1. Lack of human rights safeguards in the legal framework
There have always been significant risks in Myanmar to digital rights, such as privacy, freedom of
expression, and access to information. This is due both to the lack of human rights safeguards in the legal
framework for telecoms/ICT, and to provisions in the laws which are either vague or inconsistent with
international human rights standards. This includes laws – or the lack of them – on issues such as lawful
interception, cybersecurity, data protection and cybercrime. These gaps were analysed in MCRB’s 2015
Sector Wide Impact Assessment1 and updated in subsequent policy briefs.2
When undertaking human rights due diligence and risk assessments in Myanmar, companies therefore
need to take account of the weaknesses in the legal framework and lack of human rights protection that
it provides. In the absence of effective legal requirements, companies need to pre-emptively take
preventative and mitigating steps through the adoption of good practice and guidance from other
countries, and incorporating, applying and enforcing provisions in policies, contracts and standard
operating procedures (SOPs) which draw on international human rights standards.
MCRB summarised some of these issues in the input it made to the UN Office of the High Commissioner
on Human Rights in March 2022 concerning the High Commissioner’s report on the practical application
of the Guiding Principles on Business and Human Rights to the activities of technology companies. 3 In that
input, MCRB summarised the – unsuccessful - attempts made by MCRB, some companies and others, to
introduce safeguards into the legal framework which could reduce the human rights risks for companies
and impacts for rightsholders. Failure to incorporate human rights safeguards, in particular for lawful
interception, contributed to Telenor’s decision in 2021 to exit Myanmar.
Use of visual/video surveillance and monitoring
There is no legal framework for use of visual/video surveillance in Myanmar, generally referred to as
Closed Circuit TV (CCTV). CCTV and other security systems (e.g. alarms, entry systems, GPS trackers) can,
in addition to capturing activities, also capture sensitive personal data, including in metadata. Some of the
risks associated with this were identified in MCRB’s February 2022 Baseline Study and Human Rights Risk
Assessment of Private Security Companies in Myanmar. 4 For example, CCTV recordings can be accessed
and reviewed by public security to identify those involved in peaceful protest.
In the absence of regulation on CCTV usage, MCRB recommended companies should:
• Consider whether deployment of CCTV or other recording equipment addresses a legitimate pressing
need that cannot be addressed by other means.
• Ensure that CCTV is only used for designated purposes and legitimate aims, such as prevention of crime,
and not, for example, to spy on employees, customers or neighbours.
• Ensure that CCTV deployment is proportionate to the need. Disable audio recording. Consider whether
a live feed is sufficient, rather than recording.
1
https://www.myanmar-responsiblebusiness.org/pdf/SWIA/ICT/complete.pdf
https://www.myanmar-responsiblebusiness.org/pdf/2019-Policy-Brief-Myanmar-ICT-Legal-Framework_en.pdf
3
https://www.myanmar-responsiblebusiness.org/news/guiding-principles-tech-sector.html
4
Private Security Companies in Myanmar: A Baseline Study, Human Rights Risk Assessment and Recommendations,
MCRB February 2022.
2
2