4
4.3
Equally, whereas protection of privacy was until recently an unknown concept in
Myanmar, awareness is growing among the Myanmar business community about the
importance of personal data protection even without mandated privacy standards, such as
for emerging services such as mobile money. 324 As users weigh competing services,
companies that fail to provide strong data safeguards may start to find they lose
customers, although currently, the public’s awareness of the need to protect personal data
is quite low. A recent high profile case involving a (now dismissed) employee of an
operator giving unauthorised access to communications data to a friend will have further
served to raise awareness 325.
In May 2013, Human Rights Watch sent a letter to mobile network operators shortlisted in
the MCIT telecommunications license process seeking clarification regarding how new
telecommunications firms entering Myanmar would seek to mitigate potential human rights
impacts given Myanmar’s lack of legislation related to privacy, censorship, and
interception. Both Telenor and Ooredoo issued responses. Their company positions on
data privacy took different approaches. MPT and Yatanarpon Teleport have not issued
public statements on data privacy. Myanmar’s remaining Internet service providers also
do not provide any clarification on data privacy policies on their websites.
Ooredoo highlighted its “commitment to Myanmar to use Singapore as a benchmark” and
the intent to “implement policies and procedures that are compliant with the 2012
Singapore Data Protection Act.” 326 The Singapore Data Protection Act (PDPA) defines
personal data as “data, whether true or not, about an individual who can be identified from
that data; or from that data and other information to which the organisation has or is likely
to have access.” 327 The PDPA requires private sector companies to notify and provide
individuals with an explanation when their personal data is collected and disclosed. With
regard to telecommunications, the Singapore Personal Data Protection Commission has
issued advisory guidelines for the telecommunications sector.
However, the Singapore PDPA does not provide adequate protection for human rights. It
lacks references to specific and relevant human rights principles under international law,
exempts Government agencies and entities working on their behalf, has ambiguous
limitations on legitimate purpose for data collection and disclosure under the PDPA,
exceptions to individual consent requirements, poor transparency and accountability
mechanisms, and broad language that allows for organisations and data to be exempt
from PDPA regulations in the future. 328
Telenor’s response to Human Rights Watch’s letter cited Telenor’s “well established
privacy and data protection regime”. 329 A section of the Telenor website explains that,
“Telenor Group only processes personal data for the purposes the data was originally
324
See Myanmar Times, “Preparing the Financial System for Digital Attacks” (March 2015)
‘Ooredoo data breach brings legal action’, 3 September 2015, Myanmar Times.
326 Ooredoo response to Business and Human Rights Resource Centre’s request for a response to HRW’s
Report: Burma Telecom Winners Should Safeguard Users
327 Personal Data Protection Commission Singapore, “Legislation and Guidelines: Overview” (last accessed
August 2015).
328 Internal analysis prepared for the Institute of Human Rights and Business.
329 Human Rights Watch, “Response from Ms. Oldgard, Vice President, Head of Group Corporate
Responsibility, Telenor Group” (4 June 2013).
325
156
PAGE
CHAPTER 4.3: PRIVACY