You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 23, 2021

Myanmar Amends Legislation on the Privacy and Security of Citizens amid State of Emergency

As many are already aware, following the change of government in Myanmar on February 1, 2021, a draft Cyber Security Law was proposed which attracted widespread criticism.

However, less attention has been paid to significant amendments to two existing laws, some of which have a similar effect to parts of the draft Cyber Security Law. In other words, while the draft Cyber Security Law has not progressed further and is under public scrutiny, significant elements of it have found their way into law in Myanmar by other routes. Because these amendments are already law, it is very important that individuals and businesses in Myanmar understand their implications.

Amendments to the Law Protecting the Privacy and Security of Citizens

The Law Protecting the Privacy and Security of Citizens (2017), or the “Privacy Law,” was amended on February 13, 2021, less than two weeks after the military government came into power. These amendments chiefly address the power of the government to conduct searches, seizures, and arrests; to extend detention without judicial oversight; and to carry out broad surveillance and investigation activities that could intrude on individual privacy. The amendments accomplish this by suspending various sections of the Privacy Law for as long as the State Administration Council (the military body now governing Myanmar) is in power. The suspended sections include the following:

  • Section 5: Search, seizure, and arrest without civilian observation

The relevant part of Section 5 of the Privacy Law states, “The responsible authorities shall … when acting in accordance with existing law, not enter into a person’s residence or a room used as a residence, or a building, compound or building in a compound, for the purpose of search, seizure, or arrest, unless accompanied by minimum of two witnesses who should comprise Ward or Village Tract Administrators…”.

The suspension of this section means that government agents can now enter people’s homes for the purposes of search, seizure, and arrest without civilian witnesses.

  • Section 7: Indefinite detention (habeas corpus)

Section 7 of the Privacy Law states that “No one shall be detained for more than 24 hours without permission from a court unless the detention is in accordance with existing law.”

The suspension of this section means that individuals in Myanmar may now be detained in prison indefinitely without the intervention of court proceedings.

  • Section 8: Wide-ranging individual privacy rights

Section 8 of the Privacy Law is the most wide-ranging and covers arrest, search and seizure of property, interception of telecommunications without proper authority, and various other issues of personal privacy:

“In the absence of an order, permission, or warrant issued in accordance with existing law, or permission from the Union President or the Union Cabinet, a Responsible Authority:

      1. Shall not enter into a citizen’s private residence or a room used as a residence, or a building, compound or building in a compound, for the purpose of search, seizure, or arrest.
      2. Shall not surveil, spy upon, or investigate any citizen in a manner which could disturb their privacy and security or affect their dignity.
      3. Shall not intercept or disturb any citizen’s communication with another person or communications equipment in any way.
      4. Shall not demand or obtain personal telephonic and electronic communications data from telecommunication operators.
      5. Shall not open, search, seize or destroy another person’s private correspondence, envelope, package or parcel.
      6. Shall not unlawfully interfere with a citizen’s personal or family matters or act in any way to slander or harm their reputation.
      7. Shall not unlawfully seize the lawfully owned movable or immoveable property of a citizen, or intentionally destroy it either directly or by indirect means.”

Because of the suspension of this section, any of the above actions by governmental authorities now appear to be lawful in Myanmar.

Amendments to the Electronic Transactions Law

On February 15, 2021, the Electronic Transactions Law (2004)—the “ET Law”—was amended to introduce a broad exception allowing government confiscation of personal data, and a prohibition on sharing various types of information online. It is interesting to note that previously—in the draft of the Cyber Security Law—the administration intended to repeal the ET entirely, but this approach appears to have changed, as detailed below.

  • Government access to personal data

The data protection elements of the draft Cyber Security Law have essentially been incorporated into the new Chapter 10 of the amended ET Law. These provisions are brief and not comparable to the standards achieved by personal data protection regimes in other modern legal frameworks.

This chapter provides a new exception (Section 27-C) to the safe management of personal data in the case of “detecting, investigating, organizing of information, verifying the information conducted in accordance with management power on the cyber security and cybercrime matters relating to stability, tranquility, national security of the state.” “Stability,” “tranquility,” and “national security” are not defined in the legislation, but a wide enough interpretation would allow the government sweeping authority to obtain the personal data of any individual in Myanmar whenever it considers it necessary to do so.

  • Internet posts

Posting information on the internet is dealt with in Section 38-C of the amended law: “Whoever, at the cyber space, commits creating false news or fake news with the intention to cause public panic, to lost trust, to lower the dignity by public or to destroy the unity of any association, on conviction shall be punished with imprisonment for a term which may extend from a minimum of one year to a maximum of three years or with a fine not exceeding ten million Kyats or with both.”

