approach. Privacy International wrote to PTD to raise concerns about the plans and the risk to privacy, particularly in the absence – at the time - of data protection provisions in Myanmar law. 40 Current Situation As of mid-2022, MCRB understands that after several years of working in apparent isolation from one another, the Ministry of Immigration and Population (MIP) and the Ministry of Transport and Communications (MoTC) under the State Administration Council are working towards establishing a common biometric database that would both underpin a unique digital ID number and be used for SIM card registration.41 The use of the Universal Service Fund has doubtless helped to bring the two Ministries together, in the absence of finding other funding for an eID system. In the absence of development partner assistance, or a democratically elected government and parliament, it will fall to the de facto authorities and any private sector implementing partners to ensure that the system is implemented in a way which protects human rights including the right to privacy. Private sector implementing partners includes not only companies directly involved with the design and toll-out of the system, but also those who are supporting enrolment such as telecoms operators and other sellers of SIM cards where biometric and personal data could be collected. This project is taking place at a time when the entire country can be considered a conflict-affected and high-risk area (CAHRA), and where the military regime is committing extensive human rights abuses.42 Furthermore, there is lack of trust in the military regime and the civil service and an unwillingness on the part of much of civil society, and many businesses, to engage with it. This is likely to extend to unwillingness to participate in the planned ‘local expert group’ on eID, or in any wider public consultation, were one to be held. If the SAC proceeds with the roll-out of an eID and SIM biometric database, it is therefore important that any private sector entities involved in its implementation should fully understand the human rights at risk. They should undertake heightened, conflict sensitive, human rights due diligence and pursue proactive engagement with rightsholders. They should advocate for the incorporation of the Principles on Identification for Sustainable Development, and MOSIP, into the approach so as to build rights protecting measures into the system. They should encourage transparency and effective communication, in support of an informed public debate on these important questions. Above all, private sector entities should advocate for a data minimisation approach, and particularly one that excludes collection of data on race and religion. They should also ensure that the system is inclusive, and accessible for persons with disabilities. 4. Additional privacy-related human rights risks since 1 February 2021 The following examples have been identified by MCRB as some of the other human rights risks relating to privacy which have emerged since the military coup: 40 Myanmar: Dangerous plans for a National Digital ID and Biometric SIM Card Registration must be scrapped, Privacy International, 9 December 2019, Privacy International, updated January, March and June 2020, and January 2021 41 MCRB personal communication with industry sources May 2022 42 Myanmar: UN report urges immediate, concerted effort by international community to stem violence, hold military accountable, UNOHCHR 15 March 2022 11

Select target paragraph3