maintaining the system, effectively conscripting the private sector into financing the infrastructure of
State surveillance.
This is not a neutral technical requirement. By mandating direct system integration without
independent oversight or any requirement of individualised suspicion, Article 57 creates the
conditions for arbitrary interference with privacy rights.
Real-time tracking and database centralisation
Building on Article 57’s mandatory integration requirement, the Bill establishes a centralised database
into which private sector systems must feed, enabling the State to aggregate and access data from
banks, fintech platforms, and telecommunications providers in real time.
Through this architecture, the State is empowered to monitor Internet Protocol (IP) addresses, SIM
card usage, and financial transaction metadata, and to track financial activity on a continuous and
indiscriminate basis, regardless of any individualised grounds or suspicion. Article 15 provides for the
pooling and dissemination of information relating to financial flows and private communications.
Although Article 18 states that such information must be retained in accordance with “data protection
standards”, the Bill does not define those standards and creates no independent regulatory oversight
or compliance mechanism.
Under international data protection principles, including those reflected in the GDPR, data protection
without independent supervision is conceptually untenable. Under military rule, moreover, the
regulator and the abuser are functionally the same. The result is a performative safeguard that serves
to legitimise unrestricted State data harvesting, including against individuals involved in coordinating
civil resistance.
The continuous aggregation of communications and financial metadata on this basis is incompatible
with the principles of necessity and proportionality under international human rights law.
Mandatory data disclosure by telecommunications companies
In addition to the centralised surveillance architecture created through Articles 15 and 57, the Bill
imposes direct and immediate data surrender obligations on telecommunications providers.
Companies are required to retain comprehensive call detail records (CDRs), location data, and
identity information, and to hand that information over immediately upon military demand, without
judicial oversight.
The Bill secures compliance through criminal penalties that coerce private sector employees into
functioning as agents of State policing. Under Article 40(c), telecom employees face up to seven years’
imprisonment for failing to comply with, or delaying compliance with, non-judicial military requests.
This framework compels employees to facilitate human rights violations under threat of punishment,
directly engaging concerns of corporate complicity under Pillar II of the UN Guiding Principles on
Business and Human Rights (UNGPs), and raising serious questions as to whether continued
operations remain consistent with corporate human rights responsibilities.