Myanmar: Analysis of Draft Cyber Security Law 6. Critical Information Infrastructure Chapter 7 of the draft Law deals with critical information infrastructure. This is defined in section 3(l) as “fundamental information infrastructures” but the definition then goes on to refer to a wide range of areas of public life such as public welfare, health and finance. Section 16 expands this even further to cover natural resources, communication and even infrastructure “classified for private use only”, among other tings. For the most part, this chapter places various obligations on different actors to secure critical information infrastructure. While these obligations sometimes appear excessive given the breadth of the areas covered by this concept, that does not necessarily raise human rights issues. However, section 20 addresses information security for critical information infrastructure, requiring officials responsible for this, among other things, to keep “information on” critical information infrastructure “at a place permitted by the Ministry” and to follow the rules in dealing with this information (it is not clear who sets those rules). Failure to meet these obligations may, pursuant to section 58, lead to imprisonment for up to three years and/or a fine. The exact scope of these obligations is not clear but it could potentially cover all the information held by all of the public authorities that work in all of these sectors. If so, this would represent a massive extension of essentially security-driven control over an enormous wealth of information which has nothing whatsoever to do with security. While this may appear to be a dramatic interpretation of these provisions, it is not out of line with some other legislation adopted recently by Myanmar relating to information. Recommendations: ! The scope of the section 20 obligations should be limited to information the protection of which is essential to guaranteeing the ability of critical information infrastructure authorities to operate safely and free from cyber attacks, rather than all of the information they hold. ! Consideration should also be given to narrowing substantially the scope of authorities which are deemed to fall within the scope of critical information infrastructure. The Centre for Law and Democracy is a non-profit human rights organisation working internationally to provide legal expertise on foundational rights for democracy - 13 -

Select target paragraph3