maintaining the system, effectively conscripting the private sector into financing the infrastructure of State surveillance. This is not a neutral technical requirement. By mandating direct system integration without independent oversight or any requirement of individualised suspicion, Article 57 creates the conditions for arbitrary interference with privacy rights. Real-time tracking and database centralisation Building on Article 57’s mandatory integration requirement, the Bill establishes a centralised database into which private sector systems must feed, enabling the State to aggregate and access data from banks, fintech platforms, and telecommunications providers in real time. Through this architecture, the State is empowered to monitor Internet Protocol (IP) addresses, SIM card usage, and financial transaction metadata, and to track financial activity on a continuous and indiscriminate basis, regardless of any individualised grounds or suspicion. Article 15 provides for the pooling and dissemination of information relating to financial flows and private communications. Although Article 18 states that such information must be retained in accordance with “data protection standards”, the Bill does not define those standards and creates no independent regulatory oversight or compliance mechanism. Under international data protection principles, including those reflected in the GDPR, data protection without independent supervision is conceptually untenable. Under military rule, moreover, the regulator and the abuser are functionally the same. The result is a performative safeguard that serves to legitimise unrestricted State data harvesting, including against individuals involved in coordinating civil resistance. The continuous aggregation of communications and financial metadata on this basis is incompatible with the principles of necessity and proportionality under international human rights law. Mandatory data disclosure by telecommunications companies In addition to the centralised surveillance architecture created through Articles 15 and 57, the Bill imposes direct and immediate data surrender obligations on telecommunications providers. Companies are required to retain comprehensive call detail records (CDRs), location data, and identity information, and to hand that information over immediately upon military demand, without judicial oversight. The Bill secures compliance through criminal penalties that coerce private sector employees into functioning as agents of State policing. Under Article 40(c), telecom employees face up to seven years’ imprisonment for failing to comply with, or delaying compliance with, non-judicial military requests. This framework compels employees to facilitate human rights violations under threat of punishment, directly engaging concerns of corporate complicity under Pillar II of the UN Guiding Principles on Business and Human Rights (UNGPs), and raising serious questions as to whether continued operations remain consistent with corporate human rights responsibilities.

Select target paragraph3