Myanmar: Analysis of Draft Cyber Security Law
This Analysis focuses on six issue areas in the draft Law, namely the independence and powers
of the institutional structures created by the draft Law, the rules on personal data protection and
data storage, restrictions on the content of what may be shared online, other criminal rules in the
draft Law, the burdens placed on private sector actors (important from a freedom of expression
perspective since many of these actors serve to facilitate or enable online speech), and critical
information infrastructure. The analysis itself is drawn from international human rights
standards, for example as set out in the Universal Declaration of Human Rights (UDHR),5
adopted in 1948. As a United Nations General Assembly resolution, the UDHR is not directly
binding on States but its preeminent status as a statement of international human rights and the
fact that States rarely if ever repudiate at least some of its principles means that those principles,
including its guarantees of freedom of expression and privacy, have very likely acquired legal
force as customary international law.6
1. Institutional Structures: Independence and Powers
The draft Law creates four main institutional structures. At the top of the pyramid is the Cyber
Security Central Committee (Central Committee), appointed by the State Administration
Council, which was itself created on 2 February 2021 to serve as the peak executive body in
Myanmar under the new governing arrangements. The Chair of the State Administration Council
and the Minister of the Ministry responsible for cyber security serve as co-chairs of the Central
Committee, which also draws members from among other ministers and a secretary appointed by
the State Administration Council (section 5(a)). The Central Committee is thus entirely
controlled by the executive.
The Cyber Security Executive Committee (Executive Committee), in turn, is appointed by the
Central Committee, with the approval of the State Administration Council. The Minister of the
Ministry responsible for cyber security serves as the chair, with members being drawn from
among deputy ministers or permanent secretaries of different ministries, cyber security
professionals and representatives of non-governmental organisations (section 9). Although the
Executive Committee does include non-government representatives, its appointment by the
Central Committee gives the executive control over it. Furthermore, both the Central Committee
and the Executive Committee are served by a secretariat which is “determined” by the State
Administration Council, which performs under the supervision of the Ministry responsible for
cyber security and which is responsible for the work of both Committees (sections 7 and 8). This
further cements the executive’s control over the Executive Committee.
Third, the Executive Committee, with the agreement of the Central Committee, shall form
Working Committees, at least in the areas of Cyber Security, Cyber Crimes and Cyber Protection
5
United Nations General Assembly Resolution 217A (III), 10 December 1948.
See, for example, D'Amato, A., "Human Rights as Part of Customary International Law: A Plea for Change of
Paradigms" (2010, Faculty Working Papers, 88),
https://scholarlycommons.law.northwestern.edu/facultyworkingpapers/88; and Meron, T., Human Rights and
Humanitarian Norms as Customary Law (1989, Oxford, Clarendon Press).
6
The Centre for Law and Democracy is a non-profit human rights organisation working internationally to
provide legal expertise on foundational rights for democracy
-2-