4 4.4 that their accounts may have been hacked by “state-sponsored attackers”. 388 It is unclear if the purpose of these attacks were to gain access to journalist’s emails and identify sources, or to stem the flow of information to and from Myanmar. It was also reported that government agents visited cybercafés to “install some software”, widely believed to be ‘keylogging’ software, which records and stores keystrokes for later analysis. Some café owners have put up signs warning customers not to use the Internet for “political reasons”. It is also unclear what kind of relationship Myanmar’s existing intelligence agencies have with foreign counterparts, and what kind of intelligence exchange agreements exist. It is thought that Embassies routinely reported on the activities of the diaspora. 389 The Legal Framework in Myanmar There are currently few protections in Myanmar’s legal framework to prevent the kind of pervasive surveillance previously conducted by intelligence agencies and about which there is justifiable concern. It is unclear under which legal regime the existing intelligence agencies are operating, what their remit is and how they are exercising their powers. Although Article 357 of the 2008 Constitution does provide for privacy 390, there are no privacy protections in national legislation. The existing legal framework referring to surveillance is vague. Article 75 of the 2013 Telecommunications Law 391 grants unspecified government agents the authority “to direct the organisation concerned as necessary to intercept, irrespective of the means of communication, any information that affects the national security or rule of law”. Although the clause adds this should be undertaken without impacting the fundamental rights of citizens, there are no further details on the process or privacy protections. Most states have a specific legal framework in place to govern instances where interception of communications is permitted in real time (lawful interception). However Myanmar currently has no specific legal framework or regulations governing lawful interception, leaving an important gap in the regulatory framework. The MCIT has confirmed its interest in developing a law in accordance with international standards. It has committed to a public consultation of draft lawful interception regulations. 392 One of the current telecommunications operators, Telenor, has stated publicly that they will not respond to any interception requests from law enforcement officials until the legal framework is in place. 393 The EU has agreed to provide technical support to the Government to develop its regulations in line with human rights. The programme of work will come within the Council 388 Thomas Fulller, “E-Mails of Reporters in Myanmar Are Hacked“ New York Times (10 February 2013). Andrew Selth, “Burma’s Security Forces: Performing, Reforming or Transforming?“ Griffith Asia Institute, Griffith University, Australia (2013), pg. 18. 390 “357. The Union shall protect the privacy and security of home, property, correspondence and other communications of citizens under the law subject to the provisions of this Constitution.“ 391 See unofficial English translation of the Myanmar 2013 Telecommunications Law. 392 In November 2013, MCIT published draft proposed rules, stating: “The Ministry will be drafting other rules and procedures on a variety of issues such as standardization, type approval, and lawful interception in due time. Such rules and procedures also will be subject to a public consultation process.“ MCIT, “Proposed Rules for Telecommunications Sector Relating to Licensing, Access and Interconnection, Spectrum, Numbering, and Competition” (4 November 2013), Section I, B5 (pg. 5). 393 Telenor, “Myanmar sustainability presentation” (19 August 2014), pg. 8 of the transcript. 389 174 PAGE CHAPTER 4.4: SURVEILLANCE – LAWFUL INTERCEPTION & OTHER SURVEILLANCE METHODS

Select target paragraph3