on hold for such a change because of financial constraints, it is an
issue that must be closely monitored as if digitised the data stored
will have privacy implications which will need to be considered to
ensure that the right to privacy of citizens and their personal data
are protected.
Whilst some ICT companies,
such as Telenor, have developed and
adopted their own data retention policies, the lack of national
legislation regulating data retention, means that such internal
policies may not be strong enough to protect the privacy of users
and secure the freedom of services.42
Recommendations
34. We recommend that the government of Myanmar:
42
Ratify the International Covenant on Civil and Political Rights and
ensure relevant domestic legislation is adopted to domesticate the
rights established by the Covenant;
Recognise and take steps towards compliance with international human
rights law and standards by ensuring the application of the
following principles to communication surveillance, namely legality,
legitimacy, necessity, adequacy, proportionality and respecting
process of authorisation from a competent judicial authority; due
process, user notification, transparency, public oversight and
respect for the integrity of communications and systems as well as
ensuring safeguards against illegitimate access and right to
effective remedy;
Ensure there are appropriate controls to prevent the use of private
surveillance industry products to facilitate human rights abuses;
Immediately enact data protection legislation that complies with
international standards and establishes the creation of an
independent data protection authority to monitor, investigate and
sanction violations.
Calderaro, A., Digitalizing Myanmar: Connectivity Developments in Political Transition, Internet
Policy Observatory, pp. 10. Available at:
http://www.global.asc.upenn.edu/app/uploads/2014/12/Digitalizing-Myanmar.pdf