criticism of a government, jail journalists investigating corruption, censor freedom of expression, and more broadly discourage use of the internet. THREE STEPS FOR DEVELOPING GOOD CYBER CRIME LAWS 1. Ensure cyber crime legislation contains human rights protection and safeguards Cyber crime laws should be consistent with the Myanmar’s international obligations to protect human rights. That should also cover provisions on accessing electronic evidence in criminal matters irrespective of the way data stored extraterritorially is accessed. The human rights principles and safeguards of legality, necessity and proportionality, prior judicial authorisation, effective oversight, notification and access to effective remedy should apply.7 2. Define cyber dependent crimes narrowly These crimes should be interpreted to punish unauthorised access, with criminal intent, directed against the confidentiality, integrity and availability of computer systems and networks and the data stored there. 3. Ensure comprehensive legal frameworks for “cyber enabled crime” that focus on the fundamental nature of the crime, and not only on the use of ICT Cyber enabled crime refers to ‘traditional’ crimes committed in a new way using technology, such as fraud or distribution of child abuse images which should be a crime whether or not a computer is used. Therefore these crimes should be addressed in comprehensive criminal laws where the crime can be defined more precisely; put in its broader context; and the appropriate procedures for investigating and prosecuting the crime defined in more detail. THREE STEPS TO AVOID WHEN DEVELOPING CYBER CRIME LAWS 1. Do not criminalise behaviour that should not be criminal under international human rights law Examples include criticising the government on social media or using encrypted messaging services. 2. Do not mix surveillance together with a cyber crime law Surveillance can be necessary to fight crime. But it is an intrusive act and interferes with a range of human rights. Human rights law requires any surveillance to be legal, necessary and proportionate. Authorising surveillance powers in a cyber crime law leads to an expansion of the type of crimes for which surveillance is authorized, especially if the law authorizes surveillance for cyber enabled crimes. This can result in significantly greater intrusion into peoples’ privacy, particularly if it is not accompanied by procedural safeguards and other human rights protections within the law itself. Myanmar currently does not have a law on lawful surveillance/interception and lacks the prerequisites to a rights-respecting lawful surveillance regime8 Including a data protection law that applies to public entities as well as private ones.9 3. Do not just “copy and paste” the 2001 Budapest Convention into domestic law without additional human rights safeguards The provisions in the Budapest Convention need to be accompanied by human rights safeguards. The Budapest Convention - Council of Europe’s Convention on Cyber Crime 2001 The Council of Europe’s Convention on Cyber Crime 2001 (known as the “Budapest Convention”) is a 7 https://privacyinternational.org/advocacy-briefing/660/privacy-internationals-response-europeancommissions-public-consultation 8 For a lawful interception regime that respects human rights, see Myanmar Centre for Responsible Business’ “Recommendations to the Myanmar Government: Lawful Interception and Government Access to User Data: The Characteristics of a Rights-Respecting Model” in English Sector Wide Impact Assessment of Myanmar’s ICT Sector,” (2015), Recommendations – Annex, p. 35. And in Burmese 9 See MCRB’s companion Policy Brief on Privacy and Data Protection. 4

Select target paragraph3