Myanmar: Human Rights Analysis of Biometric Digital ID Systems
However, there are important limits to the way the 2017 Privacy Law protects privacy. First,
Article 2(c) defines privacy is a very limited and odd way to include the rights to freedom of
movement, freedom of residence and freedom of speech of a citizen, in accordance with the law.
While these rights are important, they are different from privacy, which this definition simply does
not cover. In particular, and notably for our purposes, this definition does not include a right to
privacy in relation to personal information, such as one’s biometrics or other identifying
information. It is unclear how far other provisions in the Law remedy this problem.
Second, the protections in the Privacy Law are by design weak. All that is required to overcome
the Article 8 protections, including against surveillance and search and seizure, is “permission
from the Union President or a Union-level Government body” (or a lawful order, permission or
warrant). Thus, any Union-level public authority can essentially authorise itself to avoid these
protections. Better practice is to require court authorisation for actions like surveillance and search
and seizure.
Third, there is no system of oversight for these protections, apart from the right to appeal to the
courts, which is not something most Myanmar citizens can afford to do. International standards
call for an accessible and independent administrative system of oversight for at least data
protection regimes.
Fourth, due to amendments in August 2020, the scope of the Privacy Law was limited to
“competent authorities”, essentially government actors. This means that this Law does not provide
any protection at all against breaches of privacy committed by private actors.
Fifth, at least some of the protections are unclear. For example, the prohibition on surveillance is
conditioned on the surveillance disturbing “their privacy and security or affect their dignity”. It is
not clear what would trigger this. In any cases, most countries prohibit all official surveillance
unless it can be justified, for example based on the need to investigate a crime.
Myanmar also does not have any specific data protection rules. The 2017 Privacy Law does not
establish any general rules around the collection and management of personal data, including
biometric data, by government or private actors. All it does is prohibit officials from demanding
or obtaining personal telephonic or electronic communications data from telecommunication
operators without an authorisation, which is clearly not the same thing at all. The 2013
Telecommunications Law also does not provide for personal data protection, although it does
prohibit unauthorised actors from accessing secure data without a court order.36
Ultimately, Myanmar lacks strong privacy protection or a regime governing personal data. This is
a major legal gap which should be filled before any digital ID regime is established.
2.2 Background: Identification Cards in Myanmar
36
Telecommunication Law No. 31 of Myanmar, 8 October 2015, Articles 69, 75-7. Available in English at:
http://www.asianlii.org/mm/legis/laws/tlhln312013511/.
-8-