• Undertake a data protection impact assessment when surveillance cameras are deployed, camera
positions changed or new technological capabilities such as automatic facial recognition are used.
• Where CCTV is in use, place clear signs in English and Myanmar to inform the public that they may be
recorded.
• Control access to recordings. Establish SOPs including escalation to senior management to respond to
any demands for data from public authorities. Seek to have requests for data put in writing. Do not give
unrestricted access to public authorities to CCTV monitoring points.
• Provide access to recordings of individuals who have been recorded, on their request.
• Retain CCTV footage for as short a time as possible and not more than 30 days, unless it is being used
as criminal evidence, or shows evidence of human rights abuses and may be useful to those seeking
redress.
• For scenarios involving peaceful protest, consider adopting SOPs to stop recording and immediately
delete CCTV data where there is a risk that it will otherwise be used by the authorities to arrest those
exercising their right to freedom of expression
MCRB also identified the 12 Guiding Principles of the Amended Surveillance Camera Code of Practice, UK
Government, December 2021 and the template for a data protection impact assessment for surveillance
cameras developed by the UK Information Commissioner Office and the Surveillance Camera
Commissioner as useful tools that could be applied by companies in Myanmar. However, this seems to be
an under-scrutinised area of technology use that would benefit from guidance by digital rights experts.
New legal frameworks relating to ICT
A draft cybersecurity law has been under preparation for several years in Myanmar. Shortly after taking
power on 1 February 2021, the military regime sent a limited number of business associations a draft of
the law for comment. MCRB prepared a document analysing elements of the draft law from a human
rights perspective, including the rights to privacy and freedom of expression (both of which are contained
in Myanmar’s constitution). This document was provided to organisations, particularly businesses, who
could respond to the call for comments and engage in advocacy on the draft law.
Perhaps in the face of significant concern expressed by businesses and others, rather than adopt the draft
Cybersecurity Law, the military regime instead incorporated elements of the draft cybersecurity law
concerning privacy and data protection into amendments to an earlier Electronic Transactions Law (ETL)5.
These amendments establish a requirement to protect ‘personal data’ and penalties for failure to do so.
But they lack clarity on how collected data should be handled, such as provisions on the retention period,
classification of the information to be stored and storage location. While representing the first time that
Myanmar has had a legal framework for data protection, the provisions are not consistent with
international human rights standards. Furthermore, very few people, including in the regulator, appear
aware of the new legal requirements for data protection, or doing anything to enforce them.
In January 2022, a revised draft Cybersecurity Law was circulated for comment, having been partially
amended to reflect comments received in February 2021, primarily from businesses. This included new
5
See MCRB’s consolidated version of the 2004 Electronic Transactions Law, as amended in 2014 and 2021, and
unofficial translation, and pages 76-78 of Private Security Companies in Myanmar: A Baseline Study, Human Rights
Risk Assessment and Recommendations, MCRB February 2022. Free Expression Myanmar’s analysis of 18 February
2021 of ‘Myanmar’s new Electronic Transactions Law Amendment’, highlights the relationship of these amendments
to the provisions originally included in the draft Cybersecurity law.
3