4
4.3
Current Legal Framework and Gaps
Although the Constitution declares that privacy will be protected under the law, currently
there are no separate privacy laws in Myanmar. In addition, there is no legal framework
on data protection or data privacy. A Consumer Protection Law was adopted in March
2014 but its focus is on food safety 345. As part of its ASEAN membership, Myanmar has
agreed to develop best practices on data protection by 2015 but there have been no
announcements to date on forthcoming plans. 346 Civil society have highlighted that
Myanmar has an opportunity to leapfrog its peers in regulating privacy, data protection,
Internet governance, freedom of speech/expression (partially due to the lack of legacy
regulations) and to ensure that the push to improve access does not compromise
these other issues. A civil society coalition suggested a proactive discussion among
Government and civil society and operators, rather than waiting until the Government
demands ‘private’ data (for purposes of national security). 347
The integrity of technical processes for protecting user data in Myanmar is unclear,
particularly in regards to Myanmar’s National Certificate Authority. Certificates have
significant impacts on user privacy, as they are used to verify a chain of trust whenever a
user submits personal information (such as an account username and password) to an
online service. These certificates are used to verify the website’s validity and prevent
users from submitting data to an unauthorised third party. Myanmar’s certificate authority
was established under the Electronic Transaction Law (No.5/2004). 348 Policies and
practices related to Myanmar’s existing certificate authority are unclear. Websites for
Myanmar’s Root Certification Authority, and Yatanarpon Certificate Authority are currently
offline. As the Internet now represents a global community, a lack of clear processes and
transparency among certificate authorities puts users’ private information at risk and
promotes distrust. Recently, Google and Mozilla took steps to de-trust all certificates
signed by China’s National Certificate Authority. 349
Privacy International also noted in the UPR submission,
“In 2013, the government announced that it would replace the paper National
Registration card with a smarter digital identification card to include biometric data.
Whilst it seems plans have been put on hold for such a change because of financial
constraints, it is an issue that must be closely monitored as if digitised the data
stored will have privacy implications which will need to be considered to ensure that
the right to privacy of citizens and their personal data are protected.” 350
345
‘Burma President approves consumer protection law’ Irrawaddy, 17 March 2014
ZicoLaw, “ASEAN Insights, Personal Data Protection” Issue 4 (7 November 2013).
347 Verena Weber “Diversifying the global content and apps market” (last accessed August 2015).
348 Myanmar Electronic Transactions Law (2004).
349 In April 2015, both Google and Firefox stopped trusting certificates issued by China Internet Network
Information Center (CNNIC). Google noted that CNNIC had signed fake certificates for Google domains, while
Firefox noted that CNNIC lacked documented PKI practices. For additional information please see: Emil
Protalinski, VentureBeat “Google and Mozilla decide to ban Chinese certificate authority CNNIC from Chrome
and Firefox“ (April 2nd 2015)
350 Privacy International, “UN Universal Periodic Review, Stakeholder Report 23rd Session, Myanmar, The
Right To Privacy In Myanmar” (2015), para 33.
346
160
PAGE
CHAPTER 4.3: PRIVACY