4 Telecommunications Operators  Challenge lawful interception requests without appropriate legal safeguards: 4.4  • Operators are the party in the ICT value chain that receives any request from the government for interception of the content of phone calls and emails, or access to other information such as user/subscriber information and records. As noted above, Article 75 of the 2013 Telecommunications Law includes a sweeping provision on surveillance. Subsequent regulations for assistance with real time surveillance are not in place. One of the current telecommunications operators, Telenor, has stated publicly that they will not respond to any interception requests from law enforcement officials until the legal framework is in place. 398. Even when such regulations are in place and even assuming that they are aligned with international law, given the history and current state of development of Myanmar’s judiciary, the operators may be one of the few credible actors in the process capable of challenging overly broad or inappropriate requests. Develop robust systems for responding to government requests to avoid overcomplying with illegal requests. 399 Such a company system could include for example, ensuring that there is a process in place to review each request submitted; a designated contact person in the company; a list of government departments authorised to request information; a requirement that the request to the company must be made in writing (or at least followed up in writing if such a request is made during the course of an emergency); challenging requests that do not comply with the law or human rights standards; developing criteria for escalation of requests; and where feasible, notifying affected customers or users. See the Annex to the Recommendations for further information. Be transparent about the number of requests for surveillance: Out of three telecommunications operators in Myanmar, only one telecommunications operator issues a transparency report disclosing interception requests from law enforcement, including cases the company has complied with. ‘Over the Top’ Companies (National and International)  Challenge requests for user information without appropriate safeguards: Like telecommunications operators, over the top companies which store data on servers inside Myanmar need robust systems for screening and responding to such requests to ensure that they do not contribute to potential human rights violations. 400 While certain information about a user may be publicly accessible, for example by looking at a public profile on social media, companies store much additional personal information about their users, such as names, addresses, contact numbers and private online conversations. Depending on the service, companies will also have a lot of information about a person’s movements, how they spend their time and money and the opinions they hold, which could potentially be used in gathering intelligence. Over the top companies may also be requested to turn over user information by the Government as part of its surveillance activities. 398 Telenor, “Myanmar sustainability presentation” (19 August 2014), pg. 8 of the transcript. See for example guidance on dealing with government requests: European Commission, “ICT Sector Guide on Implementing the Corporate Responsibility to Respect Human Rights” (2013), pg. 44-45 and the Telecommunications Industry Dialogue. 400 See for example guidance on dealing with government requests: European Commission, “ICT Sector Guide on Implementing the Corporate Responsibility to Respect Human Rights” (2013), pg. 44-45 and the Global Network Initiative (GNI), “Principles and Implementation Guidance” (last accessed August 2015) on dealing with government requests. 399 178 PAGE CHAPTER 4.4: SURVEILLANCE – LAWFUL INTERCEPTION & OTHER SURVEILLANCE METHODS

Select target paragraph3