4 4.3 protection requirements between the private and public sectors. 335 This is a notable difference between the GPDR and the PDPA in Singapore. As the UK NGO Privacy International notes in their submission to Myanmar’s Universal Periodic Review (UPR) at the Human Rights Council, whilst some ICT companies, such as Telenor, have developed and adopted their own data protection and retention policies, the lack of national legislation regulating data retention and the circumstances under which the Government can request access to user data means that such internal policies may not be strong enough to protect the privacy of users and secure the freedom of services. 336 In recent years, many other countries have passed data protection or data privacy legislation for the first time or updating them in response to the impact of ICTs on privacy. 337 In Asia, in addition to Singapore, Malaysia, and Taiwan have a “Personal Data Protection Act”. 338 The law of Japan is called “Act on the Protection of Personal Information”. 339 South Korea’s law is called the “Protection of Personal Data Act”.340 The equivalent law of the Philippines is called the “Data Privacy Act”. 341 International Human Rights Law on Privacy Every person has the right to privacy under international human rights law, including privacy of his/her communications. 342 Article 17 of the International Covenant on Civil and Political Rights (ICCPR) provides: “1. No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour and reputation. 335 ETNO, “ETNO supports the choice of the legal instrument for the future Data Protection framework” (4 July 2014). 336 Privacy International, “UN Universal Periodic Review, Stakeholder Report 23rd Session, Myanmar, The Right To Privacy In Myanmar” (March 2015), para 33. See also A Alderaro, “Digitalizing Myanmar: Connectivity Developments in Political Transition”, Internet Policy Observatory, (2014) pg. 10. 337 In the European Union, the suite of laws protecting personal data are currently being updatedIn 2012, the European Commission proposed to unify data protection in the EU under a single law, the General Data Protection Regulation (GDPR), to take into account technological developments such as social networking and cloud computing. A draft was presented at the European Parliament in March 2014. A final version is expected to be adopted by end 2015. See: Greens/EFA “EU General Data Protection Regulation State of play and 10 main issues by Jan Philipp Albrecht” (17 January 2015) and European Commission, “Commissioner Jourová: Concluding the EU Data Protection Reform is essential“ (28 January 2015). 338 See Malaysia and Taiwan Personal Data Protection Acts. 339 Government of Japan, Act on the Protection of Personal Information Act No. 57 (2003) 340 Korean LII, “Personal Information Protection Act” (last accessed August 2015). See also Francoise Gilbert, “Privacy v. Data Protection. What Is The Difference?“ (1 October 2014). 341 Republic of the Philippines Act No. 10173 2012 Data Privacy Act. 342 The right to privacy is also include in a wide range of international and regional human rights instruments, signalling its wide acceptance: Article 14 of the United Nations Convention on Migrant Workers; Article 16 of the UN Convention on the Rights of the Child; Article 10 of the African Charter on the Rights and Welfare of the Child; Article 4 of the African Union Principles on Freedom of Expression (the right of access to information); Article 11 of the American Convention on Human Rights; Article 5 of the American Declaration of the Rights and Duties of Man, Articles 16 and 21 of the Arab Charter on Human Rights; Article 21 of the ASEAN Human Rights Declaration; and Article 8 of the European Convention on Human Rights. See a compilation of privacy references in international and regional human rights instruments and see also http://gilc.org/privacy/survey/intro.html 158 PAGE CHAPTER 4.3: PRIVACY

Select target paragraph3