4
4.3
One company confirmed that it would “only” guarantee the privacy of the
company email system to the extent required by law, whereas a separate
statement in its Communications Policy stated that as a leading institution in
Myanmar it would strive to be as open and transparent as possible while protecting
privacy and personal information.
Stakeholder Engagement and Grievance Mechanisms
Human Rights Implicated: Right to privacy
Field Assessment Findings
The concept of privacy: The concept of privacy as outlined in international human
rights standards is not fully understood in the context of Burmese culture, in which
people live in close proximity and often with extended family, making the notion of a
truly private space in Myanmar uncommon. Stakeholders note that this lack of
familiarity with the concept carries over into the digital space.
Lack of user concern about privacy: There is, therefore, a lack of understanding
of the importance of the right to privacy online, the basic steps users should take to
protect it, e.g. using passwords to protect their online accounts and information, and
the consequences of a failure to protect one’s own privacy e.g. posting personal
information such as bank details online.
Lack of awareness on appropriate protections on social media: Users on social
media were observed sharing sensitive personal data including bank statements
and checks for donations or even more sensitive information about health status
without appropriate protections. Users reported being unaware of how to configure
privacy settings in their social media accounts. Users also reported being unaware
of how to report on content on social media.
Lack of policies or clear communication of policies: Data retention policies were
absent, or in some cases not clearly communicated to the customer/user even when
internally present (e.g. 5 years for retention of customer data on paper).
SIM Card Registration:
The Ministry of Communications and Information
Technology (MCIT) has mandated a system that in theory requires an ID, which is
recorded, to buy a SIM card. However in practice, people use their own ID and buy
multiple SIM cards for their friends and family members. People have raised
concerns regarding data protection and their ID being associated with another
user’s activity incorrectly. It was noted that in many other countries (e.g. Thailand
and India), people are not required to show IDs or register with their IDs to purchase
SIM cards.
Data Protection
Human Rights Implicated: Right to privacy
Field Assessment Findings
Physical protection of data: There was variation in the level of access control in
place for businesses with data centers. Some businesses logged visitors to data
centers, while others had multiple levels of security in place (biometric such as a
fingerprint reader, access card, and close circuit television).
Protection of data in case of emergencies: Data backups or disaster response
162
PAGE
CHAPTER 4.3: PRIVACY