Myanmar: Analysis of Draft Cyber Security Law they cannot be applied to innocent behaviours. This applies to both the main form of prohibited behaviour and the accompanying intent. ! The prohibitions on gambolling in sections 55 and 75 should be reviewed to ensure that they do not introduce an ambiguous reference to the idea of permission to conduct gambolling. 5. Burdens on Private Sector Actors The draft Law places a number of burdens on private sector actors, mostly generally on Internet service providers but sometimes more specific rules for different sub-sets of that broad category. These have implications for freedom of expression inasmuch as many of these private actors serve to facilitate online speech such that undermining their ability to operate effectively or provide certain types of services has a knock-on effect for the freedom of expression of their users. Section 27 applies to “cyber security service providers”, defined quite broadly in section 3(v) as anyone who provides cyber security services either online or through technological systems or materials. These providers are all required to develop cyber security measures to support the Department and “Cyber Security Breach Emergency Response teams”, provide warnings and “preventive guidance” on cyber security risks and develop “response plans and solutions” vis-àvis various risks. The provision of cyber security services can take many different forms, ranging from the development of specialised software in different areas, the provision of training, the direct provision of technical support to clients and so on. Imposing these broad, uniform obligations on all of these actors is simply not appropriate. For example, a specialised software developer may not be in a position to provide solutions to hacking, as required by section 27(c). According to section 44, Internet service providers, including cyber security service providers, must “coordinate and collaborate” with the three mandated Working Committees (on cyber security, cybercrime and cyber protection) in the areas set out in section 43. These include, as noted above, activities such as preventing further consequences of threats, attacks and other risks, preventing these risks from happening at all, increase levels of cyber security vis-à-vis information and investigating threats and attacks. Once again, the imposition of these uniform obligations on all Internet service providers is simply not appropriate. Indeed, it may be questioned whether it is appropriate to impose any of the obligations in sections 27 and 44 on private companies. Rather, this is an area where either the market should respond to needs or the public sector should manage affairs. According to section 28(b), all Internet service providers must register in accordance with Myanmar company law. This would pose a serious barrier to any such companies which have limited business in Myanmar and which may nevertheless be providing important services to a small clientele in the country. It is also likely that many service providers based abroad would simply refuse to register locally, which would incur costs and render them subject to local The Centre for Law and Democracy is a non-profit human rights organisation working internationally to provide legal expertise on foundational rights for democracy - 11 -

Select target paragraph3