• • • § This should be repealed and replaced by an updated and much improved Data Protection Law. Repeal the Electronic Transaction Law & Computer Science Development Law § These are both very outdated and contain vague and harmful provisions and should be repealed and replaced by the new laws. Decriminalize defamation, including through the repeal of Penal Code Section 500; and Telecommunications Law Section 66(d) § Defamation should be treated as a civil liability issue. It should be consolidated into one law, outside the telecoms regulatory framework. MoTC should no longer play a role in this issue. Repeal Sections 40(a), 69, 75 & 77 of the Telecommunications Law & Section 17 of the Narcotics and Psychotropic Substances Law (amended 2018) § These broad and contradictory provisions on lawful interception should be repealed. 3. Drawing on Other Existing, More Detailed & Relevant Assessments in Developing Policy and Legal Frameworks We are aware of the following detailed assessments that have been done on Myanmar’s cyber situation, yet we did not see any reference to these in the consultants’ reports. The significant analysis and assessment in these documents should be taken into account: • • • UNCTAD Myanmar ETrade Readiness Rapid Assessment 2018 World Bank CyberCrime Capacity Building Assessment of Myanmar 2016 A cybersecurity assessment by the University of Oxford Global Cybersecurity Capacity Centre 4. Comments on Benchmarking Study Work Item 5.1 Benchmark Study Against Global Benchmark Indexes It is a very interesting and useful study to understand how Myanmar compares and to prepare Myanmar for the 4th Industrial Revolution (4IR). However, we have two overarching comments: • Gaps: The study was (necessarily) selective on the benchmarks chosen. However, the consultants did not focus on any aspect of digital rights, such as surveillance or interception. This is a significant gap. Numerous international organisations have recognized that protection of human rights must be a core part of cyber policies and laws. See for example the ITU’s very recent 2018 guidance for Governments (like Myanmar) on developing a cybersecurity strategy that highlights that human rights should be a core part of the strategy: o “Attention should be paid to freedom of expression, privacy of communications and personal-data protection. In particular, the Strategy should avoid facilitating the practice of arbitrary, unjustified or otherwise unlawful surveillance, interception of communications, or processing of personal data.” 4 • Lack of prioritisation: While the study identifies many gaps, it does not help in prioritizing which should be addressed first. We regret that the whole process of developing the policy and legal frameworks is so rushed and worry that important priorities will be overlooked. o MCRB suggests that a good data protection law should be a top priority. We also have a comment on specific sections: • Data Protection o Table 1: C1 Privacy and Data Protection is too limited in the issues it covers on data protection. Please see attached our Policy Briefing on Data Protection. o The APEC Privacy Framework falls short of international standards such as the OECD, the EU or the Council of Europe Convention 108 on data protection. The APEC Framework relies excessively on self-regulation and voluntary commitments, which 4 ITU (World Bank and others), Guide to Developing a National Cybersecurity Strategy (2018) 4

Select target paragraph3