Some privacy and data protection breaches by government departments take place as a consequence of their own actions, due to a lack of awareness. For example, the initial version of DICA’s MyCo Companies Registry database allowed the full ID card/passport numbers of company directors to be seen in front of the paywall. Following feedback, including from MCRB, the ID numbers were masked to reveal only the last three digits of IDs, although full numbers are still available behind the paywall. 12 Some publications related to candidates for election, including from the Election Commission, included sensitive personal data such as Citizenship Scrutiny Card (CSC) number and father’s name. Such information is not needed by a voter. There are examples of government departments revealing similar personal data online, for example results of university entrance exams.13 This is particularly sensitive in the current period, when those who decide to attend state education institutions are liable to be ‘socially punished’ by those who advocate a boycott. The importance of keeping full personal identity numbers confidential has been recognized in the Aadhaar system which allows for the download of official ‘masked Aadhaar’ documentation to avoid identity theft.14 Similar arrangements need to be made in Myanmar to reduce the publication online and offline of sensitive personal data including ID numbers. Companies are also at fault due to failure to consider risks. MCRB has seen examples of Environmental Impact Assessment (EIA) reports uploaded online in which contain annexes of names of participants at public consultation meetings. In some cases participants had been required to fill in their ID card when they registered their attendance. While some project proponents and EIA consultants do not collect this data or recognise the need to mask it, not all are aware of the data protection breach. Furthermore, security in many public buildings including commercial premises require visitors to write their ID card or passport number in a publicly visible register, despite their being no security benefit from the acquisition of this information. These registers of sensitive personal data are inadequately protected, and available for scrutiny by the curious, or for capture by malicious actors. Public officials, and the public in Myanmar need to be educated to better protect personal data, including the incipient data protection provisions in the amended Electronic Transactions Law. Applying the principle of data minimisation to the collection of personal data in instances such as these helps prevent the inadvertent disclosure of confidential information relating to an individual’s personal identity. The International Association of Privacy Professionals identifies data minimisation as one of the core principles for reducing privacy harms “There should be limits to the collection of personal data, and any such data should be obtained by lawful and fair means and, where appropriate, with the knowledge or consent of the data subject.”15 3. Digital ID cards, Biometrics, and SIM Card Registration The absence of an adequate legal framework and safeguards for data protection has provided the backdrop to two ongoing initiatives to collective biometric and personal data which successive Myanmar 12 MCRB Provides Comments to DICA Consultation on the Disclosure of Company Information, 31 January 2020. MCRB also advocated for the database improve its back-end functionality so as to automatically link the same individual to multiple directorships, without needed to reveal their personal ID. 13 See for example the ID numbers, fathers’ names and addresses of the candidates for 2022 admission to Bogalay Education Degree College 14 https://www.uidai.gov.in/283-faqs/aadhaar-online-services/e-aadhaar/1887-what-is-masked-aadhaar.html 15 https://iapp.org/resources/article/fair-information-practices/ 5

Select target paragraph3