You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 23, 2021

Myanmar Amends Legislation on the Privacy and Security of Citizens amid State of Emergency

As many are already aware, following the change of government in Myanmar on February 1, 2021, a draft Cyber Security Law was proposed which attracted widespread criticism.

However, less attention has been paid to significant amendments to two existing laws, some of which have a similar effect to parts of the draft Cyber Security Law. In other words, while the draft Cyber Security Law has not progressed further and is under public scrutiny, significant elements of it have found their way into law in Myanmar by other routes. Because these amendments are already law, it is very important that individuals and businesses in Myanmar understand their implications.

Amendments to the Law Protecting the Privacy and Security of Citizens

The Law Protecting the Privacy and Security of Citizens (2017), or the “Privacy Law,” was amended on February 13, 2021, less than two weeks after the military government came into power. These amendments chiefly address the power of the government to conduct searches, seizures, and arrests; to extend detention without judicial oversight; and to carry out broad surveillance and investigation activities that could intrude on individual privacy. The amendments accomplish this by suspending various sections of the Privacy Law for as long as the State Administration Council (the military body now governing Myanmar) is in power. The suspended sections include the following:

  • Section 5: Search, seizure, and arrest without civilian observation

The relevant part of Section 5 of the Privacy Law states, “The responsible authorities shall … when acting in accordance with existing law, not enter into a person’s residence or a room used as a residence, or a building, compound or building in a compound, for the purpose of search, seizure, or arrest, unless accompanied by minimum of two witnesses who should comprise Ward or Village Tract Administrators…”.

The suspension of this section means that government agents can now enter people’s homes for the purposes of search, seizure, and arrest without civilian witnesses.

  • Section 7: Indefinite detention (habeas corpus)

Section 7 of the Privacy Law states that “No one shall be detained for more than 24 hours without permission from a court unless the detention is in accordance with existing law.”

The suspension of this section means that individuals in Myanmar may now be detained in prison indefinitely without the intervention of court proceedings.

  • Section 8: Wide-ranging individual privacy rights

Section 8 of the Privacy Law is the most wide-ranging and covers arrest, search and seizure of property, interception of telecommunications without proper authority, and various other issues of personal privacy:

“In the absence of an order, permission, or warrant issued in accordance with existing law, or permission from the Union President or the Union Cabinet, a Responsible Authority:

      1. Shall not enter into a citizen’s private residence or a room used as a residence, or a building, compound or building in a compound, for the purpose of search, seizure, or arrest.
      2. Shall not surveil, spy upon, or investigate any citizen in a manner which could disturb their privacy and security or affect their dignity.
      3. Shall not intercept or disturb any citizen’s communication with another person or communications equipment in any way.
      4. Shall not demand or obtain personal telephonic and electronic communications data from telecommunication operators.
      5. Shall not open, search, seize or destroy another person’s private correspondence, envelope, package or parcel.
      6. Shall not unlawfully interfere with a citizen’s personal or family matters or act in any way to slander or harm their reputation.
      7. Shall not unlawfully seize the lawfully owned movable or immoveable property of a citizen, or intentionally destroy it either directly or by indirect means.”

Because of the suspension of this section, any of the above actions by governmental authorities now appear to be lawful in Myanmar.

Amendments to the Electronic Transactions Law

On February 15, 2021, the Electronic Transactions Law (2004)—the “ET Law”—was amended to introduce a broad exception allowing government confiscation of personal data, and a prohibition on sharing various types of information online. It is interesting to note that previously—in the draft of the Cyber Security Law—the administration intended to repeal the ET entirely, but this approach appears to have changed, as detailed below.

  • Government access to personal data

The data protection elements of the draft Cyber Security Law have essentially been incorporated into the new Chapter 10 of the amended ET Law. These provisions are brief and not comparable to the standards achieved by personal data protection regimes in other modern legal frameworks.

This chapter provides a new exception (Section 27-C) to the safe management of personal data in the case of “detecting, investigating, organizing of information, verifying the information conducted in accordance with management power on the cyber security and cybercrime matters relating to stability, tranquility, national security of the state.” “Stability,” “tranquility,” and “national security” are not defined in the legislation, but a wide enough interpretation would allow the government sweeping authority to obtain the personal data of any individual in Myanmar whenever it considers it necessary to do so.

  • Internet posts

Posting information on the internet is dealt with in Section 38-C of the amended law: “Whoever, at the cyber space, commits creating false news or fake news with the intention to cause public panic, to lost trust, to lower the dignity by public or to destroy the unity of any association, on conviction shall be punished with imprisonment for a term which may extend from a minimum of one year to a maximum of three years or with a fine not exceeding ten million Kyats or with both.”

This legislation does not  define “false news,” “fake news,” “public panic,” “lost trust,” “lower dignity,” or “destroy unity” which leaves room for wide interpretation and use.

The combined effect of these amendments is that government agents may, without court intervention:

  • Arrest and indefinitely detain anybody in Myanmar;
  • Seize or destroy property;
  • Intercept communications whether electronic or postal;
  • Access personal data wherever located;
  • Demand information from telecommunications service providers; and
  • Arrest and detain individuals for online posting of content deemed undesirable.

As these legal developments represent potentially significant shifts in the legal landscape for Myanmar, all individuals and businesses in Myanmar need to be fully aware of the changes.

