Photo 4 Panel Discussion, MDRF 2019 It was suggested that digital ID does not need to be all encompassing and instead could be better thought of as “ID stacks” – where different parts of the ID stack are used for different purposes – as in everyday life. Further issues raised were related to quality and standardization of the equipment used for these initiatives. Early cost- cutting without an understanding of the wider system may result in "technical debt", where the legacy is a harmonization problem across different types of systems and hardware which in the end results in higher spending. It was recommended that Myanmar identity the right international standards for its planned systems first and to proceed cautiously rather than jumping into a digital ID programme. Session 2 on ‘Strengthening Cyber Security and Fighting Cyber Crime: getting the principles and the framework right’ began with an overview from World Bank funded consultants to the Government on ongoing work to develop an overarching cyber policy and legal framework that will cover E-Government, E-commerce and Cybersecurity. This included a benchmark study comparing Myanmar to other countries in the region and the EU, and against international benchmarks, to identify the gaps that need to be addressed in the policy and legal framework. Another panelist noted that some countries such as Vietnam should not be used as a benchmark given their use of legislation for surveillance and suppressing freedom of speech, rather than for the purpose of cyber security. Speakers also highlighted differences between cyber security and cyber-crime and questioned the choice of addressing both under a single piece of legislation. The variety of cybercrimes cyber-dependent and cyber-enabled - should be identified; it is not sufficient to simply implement the recommendations and outcomes of the Budapest Convention without considering additional safeguards that need to be in place to protect online freedoms. The importance of Myanmar building on international standards was stressed. It should directly engage in international forums where cyber security standards are developed. Myanmar’s human resources in this area needed development. Session 3 on ‘Data Protection: balancing convenience, privacy and security’ included a presentation from the government representative on plans for policy and regulation of data 9

Select target paragraph3