Myanmar: Analysis of Draft Cyber Security Law Taken together, the complete lack of independence of the institutional structures under the draft Law, the extremely extensive and largely unconstrained powers granted to them to investigate, seize evidence and even impose sanctions, and the barring of any appeal to an independent body, apparently including the courts, constitute serious breaches of both due process rights and, given the fact that many of those subject to these measures will be involved in facilitating online communications, the right to freedom of expression. Recommendations: ! The Central and Executive Committees should either not have any direct regulatory powers or they should be transformed into bodies that are independent of government. ! The powers that these bodies and the bodies that operate under them wield should be subject to appropriate both substantive and procedural conditions, along the lines of the constraints to which similar powers exercised by analogous actors, such as the police, are subject to in rule of law systems. ! The power to impose more intrusive sanctions, such as suspensions or terminations of service, should be subject to particularly limiting conditions. ! The imposition of the sorts of measures in the hands of the Central and Executive Committees, including sanctions, on private sector actors should always include a right of appeal to the courts. 2. Personal Data Protection and Data Storage Rules Myanmar does not currently have a data protection regime or even a proper set of rules on the protection of privacy, although these are both a key part of protecting basic human rights, in particular the right to privacy. Sections 13-15 of the draft Law, along with the sanctions envisaged in sections 56-57, create a very basic system of data protection. Section 13 calls on what are commonly referred to as “data controllers” to “systematically keep, protect and manage the personal information” in accordance with the law, along with a few more specific rules, such as destroying personal data once it is no longer needed. Section 14 also requires investigation teams to respect the confidentiality of personal data, subject to the law. Articles 56 and 57 provide for sanctions for data controllers who do not respect the rules and for others who interact in various ways with personal data without approval. This only begins to scratch the surface of what would constitute a proper personal data protection regime. A properly developed system would, among other things, place far more detailed obligations on data controllers, define precise and narrow exceptions to data protection principles, create a number of direct rights for data subjects (those to whom the data relates), including to inspect and correct or require the deletion of data in appropriate cases, and create an independent and empowered administrative oversight body to enforce the rules. The Centre for Law and Democracy is a non-profit human rights organisation working internationally to provide legal expertise on foundational rights for democracy -5-

Select target paragraph3