8. Protect personal data, maintain cyber security, and safeguard people’s rights through a comprehensive legal and regulatory framework. 9. Establish clear institutional mandates and accountability. 10. Enforce legal and trust frameworks through independent oversight and adjudication of grievances. 28 Another source of good practice to which Myanmar could turn is the Modular Open Source Identity Platform (MOSIP) and its ten principles.29 To date, there is no information publicly available about what human rights and privacy safeguards will be applied to the eID system, including how data will be collected, stored and accessed.30 Concerning the planned six items of personal or ‘biographic’ data which are to be collected, MCRB understands that the six items under consideration by the Committee may be name, date of birth, place of birth, gender, father’s name and mother’s name.31 However there is no information publicly available to confirm this. There has also not been a public comment to date on whether the Committee has adopted a policy of data minimisation. A data minimization approach means that data on race and religion – currently in the Citizenship Scrutiny Card (CSC) - should not be included in an eID. Personal data that is not collected cannot be used to cause harm.32 Given Myanmar’s recent history, including discrimination and violence directed at certain religious and ethnic minorities, this is a risk. Information on race and religion is not necessary to establish a digital identity. It is not included in the Indian Aadhaar system which only includes four compulsory biographic or personal data: name, address, gender, and date of birth (and parent/guardian name in the case of children). Two others - mobile number and email - are optional in the Indian system. Concerning conflict sensitivity, there is – unsurprisingly - no information available about how the Committee plans to approach the implementation of an eID scheme (and biometric SIM Card registration – see below) in the increasing number of areas of contested control. The choice of Naypyidaw, Mandalay and Yangon for rolling out ‘Unit-ID’ may be a tacit recognition of this challenge. However, the design of the eID system needs to take into account the views and interests of those in other areas included ethnic and contested areas which have, or seek, greater autonomy. SIM Card Registration and Biometrics The issue of implementing eID is linked to the Myanmar government requirement for all mobile phone users to have a registered SIM card, and ambitions to establish a biometric database to achieve that. However it has not always been clear how the eID and SIM card registration programmes have been coordinated, if at all. As with plans for eID, there is little information and debate about SIM card registration, and privacy safeguards. 28 https://id4d.worldbank.org/principles https://mosip.io/index.php 30 See for example Protection of the Individual in the UIDAI System, Unique Identification Authority of India 31 Personal communication, May 2022 32 https://www.accessnow.org/cms/assets/uploads/2021/05/Data-Minimization-Report.pdf 29 9

Select target paragraph3