collected, and only for as long as the purpose exists. The companies in Telenor Group will ensure that:  “Persons we process data about are properly informed when their personal data is being collected;  All persons we process information about have the right to obtain relevant information on the processing of personal data related to them;  Persons we process and store data about are able to exercise user choice and control and have appropriate rights to correct or delete their personal data;  Personal data are kept in a form which permits identification of persons for no longer than is necessary for the purposes for which the data were collected;  Transfer of personal data does not compromise an adequate level of protection;  Risk based, planned and systematic measures are undertaken to ensure satisfactory information security in connection with the processing of personal data;  The processing of personal data is properly documented;  Appropriate training is given to relevant personnel involved in the processing of personal data.” 330 Telenor specifically cited its participation in privacy projects with the GSMA (where it is a full member), 331 and the European Telecommunications Network Operator’s Association (ETNO) working group on data protection 332. In their Mobile Privacy Principles, the global industry association GSMA defines personal data more specifically than Singapore does in the PDPA. While acknowledging that personal information ultimately depends on its local legal definition, the GSMA defines personal data as: 333  “Any data that is collected directly from a user (e.g. entered by the user via an application’s user interface and which may include name and address, credit card details);  Any data about a user that is gathered indirectly (e.g. mobile phone number, email address, name, gender, birth data, location data, IP address, IMEI, unique phone ID);  Any data about a user’s behavior (e.g. location data, service and product use data, website visits);  Any user-generated data held on a user’s device (call logs, messages, user-generated images, contact lists or address books, notes, and security credentials.” The ETNO works closely with the GSMA, and focuses on the review of legal frameworks impacting data protection in Europe. In terms of data protection and privacy, the draft EU General Data Protection Regulation (GPDR) is regarded as providing high standards in the protection of personal data by the international community. 334 As part of that process, the ETNO has supported the notion that there should be no preferential treatment in data 330 Telenor Group, “Our Privacy Position” (last accessed August 2015). GSMA, “Mobile and Privacy” (last accessed August 2015). The GSMA is an industry association representing mobile operators worldwide. 332 ETNO, “Data Protection, Trust & Security” (last accessed August 2015). 333 GSMA, “Mobile Privacy Principles” (2012). 334 See European Commission, “Proposal for a Regulation Of The European Parliament And Of The Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation)” (25 January 2012). The legislation is not without criticism from global technology firms such as Google who have recently complied with users’ “right to be forgotten and to erasure” requests under Article 17 of the GPDR. Telenor Myanmar is a wholly owned subsidiary of the Telenor Group per the license requirements stipulated by MCIT. Telenor Group is headquartered in Oslo, Norway. Norway is not a member state of the European Union but has implemented the EU Data Protection Directive 95/46/EC. 331 CHAPTER 4.3: PRIVACY 157 4 4.3

Select target paragraph3