5/22/22, 12:03 AM Myanmar: Freedom on the Net 2021 Country Report | Freedom House Soe Oo were arrested in 2017 (see C3), the police were accused of using Wa Lone’s confiscated phone to send a WhatsApp message on his account. 309 The police used the Israeli phone-breaching product known as Cellebrite to collect data from the journalists’ smartphones. 310 Cellebrite technology has been used by the police since 2016, and although the company ceased selling its products in Myanmar in late 2018, authorities continue to employ them. In 2019, FinSpy malware developed by Germany’s Gamma Group was reported to be in operation in Myanmar. 311 It is unclear who purchased the spyware. In 2018 the MoTC announced its intention to build a data center that would serve as a secure base for its planned e-government services in Naypyidaw, and in December of that year the ministry requested that the parliament approve a $95 million loan from South Korea to support the project. 312 The Mandalay regional government launched a data center in January 2019 to provide e-government services. 313 Concerns have been raised that these data centers will lack adequate privacy and security safeguards. 314 C6 0-6 pts Does monitoring and collection of user data by service providers and other technology companies infringe on users’ right to privacy? 1/6 Service providers are increasingly obliged to hand data over to the state without sufficient oversight or safeguards. The Law Protecting the Privacy and Security of Citizens, passed in 2017 and partially suspended since the coup, 315 prohibits the interception of personal communications without a warrant, but it contains a vague exception allowing surveillance if permission is granted by the president or a government body. 316 The law does not outline clear procedures to prevent data from being collected and stored, nor does it provide for judicial review. Critics argue that the law’s definition of privacy is inadequate and inconsistent with international human rights standards. 317 Other privacy-related laws demanded by a range of private-sector and civil society stakeholders, including a robust data protection law, have not yet been introduced. 318 The Telecommunications Law grants the government the power to direct unspecified persons “to secure any information or communication which may harm security, rule of law, or peace of the state.” 319 A provision stating that any interception should not “hurt the fundamental rights of citizens” is an inadequate safeguard against abuse. 320 The Telecommunications Law also grants the government the power to inspect the premises of telecommunications license holders and to require them to hand over documents—for the ill-defined purposes of defending the “security of the state” or “the benefit of the people”—without safeguards for individuals’ privacy and other human rights. 321 A 2018 amendment to the Narcotic Drugs and Psychotropic Substances Law included a new provision requiring telecommunications providers to disclose user information without due process. 322 There are no requirements for judicial review. Civil society activists have raised concerns that the opaque mass directives being issued to service TOP providers by the military since the coup include orders for widespread interception (see A4, B1, and B3). 323 The draft cybercrimes law would also require service providers to store data on servers designated by and fully accessible to the military (see C5). There is little room for providers to push back against the military’s directives, though in at least one instance they did so effectively. On March 30, one regional https://freedomhouse.org/country/myanmar/freedom-net/2021 24/28

Select target paragraph3