policies were mostly absent. One bank maintained a data centre for production and
a data centre for disaster recovery.
Protection of data from unauthorised access within the company: Rolesegregation varied among businesses collecting customer’s personal data. One
bank segregated employees conducting a ‘Know Your Customer’ check (where
basic information was provided, such as a National Registration Card) from
employees conducting financial transactions.
Affordability of data protection: Many businesses used pirated software for
internal business functions including email which presents a data protection risk.
Small and medium size businesses complained about the cost of buying licensed
software.
Lack of policies or clear communication of policies: Data retention policies were
absent, or in some cases not clearly communicated to the customer/user even when
internally present (e.g. 5 years for retention of customer data on paper).
Myanmar Good Practice Examples:
Companies are beginning to conduct threat and vulnerability assessments across
their applications, network, and infrastructure on an ongoing basis to test the
security of the data held in their systems. One bank uses two separate companies
to perform assessments (one local and one international).
C. Privacy: Recommendations for ICT Companies
General
Understand contextual risks around Myanmar’s history and Government action:
Given Myanmar’s historical legacy of Government surveillance and information
control, coupled with ICT policies and laws that are not aligned with international
human rights standards, there exist significant risks for violation of ICT user rights to
protection of privacy and anonymity. There are also risks for any ICT company that
may be implicated in such violations. Risks related to the violation of the right to
privacy in Myanmar with respect to Government actions can be categorised into at
least two separate but closely related areas of concern:
• Government monitoring and surveillance of user activity and content; and
• Government access to user-identifying information (See Chapter 4.4 on
Surveillance).
Use company procedures to plug gaps in the Myanmar legal framework: As
Myanmar currently has no legal requirements for mandatory protection of data of ICT
users, this means that the protection of personal data is left to individual companies or
Government departments, if at all. Sectors such as ICT or the financial sector are
likely to be more aware of the importance of data protection. Companies in these
sectors may have their own policies and procedures, or industry-specific standards to
assist in developing systems and policies. But other companies will also need to
develop systems to protect personal information, as well as externally available
policies to inform customers about how their data is being handled (see next point).
Develop and implement appropriate policies and procedures to safeguard data
privacy: Companies in the ICT value chain, which often collect and store a large
amount of personal information about their users, need processes and policies in
place to ensure they protect user information. These must be clear about how they will
collect, store and share user information with third parties, and under what
circumstances the Government (or others) can have access to information or intercept
communications. This information would usually be set out in a company’s ‘privacy
CHAPTER 4.3: PRIVACY
163
4
4.3