Recs Groups at Risk:  Develop a more comprehensive framework for child protection, including relevant provisions for child safety online. The Government should consider asking companies and other governments to share expertise and good practices from other jurisdictions.  Consider including protections for women against online harassment in the forthcoming law on violence against women. See Chapter 4.8 on Groups at Risk for further information. 4. Adopt a rights-respecting lawful interception model and maintain open access to the Internet to ensure Myanmar does not become a modern “surveillance state”. UN Guiding Principles on Business and Human Rights: The State-Business Nexus 5. States should exercise adequate oversight in order to meet their international human rights obligations when they contract with, or legislate for, business enterprises to provide services that may impact upon the enjoyment of human rights. 6. States should promote respect for human rights by business enterprises with which they conduct commercial transactions. The Government has previously used ICTs to conduct surveillance of its citizens, both within the country and abroad. A modern legal framework limiting Government surveillance is overdue. (See Chapter 4.4 on Surveillance for further information). Key Points for Implementation  Follow through on the Government’s stated commitment to align the forthcoming lawful interception regulations or framework to international human rights standards. See the Annex to the Recommendations for key considerations for each step of the interception process that should be incorporated into the forthcoming regulations. As it has with other draft ICT laws and regulations, MCIT should make any draft regulation or framework on lawful interception available for public comment for at least three weeks, and widely publicise the consultation process.  Publicly commit to prohibit “mass surveillance” (commonly understood to refer to the bulk access and/or collection of many users’ communications without prior suspicion of criminal activity). Such a commitment should also be incorporated into the forthcoming lawful interception regulation or framework (which should authorise only targeted interception where there is a prior suspicion of recognisably criminal activity).  Refrain from purchasing and utilising invasive and often unregulated communications surveillance technology to carry out communications surveillance. Once Myanmar intelligence agencies have such capabilities, it will be much more difficult to eliminate or regulate their use. It is important for the Government, and the ICT companies that may be subject to lawful intercept orders, to make the distinction between software and other tools that comply with international standards on lawful interception, and products that fall below international standards because they are unregulated and pose a risk to human rights. 5. Improve data protection standards and cybersecurity. Myanmar currently does not have any requirements or standards on data protection for companies. A failure to protect people’s personal information and identity can pose significant risks to the right to privacy and security. As Myanmar puts in place its 18 PAGE RECOMMENDATIONS TO THE GOVERNMENT OF MYANMAR

Select target paragraph3