Myanmar: Analysis of Draft Cyber Security Law
requirements are very important to ensure that the rules are only applied to genuinely bad faith
behaviour. Such intent requirements need to go beyond simple intent (i.e. an intention to do the
act described) and should incorporate a more specific intent (such as bad faith or fraud or a
desire to effect some other type of malfeasance). Section 62 is the first one which makes any
specific mention of intent, in that case of “bad faith or dishonesty”. The lack of any intent
requirement in the other provisions may lead to them being applied too broadly.
Third, many of the provisions are phrased too broadly. For example, section 60 applies whenever
someone discloses data to a third party without the consent of both the original sender and
receiver. Almost everyone in the world who uses a digital device is guilty of this offence, which
would be committed whenever someone who was copied on an email forwarded it to another
person, without first getting the consent of the sender and the primary addressee. Section 39 does
not even require any lack of authorisation, so that one may fall foul of it even using ones’ own
computer. Although section 62 does include an appropriate intent requirement, some of its rules
are too broad, such as the prohibition on deceiving others.
In some cases, this overbreadth applies to the issue of intent. For example, section 70 refers to
intent to hurt someone or threaten security (legitimate) but also to disturb national solidarity (not
legitimate). Similarly, section 71 includes among its list of prohibited intents that of helping
another country, which is normally perfectly legitimate.
Section 55 prohibits online gambolling without permission, but fails to specify who should
provide such permission. This is buttressed by section 75, which provides that those who breach
this rule shall be punished under the Gambling Law. It is possible that the latter indicates who
may provide permission for gambolling and how one may obtain it. Otherwise, however, this
sort of prohibition is likely to create confusion and potentially misapplication of the law.
Overall, these provisions should be rationalised and simplified – the legitimate goals they
collectively cover could be captured in far fewer provisions – and the problems above should be
addressed.
Recommendations:
! The various prohibitions on different sorts of online behaviour in the draft Law should
be substantially revised and rationalised to remove duplication and similar offences
being described with only minor, unclear linguistic difference. This applies with
particular force to the rules in sections 36, 37, 38, 40, 41, 59 and 60, where the problem
is particularly problematical given that these sections fall into two very different
chapters of the draft Law.
! All of these prohibitions should be accompanied by clear and specific intent
requirements which go beyond merely the intent to commit the act and include an
intent to cause harm, act in bad faith or something else along those lines.
! Any prohibitions along these lines should be drafted in clear and narrow terms so that
The Centre for Law and Democracy is a non-profit human rights organisation working internationally to
provide legal expertise on foundational rights for democracy
- 10 -