• • • • § Again, we are not experts on E Commerce and defer to the technical expertise of the TPRC team on the technical matters. Law on Cyber Security § This law should have the objective of protecting individuals, devices and networks while at the same time protecting the freedom of expression and privacy in particular. § We would urge that Myanmar direct its limited sources to investing in defensive capabilities to detect and manage threats in order to build trust in business and government services. § Please see the attached Policy Briefing on Cyber Security and Cyber Crime for our suggestions on what should be included and what should not. Law on Cyber Crime § Cyber security and cyber crime are different and require distinct approaches. Cyber crime is a criminal law matter and should be treated as a criminal law, not grouped together with cyber security. § Please see the attached Policy Briefing on Cyber Security and Cyber Crime for our suggestions on what should be included and what should not. § In particular, a cyber crime law should not be used to enhance surveillance, as has occurred in some countries without democratically elected governments such as Vietnam. § Any cyber crime provisions should be complemented by human rights safeguards in criminal matters. Law on Data Protection § Data protection is at the heart of all the actions above and is critical to building trust in use of E-Government and E-Commerce systems and facilitating e-connections with other countries. § Myanmar has an opportunity to set an example for the region with a data protection law that recognizes privacy rights and has strong accountability mechanisms. The Benchmark Report 5.2 covered the EU’s new data protection law,2 which is rapidly becoming the global standard. Japan and Korea are seeking to demonstrate that their systems are equivalent.3 § For detail, please see our attached our Policy Brief on Data Protection that draws on the EU’s GDPR and that sets out what should be covered in a modern, updated data protection law. Law on Lawful Interception § This law should be based on an objective and presumption of protecting freedom of expression while permitting restrictions, monitoring and surveillance only in narrowly defined circumstances as set out in international human rights law for protection of the population. § Myanmar needs one consolidated, clear law on lawful interception that incorporates human rights protections. It should clarify, make transparent and restrict the role of the Social Media Monitoring Centre. Please see our attached Recommendations on a rights-respecting lawful interception framework. § This should be accompanied by the repeal of existing lawful interception provisions in the Telecoms Law and Narcotics Law. c) Repeal of Existing, Outdated Laws and Contradictory Provisions in Laws It was not clear from the consultation whether the consultants have been specifically tasked with making recommendations on amending or repealing existing laws. It will be very important to repeal contradictory existing laws or sections of existing laws to ensure that relevant government ministries, companies and other stakeholders have legal clarity. Leaving existing, outdated laws in place would cause confusion and undermine the whole purpose of putting new, updated legal framework. • Repeal Citizen Privacy and Security Law 2 The EU General Data Protection Regulation (GDPR) https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacyprotection-personal-data-non-eu-countries_en 3 3

Select target paragraph3