1. Lack of human rights safeguards in the legal framework There have always been significant risks in Myanmar to digital rights, such as privacy, freedom of expression, and access to information. This is due both to the lack of human rights safeguards in the legal framework for telecoms/ICT, and to provisions in the laws which are either vague or inconsistent with international human rights standards. This includes laws – or the lack of them – on issues such as lawful interception, cybersecurity, data protection and cybercrime. These gaps were analysed in MCRB’s 2015 Sector Wide Impact Assessment1 and updated in subsequent policy briefs.2 When undertaking human rights due diligence and risk assessments in Myanmar, companies therefore need to take account of the weaknesses in the legal framework and lack of human rights protection that it provides. In the absence of effective legal requirements, companies need to pre-emptively take preventative and mitigating steps through the adoption of good practice and guidance from other countries, and incorporating, applying and enforcing provisions in policies, contracts and standard operating procedures (SOPs) which draw on international human rights standards. MCRB summarised some of these issues in the input it made to the UN Office of the High Commissioner on Human Rights in March 2022 concerning the High Commissioner’s report on the practical application of the Guiding Principles on Business and Human Rights to the activities of technology companies. 3 In that input, MCRB summarised the – unsuccessful - attempts made by MCRB, some companies and others, to introduce safeguards into the legal framework which could reduce the human rights risks for companies and impacts for rightsholders. Failure to incorporate human rights safeguards, in particular for lawful interception, contributed to Telenor’s decision in 2021 to exit Myanmar. Use of visual/video surveillance and monitoring There is no legal framework for use of visual/video surveillance in Myanmar, generally referred to as Closed Circuit TV (CCTV). CCTV and other security systems (e.g. alarms, entry systems, GPS trackers) can, in addition to capturing activities, also capture sensitive personal data, including in metadata. Some of the risks associated with this were identified in MCRB’s February 2022 Baseline Study and Human Rights Risk Assessment of Private Security Companies in Myanmar. 4 For example, CCTV recordings can be accessed and reviewed by public security to identify those involved in peaceful protest. In the absence of regulation on CCTV usage, MCRB recommended companies should: • Consider whether deployment of CCTV or other recording equipment addresses a legitimate pressing need that cannot be addressed by other means. • Ensure that CCTV is only used for designated purposes and legitimate aims, such as prevention of crime, and not, for example, to spy on employees, customers or neighbours. • Ensure that CCTV deployment is proportionate to the need. Disable audio recording. Consider whether a live feed is sufficient, rather than recording. 1 https://www.myanmar-responsiblebusiness.org/pdf/SWIA/ICT/complete.pdf https://www.myanmar-responsiblebusiness.org/pdf/2019-Policy-Brief-Myanmar-ICT-Legal-Framework_en.pdf 3 https://www.myanmar-responsiblebusiness.org/news/guiding-principles-tech-sector.html 4 Private Security Companies in Myanmar: A Baseline Study, Human Rights Risk Assessment and Recommendations, MCRB February 2022. 2 2

Select target paragraph3