9/22/26, 11:13 AM
Myanmar Telecom Risk, Part 1 of 4: Surveillance and the Law
disinformation and to open personal data to the government.19 Online speech cases continue to be
brought mainly under Section 505A, Section 50(j) of the Counter-Terrorism Law, or the 2025
Election Protection Law. As of September 2026, we had found no published prosecutions under the
Cybersecurity Law, and the implementing rules and licensing procedures had not been issued.
Two measures adopted in 2026 send more data to the state. The Anti-Online Scam Law, enacted in
late July 2026, allows banks to freeze a suspect account within 15 minutes. It also creates a central
database linking bank accounts, SIM cards, IP addresses, and phone records.20 Digital rights
monitors interpret it as also obliging operators to archive subscriber location data and call records for
official access.13 A March 2026 amendment to the Anti-Money Laundering Law empowers the
Ministry of Home Affairs to intercept and disconnect communication lines.21 The government
describes both as anti-fraud measures, but their practical effect is to widen what the authorities may
lawfully collect.
Risk Snapshot
Personal risk. Calls, messages, and unencrypted traffic on every Myanmar operator are vulnerable
to interception without judicial oversight, and cell data gives authorities a subscriber's location in real
time. Arrests under Section 505A and the counter-terrorism law have followed Facebook comments,
TikTok captions, and private messages, and documented cases number in the thousands. The
Cybersecurity Law continues to apply to Myanmar citizens even after they leave the country.
Business risk. State interception or filtering equipment is present on the networks of all four mobile
operators and nine ISPs, so a company cannot avoid it by choosing a different carrier. A corporate
VPN has no route to approval and therefore operates unlicensed. Platforms with more than 100,000
Myanmar users are required to register and retain data for three years, but no regulator is yet in a
position to accept this. Banks and operators are legally bound to assist the monitoring committee,
which places financial and call records within easy reach of the state. Doing business with the
named operators is lawful, though it carries reputational exposure and should be covered in
sanctions monitoring.
Safety measures. Treat the mobile network as hostile and prefer end-to-end encrypted messaging
over trusted Wi-Fi for any traffic sent through a registered SIM. Keep material critical of the military
off every device entering the country. Ensure local staff understand that the law applies to them
abroad, and do not ask them to take risks on the company's behalf. Send sensitive corporate traffic
through infrastructure outside Myanmar, and keep as little data in the country as possible. Encrypt
what remains, following the detailed guidance in Part 3.
Sources
1. Freedom House. Myanmar: Freedom on the Net 2025. November 2025.
https://freedomhouse.org/country/myanmar/freedom-net/2025
2. Reuters via Al Jazeera. Months before the coup, Myanmar army ordered intercept spyware. 19
May 2021.
https://www.aljazeera.com/economy/2021/5/19/months-before-the-coup-myanmar-army-orderedintercept-spyware
https://www.search-risk.com/insights/myanmar-telecom-risk-part-1-4-surveillance-and-law
4/9