Myanmar: Analysis of Draft Cyber Security Law
Recommendations:
! Myanmar should adopt a fully developed personal data protection regime, in line with
international standards, including as to any exceptions.
! The local data storage system in the draft Law should either be removed entirely or
replaced with a far more narrow and tailored system that takes into account the needs
of Internet service providers in Myanmar.
! The data retention requirements should be removed.
! The power of authorities to require Internet service providers to provide personal user
data should be subject to appropriate legal conditions, in line with the purpose for
which the authority is seeking access.
3. Content Restrictions
The draft Law contains a number of restrictions on the types of content that may be disseminated
online, and puts in place systems to counter these types of content. The primary provision in this
regard is section 29, calling for the “prevention, removal, destruction and cessation” by Internet
service providers, “in a timely manner”, at the request of the Department, of the types of content
it identifies, where that content is “on cyber space”. The exact modalities by which this system is
intended to work are not clear from the provision. However, the approach appears to be very
problematical. First, while all regulation by bodies that are not independent of government which
affects freedom of expression represents a breach of international law, as noted above, direct
content regulation along these lines by far the most problematical, for fairly obvious reasons (i.e.
because such powers are likely to be used in a less than politically objective manner). Second,
any system of content regulation should set out clear rules, including procedures, governing the
way content deemed to be contrary to the rules will be addressed. This provision simply refers to
a range of possible measures – prevention, removal, destruction, cessation – without indicating
how the system will work. It seems likely that Internet service providers will simply be expected
to do whatever the Department “orders” in relation to specific content. They may also be
expected to take measures vis-à-vis the users responsible for this content, for example under the
rubric of “prevention”. If so, this provision would engage a number of due process and other
rights concerns. Third, content regulation systems should incorporate due process protections for
users, whereby they can contest any actions taken against their content. No such protection
appears to be envisaged here. Fourth, the provision is unclear as to whether the content in
question even needs to have been made available publicly. Cyber space includes fully public
communications, such as open content on public websites, partially public communications, such
as information shared with a pre-defined group on a social media platform, and private
communications, such as one-to-one communications. All of these would appear to be captured
by this provision.
The Centre for Law and Democracy is a non-profit human rights organisation working internationally to
provide legal expertise on foundational rights for democracy
-7-