9/22/26, 11:13 AM Myanmar Telecom Risk, Part 1 of 4: Surveillance and the Law disinformation and to open personal data to the government.19 Online speech cases continue to be brought mainly under Section 505A, Section 50(j) of the Counter-Terrorism Law, or the 2025 Election Protection Law. As of September 2026, we had found no published prosecutions under the Cybersecurity Law, and the implementing rules and licensing procedures had not been issued. Two measures adopted in 2026 send more data to the state. The Anti-Online Scam Law, enacted in late July 2026, allows banks to freeze a suspect account within 15 minutes. It also creates a central database linking bank accounts, SIM cards, IP addresses, and phone records.20 Digital rights monitors interpret it as also obliging operators to archive subscriber location data and call records for official access.13 A March 2026 amendment to the Anti-Money Laundering Law empowers the Ministry of Home Affairs to intercept and disconnect communication lines.21 The government describes both as anti-fraud measures, but their practical effect is to widen what the authorities may lawfully collect. Risk Snapshot Personal risk. Calls, messages, and unencrypted traffic on every Myanmar operator are vulnerable to interception without judicial oversight, and cell data gives authorities a subscriber's location in real time. Arrests under Section 505A and the counter-terrorism law have followed Facebook comments, TikTok captions, and private messages, and documented cases number in the thousands. The Cybersecurity Law continues to apply to Myanmar citizens even after they leave the country. Business risk. State interception or filtering equipment is present on the networks of all four mobile operators and nine ISPs, so a company cannot avoid it by choosing a different carrier. A corporate VPN has no route to approval and therefore operates unlicensed. Platforms with more than 100,000 Myanmar users are required to register and retain data for three years, but no regulator is yet in a position to accept this. Banks and operators are legally bound to assist the monitoring committee, which places financial and call records within easy reach of the state. Doing business with the named operators is lawful, though it carries reputational exposure and should be covered in sanctions monitoring. Safety measures. Treat the mobile network as hostile and prefer end-to-end encrypted messaging over trusted Wi-Fi for any traffic sent through a registered SIM. Keep material critical of the military off every device entering the country. Ensure local staff understand that the law applies to them abroad, and do not ask them to take risks on the company's behalf. Send sensitive corporate traffic through infrastructure outside Myanmar, and keep as little data in the country as possible. Encrypt what remains, following the detailed guidance in Part 3. Sources 1. Freedom House. Myanmar: Freedom on the Net 2025. November 2025. https://freedomhouse.org/country/myanmar/freedom-net/2025 2. Reuters via Al Jazeera. Months before the coup, Myanmar army ordered intercept spyware. 19 May 2021. https://www.aljazeera.com/economy/2021/5/19/months-before-the-coup-myanmar-army-orderedintercept-spyware https://www.search-risk.com/insights/myanmar-telecom-risk-part-1-4-surveillance-and-law 4/9

Select target paragraph3