8/23/22, 12:15 AM
Update on Draft Cybersecurity Law and its Impacts on Digital Rights and the Digital Economy - News
Criminalise the use of Virtual Private Networks (VPN) with a punishment of up to three
years imprisonment and a fine (Art. 90). In the current circumstances this would effectively
Rights to the activities of technology
companies.
criminalise access to Facebook, which has been blocked by the military since 4 February
2021. Given that VPNs are needed to access Facebook, any individual or business that
posted on Facebook could in effect be creating evidence of a crime. Businesses also use
VPNs to exchange data securely, but could potentially apply for a waiver to the ban (Art. 62).
Any individual that encouraged the use of VPNs could also face a punishment of up to three
years imprisonment and a fine (Art. 89c which covers ‘(c) Encouraging or assisting access to
cyber source in violation of the regulations prescribed by the law’. This could include
businesses which used Facebook to communicate with customers, phone shops that install
VPNs, media outlets and civil society organisations who promote VPN use, or digital rights
defenders who give security training.
Undermine judicial due process, regarding the right of those accused of crimes to be
confronted with the evidence against them; instead courts must defer to findings of a
proposed State-run “National Digital Forensic Laboratory” (Art. 63–67). There are also a
variety of provisions which give the government legal authority to check and take over the
systems of digital businesses, order content deleted, block digital platforms, revoke business
licences, and seize individuals’ computers or phones, all without judicial oversight (Arts. 60,
61b, 35, 61c, 71-78, 55, 57).
Allow for blocks to digital businesses and social media on arbitrary grounds and
without safeguards or judicial due process (Chapter 15) in violation of the right to freedom of
expression
Criminalise platforms like Facebook for hosting criticism. The previous 2021 draft would
have made digital businesses, such as Facebook and YouTube, criminally liable for hosting
any expression that the authorities decided fell under five vague categories (Arts. 29 and 61).
The five categories included expressions that were vital for democratic debate and were
lawful offline. The 2022 draft adds a sixth vague category of expression that the authorities
could order deleted: “expressions that damage an individual’s social standing and livelihood”
(Art. 35f). This sixth category does not use any of the common Burmese language
descriptions of defamation, and there is no requirement that the expression needs to be true,
or needs to be an assertion of fact, or that it should create serious harm. Instead, it would
best be described as simple criticism. Any international businesses operating outside of
Myanmar could ignore the order. However, they would still face the risk of their employees
being charged in absentia, or their services being blocked (Art 86, 100, 101)
Removal of provisions criminalising the specific crime of seeking, receiving, or
imparting content showing sexual abuse of children (Art. 69). However the crime of
sharing sexually explicit content (Art. 96) is retained in the 2022 draft. The provision is vague
and could be used to violate the right to freedom of expression and access to information.
For example, people, including teachers and civil society workers, could be criminalised for
providing sex education, discussing women’s bodies, or raising awareness of LGBTIQ issues.
Digital rights NGO Access Now also released a 27 January statement highlighting the
shortcomings of the draft.
On May 2, 2022 The Centre for Law and Democracy (CLD) provided its assessment of the draft
Law which reflects the above-mentioned concerns and explains how the draft Law breaches
international human rights guarantees.
From the private sector perspective, the Global Network Initiative, a multistakeholder coalition that
brings together major ICT companies and others, in a statement on 31 January 2022 called for
withdrawal of the draft law and identified its ‘vague and overbroad’ approach to the prohibition
and regulation of content, prosecution of cybercrime, data retention, and the use of virtual private
networks (VPNs) as being out of line with international law, business expectations, and the SAC’s
stated intentions to enable safety and security, protect personal information, support the digital
economy, and “protect the authenticity and integrity of electronic information.” More specifically it
identified:
Vague and Overbroad Prohibitions of content, all of which are “either too vague or
described too broadly to comport with international standards related to freedom of
expression (Art. 35)” and “new provisions criminalizing vaguely-defined forms of content
and conduct online, including troubling penalties for misinformation and disinformation (Art.
91).”
https://www.myanmar-responsiblebusiness.org/news/draft-cybersecurity-law.html
Myanmar’s Legal Framework For
Cybersecurity Needs To Be Built To
International Standards
May 10, 2021
On 15 February 2021, the State
Administration Council (SAC) adopted an
amendment to the 2004 Electronic
Transactions Law (as amended 2014) which
added an aim of ‘protecting personal data’
to the existing law.
DOWNLOAD THE MYANMAR ICT
SWIA:
Full Report (284 pages/5.35mb)
Executive Summary and Recommendations
Executive Summary & Recommendations
(Burmese)
Chapter 01: Introduction
Chapter 02: ICT Government Institutions,
Policies & Legal Frameworks
Chapter 03: Sector-Level Impacts
Chapter 04: Operational-Level Impacts
4.1: Freedom of Expression
4.2: Hate Speech
4.3: Privacy
4.4: Surveillance
4.5: Cyber-Security
4.6: Labour
4.7: Land
4.8: Groups at Risk
4.9: Stakeholder Engagement and
Grievance Mechanisms
4.10: Security and Conflict
Chapter 05: Cumulative-Level Impacts
Annex: Background On SWIA Methodology
Linked Initiatives on ICT/Human Rights in
Myanmar
2/5