Myanmar: Analysis of Draft Cyber Security Law Furthermore, section 15 carves out a number of very broad exceptions from even these limited general data protection obligations. These cover a wide range of functions that the draft Law addresses, such as prevention, search, enquiry, investigation, data collection, information sharing and coordination relating to cyber security and various other cyber risks. While every country recognises some limitations to personal data protection rules for purposes of the administration of justice, these need to be clearly and appropriately defined, which is not the case here. The introduction of any data protection rules for Myanmar could be seen as a move in the right directly. However, this would not be the case if this were in any way to serve as a barrier to the adoption of a proper data protection system, which Myanmar urgently needs to do. Section 28(a) of the draft Law calls on Internet service providers “in Myanmar” to ensure that users’ data is stored “in a place designated by the Ministry”. It is not clear how the Ministry might go about designating places for data storage but this sort of language is usually used to refer to requirements to host data locally (i.e. within the jurisdiction). While many countries have some local data storage requirements, the potential scope of this obligation under the draft law is very broad indeed. Internet service providers are defined in section 3(u) as including any “person or any business providing the online service to be used in Myanmar”, while section 3(t) defines an “online service” very broadly to include any service provided online using digital equipment. If applied broadly by the Ministry, these rules would make it impossible for many service providers, including the social media platforms which provide essential services to enable freedom of expression, to operate in Myanmar. Better practice would be to set much more precise and limited rules and conditions for the designation of data storage places by the Ministry. At a minimum, the Ministry should go about this task in a manner that does not threaten the ability of communication service providers to operate effectively. The draft Law sets strict rules on data retention by Internet service providers, with Section 30 requiring an extensive range of user data to be retained for “up to three years” (which we understand as meaning for three years, since otherwise one day qualify as “up to three years”). This includes name, address and ID details of the user, the service record of the user (which could include telephone metadata for phone service providers – which numbers were called, for how long and potentially even from where – or browsing history for Internet access providers) and any other information the Department requires. International law has quite clear standards in this area which prohibit the imposition of mass data retention requirements on service providers (beyond what is needed for commercial purposes). Such requirements breach the right to privacy and potentially also the presumption of innocence. Section 31 then requires Internet service providers to provide this data to an “assigned person or authorised organisation requested under any existing law”. The legitimacy of this depends on the conditions in other laws for requiring third parties to provide private data to authorised bodies, which is beyond the scope of this Analysis. However, international law establishes strict conditions for accessing this sort of information. Furthermore, extensive experience in countries around the world shows that it is very difficult to ensure respect even for legal provisions in this space, which is another reason why mass data retention rules are not legitimate in the first place. The Centre for Law and Democracy is a non-profit human rights organisation working internationally to provide legal expertise on foundational rights for democracy -6-

Select target paragraph3