Myanmar: Note on New Draft Cyber Security Law
•
Very significant powers, including regulatory powers over freedom of expression and
the power to impose sanctions, are allocated to bodies such as the Central and Steering
Committees which are not independent of the military regime, the exercise of those
powers is not subject to appropriate either procedural or substantive constraints, and
the decisions of those bodies are not subject to court review.
•
Broad-ranging and vaguely-worded restrictions on the content of what may be
disseminated online are imposed (and applied by the bodies noted above).
•
A number of other (i.e. beyond content) criminal offences are created which are again
vague, are repetitive with only minor linguistic differences between provisions, and
lack the appropriate (and specific) intent requirements that would be needed to justify
such prohibitions.
•
A number of onerous obligations are imposed on digital service providers, defined
very broadly, as well as sub-sets of that broad category (such as “cyber security service
providers”), some of which are clearly designed to further military control of digital
communications, some of which are unreasonably burdensome for service providers
and many of which simply fail to take into account the working reality of international
service providers.
•
The scope of special obligations ostensibly designed to protect critical information
infrastructure is far too broad both in terms of the way that infrastructure is defined
and the bodies which may be deemed to be subject to these rules.
Our February 2021 Analysis also included a critique of the rules in the February 2021 version
of the draft Law on personal data protection. These rules have been retained, essentially
verbatim, in the current version of the draft Law. We note that these rules are already part of
the current legal framework of Myanmar as they were included, again essentially verbatim,
in the amendments to the Electronic Transactions Act (ETA) which were introduced in
February 2021.4 While the current draft of the Cyber Security Law would repeal the ETA, it
remains the case that this is a fundamentally limited set of protective rules on personal data
protection, while other rules in the draft Law require this data to be stored locally and to be
retained for “up to three years” (which we understand as meaning for three years), both of
which are not legitimate under international law, as well as to be shared with an “assigned
person or authorised organisation requested under any existing law”, without adequate
protections for this being put in place.
Those amendments were introduced around the same time as the February 2021 draft Cyber Security Law was
withdrawn and were drawn directly from that draft Law.
4
The Centre for Law and Democracy is a non-profit human rights organisation working
internationally to provide legal expertise on foundational rights for democracy.
2