engines, VoIP (e.g. Skype) and mobile phones. Globally, ICT companies use this information in various ways. For example, free applications or services frequently offer the advertisers who support them a platform for user-targeted advertisements, based on data collected from users. Geographic location data can be used to identify where a user is physically located and provide location based advertisements or services such as taxis, restaurant recommendations, or directions. As a country’s ICT sector grows, more and more personal data is collected and stored by governments and companies providing goods and services online. This more extensive and innovative use of personal data brings greater economic and social benefits, but also increases privacy risks. 313 How the information is shared and who has access to it determines whether or not privacy is protected and respected. In many countries, national data protection laws require companies to secure and protect such information from access by unauthorised third parties. Data protection or data privacy laws 314 should safeguard user privacy. Such protections are intended to regulate how, when, and why a user’s personal information or data may be used or stored by a third party. They should put limits on governments and companies concerning the collection, storage and sharing of personal data generated by using ICTs when trading, or using goods and services online. This should ensure that it is gathered for a legitimate purpose and protected from misuse. There should be restrictions or limits in each country’s data protection or data privacy legislation as to how this information is collected, stored and shared by companies for commercial reasons, or by governments obtaining this kind of information for services such as voting registration, health records or tax purposes. Legislation that regulates data privacy typically details a consent mechanism to inform and request permission from users, provides a legal definition of what constitutes personal data, mandates an allowable timeframe for the use of any data after consent is given, and includes regulatory mechanisms for pursuing grievances about the use of data. However many national frameworks lack ‘use limitations’, instead allowing the collection of data for one legitimate aim, but subsequent use for others. 315 In addition, a lack of a data protection framework means there is no opportunity for individuals to seek redress or compensation in cases of unauthorised sharing or use of personal data. 316 Myanmar currently lacks a data protection law. 313 OECD, “The OECD Privacy Framework”, (2013). Outside Europe, the term ‘data protection’ and ‘data privacy’ is used to commonly mean the same thing. 315 OHCHR, “The right to privacy in the digital age”, A/HRC/27/37, (June 2014), para. 27. 316 Privacy International, “UN Universal Periodic Review, Stakeholder Report 23rd Session, Myanmar, The Right To Privacy In Myanmar”, (March 2015), para 32. 314 CHAPTER 4.3: PRIVACY 153 4 4.3

Select target paragraph3