2. Authorisation Processes  Specific instances of communications surveillance should be authorised by an independent and competent judicial authority prior to surveillance taking place. Some states have a process of executive sign-off rather than judicial authorisation.  Independence in this circumstance means separate and not connected to the authorities that will be carrying out the surveillance. Competence means that those with responsibility for giving authorisation must have sufficient knowledge of the issues, both technologically and from a human rights perspective. This independence and competence is absolutely critical to the integrity of any legal framework. Some states have a process of executive sign-off rather than judicial authorisation. But the prevailing view at the UN level and among civil society is that judicial authorisation is preferable for its independence (the Authorising Authority). • The Government of Myanmar has already committed to judicial authorisation. 16  Communications surveillance must be limited to that necessary to achieve a legitimate aim and use the means least likely to infringe rights; it must be both necessary and proportionate. An objective assessment of the necessity and proportionality of the contemplated surveillance should be a core part of the authorisation process.  The legal framework should set out which agencies among government bodies can request lawful interception (the Requesting Agencies).  The legal framework should also set out the criteria and conditions on which the court will make the decision on whether to authorise the request.  Any authorisation should be time-bound with a requirement for the Requesting Agency to return to the Authorising Authority to request a renewal as that period of time expires; automatic renewals of surveillance requests should not be permitted.  The legal framework should set out clear limits on the amount of time that data collected can be stored. It should require that data is destroyed once the period expires. In addition, it should require that any data illegally collected is immediately destroyed and not used. 3. Oversight  There is an on-going global debate about the best form of oversight of lawful interception and access to user data. Increasingly there is interest in mixed models of oversight that incorporate administrative, judicial and parliamentary actors.  Oversight must be vested in another body (or bodies) that is independent of the Authorising Authority that originally authorised the surveillance.  Oversight must be rigorous and not a rubber stamping exercise.  Consideration should be given to permitting a confidential public interest advocate, for example an independent human rights expert, within the surveillance authorisation process to ensure that appropriate consideration is given to the human rights implications of the request. This is particularly important given the high degree of secrecy of authorisation processes that relate to national security.  The oversight body must have access to all potentially relevant information to enable it to evaluate whether the government is carrying out its activities in a lawful way. This must include secret and classified information. Third parties, for example companies, should have the ability to bring relevant information to the oversight body.  The oversight body must have the resources and expertise to be able to carry out effective oversight. Sector Relating to Licensing, Access and Interconnection, Spectrum, Numbering, and Competition (November 4, 2013) 16 Telenor Myanmar sustainability presentation (August 19th 2014). See p8 of the transcript. ANNEX TO THE RECOMMENDATIONS: LAWFUL INTERCEPTION AND GOVERNMENT ACCESS TO USER DATA 37 Annex to Recs

Select target paragraph3