is not sufficient to regulate company data processing. These other, updated international convention protect people’s privacy as a matter of right. That is why countries such as Korea and Japan are working towards being recognised as having an equivalent level of data protection to the EU. • Cybersecurity and cybercrime o Again, we think the benchmarking on this area is too limited. In addition, cyber security and cyber crime are not the same and should be treated separately. Please see attached our Policy Briefing. We do however, agree with the brief recommendations on cyber crime in the report. o In addition, as noted above, the report does not take account of the World Bank assessment of Myanmar on cyber crime. • Electronic Authentication o On e-authentication we do not think Myanmar should be moving ahead on digital identification unless the Government: § has a data protection law in place that provides robust protection for data gathered by the Government § is clear on the objectives and purposes of the developing digital IDs § has carefully considered the pros and cons of different systems, considering, for example the serious data breaches that the Indian Aadhaar system has already experienced § will provide digital IDs to all on a non-discriminatory basis. • 5. We welcome the coverage of open government data and consumer protection. Comments on Benchmarking Study Work Item 5.2 Benchmark Study of Cyber Laws by Jurisdiction • We agree with the overall assessment of the legislative gaps in Myanmar. • We re-emphasise that the study had found no other countries with an overall, allencompassing cyber law as is currently proposed in Myanmar. That is for good reason as each of these areas is complex and should be treated appropriately in specific but coordinated legislation. The study notes that “an omnibus law has many limitations” and that many of the issues can be dealt with through policy or other non-legislative approaches. • Hong Kong is considered to be the most forward-looking data protection regime in the region, whereas Singapore has come under consistent criticisms from the digital rights community for its failure to adequately protect privacy. Attachments • • • • MCRB Policy Brief: The Legal and Policy Framework for Information Communication Technology (ICT) In Myanmar: Implications For Human Rights MCRB Policy Brief Cyber Security and Cyber Crime: Issues For Myanmar MCRB Policy Brief: A Data Protection Law That Protects Privacy: Issues For Myanmar MCRB Recommendations: A Rights-Respecting Lawful Interception Framework (see pp. 35-39) 5

Select target paragraph3