Myanmar: Analysis of Draft Cyber Security Law jurisdictional rules (note that if they did this in Myanmar, they could hardly refuse to do it in other countries as well). It is not clear how such a rule could be enforced in any case. A similar problem relates to section 28(c), about paying local taxes. While this may appear reasonable, and many jurisdictions are indeed looking at how they can claim taxes relating to profits which online companies in fact harvest in their countries, even if they do not have any material base of operations there, in fact the issue is quite complicated and a simple provision like this, which does not take into account any of the actual complexity of the situation, may put users at risk without actually being able to be implemented. Sections 32-35 deal with licensing and registration, which is undertaken by the Department, while section 78 gives existing providers a year to renew their operating arrangements in this regard. While it is not unreasonable to expect, respectively, electronic certification issuers (section 32) and cyber security services (section 33) to have licences, given the security nature of their work, and Internet service providers to register (section 34), there are a few problems with this. First, there is the problem noted above, of companies that provide these services but are based in other countries. Second, it is not reasonable to require Internet service providers both to incorporate under the companies law and to register with the Department. Third, section 78 may breach the legal rights of some existing providers, potentially even through the Department refusing to renew a licence which had had a number of years’ duration remaining. It is not clear why existing licences should not be continued, perhaps by providing that they are deemed to be amended as necessary to conform to the new legal rules. Finally, the importance of having this sort of function undertaken by an independent body has already been noted. The problems with the provisions above are exacerbated by section 61, which provides for imprisonment for up to three years and/or a fine of up to MMK 10,000,000 (approximately USD 7,000) for breach by any Internet service provider of “provisions prescribed in this law”. This is quite a harsh maximum penalty, especially for some of the rules. It is not clear how imprisonment might apply under Myanmar law to a company, which these entities would be legally required by the draft Law to be, but to the extent that directors might be personally liable under these provisions, this could deter worthy people from taking up these sorts of positions. Recommendations: ! Consideration should be given to removing entirely sections 27 and 44. At a minimum, they should be scaled back considerably to apply only as appropriate and relevant to different Internet service providers. ! The rules on incorporation, taxation, licensing and registration should be fundamentally reconsidered. At a minimum, the working needs and reality of companies based abroad should be recognised and any obligations on them should be carefully tailored based on this, existing companies should have their licences respected and the sanctions should be more carefully adapted to the different sorts of breaches by private companies. The Centre for Law and Democracy is a non-profit human rights organisation working internationally to provide legal expertise on foundational rights for democracy - 12 -

Select target paragraph3