4. Computer Science Development Law (CSL) (1996) & the Electronic Transactions Law (ETL) (2004 – Amended in 2014) Risks to Right to Freedom of Expression  The Laws include vague and overly-broad criminalisation of expression “detrimental to security of the State or prevalence of law and order or community peace and tranquility or national solidarity or national economy or national culture, national security and social unity” (ETL Art. 33(1) & (b) and CSL Art. 35).  The ETL grants broad powers granted to a “Control Board” that is able to access and inspect any ICT it has “reasonable cause” to suspect it was used in an offence under the Act (ETL Art. 9 &10.i). Risks to Right to Privacy  Both laws are outdated and not compatible with current situations and modern technology; there have been numerous calls for their repeal.  The laws do not provide for data protection, protection of privacy or protection against cyber crime. Implicating Private Sector Companies in Human Rights Violations  Since Government-issued licenses are required for entities to become a “certification authority” for purposes of engaging in electronic transactions, licensees are subject to suspension or cancellation of licenses for failure to comply with Government imposed conditions. This could include requests to turn over information on the identity of users. (ETL Art. 28). NEXT STEPS TO BUILD A BETTER ICT LEGAL FRAMEWORK FOR MYANMAR Myanmar needs to update and revise its ICT framework through consultation with stakeholders, building on past good practice examples of consultations hosted by the Ministry of Transport and Telecommunications.17 The ICT framework should be based on international human rights and internationally agreed principles and frameworks18 that incorporate human rights and seek to balance them with the needs of government and users. Steps towards this could include:   17 18 Developing an ICT strategy for the country to prepare itself for 4IR that is consistent with international human rights standards Establishing a coherent policy and legal framework for the ICT sector that involves the repeal or amendment of the existing ICT laws to take account of the concerns highlighted above and includes: o Establishing a cyber security framework, that includes laws and other approaches o Adopting a separate law or laws which narrowly define cyber crimes (see MCRB’s separate Policy Briefing on Cyber Security and Cyber Crime) o Adopting a Data Protection Law that protects users’ privacy and data online (see MCRB’s separate Policy Briefing on Data Protection), as a precursor for e-government and digital ID o Ensuring that the design and implementation of the e-government and digital ID programmes protects human rights o Adopting a rights-respecting lawful interception framework and laws based on the seven principles set out in the MCRB ICT SWIA (see Annex to the Recommendations) See for example the earlier consultation on the Draft Universal Service Strategy. See for example, the Global Commission on Internet Governance’s “One Internet” set of principles (2016). 5

Select target paragraph3