use on how their data will be deployed, without being excluded from the use of
software or services customary for participation in the information age. Such
businesses should also demonstrate accountability and provide redress in the case
of a security breach.
There is a need to reverse the erosion of trust in the Internet brought about by the
non-transparent market in collecting, centralising, integrating and analysing
enormous quantities of private information about individuals and enterprises — a kind
of private surveillance in the service of ‘big data’, often under the guise of offering a
free service.”
Increasingly, there are calls for standards and accountability mechanisms to bolster
confidence in the use of the Internet. ‘Data due process’, access to remedy, and greater
transparency – by governments and business – are all being advocated as important
steps in maintaining an open and accessible Internet.
In addition, because companies may hold a lot of personal information, they may be
subject to requests to hand over information about a user to a government - with or
without legal authorisation - in a manner that is not in line with human rights. When a
country’s law enforcement or intelligence agencies request, access or intercept
information collected and stored by ICT companies to support law enforcement or national
security investigations, this triggers privacy concerns. This dimension is addressed in
Chapter 4.4 on Surveillance.
Privacy in the Myanmar Context
In Myanmar, businesses and Government are transitioning from storing information in
filing cabinets to electronic databases. Data can now be stored on remotely located
servers, and accessed over the Internet, otherwise known as ‘the Cloud’. 321 It means that
users have access to an almost unlimited amount of storage of their data, which can be
accessed from any computer. Cloud storage is most commonly used for email (such as
Gmail) and storing data (such as Dropbox).
The improved efficiency and ease of access provided by digitally storing information is
obvious, as are the potential human and commercial risks and need for accompanying
legal frameworks. Myanmar companies who long operated in isolation may be finding that
data protection requirements are now necessary if they are involved in the cross-border
exchange of commerce and data. ASEAN has already put in place frameworks on data
protection, as have other regional bodies, 322 including the EU, where appropriate data
protection is a prerequisite of before any data can be transferred from the EU. 323
321
In the simplest terms, cloud computing means accessing files and applications over the internet, rather
than on personal hard drives or servers, via third party services.
322 See in particular, the basic principles on data protection in the OECD, “Guidelines Governing The
Protection Of Privacy And Transborder Flows Of Personal Data” (2013).
323 Under the EU Data Protection Directive, personal data may only be transferred to third countries i.e.
countries outside of the European Union, if that country provides an adequate level of data protection. This
created an incentive for some countries to increase data protection standards, due to the economic benefits
through increased trade with EU countries.
CHAPTER 4.3: PRIVACY
155
4
4.3