Myanmar: Analysis of Draft Cyber Security Law
they cannot be applied to innocent behaviours. This applies to both the main form of
prohibited behaviour and the accompanying intent.
! The prohibitions on gambolling in sections 55 and 75 should be reviewed to ensure that
they do not introduce an ambiguous reference to the idea of permission to conduct
gambolling.
5. Burdens on Private Sector Actors
The draft Law places a number of burdens on private sector actors, mostly generally on Internet
service providers but sometimes more specific rules for different sub-sets of that broad category.
These have implications for freedom of expression inasmuch as many of these private actors
serve to facilitate online speech such that undermining their ability to operate effectively or
provide certain types of services has a knock-on effect for the freedom of expression of their
users.
Section 27 applies to “cyber security service providers”, defined quite broadly in section 3(v) as
anyone who provides cyber security services either online or through technological systems or
materials. These providers are all required to develop cyber security measures to support the
Department and “Cyber Security Breach Emergency Response teams”, provide warnings and
“preventive guidance” on cyber security risks and develop “response plans and solutions” vis-àvis various risks. The provision of cyber security services can take many different forms, ranging
from the development of specialised software in different areas, the provision of training, the
direct provision of technical support to clients and so on. Imposing these broad, uniform
obligations on all of these actors is simply not appropriate. For example, a specialised software
developer may not be in a position to provide solutions to hacking, as required by section 27(c).
According to section 44, Internet service providers, including cyber security service providers,
must “coordinate and collaborate” with the three mandated Working Committees (on cyber
security, cybercrime and cyber protection) in the areas set out in section 43. These include, as
noted above, activities such as preventing further consequences of threats, attacks and other
risks, preventing these risks from happening at all, increase levels of cyber security vis-à-vis
information and investigating threats and attacks. Once again, the imposition of these uniform
obligations on all Internet service providers is simply not appropriate. Indeed, it may be
questioned whether it is appropriate to impose any of the obligations in sections 27 and 44 on
private companies. Rather, this is an area where either the market should respond to needs or the
public sector should manage affairs.
According to section 28(b), all Internet service providers must register in accordance with
Myanmar company law. This would pose a serious barrier to any such companies which have
limited business in Myanmar and which may nevertheless be providing important services to a
small clientele in the country. It is also likely that many service providers based abroad would
simply refuse to register locally, which would incur costs and render them subject to local
The Centre for Law and Democracy is a non-profit human rights organisation working internationally to
provide legal expertise on foundational rights for democracy
- 11 -