information against attacks will become a central issue to the Government of Myanmar’s internet governance policy. However, there is currently no legal framework in Myanmar that clearly defines what constitutes Personally Identifiable Information (PII) or stipulates any requirements around the collection, management, or transfer of personal data for companies. Hacking is criminalised under article 34 of the Electronic Transactions Law (No 5/2004). 426 A cyber-security/cyber-crime law is rumoured to be in development by either the Ministry of Information and Communication Technology or the Ministry of Home Affairs, both with likely support from the Myanmar Computer Federation (MCF). A specific timeline for the law’s development is unclear. In 2014 it was reported that the Government was seeking support and knowledge sharing opportunities from private companies in the cybersecurity space, such as Microsoft. 427 One of the high priority items under the 2011–2015 ICT Master Plan’s Infrastructure component is the establishment of a “Cyber Security Centre” 428, including the creation of a Cyber Information Act and Information Security Committee to select the specific technology (hardware and software) that would be used by the Cyber Security Centre. The follow up report to the 2005-2010 ICT Master Plan states the intention to build a Cybersecurity Protection Agency to protect Myanmar's critical information and infrastructure 429, whose role is to enhance Internet security and creating a safe Internet environment. It states the strategic objectives of this agency are to “Prevent cyber-attacks against Myanmar’s critical infrastructures; Reduce national vulnerability to cyber-attacks; Minimise damage and recovery time from cyber-attacks that do occur”. In addition, the agency would protect citizen’s personal information, provide guidance and training for Internet and information security, protect critical infrastructure by analysing and evaluating weaknesses in facilities, strengthening security for electronic government services and protection of public information. In 2015, MCIT published a draft ICT Master Plan for public consultation. 430 It outlined plans to create and publish a national cyber security policy by 2016, but did not repeat the specifics outlined in the 2011 follow up report. 426 Myanmar Electronic Transactions Law. 427 Htun Htun Minn, “Microsoft Tapped To Assist Myanmar Develop Cyber Security Measures” Myanmar Business Today (24 June 2014). 428 See, Ministry of Communications and Information Technology, “The Follow-Up Project of the Establishment of an ICT Master Plan: Final Report” (2011), pages 89-94. 429 Ibid, Section 3.6.1.6. 430 See MCIT, “Draft Telecommunications Masterplan” (7 August 2015) and MCRB, “Comments on the draft Myanmar Telecommunications Master Plan” (30 July 2015). CHAPTER 4.5: CYBER-SECURITY 185 4 4.5

Select target paragraph3