ANALYSIS OF THE PROVISIONS OF THE DRAFT CYBER SECURITY LAW
Chapter
VII
assigned duties by the Central Committee in respect of
Cybersecurity, Cyber-attacks, Cyber-terrorism, Cyber
Misuse, Cyber Incident and Cybercrimes;
b) Any detection, inspection, collection of news, litigation and
submission of the evidence to any court conducted by the
government departments, investigation teams, or
regulatory bodies assigned the duties by the Central
Committee according to criminal cases;
c) Any detection, inspection, collection of news and
coordinating of information that are conducted according
to the relevant Cybersecurity and Cybercrime related cases
if such cases impact the country’s sovereignty, stability and
peace; and
d) The administrative power shall be determined by the
Central Committee or Related Ministry or Department in
the course of administrating the cases prescribed in subsection (c).
Protecting Critical Information Infrastructure
Section 16:
Sections The Critical Information Infrastructure shall be as following:
16, 17 and
a) e- Government Services,
20
b) Electronic information and infrastructure related to finance;
c) Electronic information and infrastructure related to water
resources;
d) Electronic information and infrastructure related to
transportation;
e) Electronic information and infrastructure related to
communication;
f) Electronic information and infrastructure related to public
health sector;
g) Electronic information and infrastructure related to
electricity and energy;
h) Electronic information and infrastructure related to natural
resources; and
12 February 2021
Considering the wide scope of the provisions, the management of personal
data for an enlarged scope of enforcement activities vests with the
governmental authorities where personal data would necessarily need to be
transferred to the governmental authorities.
A. Section 16 gives the definition of Critical Information Infrastructure as
decided and designated by the government authorities.
B. Further, under Section 17 it may be interpreted that unfettered power is
given to the governmental authorities under which the governmental
authorities may amend the list of the Critical Information Infrastructure
as from time to time.
C. In accordance with this chapter, the governmental authorities may lay
down policies for the storage and maintenance of the facts and
information that are related to the Critical Information Infrastructure.
D. Most importantly, under Section 20, the person responsible for the
processing and maintaining of the Critical Information Infrastructure,
shall keep the facts and information that are related to the Critical
Information Infrastructure, at the place determined and approved by the
Ministry. Therefore, the effect of this is two-pronged- all such critical
information (deemed to be) shall be kept inside Myanmar and such data
may have unrestricted access by the governmental authorities.
3