4 4.3 Current Legal Framework and Gaps Although the Constitution declares that privacy will be protected under the law, currently there are no separate privacy laws in Myanmar. In addition, there is no legal framework on data protection or data privacy. A Consumer Protection Law was adopted in March 2014 but its focus is on food safety 345. As part of its ASEAN membership, Myanmar has agreed to develop best practices on data protection by 2015 but there have been no announcements to date on forthcoming plans. 346 Civil society have highlighted that Myanmar has an opportunity to leapfrog its peers in regulating privacy, data protection, Internet governance, freedom of speech/expression (partially due to the lack of legacy regulations) and to ensure that the push to improve access does not compromise these other issues. A civil society coalition suggested a proactive discussion among Government and civil society and operators, rather than waiting until the Government demands ‘private’ data (for purposes of national security). 347 The integrity of technical processes for protecting user data in Myanmar is unclear, particularly in regards to Myanmar’s National Certificate Authority. Certificates have significant impacts on user privacy, as they are used to verify a chain of trust whenever a user submits personal information (such as an account username and password) to an online service. These certificates are used to verify the website’s validity and prevent users from submitting data to an unauthorised third party. Myanmar’s certificate authority was established under the Electronic Transaction Law (No.5/2004). 348 Policies and practices related to Myanmar’s existing certificate authority are unclear. Websites for Myanmar’s Root Certification Authority, and Yatanarpon Certificate Authority are currently offline. As the Internet now represents a global community, a lack of clear processes and transparency among certificate authorities puts users’ private information at risk and promotes distrust. Recently, Google and Mozilla took steps to de-trust all certificates signed by China’s National Certificate Authority. 349 Privacy International also noted in the UPR submission, “In 2013, the government announced that it would replace the paper National Registration card with a smarter digital identification card to include biometric data. Whilst it seems plans have been put on hold for such a change because of financial constraints, it is an issue that must be closely monitored as if digitised the data stored will have privacy implications which will need to be considered to ensure that the right to privacy of citizens and their personal data are protected.” 350 345 ‘Burma President approves consumer protection law’ Irrawaddy, 17 March 2014 ZicoLaw, “ASEAN Insights, Personal Data Protection” Issue 4 (7 November 2013). 347 Verena Weber “Diversifying the global content and apps market” (last accessed August 2015). 348 Myanmar Electronic Transactions Law (2004). 349 In April 2015, both Google and Firefox stopped trusting certificates issued by China Internet Network Information Center (CNNIC). Google noted that CNNIC had signed fake certificates for Google domains, while Firefox noted that CNNIC lacked documented PKI practices. For additional information please see: Emil Protalinski, VentureBeat “Google and Mozilla decide to ban Chinese certificate authority CNNIC from Chrome and Firefox“ (April 2nd 2015) 350 Privacy International, “UN Universal Periodic Review, Stakeholder Report 23rd Session, Myanmar, The Right To Privacy In Myanmar” (2015), para 33. 346 160 PAGE CHAPTER 4.3: PRIVACY

Select target paragraph3