Myanmar: Digital Content Proposals and likely effect of posing a serious risk of harm to national security or to the maintenance of law and order. Note: As with the previous provision, the requirements of intent and creating an actual risk of serious harm have been added. Once again, references to “community peace and tranquillity or national solidarity or national economy or national culture” have been removed as being overbroad and unnecessary. 34. Whoever commits any of the following acts by using electronic transactions technology shall on conviction be punished with imprisonment for a term which may extend to 5 years or with a fine or with both: (a) hacking, modifying, destroying, or causing damage to an electronic record, an electronic data message or the whole or part of a computer programme in the absence of any express or implied authorisation and with the intent of causing harm to the legitimate interests of a third party; Note: Stealing is already a crime pursuant to the Penal Code, for example, sections 378-382. Sending has been removed because this is not a new (digital) phenomenon and the rare cases in which it might be illegal (such as because it is a threat or an attempt to blackmail) are already addressed in the Penal Code. ‘Altering’ is already covered by ‘modifying’ and the notion of ‘causing loss’ is covered by ‘causing damage’. The defences of having authorisation and the need to cause harm to the legitimate interests of a third party have been added, and the intent requirement has been clarified. (b) intercepting of any private communication within the computer network, using or giving access to any person of any fact in any private communication in the absence of any express or implied authorisation and in a way that poses a serious risk of harm to the legitimate interests of a third party, including privacy; and Note: The scope of this has been limited to private communications, since it is legitimate to distribute public communications. The requirement of permission has been replaced by the idea of an absence of either express or implied authorisation. It is clearly not reasonable to require permission to send someone an email; implied authorisation is enough. A requirement of causing harm to the legitimate interests of a third party has also been added since even an unauthorised action which fails to cause any harm should not be punished. (c) communicating to any other person directly or indirectly a security number, password or electronic signature of any person in the absence of any express or implied authorisation and in a way that poses a serious risk of harm to the legitimate interests of a third party, including privacy. Note: The requirement of permission or consent has been replaced by the idea of an absence of either express or implied authorisation. Forwarding emails often involves forwarding a digital signature and this should not require permission; implied authorisation is enough. As with the previous provision, a requirement of causing harm to a legitimate interest has also been added. (d) [Repealed in favour of section new 34A] 34A. The distribution of content to third parties using electronic transactions technology shall be deemed to be included within the meaning of the phrase “makes -7-

Select target paragraph3