Contd. Investcom Holding, the parent company behind ATOM (formerly Telenor Myanmar): Awareness of “mass surveillance and censorship” for MOTC using Geedge products. We are aware of claims relating to third-party technologies in Myanmar. As a policy, we do not confirm or deny the existence of third-party systems. ATOM operations follow applicable Myanmar law and regulatory conditions. Like operators elsewhere, the network reviews the legal basis of any lawful surveillance request and requires appropriate authority. Use of “TSG” to block VPNs/websites/apps We do not comment on specific vendors or devices. If/when the network receives a legally valid directive to restrict access to specified services or domains, it is obliged to implement it, in compliance with Myanmar law and regulatory obligations. Though network-level restrictions (including on VPNs) have been reported across Myanmar, such measures – if confirmed – would eventually be mandated by the local authorities, not initiated by any telecom network, including ours. We do not have any contractual relationship with the mentioned vendor whatsoever. When any such Geedge technology was installed/activated Again, ATOM does not disclose operational security timelines &/or vendor specifics. Our compliance is driven by Myanmar law and regulatory obligations, which, like in many jurisdictions globally, include the ability to execute lawful orders and implement technical capabilities, as required by official institutions &/or regulatory bodies. We do not have any contractual relationship with the mentioned vendor whatsoever. Role in purchase/import/installation/activation; involvement of third parties Procurement and integration of network security equipment, where required, follow internal controls and applicable import and global telecoms regulations. We do not disclose supplier identities, or integration details, for safety and security reasons. Human-rights due diligence ATOM follows a risk-based process that includes legal review, senior-level escalation, z stringent access controls, and minimi ation where feasible under law. The network z assesses requests against its policies and the UNGPs, while recogni ing the limited discretion private operators have when faced with binding orders from state players. End-user security concerns The ’ country s legal framework grants local authorities broad powers over digital communications, applying equally to all telecom operators. While networks must comply with binding directives, ATOM advises end-users to adopt safe digital practices and consult trusted digital-rights resources. These obligations are industry-wide, not unique to our network. Like operators in most countries, we comply with binding legal, regulatory and z ethical requirements, while enforcing strict internal governance to minimi e user impact within the limits of the law.

Select target paragraph3