information against attacks will become a central issue to the Government of Myanmar’s
internet governance policy. However, there is currently no legal framework in Myanmar
that clearly defines what constitutes Personally Identifiable Information (PII) or stipulates
any requirements around the collection, management, or transfer of personal data for
companies. Hacking is criminalised under article 34 of the Electronic Transactions Law
(No 5/2004). 426 A cyber-security/cyber-crime law is rumoured to be in development by
either the Ministry of Information and Communication Technology or the Ministry of Home
Affairs, both with likely support from the Myanmar Computer Federation (MCF). A specific
timeline for the law’s development is unclear. In 2014 it was reported that the Government
was seeking support and knowledge sharing opportunities from private companies in the
cybersecurity space, such as Microsoft. 427
One of the high priority items under the 2011–2015 ICT Master Plan’s Infrastructure
component is the establishment of a “Cyber Security Centre” 428, including the creation of a
Cyber Information Act and Information Security Committee to select the specific
technology (hardware and software) that would be used by the Cyber Security Centre.
The follow up report to the 2005-2010 ICT Master Plan states the intention to build a
Cybersecurity Protection Agency to protect Myanmar's critical information and
infrastructure 429, whose role is to enhance Internet security and creating a safe Internet
environment. It states the strategic objectives of this agency are to “Prevent cyber-attacks
against Myanmar’s critical infrastructures; Reduce national vulnerability to cyber-attacks;
Minimise damage and recovery time from cyber-attacks that do occur”. In addition, the
agency would protect citizen’s personal information, provide guidance and training for
Internet and information security, protect critical infrastructure by analysing and evaluating
weaknesses in facilities, strengthening security for electronic government services and
protection of public information. In 2015, MCIT published a draft ICT Master Plan for
public consultation. 430 It outlined plans to create and publish a national cyber security
policy by 2016, but did not repeat the specifics outlined in the 2011 follow up report.
426
Myanmar Electronic Transactions Law.
427 Htun Htun Minn, “Microsoft Tapped To Assist Myanmar Develop Cyber Security Measures” Myanmar
Business Today (24 June 2014).
428 See, Ministry of Communications and Information Technology, “The Follow-Up Project of the
Establishment of an ICT Master Plan: Final Report” (2011), pages 89-94.
429 Ibid, Section 3.6.1.6.
430 See MCIT, “Draft Telecommunications Masterplan” (7 August 2015) and MCRB, “Comments on the draft
Myanmar Telecommunications Master Plan” (30 July 2015).
CHAPTER 4.5: CYBER-SECURITY
185
4
4.5