4 4.3 Equally, whereas protection of privacy was until recently an unknown concept in Myanmar, awareness is growing among the Myanmar business community about the importance of personal data protection even without mandated privacy standards, such as for emerging services such as mobile money. 324 As users weigh competing services, companies that fail to provide strong data safeguards may start to find they lose customers, although currently, the public’s awareness of the need to protect personal data is quite low. A recent high profile case involving a (now dismissed) employee of an operator giving unauthorised access to communications data to a friend will have further served to raise awareness 325. In May 2013, Human Rights Watch sent a letter to mobile network operators shortlisted in the MCIT telecommunications license process seeking clarification regarding how new telecommunications firms entering Myanmar would seek to mitigate potential human rights impacts given Myanmar’s lack of legislation related to privacy, censorship, and interception. Both Telenor and Ooredoo issued responses. Their company positions on data privacy took different approaches. MPT and Yatanarpon Teleport have not issued public statements on data privacy. Myanmar’s remaining Internet service providers also do not provide any clarification on data privacy policies on their websites. Ooredoo highlighted its “commitment to Myanmar to use Singapore as a benchmark” and the intent to “implement policies and procedures that are compliant with the 2012 Singapore Data Protection Act.” 326 The Singapore Data Protection Act (PDPA) defines personal data as “data, whether true or not, about an individual who can be identified from that data; or from that data and other information to which the organisation has or is likely to have access.” 327 The PDPA requires private sector companies to notify and provide individuals with an explanation when their personal data is collected and disclosed. With regard to telecommunications, the Singapore Personal Data Protection Commission has issued advisory guidelines for the telecommunications sector. However, the Singapore PDPA does not provide adequate protection for human rights. It lacks references to specific and relevant human rights principles under international law, exempts Government agencies and entities working on their behalf, has ambiguous limitations on legitimate purpose for data collection and disclosure under the PDPA, exceptions to individual consent requirements, poor transparency and accountability mechanisms, and broad language that allows for organisations and data to be exempt from PDPA regulations in the future. 328 Telenor’s response to Human Rights Watch’s letter cited Telenor’s “well established privacy and data protection regime”. 329 A section of the Telenor website explains that, “Telenor Group only processes personal data for the purposes the data was originally 324 See Myanmar Times, “Preparing the Financial System for Digital Attacks” (March 2015) ‘Ooredoo data breach brings legal action’, 3 September 2015, Myanmar Times. 326 Ooredoo response to Business and Human Rights Resource Centre’s request for a response to HRW’s Report: Burma Telecom Winners Should Safeguard Users 327 Personal Data Protection Commission Singapore, “Legislation and Guidelines: Overview” (last accessed August 2015). 328 Internal analysis prepared for the Institute of Human Rights and Business. 329 Human Rights Watch, “Response from Ms. Oldgard, Vice President, Head of Group Corporate Responsibility, Telenor Group” (4 June 2013). 325 156 PAGE CHAPTER 4.3: PRIVACY

Select target paragraph3