in the controlled list needs an investment permit from Planning and Investment on top of the sector business permit, while one outside it needs only the sector permit. Whether an investigation-type business is on that list is unresolved. It affects how such a company is formed; it does not affect the licensing or data findings above. The official gazette does not hold it, and we have stopped looking there. Four checks establish that, each a different route: the attachment is not published with the decree; a controlled, fully paged search of the register returns exactly one document for controlled business, the decree itself; the decree’s own register page carries a single file; and the 2011 decree implementing the Investment Promotion Law, read through to the Prime Minister’s signature, has fifteen chapters, seventy articles and no annex. Anyone who needs the list should request it from the Ministry of Industry and Commerce or from Planning and Investment directly rather than expect to find it published.

How this compares

JurisdictionWhat the state regulatesThe short answer
SingaporeProfessionLicensed, source-agnostic definition, two licences
MalaysiaProfessionLicensed under the Private Agencies Act 1971
PhilippinesProfessionLicensed under RA 11917
ThailandNeitherGuarding is licensed; investigation is not mentioned
IndonesiaNeitherSix licensed security categories; investigation is not one
VietnamActivityData analysis and processing become conditional business lines
LaosNeitherGuarding is licensed and fenced; personal data needs the subject's permission

Primary sources

  • Lao Official Gazette — the register carries a genuine status field distinguishing instruments in force from superseded ones, which is why Laos could be resolved when Cambodia and Myanmar could not
  • Decree on Security Enterprises No. 138/GoL, 2 March 2020, gazetted 6 May 2020, Ministry of Public Security. 30 pages, scanned, read in full
  • Law on Electronic Data Protection No. 25/NA, 12 May 2017, with National Assembly Resolution No. 012/NA of the same date. 15 pages, scanned, read in full
  • Decree approving the list of controlled business types, No. 68/PM, 28 April 2008 — enacting decree read in full; attachment ka, which is the list itself, not published with it and not located
  • Law on Investment Promotion, revised 28 June 2024, gazetted 16 December 2024 — in force. Note the supersession trap: the 2016 revision and the 2009 original are both marked superseded on the register, and the 2016 is the version English-language guidance still cites
  • Instruction on the implementation of enterprise registration, Ministry of Industry and Commerce, 22 December 2023 — the only Lao instrument found in this pass with a machine-readable text layer

Related

General information for practitioners, not legal advice. Engage Lao counsel before relying on this reading for a live matter. The English on this page is our own translation from the Lao text; the Lao governs. Absence of a licensing regime is not absence of legal risk, and in Laos the data statute is the more demanding of the two.

AI9OS turns public information into verified, chain-of-custody findings for licensed investigation agencies, law firms and corporate risk teams.

Request a demo