Myanmar: Analysis of Draft Cyber Security Law This Analysis focuses on six issue areas in the draft Law, namely the independence and powers of the institutional structures created by the draft Law, the rules on personal data protection and data storage, restrictions on the content of what may be shared online, other criminal rules in the draft Law, the burdens placed on private sector actors (important from a freedom of expression perspective since many of these actors serve to facilitate or enable online speech), and critical information infrastructure. The analysis itself is drawn from international human rights standards, for example as set out in the Universal Declaration of Human Rights (UDHR),5 adopted in 1948. As a United Nations General Assembly resolution, the UDHR is not directly binding on States but its preeminent status as a statement of international human rights and the fact that States rarely if ever repudiate at least some of its principles means that those principles, including its guarantees of freedom of expression and privacy, have very likely acquired legal force as customary international law.6 1. Institutional Structures: Independence and Powers The draft Law creates four main institutional structures. At the top of the pyramid is the Cyber Security Central Committee (Central Committee), appointed by the State Administration Council, which was itself created on 2 February 2021 to serve as the peak executive body in Myanmar under the new governing arrangements. The Chair of the State Administration Council and the Minister of the Ministry responsible for cyber security serve as co-chairs of the Central Committee, which also draws members from among other ministers and a secretary appointed by the State Administration Council (section 5(a)). The Central Committee is thus entirely controlled by the executive. The Cyber Security Executive Committee (Executive Committee), in turn, is appointed by the Central Committee, with the approval of the State Administration Council. The Minister of the Ministry responsible for cyber security serves as the chair, with members being drawn from among deputy ministers or permanent secretaries of different ministries, cyber security professionals and representatives of non-governmental organisations (section 9). Although the Executive Committee does include non-government representatives, its appointment by the Central Committee gives the executive control over it. Furthermore, both the Central Committee and the Executive Committee are served by a secretariat which is “determined” by the State Administration Council, which performs under the supervision of the Ministry responsible for cyber security and which is responsible for the work of both Committees (sections 7 and 8). This further cements the executive’s control over the Executive Committee. Third, the Executive Committee, with the agreement of the Central Committee, shall form Working Committees, at least in the areas of Cyber Security, Cyber Crimes and Cyber Protection 5 United Nations General Assembly Resolution 217A (III), 10 December 1948. See, for example, D'Amato, A., "Human Rights as Part of Customary International Law: A Plea for Change of Paradigms" (2010, Faculty Working Papers, 88), https://scholarlycommons.law.northwestern.edu/facultyworkingpapers/88; and Meron, T., Human Rights and Humanitarian Norms as Customary Law (1989, Oxford, Clarendon Press). 6 The Centre for Law and Democracy is a non-profit human rights organisation working internationally to provide legal expertise on foundational rights for democracy -2-

Select target paragraph3