Cyber security compliance in Tonga
Tonga passed three significant laws in 2025: a Cybersecurity Act for critical infrastructure, a Privacy Act and a new Computer Crimes Act. Each commences on a date proclaimed by Cabinet, and we could not find those proclamations as of late September 2026, so check their status before planning around them. Banks already work to the National Reserve Bank's cybersecurity standard.
- Frameworks listed6
- Issuing bodies6
- Framework pages1
- Platform languagesEnglish and Arabic
- DeploymentSaaS, private cloud or on-premises
Cybersecurity and data protection frameworks in Tonga
Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.
Cybersecurity Act 2025
Operators designated as critical infrastructure: periodic assessments and incident reports to CERT Tonga within 24 hours. Commences on Cabinet proclamation
Privacy Act 2025
Controllers and processors of personal data. Restricts transfers outside Tonga. Commences on Cabinet proclamation
Prudential Banking Standards No. 14 (Operational Risk) and No. 15 (Cybersecurity)
Banks, effective 1 July 2021 under the Banking Act 2020
Computer Crimes Act 2025
Everyone. Replaces the Computer Crimes Act 2003 when it commences
Tonga National Cybersecurity Framework and Cybersecurity Manual
Government and public enterprises, as guidance
ISO/IEC 27001
The reference standard behind Tonga's government Cybersecurity Manual, which is based on ISO/IEC 27002 and 27005
Open the framework page →Which cybersecurity laws apply in Tonga?
The Cybersecurity Act 2025 creates binding duties for critical infrastructure, the Privacy Act 2025 introduces data protection, and the Computer Crimes Act 2025 replaces the 2003 cybercrime law. All three received royal assent in 2025 and commence on a date Cabinet proclaims. For banks, the National Reserve Bank's Prudential Banking Standard No. 15 on cybersecurity has applied since July 2021.
What will the Cybersecurity Act 2025 require?
The minister responsible for cyber policy designates critical infrastructure by notice, with banking, financial services and electronic communications among the criteria. Designated operators must carry out periodic cybersecurity assessments, report incidents to CERT Tonga within 24 hours, follow remedial orders and keep policies and records. Civil penalties reach 500,000 pa'anga for individuals and 1,000,000 pa'anga for companies.
Does Tonga have a privacy law?
Yes, since the Privacy Act 2025 received assent in December 2025, although it commences on proclamation. It creates a Privacy Commission, restricts transfers of personal data outside Tonga without consent or equivalent protection, and sets penalties of up to 100,000 pa'anga for repeat breaches by organisations. Its 72-hour breach notification duty applies only from the second anniversary of commencement. Sources still saying Tonga has no privacy law are out of date.
Which language governs Tongan law?
Tongan laws are published in Tongan and English. Where the two genuinely differ, the Tongan text prevails. GRCLens records each obligation with its source reference so a compliance team can trace it to the authoritative text.
How GRCLens supports organisations in Tonga
GRCLens runs the National Reserve Bank's standards and the Cybersecurity Act's critical infrastructure duties on one control model with ISO/IEC 27001, so a bank that is also designated critical infrastructure evidences each control once. The 24-hour incident clock is tracked as an indicator. GRCLens can be hosted in the region or fully on-premises.
Official portals and publications
Cyber compliance in Tonga: common questions
Does Tonga have a cybersecurity law?
Yes. The Cybersecurity Act 2025 received royal assent in August 2025. It commences on a date proclaimed by Cabinet, which we could not confirm as of September 2026.
How fast must a critical infrastructure operator in Tonga report an incident?
Within 24 hours to CERT Tonga, under the Cybersecurity Act 2025, once it commences and the operator is designated.
Does Tonga have a privacy law?
Yes. The Privacy Act 2025 received assent in December 2025 and commences on proclamation. Its breach notification duty applies from the second anniversary of commencement.
Which cyber standard applies to banks in Tonga?
The National Reserve Bank of Tonga's Prudential Banking Standard No. 15 on cybersecurity, effective 1 July 2021, alongside No. 14 on operational risk.
Sources
Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Tonga's frameworks on one platform
See GRCLens with your own frameworks loaded. Need hands-on help? Cyber security services in Fiji and the Pacific from Security Solution Consultants.