In 2014, the Myanmar Government held a public consultation on the issue of mandatory
registration of personal information of SIM card and mobile phone purchasers’ cards. 351
This indicates the Government may not be considering the data privacy implications of its
telecommunications regulations. The mandatory registration of SIM cards in other
jurisdictions has shown that there are a range of unintended consequences, prompting
other governments to consider and then reject the idea. 352 MCIT proposed that mandatory
SIM registration would enable new and innovative services (e.g., mobile money and
mHealth services). However, where such sensitive data is exchanged, these services
should be required to register for extra mobile-enabled services; such registration should
always be service focused. Mandatory registration could act as a barrier to accessing
mobile services because people may not have an address or registration number or may
be reluctant to provide personal details due to distrust of the Government.
MCIT is yet to define its procedures for the lawful interception of user communications, or
access to communications data (See Chapter 4.4 on Surveillance), though it has
committed to doing so. This is a crucial and important procedure that requires further
consultation and consideration before any mass collection of customer data through
mandatory registration is considered. Without data retention requirements, large amount
of data, held for an indefinite amount of time, would be susceptible to unlawful uses,
including unauthorised surveillance, leaks, and security breaches resulting in negative,
and in some cases, severe impacts on the enjoyment of the right to privacy.
B. Field Research Findings
Privacy Policies by Myanmar Companies
Human Rights Implicated: Right to privacy
Field Assessment Findings
MCRB reviewed the websites of 73 companies as part of the Transparency in
Myanmar Enterprises project (TiME) (or ‘Pwint Thit Sa’ in Burmese) to collect a
small sample of the use and disclosure of privacy policies and protections by
Myanmar companies. 353
Of the 73 company websites reviewed, only 6 explicitly explaine how they
handled and used customers’, users’, workers’ and others’ data.
Only 1 company actually adopted a formal privacy policy outlining in detail its
security and data handling measures.
4 company’s statements were contained within other operational policies,
such as a code of conduct or code of ethics.
1 ISP explicitly did not commit to any level of data protection, instead
confirming that it may monitor its service from time to time and disclose any
information regarding customers or their use as required under national law,
regulations, Government requests, or that it saw fit.
A majority of the companies reviewed presented no accessible information
about the ways in which they handle and use data.
351
See: MCRB, “MCRB calls for Further Consideration of the Impacts of Requiring SIM Card Registration in
Myanmar” (21 May 2014).
352 Ibid.
353 MCRB, ”Pwint Thit Sa Project (TiME)“ (2015).
CHAPTER 4.3: PRIVACY
161
4
4.3