Some privacy and data protection breaches by government departments take place as a consequence of
their own actions, due to a lack of awareness. For example, the initial version of DICA’s MyCo Companies
Registry database allowed the full ID card/passport numbers of company directors to be seen in front of
the paywall. Following feedback, including from MCRB, the ID numbers were masked to reveal only the
last three digits of IDs, although full numbers are still available behind the paywall. 12
Some publications related to candidates for election, including from the Election Commission, included
sensitive personal data such as Citizenship Scrutiny Card (CSC) number and father’s name. Such
information is not needed by a voter. There are examples of government departments revealing similar
personal data online, for example results of university entrance exams.13 This is particularly sensitive in
the current period, when those who decide to attend state education institutions are liable to be ‘socially
punished’ by those who advocate a boycott.
The importance of keeping full personal identity numbers confidential has been recognized in the Aadhaar
system which allows for the download of official ‘masked Aadhaar’ documentation to avoid identity
theft.14 Similar arrangements need to be made in Myanmar to reduce the publication online and offline
of sensitive personal data including ID numbers.
Companies are also at fault due to failure to consider risks. MCRB has seen examples of Environmental
Impact Assessment (EIA) reports uploaded online in which contain annexes of names of participants at
public consultation meetings. In some cases participants had been required to fill in their ID card when
they registered their attendance. While some project proponents and EIA consultants do not collect this
data or recognise the need to mask it, not all are aware of the data protection breach. Furthermore,
security in many public buildings including commercial premises require visitors to write their ID card or
passport number in a publicly visible register, despite their being no security benefit from the acquisition
of this information. These registers of sensitive personal data are inadequately protected, and available
for scrutiny by the curious, or for capture by malicious actors.
Public officials, and the public in Myanmar need to be educated to better protect personal data, including
the incipient data protection provisions in the amended Electronic Transactions Law. Applying the
principle of data minimisation to the collection of personal data in instances such as these helps prevent
the inadvertent disclosure of confidential information relating to an individual’s personal identity. The
International Association of Privacy Professionals identifies data minimisation as one of the core principles
for reducing privacy harms “There should be limits to the collection of personal data, and any such data
should be obtained by lawful and fair means and, where appropriate, with the knowledge or consent of
the data subject.”15
3. Digital ID cards, Biometrics, and SIM Card Registration
The absence of an adequate legal framework and safeguards for data protection has provided the
backdrop to two ongoing initiatives to collective biometric and personal data which successive Myanmar
12
MCRB Provides Comments to DICA Consultation on the Disclosure of Company Information, 31 January 2020.
MCRB also advocated for the database improve its back-end functionality so as to automatically link the same
individual to multiple directorships, without needed to reveal their personal ID.
13
See for example the ID numbers, fathers’ names and addresses of the candidates for 2022 admission to Bogalay
Education Degree College
14
https://www.uidai.gov.in/283-faqs/aadhaar-online-services/e-aadhaar/1887-what-is-masked-aadhaar.html
15
https://iapp.org/resources/article/fair-information-practices/
5