8/23/22, 12:15 AM Update on Draft Cybersecurity Law and its Impacts on Digital Rights and the Digital Economy - News Criminalise the use of Virtual Private Networks (VPN) with a punishment of up to three years imprisonment and a fine (Art. 90). In the current circumstances this would effectively Rights to the activities of technology companies. criminalise access to Facebook, which has been blocked by the military since 4 February 2021. Given that VPNs are needed to access Facebook, any individual or business that posted on Facebook could in effect be creating evidence of a crime. Businesses also use VPNs to exchange data securely, but could potentially apply for a waiver to the ban (Art. 62). Any individual that encouraged the use of VPNs could also face a punishment of up to three years imprisonment and a fine (Art. 89c which covers ‘(c) Encouraging or assisting access to cyber source in violation of the regulations prescribed by the law’. This could include businesses which used Facebook to communicate with customers, phone shops that install VPNs, media outlets and civil society organisations who promote VPN use, or digital rights defenders who give security training. Undermine judicial due process, regarding the right of those accused of crimes to be confronted with the evidence against them; instead courts must defer to findings of a proposed State-run “National Digital Forensic Laboratory” (Art. 63–67). There are also a variety of provisions which give the government legal authority to check and take over the systems of digital businesses, order content deleted, block digital platforms, revoke business licences, and seize individuals’ computers or phones, all without judicial oversight (Arts. 60, 61b, 35, 61c, 71-78, 55, 57). Allow for blocks to digital businesses and social media on arbitrary grounds and without safeguards or judicial due process (Chapter 15) in violation of the right to freedom of expression Criminalise platforms like Facebook for hosting criticism. The previous 2021 draft would have made digital businesses, such as Facebook and YouTube, criminally liable for hosting any expression that the authorities decided fell under five vague categories (Arts. 29 and 61). The five categories included expressions that were vital for democratic debate and were lawful offline. The 2022 draft adds a sixth vague category of expression that the authorities could order deleted: “expressions that damage an individual’s social standing and livelihood” (Art. 35f). This sixth category does not use any of the common Burmese language descriptions of defamation, and there is no requirement that the expression needs to be true, or needs to be an assertion of fact, or that it should create serious harm. Instead, it would best be described as simple criticism. Any international businesses operating outside of Myanmar could ignore the order. However, they would still face the risk of their employees being charged in absentia, or their services being blocked (Art 86, 100, 101) Removal of provisions criminalising the specific crime of seeking, receiving, or imparting content showing sexual abuse of children (Art. 69). However the crime of sharing sexually explicit content (Art. 96) is retained in the 2022 draft. The provision is vague and could be used to violate the right to freedom of expression and access to information. For example, people, including teachers and civil society workers, could be criminalised for providing sex education, discussing women’s bodies, or raising awareness of LGBTIQ issues. Digital rights NGO Access Now also released a 27 January statement highlighting the shortcomings of the draft. On May 2, 2022 The Centre for Law and Democracy (CLD) provided its assessment of the draft Law which reflects the above-mentioned concerns and explains how the draft Law breaches international human rights guarantees. From the private sector perspective, the Global Network Initiative, a multistakeholder coalition that brings together major ICT companies and others, in a statement on 31 January 2022 called for withdrawal of the draft law and identified its ‘vague and overbroad’ approach to the prohibition and regulation of content, prosecution of cybercrime, data retention, and the use of virtual private networks (VPNs) as being out of line with international law, business expectations, and the SAC’s stated intentions to enable safety and security, protect personal information, support the digital economy, and “protect the authenticity and integrity of electronic information.” More specifically it identified: Vague and Overbroad Prohibitions of content, all of which are “either too vague or described too broadly to comport with international standards related to freedom of expression (Art. 35)” and “new provisions criminalizing vaguely-defined forms of content and conduct online, including troubling penalties for misinformation and disinformation (Art. 91).” https://www.myanmar-responsiblebusiness.org/news/draft-cybersecurity-law.html Myanmar’s Legal Framework For Cybersecurity Needs To Be Built To International Standards May 10, 2021 On 15 February 2021, the State Administration Council (SAC) adopted an amendment to the 2004 Electronic Transactions Law (as amended 2014) which added an aim of ‘protecting personal data’ to the existing law. DOWNLOAD THE MYANMAR ICT SWIA: Full Report (284 pages/5.35mb) Executive Summary and Recommendations Executive Summary & Recommendations (Burmese) Chapter 01: Introduction Chapter 02: ICT Government Institutions, Policies & Legal Frameworks Chapter 03: Sector-Level Impacts Chapter 04: Operational-Level Impacts 4.1: Freedom of Expression 4.2: Hate Speech 4.3: Privacy 4.4: Surveillance 4.5: Cyber-Security 4.6: Labour 4.7: Land 4.8: Groups at Risk 4.9: Stakeholder Engagement and Grievance Mechanisms 4.10: Security and Conflict Chapter 05: Cumulative-Level Impacts Annex: Background On SWIA Methodology Linked Initiatives on ICT/Human Rights in Myanmar 2/5

Select target paragraph3