ANALYSIS OF THE PROVISIONS OF THE DRAFT CYBER SECURITY LAW Chapter VII assigned duties by the Central Committee in respect of Cybersecurity, Cyber-attacks, Cyber-terrorism, Cyber Misuse, Cyber Incident and Cybercrimes; b) Any detection, inspection, collection of news, litigation and submission of the evidence to any court conducted by the government departments, investigation teams, or regulatory bodies assigned the duties by the Central Committee according to criminal cases; c) Any detection, inspection, collection of news and coordinating of information that are conducted according to the relevant Cybersecurity and Cybercrime related cases if such cases impact the country’s sovereignty, stability and peace; and d) The administrative power shall be determined by the Central Committee or Related Ministry or Department in the course of administrating the cases prescribed in subsection (c). Protecting Critical Information Infrastructure Section 16: Sections The Critical Information Infrastructure shall be as following: 16, 17 and a) e- Government Services, 20 b) Electronic information and infrastructure related to finance; c) Electronic information and infrastructure related to water resources; d) Electronic information and infrastructure related to transportation; e) Electronic information and infrastructure related to communication; f) Electronic information and infrastructure related to public health sector; g) Electronic information and infrastructure related to electricity and energy; h) Electronic information and infrastructure related to natural resources; and 12 February 2021 Considering the wide scope of the provisions, the management of personal data for an enlarged scope of enforcement activities vests with the governmental authorities where personal data would necessarily need to be transferred to the governmental authorities. A. Section 16 gives the definition of Critical Information Infrastructure as decided and designated by the government authorities. B. Further, under Section 17 it may be interpreted that unfettered power is given to the governmental authorities under which the governmental authorities may amend the list of the Critical Information Infrastructure as from time to time. C. In accordance with this chapter, the governmental authorities may lay down policies for the storage and maintenance of the facts and information that are related to the Critical Information Infrastructure. D. Most importantly, under Section 20, the person responsible for the processing and maintaining of the Critical Information Infrastructure, shall keep the facts and information that are related to the Critical Information Infrastructure, at the place determined and approved by the Ministry. Therefore, the effect of this is two-pronged- all such critical information (deemed to be) shall be kept inside Myanmar and such data may have unrestricted access by the governmental authorities. 3

Select target paragraph3