Myanmar: Analysis of Draft Cyber Security Law
jurisdictional rules (note that if they did this in Myanmar, they could hardly refuse to do it in
other countries as well). It is not clear how such a rule could be enforced in any case. A similar
problem relates to section 28(c), about paying local taxes. While this may appear reasonable, and
many jurisdictions are indeed looking at how they can claim taxes relating to profits which
online companies in fact harvest in their countries, even if they do not have any material base of
operations there, in fact the issue is quite complicated and a simple provision like this, which
does not take into account any of the actual complexity of the situation, may put users at risk
without actually being able to be implemented.
Sections 32-35 deal with licensing and registration, which is undertaken by the Department,
while section 78 gives existing providers a year to renew their operating arrangements in this
regard. While it is not unreasonable to expect, respectively, electronic certification issuers
(section 32) and cyber security services (section 33) to have licences, given the security nature of
their work, and Internet service providers to register (section 34), there are a few problems with
this. First, there is the problem noted above, of companies that provide these services but are
based in other countries. Second, it is not reasonable to require Internet service providers both to
incorporate under the companies law and to register with the Department. Third, section 78 may
breach the legal rights of some existing providers, potentially even through the Department
refusing to renew a licence which had had a number of years’ duration remaining. It is not clear
why existing licences should not be continued, perhaps by providing that they are deemed to be
amended as necessary to conform to the new legal rules. Finally, the importance of having this
sort of function undertaken by an independent body has already been noted.
The problems with the provisions above are exacerbated by section 61, which provides for
imprisonment for up to three years and/or a fine of up to MMK 10,000,000 (approximately USD
7,000) for breach by any Internet service provider of “provisions prescribed in this law”. This is
quite a harsh maximum penalty, especially for some of the rules. It is not clear how
imprisonment might apply under Myanmar law to a company, which these entities would be
legally required by the draft Law to be, but to the extent that directors might be personally liable
under these provisions, this could deter worthy people from taking up these sorts of positions.
Recommendations:
! Consideration should be given to removing entirely sections 27 and 44. At a minimum,
they should be scaled back considerably to apply only as appropriate and relevant to
different Internet service providers.
! The rules on incorporation, taxation, licensing and registration should be fundamentally
reconsidered. At a minimum, the working needs and reality of companies based abroad
should be recognised and any obligations on them should be carefully tailored based on
this, existing companies should have their licences respected and the sanctions should
be more carefully adapted to the different sorts of breaches by private companies.
The Centre for Law and Democracy is a non-profit human rights organisation working internationally to
provide legal expertise on foundational rights for democracy
- 12 -