In 2014, the Myanmar Government held a public consultation on the issue of mandatory registration of personal information of SIM card and mobile phone purchasers’ cards. 351 This indicates the Government may not be considering the data privacy implications of its telecommunications regulations. The mandatory registration of SIM cards in other jurisdictions has shown that there are a range of unintended consequences, prompting other governments to consider and then reject the idea. 352 MCIT proposed that mandatory SIM registration would enable new and innovative services (e.g., mobile money and mHealth services). However, where such sensitive data is exchanged, these services should be required to register for extra mobile-enabled services; such registration should always be service focused. Mandatory registration could act as a barrier to accessing mobile services because people may not have an address or registration number or may be reluctant to provide personal details due to distrust of the Government. MCIT is yet to define its procedures for the lawful interception of user communications, or access to communications data (See Chapter 4.4 on Surveillance), though it has committed to doing so. This is a crucial and important procedure that requires further consultation and consideration before any mass collection of customer data through mandatory registration is considered. Without data retention requirements, large amount of data, held for an indefinite amount of time, would be susceptible to unlawful uses, including unauthorised surveillance, leaks, and security breaches resulting in negative, and in some cases, severe impacts on the enjoyment of the right to privacy. B. Field Research Findings Privacy Policies by Myanmar Companies Human Rights Implicated: Right to privacy Field Assessment Findings  MCRB reviewed the websites of 73 companies as part of the Transparency in Myanmar Enterprises project (TiME) (or ‘Pwint Thit Sa’ in Burmese) to collect a small sample of the use and disclosure of privacy policies and protections by Myanmar companies. 353  Of the 73 company websites reviewed, only 6 explicitly explaine how they handled and used customers’, users’, workers’ and others’ data.  Only 1 company actually adopted a formal privacy policy outlining in detail its security and data handling measures.  4 company’s statements were contained within other operational policies, such as a code of conduct or code of ethics.  1 ISP explicitly did not commit to any level of data protection, instead confirming that it may monitor its service from time to time and disclose any information regarding customers or their use as required under national law, regulations, Government requests, or that it saw fit.  A majority of the companies reviewed presented no accessible information about the ways in which they handle and use data. 351 See: MCRB, “MCRB calls for Further Consideration of the Impacts of Requiring SIM Card Registration in Myanmar” (21 May 2014). 352 Ibid. 353 MCRB, ”Pwint Thit Sa Project (TiME)“ (2015). CHAPTER 4.3: PRIVACY 161 4 4.3

Select target paragraph3