criticism of a government, jail journalists investigating corruption, censor freedom of expression, and
more broadly discourage use of the internet.
THREE STEPS FOR DEVELOPING GOOD CYBER CRIME LAWS
1. Ensure cyber crime legislation contains human rights protection and safeguards
Cyber crime laws should be consistent with the Myanmar’s international obligations to protect human
rights. That should also cover provisions on accessing electronic evidence in criminal matters
irrespective of the way data stored extraterritorially is accessed. The human rights principles and
safeguards of legality, necessity and proportionality, prior judicial authorisation, effective oversight,
notification and access to effective remedy should apply.7
2. Define cyber dependent crimes narrowly
These crimes should be interpreted to punish unauthorised access, with criminal intent, directed
against the confidentiality, integrity and availability of computer systems and networks and the data
stored there.
3. Ensure comprehensive legal frameworks for “cyber enabled crime” that focus on the
fundamental nature of the crime, and not only on the use of ICT
Cyber enabled crime refers to ‘traditional’ crimes committed in a new way using technology, such as
fraud or distribution of child abuse images which should be a crime whether or not a computer is used.
Therefore these crimes should be addressed in comprehensive criminal laws where the crime can be
defined more precisely; put in its broader context; and the appropriate procedures for investigating
and prosecuting the crime defined in more detail.
THREE STEPS TO AVOID WHEN DEVELOPING CYBER CRIME LAWS
1. Do not criminalise behaviour that should not be criminal under international human rights
law
Examples include criticising the government on social media or using encrypted messaging services.
2. Do not mix surveillance together with a cyber crime law
Surveillance can be necessary to fight crime. But it is an intrusive act and interferes with a range of
human rights. Human rights law requires any surveillance to be legal, necessary and proportionate.
Authorising surveillance powers in a cyber crime law leads to an expansion of the type of crimes for
which surveillance is authorized, especially if the law authorizes surveillance for cyber enabled crimes.
This can result in significantly greater intrusion into peoples’ privacy, particularly if it is not
accompanied by procedural safeguards and other human rights protections within the law itself.
Myanmar currently does not have a law on lawful surveillance/interception and lacks the prerequisites to a rights-respecting lawful surveillance regime8 Including a data protection law that applies
to public entities as well as private ones.9
3. Do not just “copy and paste” the 2001 Budapest Convention into domestic law without
additional human rights safeguards
The provisions in the Budapest Convention need to be accompanied by human rights safeguards.
The Budapest Convention - Council of Europe’s Convention on Cyber Crime 2001
The Council of Europe’s Convention on Cyber Crime 2001 (known as the “Budapest Convention”) is a
7
https://privacyinternational.org/advocacy-briefing/660/privacy-internationals-response-europeancommissions-public-consultation
8
For a lawful interception regime that respects human rights, see Myanmar Centre for Responsible Business’
“Recommendations to the Myanmar Government: Lawful Interception and Government Access to User Data: The
Characteristics of a Rights-Respecting Model” in English Sector Wide Impact Assessment of Myanmar’s ICT Sector,” (2015),
Recommendations – Annex, p. 35. And in Burmese
9
See MCRB’s companion Policy Brief on Privacy and Data Protection.
4