RELATED INSIGHTS​ 

July 23, 2026
Aviation law experts from Tilleke & Gibbins’ Vietnam offices have prepared the Vietnam chapter of Aviation Finance & Leasing 2026 from Chambers and Partners. Covering nearly 40 jurisdictions worldwide, the guide addresses key legal considerations for aircraft lessors, lessees, and financiers. Alongside the Vietnam chapter, Tilleke & Gibbins also provided the Thailand chapter for this year’s edition. The Vietnam chapter delivers detailed insights into the legal environment affecting aircraft sale and purchase, aircraft and engine leasing, and aircraft debt finance. Some of the topics it examines include: sale and lease agreement terms taxation lease registration and enforcement lease assignment/novation insurance and reinsurance debt structuring securities liens The guide also covers other issues influencing the day-to-day activities of aviation industry participants in Vietnam. Chambers and Partners’ Global Practice Guides provide in-house counsel with authoritative analysis of practical legal matters impacting business, enabling readers to compare legislation and relevant procedures across leading jurisdictions. The Vietnam chapter of Aviation Finance & Leasing 2026 is available on the Chambers and Partners website.
July 21, 2026
Thailand’s Ministry of Digital Economy and Society (MDES) published a notification establishing an expedited court-ordered takedown mechanism for online content in cases of “urgent necessity.” The notification, which was issued on July 17, 2026, under the Computer Crime Act B.E. 2550 (2007), as amended, took effect the following day. It significantly expands the categories of content subject to rapid government-initiated removal. Content Categories Subject to Takedown The notification defines “urgent necessity” (section 20, paragraph 5, of the Computer Crime Act) as circumstances where any delay in suppressing computer data may impact national security, religion, the monarchy, good morals, social culture, or public order. In this regard, it establishes four broad categories of content: Computer Crime Act offenses. National security offenses. IP and other criminal offenses, where it is contrary to public order or good morals and a competent officer has requested its suppression. Content contrary to public order or good morals, a broad residual category encompassing 14 subcategories approved by the Computer Data Screening Committee. The fourth category is the most expansive. Its 14 subcategories include: Content defaming, mocking, satirizing, or devaluing the monarchy. Online gambling advertising or facilitation. Offering illegal firearms for sale. Offering baraku (hookah) products or e-cigarettes for sale. Offering cannabis inflorescences or processed cannabis products for sale. Advertising or soliciting prostitution. Content inciting violence, hatred, or social division. Unauthorized overseas employment advertising. Offering boiled kratom juice for sale. Online sale or advertising of alcoholic beverages. Content satirizing or degrading Buddhism. Money lending at interest rates exceeding legally prescribed limits. Advertising or disseminating information about surrogacy services. Forgery of documents, cards, or official documents. Enforcement Procedure In cases of urgent necessity, a competent official assigned by the MDES permanent secretary must file a petition with supporting evidence to the court with jurisdiction, requesting an order to
July 20, 2026
On July 16, 2026, Thailand’s Personal Data Protection Committee (PDPC) published a notification in the Government Gazette establishing detailed rules governing data subjects’ right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notification will take effect 60 days after publication—mid-September 2026—giving data controllers a limited window to bring their processes into compliance. Scope The notification covers requests to access or obtain copies of personal data and requests for disclosure of the source of data collected without consent. Data subjects may exercise their rights directly or through authorized representatives. Key Requirements Important requirements set by the notification include the following: Required request channels. Controllers must provide at least two request channels: direct submission at the business location and registered mail. Electronic channels are optional but, if offered, may also be used for fulfilling requests. Request contents. Requests must be in writing or in electronic form and include the data subject’s name, the preferred access method, details of the data requested, and the requester’s signature. Controllers may request additional identifying information as needed. Identity and authority verification. Controllers may require official identity documents for verification. Authorized representatives must provide authorization documents and identity documents for both the data subject and the representative. Alternative verification methods (e.g., digital authentication) are permitted if they do not unreasonably obstruct data subjects’ rights. Review and response timelines. Controllers must review requests within 15 days. If the request is incomplete, the controller must notify the requester and allow at least 15 days to correct deficiencies. If not corrected, the request may be treated as abandoned. Once verified, controllers must fulfill requests within 30 days, extendable by another 30 days for large-volume or complex requests with notice to the requester. Methods for providing access or copies. Controllers may fulfill
July 16, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) published a series of draft guidance documents for public consultation on July 7, 2026. Issued under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), the drafts address a range of compliance issues and offer insight into the regulator’s current enforcement priorities. This article examines two of those drafts: one on lawful bases for processing personal data, and another on marketing and direct marketing. Together, they reflect the Office of the PDPC’s evolving expectations on lawful-basis selection, accountability, and the use of personal data in marketing. Organizations operating in Thailand should assess the practical implications now, before the guidance is finalized. Lawful Bases: A Structured Selection Process The draft guidance on lawful bases introduces a systematic five-step process for selecting an appropriate lawful basis for each processing activity. Organizations are expected to: Identify the processing activity involved. Assess the appropriate lawful basis. Evaluate whether the data is necessary for the processing. Conduct a legitimate interest assessment (LIA) where applicable. Ensure transparency through privacy notices. The guidance provides practical explanations and examples for each lawful basis under section 24 of the PDPA—including archiving, research, statistics, vital interests, contractual necessity, legal obligation, public task, legitimate interests, and consent—as well as the bases applicable to sensitive personal data under section 26. The aim is to promote more consistent and accurate lawful-basis selection across public- and private-sector organizations. A recurring theme throughout the guidance is that organizations should select the lawful basis that most accurately reflects the actual purpose and circumstances of the processing activity. The guidance cautions against treating consent as a default or catch-all basis where another lawful basis is more appropriate. For processing based on legitimate interests, organizations should conduct and document an LIA. Processing involving sensitive personal data may require