Myanmar: Analysis of Draft Cyber Security Law
Furthermore, section 15 carves out a number of very broad exceptions from even these limited
general data protection obligations. These cover a wide range of functions that the draft Law
addresses, such as prevention, search, enquiry, investigation, data collection, information sharing
and coordination relating to cyber security and various other cyber risks. While every country
recognises some limitations to personal data protection rules for purposes of the administration
of justice, these need to be clearly and appropriately defined, which is not the case here.
The introduction of any data protection rules for Myanmar could be seen as a move in the right
directly. However, this would not be the case if this were in any way to serve as a barrier to the
adoption of a proper data protection system, which Myanmar urgently needs to do.
Section 28(a) of the draft Law calls on Internet service providers “in Myanmar” to ensure that
users’ data is stored “in a place designated by the Ministry”. It is not clear how the Ministry
might go about designating places for data storage but this sort of language is usually used to
refer to requirements to host data locally (i.e. within the jurisdiction). While many countries have
some local data storage requirements, the potential scope of this obligation under the draft law is
very broad indeed. Internet service providers are defined in section 3(u) as including any “person
or any business providing the online service to be used in Myanmar”, while section 3(t) defines
an “online service” very broadly to include any service provided online using digital equipment.
If applied broadly by the Ministry, these rules would make it impossible for many service
providers, including the social media platforms which provide essential services to enable
freedom of expression, to operate in Myanmar. Better practice would be to set much more
precise and limited rules and conditions for the designation of data storage places by the
Ministry. At a minimum, the Ministry should go about this task in a manner that does not
threaten the ability of communication service providers to operate effectively.
The draft Law sets strict rules on data retention by Internet service providers, with Section 30
requiring an extensive range of user data to be retained for “up to three years” (which we
understand as meaning for three years, since otherwise one day qualify as “up to three years”).
This includes name, address and ID details of the user, the service record of the user (which
could include telephone metadata for phone service providers – which numbers were called, for
how long and potentially even from where – or browsing history for Internet access providers)
and any other information the Department requires. International law has quite clear standards in
this area which prohibit the imposition of mass data retention requirements on service providers
(beyond what is needed for commercial purposes). Such requirements breach the right to privacy
and potentially also the presumption of innocence.
Section 31 then requires Internet service providers to provide this data to an “assigned person or
authorised organisation requested under any existing law”. The legitimacy of this depends on the
conditions in other laws for requiring third parties to provide private data to authorised bodies,
which is beyond the scope of this Analysis. However, international law establishes strict
conditions for accessing this sort of information. Furthermore, extensive experience in countries
around the world shows that it is very difficult to ensure respect even for legal provisions in this
space, which is another reason why mass data retention rules are not legitimate in the first place.
The Centre for Law and Democracy is a non-profit human rights organisation working internationally to
provide legal expertise on foundational rights for democracy
-6-