4
4.4
that their accounts may have been hacked by “state-sponsored attackers”. 388 It is unclear
if the purpose of these attacks were to gain access to journalist’s emails and identify
sources, or to stem the flow of information to and from Myanmar. It was also reported that
government agents visited cybercafés to “install some software”, widely believed to be
‘keylogging’ software, which records and stores keystrokes for later analysis. Some café
owners have put up signs warning customers not to use the Internet for “political reasons”.
It is also unclear what kind of relationship Myanmar’s existing intelligence agencies have
with foreign counterparts, and what kind of intelligence exchange agreements exist. It is
thought that Embassies routinely reported on the activities of the diaspora. 389
The Legal Framework in Myanmar
There are currently few protections in Myanmar’s legal framework to prevent the kind of
pervasive surveillance previously conducted by intelligence agencies and about which
there is justifiable concern. It is unclear under which legal regime the existing intelligence
agencies are operating, what their remit is and how they are exercising their powers.
Although Article 357 of the 2008 Constitution does provide for privacy 390, there are no
privacy protections in national legislation. The existing legal framework referring to
surveillance is vague. Article 75 of the 2013 Telecommunications Law 391 grants
unspecified government agents the authority “to direct the organisation concerned as
necessary to intercept, irrespective of the means of communication, any information that
affects the national security or rule of law”. Although the clause adds this should be
undertaken without impacting the fundamental rights of citizens, there are no further
details on the process or privacy protections.
Most states have a specific legal framework in place to govern instances where
interception of communications is permitted in real time (lawful interception). However
Myanmar currently has no specific legal framework or regulations governing lawful
interception, leaving an important gap in the regulatory framework. The MCIT has
confirmed its interest in developing a law in accordance with international standards. It
has committed to a public consultation of draft lawful interception regulations. 392 One of
the current telecommunications operators, Telenor, has stated publicly that they will not
respond to any interception requests from law enforcement officials until the legal
framework is in place. 393
The EU has agreed to provide technical support to the Government to develop its
regulations in line with human rights. The programme of work will come within the Council
388
Thomas Fulller, “E-Mails of Reporters in Myanmar Are Hacked“ New York Times (10 February 2013).
Andrew Selth, “Burma’s Security Forces: Performing, Reforming or Transforming?“ Griffith Asia Institute,
Griffith University, Australia (2013), pg. 18.
390 “357. The Union shall protect the privacy and security of home, property, correspondence and other
communications of citizens under the law subject to the provisions of this Constitution.“
391 See unofficial English translation of the Myanmar 2013 Telecommunications Law.
392 In November 2013, MCIT published draft proposed rules, stating: “The Ministry will be drafting other rules
and procedures on a variety of issues such as standardization, type approval, and lawful interception in due
time. Such rules and procedures also will be subject to a public consultation process.“ MCIT, “Proposed Rules
for Telecommunications Sector Relating to Licensing, Access and Interconnection, Spectrum, Numbering, and
Competition” (4 November 2013), Section I, B5 (pg. 5).
393 Telenor, “Myanmar sustainability presentation” (19 August 2014), pg. 8 of the transcript.
389
174
PAGE
CHAPTER 4.4: SURVEILLANCE –
LAWFUL INTERCEPTION & OTHER SURVEILLANCE METHODS