Myanmar: Human Rights Analysis of Biometric Digital ID Systems However, there are important limits to the way the 2017 Privacy Law protects privacy. First, Article 2(c) defines privacy is a very limited and odd way to include the rights to freedom of movement, freedom of residence and freedom of speech of a citizen, in accordance with the law. While these rights are important, they are different from privacy, which this definition simply does not cover. In particular, and notably for our purposes, this definition does not include a right to privacy in relation to personal information, such as one’s biometrics or other identifying information. It is unclear how far other provisions in the Law remedy this problem. Second, the protections in the Privacy Law are by design weak. All that is required to overcome the Article 8 protections, including against surveillance and search and seizure, is “permission from the Union President or a Union-level Government body” (or a lawful order, permission or warrant). Thus, any Union-level public authority can essentially authorise itself to avoid these protections. Better practice is to require court authorisation for actions like surveillance and search and seizure. Third, there is no system of oversight for these protections, apart from the right to appeal to the courts, which is not something most Myanmar citizens can afford to do. International standards call for an accessible and independent administrative system of oversight for at least data protection regimes. Fourth, due to amendments in August 2020, the scope of the Privacy Law was limited to “competent authorities”, essentially government actors. This means that this Law does not provide any protection at all against breaches of privacy committed by private actors. Fifth, at least some of the protections are unclear. For example, the prohibition on surveillance is conditioned on the surveillance disturbing “their privacy and security or affect their dignity”. It is not clear what would trigger this. In any cases, most countries prohibit all official surveillance unless it can be justified, for example based on the need to investigate a crime. Myanmar also does not have any specific data protection rules. The 2017 Privacy Law does not establish any general rules around the collection and management of personal data, including biometric data, by government or private actors. All it does is prohibit officials from demanding or obtaining personal telephonic or electronic communications data from telecommunication operators without an authorisation, which is clearly not the same thing at all. The 2013 Telecommunications Law also does not provide for personal data protection, although it does prohibit unauthorised actors from accessing secure data without a court order.36 Ultimately, Myanmar lacks strong privacy protection or a regime governing personal data. This is a major legal gap which should be filled before any digital ID regime is established. 2.2 Background: Identification Cards in Myanmar 36 Telecommunication Law No. 31 of Myanmar, 8 October 2015, Articles 69, 75-7. Available in English at: http://www.asianlii.org/mm/legis/laws/tlhln312013511/. -8-

Select target paragraph3