Myanmar: Analysis of Draft Cyber Security Law
6. Critical Information Infrastructure
Chapter 7 of the draft Law deals with critical information infrastructure. This is defined in
section 3(l) as “fundamental information infrastructures” but the definition then goes on to refer
to a wide range of areas of public life such as public welfare, health and finance. Section 16
expands this even further to cover natural resources, communication and even infrastructure
“classified for private use only”, among other tings. For the most part, this chapter places various
obligations on different actors to secure critical information infrastructure. While these
obligations sometimes appear excessive given the breadth of the areas covered by this concept,
that does not necessarily raise human rights issues.
However, section 20 addresses information security for critical information infrastructure,
requiring officials responsible for this, among other things, to keep “information on” critical
information infrastructure “at a place permitted by the Ministry” and to follow the rules in
dealing with this information (it is not clear who sets those rules). Failure to meet these
obligations may, pursuant to section 58, lead to imprisonment for up to three years and/or a fine.
The exact scope of these obligations is not clear but it could potentially cover all the information
held by all of the public authorities that work in all of these sectors. If so, this would represent a
massive extension of essentially security-driven control over an enormous wealth of information
which has nothing whatsoever to do with security. While this may appear to be a dramatic
interpretation of these provisions, it is not out of line with some other legislation adopted
recently by Myanmar relating to information.
Recommendations:
! The scope of the section 20 obligations should be limited to information the protection
of which is essential to guaranteeing the ability of critical information infrastructure
authorities to operate safely and free from cyber attacks, rather than all of the
information they hold.
! Consideration should also be given to narrowing substantially the scope of authorities
which are deemed to fall within the scope of critical information infrastructure.
The Centre for Law and Democracy is a non-profit human rights organisation working internationally to
provide legal expertise on foundational rights for democracy
- 13 -