Annex to the Recommendations
Annex
to Recs
Lawful Interception and
Government Access to User
Data: The Characteristics of a
Rights-Respecting Model
Purpose
At the time of this report, a key part of Myanmar’s telecommunications framework on
lawful interception (LI) had yet to be finalised. Regulators need to define the limits of
lawful communications surveillance and clarify the capabilities and the uses of
communications surveillance technology used for lawful interception, which refers to
access of communications content in real time. The section below lays out the
characteristics of a framework that protects human rights to cover both lawful interception
and government access to user data. Both are considered to be acts of surveillance.
The distinction between lawful interception and access to user data is that lawful
interception covers real time access to communications and access to user data is about
historical data, known as “communications data”. 9 In many countries the laws governing
what can be accessed, and when, make distinctions between the two, with a higher
burden of proof to authorise lawful interception.
In recent decades, both physical and communications surveillance was widely conducted
in the absence of a legal framework or oversight. There is an opportunity for the
Government of Myanmar to develop legal protections that respect human rights, as part of
the wider ‘people-centred’ reforms, and to take a leadership position within the region.
Such a lawful interception framework will build trust in the use of Myanmar’s ICTs among
users, service providers and other governments by being robust and aligned with
international human rights standards. 10
As outlined above, the only existing legal framework is Article 75 of the 2013
Telecommunications Law, which allows interception but does not clearly articulate
definitions or justifications. 11 The Government of Myanmar has asked the European
Union for technical assistance in drafting implementing legislation. To assist this drafting
9
Communications Data (sometimes referred to as metadata) is basically everything but the content and
includes telephone numbers of both the caller and the recipient, the time and duration of a call, unique
identifying numbers (each subscriber is allocated one, as is each mobile device), email addresses, web
domains visited and location data. This information is important as it builds up a detailed picture of a person’s
life and movements, so that often intercepting the content of a call or email is not necessary. In contrast to
content, there are often weaker legal protections around interception of stored communications data.
10 See for example: See for example the Global Conference on Cyberspace 2015, the Global Commission on
Internet Governance
11 Article 75 states: “The Union Government may, as may be necessary, direct to the relevant organization for
enabling to obtain any information and telecommunications which causes harm to national security and
prevalence of law without affecting the fundamental rights of the citizens.” See unofficial English translation of
the Telecommunications Law (2013)
ANNEX TO THE RECOMMENDATIONS:
LAWFUL INTERCEPTION AND GOVERNMENT ACCESS TO USER DATA
35