5/22/22, 12:03 AM
Myanmar: Freedom on the Net 2021 Country Report | Freedom House
Soe Oo were arrested in 2017 (see C3), the police were accused of using Wa Lone’s confiscated phone to
send a WhatsApp message on his account. 309 The police used the Israeli phone-breaching product
known as Cellebrite to collect data from the journalists’ smartphones. 310 Cellebrite technology has been
used by the police since 2016, and although the company ceased selling its products in Myanmar in late
2018, authorities continue to employ them. In 2019, FinSpy malware developed by Germany’s Gamma
Group was reported to be in operation in Myanmar. 311 It is unclear who purchased the spyware.
In 2018 the MoTC announced its intention to build a data center that would serve as a secure base for its
planned e-government services in Naypyidaw, and in December of that year the ministry requested that
the parliament approve a $95 million loan from South Korea to support the project. 312 The Mandalay
regional government launched a data center in January 2019 to provide e-government services. 313
Concerns have been raised that these data centers will lack adequate privacy and security safeguards. 314
C6 0-6 pts
Does monitoring and collection of user data by service providers and other technology
companies infringe on users’ right to privacy?
1/6
Service providers are increasingly obliged to hand data over to the state without sufficient oversight or
safeguards.
The Law Protecting the Privacy and Security of Citizens, passed in 2017 and partially suspended since the
coup, 315 prohibits the interception of personal communications without a warrant, but it contains a
vague exception allowing surveillance if permission is granted by the president or a government body.
316 The law does not outline clear procedures to prevent data from being collected and stored, nor
does it provide for judicial review. Critics argue that the law’s definition of privacy is inadequate and
inconsistent with international human rights standards. 317 Other privacy-related laws demanded by a
range of private-sector and civil society stakeholders, including a robust data protection law, have not yet
been introduced. 318
The Telecommunications Law grants the government the power to direct unspecified persons “to secure
any information or communication which may harm security, rule of law, or peace of the state.” 319 A
provision stating that any interception should not “hurt the fundamental rights of citizens” is an
inadequate safeguard against abuse. 320 The Telecommunications Law also grants the government the
power to inspect the premises of telecommunications license holders and to require them to hand over
documents—for the ill-defined purposes of defending the “security of the state” or “the benefit of the
people”—without safeguards for individuals’ privacy and other human rights. 321 A 2018 amendment to
the Narcotic Drugs and Psychotropic Substances Law included a new provision requiring
telecommunications providers to disclose user information without due process. 322 There are no
requirements for judicial review.
Civil society activists have raised concerns that the opaque mass directives being issued to service
TOP
providers by the military since the coup include orders for widespread interception (see A4, B1, and
B3).
323 The draft cybercrimes law would also require service providers to store data on servers designated
by and fully accessible to the military (see C5). There is little room for providers to push back against the
military’s directives, though in at least one instance they did so effectively. On March 30, one regional
https://freedomhouse.org/country/myanmar/freedom-net/2021
24/28