Myanmar: Analysis of Draft Cyber Security Law Recommendations: ! Myanmar should adopt a fully developed personal data protection regime, in line with international standards, including as to any exceptions. ! The local data storage system in the draft Law should either be removed entirely or replaced with a far more narrow and tailored system that takes into account the needs of Internet service providers in Myanmar. ! The data retention requirements should be removed. ! The power of authorities to require Internet service providers to provide personal user data should be subject to appropriate legal conditions, in line with the purpose for which the authority is seeking access. 3. Content Restrictions The draft Law contains a number of restrictions on the types of content that may be disseminated online, and puts in place systems to counter these types of content. The primary provision in this regard is section 29, calling for the “prevention, removal, destruction and cessation” by Internet service providers, “in a timely manner”, at the request of the Department, of the types of content it identifies, where that content is “on cyber space”. The exact modalities by which this system is intended to work are not clear from the provision. However, the approach appears to be very problematical. First, while all regulation by bodies that are not independent of government which affects freedom of expression represents a breach of international law, as noted above, direct content regulation along these lines by far the most problematical, for fairly obvious reasons (i.e. because such powers are likely to be used in a less than politically objective manner). Second, any system of content regulation should set out clear rules, including procedures, governing the way content deemed to be contrary to the rules will be addressed. This provision simply refers to a range of possible measures – prevention, removal, destruction, cessation – without indicating how the system will work. It seems likely that Internet service providers will simply be expected to do whatever the Department “orders” in relation to specific content. They may also be expected to take measures vis-à-vis the users responsible for this content, for example under the rubric of “prevention”. If so, this provision would engage a number of due process and other rights concerns. Third, content regulation systems should incorporate due process protections for users, whereby they can contest any actions taken against their content. No such protection appears to be envisaged here. Fourth, the provision is unclear as to whether the content in question even needs to have been made available publicly. Cyber space includes fully public communications, such as open content on public websites, partially public communications, such as information shared with a pre-defined group on a social media platform, and private communications, such as one-to-one communications. All of these would appear to be captured by this provision. The Centre for Law and Democracy is a non-profit human rights organisation working internationally to provide legal expertise on foundational rights for democracy -7-

Select target paragraph3