Myanmar: Analysis of Draft Cyber Security Law requirements are very important to ensure that the rules are only applied to genuinely bad faith behaviour. Such intent requirements need to go beyond simple intent (i.e. an intention to do the act described) and should incorporate a more specific intent (such as bad faith or fraud or a desire to effect some other type of malfeasance). Section 62 is the first one which makes any specific mention of intent, in that case of “bad faith or dishonesty”. The lack of any intent requirement in the other provisions may lead to them being applied too broadly. Third, many of the provisions are phrased too broadly. For example, section 60 applies whenever someone discloses data to a third party without the consent of both the original sender and receiver. Almost everyone in the world who uses a digital device is guilty of this offence, which would be committed whenever someone who was copied on an email forwarded it to another person, without first getting the consent of the sender and the primary addressee. Section 39 does not even require any lack of authorisation, so that one may fall foul of it even using ones’ own computer. Although section 62 does include an appropriate intent requirement, some of its rules are too broad, such as the prohibition on deceiving others. In some cases, this overbreadth applies to the issue of intent. For example, section 70 refers to intent to hurt someone or threaten security (legitimate) but also to disturb national solidarity (not legitimate). Similarly, section 71 includes among its list of prohibited intents that of helping another country, which is normally perfectly legitimate. Section 55 prohibits online gambolling without permission, but fails to specify who should provide such permission. This is buttressed by section 75, which provides that those who breach this rule shall be punished under the Gambling Law. It is possible that the latter indicates who may provide permission for gambolling and how one may obtain it. Otherwise, however, this sort of prohibition is likely to create confusion and potentially misapplication of the law. Overall, these provisions should be rationalised and simplified – the legitimate goals they collectively cover could be captured in far fewer provisions – and the problems above should be addressed. Recommendations: ! The various prohibitions on different sorts of online behaviour in the draft Law should be substantially revised and rationalised to remove duplication and similar offences being described with only minor, unclear linguistic difference. This applies with particular force to the rules in sections 36, 37, 38, 40, 41, 59 and 60, where the problem is particularly problematical given that these sections fall into two very different chapters of the draft Law. ! All of these prohibitions should be accompanied by clear and specific intent requirements which go beyond merely the intent to commit the act and include an intent to cause harm, act in bad faith or something else along those lines. ! Any prohibitions along these lines should be drafted in clear and narrow terms so that The Centre for Law and Democracy is a non-profit human rights organisation working internationally to provide legal expertise on foundational rights for democracy - 10 -

Select target paragraph3