• Undertake a data protection impact assessment when surveillance cameras are deployed, camera positions changed or new technological capabilities such as automatic facial recognition are used. • Where CCTV is in use, place clear signs in English and Myanmar to inform the public that they may be recorded. • Control access to recordings. Establish SOPs including escalation to senior management to respond to any demands for data from public authorities. Seek to have requests for data put in writing. Do not give unrestricted access to public authorities to CCTV monitoring points. • Provide access to recordings of individuals who have been recorded, on their request. • Retain CCTV footage for as short a time as possible and not more than 30 days, unless it is being used as criminal evidence, or shows evidence of human rights abuses and may be useful to those seeking redress. • For scenarios involving peaceful protest, consider adopting SOPs to stop recording and immediately delete CCTV data where there is a risk that it will otherwise be used by the authorities to arrest those exercising their right to freedom of expression MCRB also identified the 12 Guiding Principles of the Amended Surveillance Camera Code of Practice, UK Government, December 2021 and the template for a data protection impact assessment for surveillance cameras developed by the UK Information Commissioner Office and the Surveillance Camera Commissioner as useful tools that could be applied by companies in Myanmar. However, this seems to be an under-scrutinised area of technology use that would benefit from guidance by digital rights experts. New legal frameworks relating to ICT A draft cybersecurity law has been under preparation for several years in Myanmar. Shortly after taking power on 1 February 2021, the military regime sent a limited number of business associations a draft of the law for comment. MCRB prepared a document analysing elements of the draft law from a human rights perspective, including the rights to privacy and freedom of expression (both of which are contained in Myanmar’s constitution). This document was provided to organisations, particularly businesses, who could respond to the call for comments and engage in advocacy on the draft law. Perhaps in the face of significant concern expressed by businesses and others, rather than adopt the draft Cybersecurity Law, the military regime instead incorporated elements of the draft cybersecurity law concerning privacy and data protection into amendments to an earlier Electronic Transactions Law (ETL)5. These amendments establish a requirement to protect ‘personal data’ and penalties for failure to do so. But they lack clarity on how collected data should be handled, such as provisions on the retention period, classification of the information to be stored and storage location. While representing the first time that Myanmar has had a legal framework for data protection, the provisions are not consistent with international human rights standards. Furthermore, very few people, including in the regulator, appear aware of the new legal requirements for data protection, or doing anything to enforce them. In January 2022, a revised draft Cybersecurity Law was circulated for comment, having been partially amended to reflect comments received in February 2021, primarily from businesses. This included new 5 See MCRB’s consolidated version of the 2004 Electronic Transactions Law, as amended in 2014 and 2021, and unofficial translation, and pages 76-78 of Private Security Companies in Myanmar: A Baseline Study, Human Rights Risk Assessment and Recommendations, MCRB February 2022. Free Expression Myanmar’s analysis of 18 February 2021 of ‘Myanmar’s new Electronic Transactions Law Amendment’, highlights the relationship of these amendments to the provisions originally included in the draft Cybersecurity law. 3

Select target paragraph3