8. Protect personal data, maintain cyber security, and safeguard people’s rights through a
comprehensive legal and regulatory framework.
9. Establish clear institutional mandates and accountability.
10. Enforce legal and trust frameworks through independent oversight and adjudication of
grievances. 28
Another source of good practice to which Myanmar could turn is the Modular Open Source Identity
Platform (MOSIP) and its ten principles.29
To date, there is no information publicly available about what human rights and privacy safeguards will
be applied to the eID system, including how data will be collected, stored and accessed.30
Concerning the planned six items of personal or ‘biographic’ data which are to be collected, MCRB
understands that the six items under consideration by the Committee may be name, date of birth, place
of birth, gender, father’s name and mother’s name.31 However there is no information publicly available
to confirm this. There has also not been a public comment to date on whether the Committee has
adopted a policy of data minimisation.
A data minimization approach means that data on race and religion – currently in the Citizenship Scrutiny
Card (CSC) - should not be included in an eID. Personal data that is not collected cannot be used to cause
harm.32 Given Myanmar’s recent history, including discrimination and violence directed at certain
religious and ethnic minorities, this is a risk. Information on race and religion is not necessary to establish
a digital identity. It is not included in the Indian Aadhaar system which only includes four compulsory
biographic or personal data: name, address, gender, and date of birth (and parent/guardian name in the
case of children). Two others - mobile number and email - are optional in the Indian system.
Concerning conflict sensitivity, there is – unsurprisingly - no information available about how the
Committee plans to approach the implementation of an eID scheme (and biometric SIM Card registration
– see below) in the increasing number of areas of contested control. The choice of Naypyidaw, Mandalay
and Yangon for rolling out ‘Unit-ID’ may be a tacit recognition of this challenge. However, the design of
the eID system needs to take into account the views and interests of those in other areas included ethnic
and contested areas which have, or seek, greater autonomy.
SIM Card Registration and Biometrics
The issue of implementing eID is linked to the Myanmar government requirement for all mobile phone
users to have a registered SIM card, and ambitions to establish a biometric database to achieve that.
However it has not always been clear how the eID and SIM card registration programmes have been
coordinated, if at all. As with plans for eID, there is little information and debate about SIM card
registration, and privacy safeguards.
28
https://id4d.worldbank.org/principles
https://mosip.io/index.php
30
See for example Protection of the Individual in the UIDAI System, Unique Identification Authority of India
31
Personal communication, May 2022
32
https://www.accessnow.org/cms/assets/uploads/2021/05/Data-Minimization-Report.pdf
29
9