ANALYSIS OF THE PROVISIONS OF THE DRAFT CYBER SECURITY LAW
Chapter IX
Section 31
An Online Service Provider in Myanmar shall provide all or any part A. Section 30 of the Draft Cyber Security Law requires Online Service Providers
of the information prescribed in Section 30 upon the request of a
to store for three (3) years information of its users such as (username, IP
person or organization assigned by any existing laws.
address, telephone number, ID No. etc.).
B. Upon being requested by the governmental authorities, the Online Service
Provider will be required to provide all such information to the
governmental authority.
C. The governmental authority does not need to provide any reasoning or a
warrant/sanction from a judicial body of competent authority to the Online
Service Providers to share such information.
Chapter XI
Section 41
Chapter
XII
Sections
47 and 48
Conclusion:
Therefore, this provision may also be seen as a breach of privacy as the
governmental authorities can obtain user information without providing any
justification or valid sanction/warrant from a judicial body of competent
authority.
Section 41:
A. Under Section 41, the term ‘authorised person’ has not been defined under
Interception made to a computer program or data by a person
the Draft Cyber Security Law and thus there is a possibility that ‘authorised
with any of the following methods shall be deemed an illegal
person’ may be deemed to be a ‘person’ or ‘authority’ as designated by the
interception:
Committee/Department under the Draft Cyber Security Law. In such a case
(a) If the person is not the authorised person for a specific
interception made to a computer program’ by such person will not be
computer system;
deemed to be illegal.
(b) If the person is not the authorised one to decide whether
to make the aforementioned interception or not;
B. Further, sections 47 and 48 make interceptions by the government
(c) If the person is not the one who has a permission from a
authorities legal and the companies and organizations are required to
responsible person to make interceptions for a specific
prepare and arrange for governmental authorities to intercept.
computer system.
C. The provisions are broad enough to include surveillance through any online
Section 47:
devices and thus the government authorities may have the right to
The State Administration Council shall grant the right to the
intercept a computer/a mobile phone or any such device without the
relevant person or organization in order to intercept as prescribed
knowledge or the consent of the owner of such data/device. However,
in any existing law.
there is no clear indication whether ‘snooping’ would be a part of such
interception. There is no express restriction under Draft Cyber Security Law
Section 48:
either.
7
12 February 2021