   policies were mostly absent. One bank maintained a data centre for production and a data centre for disaster recovery. Protection of data from unauthorised access within the company: Rolesegregation varied among businesses collecting customer’s personal data. One bank segregated employees conducting a ‘Know Your Customer’ check (where basic information was provided, such as a National Registration Card) from employees conducting financial transactions. Affordability of data protection: Many businesses used pirated software for internal business functions including email which presents a data protection risk. Small and medium size businesses complained about the cost of buying licensed software. Lack of policies or clear communication of policies: Data retention policies were absent, or in some cases not clearly communicated to the customer/user even when internally present (e.g. 5 years for retention of customer data on paper). Myanmar Good Practice Examples:  Companies are beginning to conduct threat and vulnerability assessments across their applications, network, and infrastructure on an ongoing basis to test the security of the data held in their systems. One bank uses two separate companies to perform assessments (one local and one international). C. Privacy: Recommendations for ICT Companies General  Understand contextual risks around Myanmar’s history and Government action:   Given Myanmar’s historical legacy of Government surveillance and information control, coupled with ICT policies and laws that are not aligned with international human rights standards, there exist significant risks for violation of ICT user rights to protection of privacy and anonymity. There are also risks for any ICT company that may be implicated in such violations. Risks related to the violation of the right to privacy in Myanmar with respect to Government actions can be categorised into at least two separate but closely related areas of concern: • Government monitoring and surveillance of user activity and content; and • Government access to user-identifying information (See Chapter 4.4 on Surveillance). Use company procedures to plug gaps in the Myanmar legal framework: As Myanmar currently has no legal requirements for mandatory protection of data of ICT users, this means that the protection of personal data is left to individual companies or Government departments, if at all. Sectors such as ICT or the financial sector are likely to be more aware of the importance of data protection. Companies in these sectors may have their own policies and procedures, or industry-specific standards to assist in developing systems and policies. But other companies will also need to develop systems to protect personal information, as well as externally available policies to inform customers about how their data is being handled (see next point). Develop and implement appropriate policies and procedures to safeguard data privacy: Companies in the ICT value chain, which often collect and store a large amount of personal information about their users, need processes and policies in place to ensure they protect user information. These must be clear about how they will collect, store and share user information with third parties, and under what circumstances the Government (or others) can have access to information or intercept communications. This information would usually be set out in a company’s ‘privacy CHAPTER 4.3: PRIVACY 163 4 4.3

Select target paragraph3