4
4.3
protection requirements between the private and public sectors. 335 This is a notable
difference between the GPDR and the PDPA in Singapore.
As the UK NGO Privacy International notes in their submission to Myanmar’s Universal
Periodic Review (UPR) at the Human Rights Council, whilst some ICT companies, such
as Telenor, have developed and adopted their own data protection and retention policies,
the lack of national legislation regulating data retention and the circumstances under
which the Government can request access to user data means that such internal policies
may not be strong enough to protect the privacy of users and secure the freedom of
services. 336
In recent years, many other countries have passed data protection or data privacy
legislation for the first time or updating them in response to the impact of ICTs on
privacy. 337 In Asia, in addition to Singapore, Malaysia, and Taiwan have a “Personal Data
Protection Act”. 338 The law of Japan is called “Act on the Protection of Personal
Information”. 339 South Korea’s law is called the “Protection of Personal Data Act”.340 The
equivalent law of the Philippines is called the “Data Privacy Act”. 341
International Human Rights Law on Privacy
Every person has the right to privacy under international human rights law, including
privacy of his/her communications. 342 Article 17 of the International Covenant on Civil
and Political Rights (ICCPR) provides:
“1. No one shall be subjected to arbitrary or unlawful interference with his
privacy, family, home or correspondence, nor to unlawful attacks on his
honour and reputation.
335
ETNO, “ETNO supports the choice of the legal instrument for the future Data Protection framework” (4 July
2014).
336 Privacy International, “UN Universal Periodic Review, Stakeholder Report 23rd Session, Myanmar, The
Right To Privacy In Myanmar” (March 2015), para 33. See also A Alderaro, “Digitalizing Myanmar:
Connectivity Developments in Political Transition”, Internet Policy Observatory, (2014) pg. 10.
337 In the European Union, the suite of laws protecting personal data are currently being updatedIn 2012, the
European Commission proposed to unify data protection in the EU under a single law, the General Data
Protection Regulation (GDPR), to take into account technological developments such as social networking
and cloud computing. A draft was presented at the European Parliament in March 2014. A final version is
expected to be adopted by end 2015. See: Greens/EFA “EU General Data Protection Regulation State of play
and 10 main issues by Jan Philipp Albrecht” (17 January 2015) and European Commission, “Commissioner
Jourová: Concluding the EU Data Protection Reform is essential“ (28 January 2015).
338 See Malaysia and Taiwan Personal Data Protection Acts.
339 Government of Japan, Act on the Protection of Personal Information Act No. 57 (2003)
340 Korean LII, “Personal Information Protection Act” (last accessed August 2015). See also Francoise Gilbert,
“Privacy v. Data Protection. What Is The Difference?“ (1 October 2014).
341 Republic of the Philippines Act No. 10173 2012 Data Privacy Act.
342 The right to privacy is also include in a wide range of international and regional human rights instruments,
signalling its wide acceptance: Article 14 of the United Nations Convention on Migrant Workers; Article 16 of
the UN Convention on the Rights of the Child; Article 10 of the African Charter on the Rights and Welfare of
the Child; Article 4 of the African Union Principles on Freedom of Expression (the right of access to
information); Article 11 of the American Convention on Human Rights; Article 5 of the American Declaration of
the Rights and Duties of Man, Articles 16 and 21 of the Arab Charter on Human Rights; Article 21 of the
ASEAN Human Rights Declaration; and Article 8 of the European Convention on Human Rights. See a
compilation of privacy references in international and regional human rights instruments and see also
http://gilc.org/privacy/survey/intro.html
158
PAGE
CHAPTER 4.3: PRIVACY