This legislation does not  define “false news,” “fake news,” “public panic,” “lost trust,” “lower dignity,” or “destroy unity” which leaves room for wide interpretation and use.

The combined effect of these amendments is that government agents may, without court intervention:

  • Arrest and indefinitely detain anybody in Myanmar;
  • Seize or destroy property;
  • Intercept communications whether electronic or postal;
  • Access personal data wherever located;
  • Demand information from telecommunications service providers; and
  • Arrest and detain individuals for online posting of content deemed undesirable.

As these legal developments represent potentially significant shifts in the legal landscape for Myanmar, all individuals and businesses in Myanmar need to be fully aware of the changes.

RELATED INSIGHTS​ 

January 13, 2025
The State Bank of Vietnam’s Circular No. 50/2024/TT-NHNN regulating safety and security for the provision of online services in the banking sector (“Circular 50”), issued on October 31, 2024, took effect on January 1, 2025, with delayed effectiveness for certain provisions on (i) network, communication, and security systems, online banking application software, and mobile banking application software (July 1, 2025); (ii) transaction confirmation for payment transactions conducted via the straight-through processing method (January 1, 2026); and (iii) authentication forms and reporting obligations (July 1, 2026). The cybersecurity situation in Vietnam is complicated, and the banking and finance sector has been one of the top targets of high-tech criminals. Circular 50 seeks to enhance user protection by expanding the technical requirements to more services in the banking sector as well as standardizing how transactions are authenticated. Expanded Scope of Services Covered Previous regulations on safety and security of online services in the banking sector only covered banking services and intermediary payment services. Circular 50 expands the scope to include other services of credit institutions and foreign bank branches such as credit information services, foreign exchange services, securities depository services, and services related to factoring and letters of credit, which now need to comply with technical requirements and standards for online services such as firewalls and DMZ network barriers. Risk-Based Approach to Authentication Circular 50 sets out standards for payment transactions and card transactions by: Classifying various online transactions based on the type of client, the purpose of the transfer, the value of the specific transaction, and the total value of certain transactions during the day; and Applying various types of authentication for the corresponding types of online transactions, e.g., using passwords or PINs for small-value online transactions, and using OTPs (through SMS, voice, or email), biometric matching, or e-signatures for
January 10, 2025
On January 8, 2025, Thailand’s Office of the Personal Data Protection Committee published two notifications in the Government Gazette—one for data controllers and the other for data processors—concerning exemptions for data controllers and data processors from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019). The notification for data processors took effect on January 9, 2025, the day after its publication. The notification for data controllers will take effect on April 8, 2025. The content of these notifications is identical to that in the draft versions of the notifications previously released for public consultation in October 2024. For more information on the ROPA exemptions for data controllers and data processors, or on any aspect of personal data protection in Thailand, please contact Nopparat Lalitkomon at [email protected] or Wilin Somya at [email protected].
January 9, 2025
On January 1, 2025, Myanmar’s State Administration Council enacted Cybersecurity Law No. 1/2025, which aims to regulate various aspects of digital security and online activities. The law has not yet been implemented and will come into force on a date specified by the Myanmar president, who will also provide an official adoption and compliance timeline for individuals and organizations impacted by the new regulations. Below are some of the key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The
January 6, 2025
On December 24, 2024, the government of Vietnam issued Decree No. 163/2024/ND-CP, providing guidelines for implementing the new Telecommunications Law that took effect on July 1, 2024 (“Decree 163”). This new decree replaces Decree No. 25/2011/ND-CP and its amendments (“Decree 25”) and took effect immediately upon issuance, with regulations on data center services, cloud computing services, and basic telecom services over the internet (“over-the-top” or OTT telecom services) having an official effective date of January 1, 2025. Decree 163 introduces substantial changes across the telecom sector, covering various aspects including service provision, licensing, standards and technical regulations, quality, passive infrastructure planning, dispute resolution, and more. Hence, it is necessary for enterprises to conduct a compliance review to identify gaps between the new decree and their business models, and take necessary steps to ensure lawful business operations in Vietnam. Below are some highlights of Decree 163. Expanded Scope of Services For basic telecom services, Decree 163 has introduced machine-to-machine (M2M) communication and classified it as a basic telecom service. This establishes a regulatory framework for IoT device communication, previously unregulated in Decree 25. For value-added telecom services, in light of the new Telecommunications Law, Decree 163 provides more detailed regulations for new telecom services such as data center services, cloud computing services, and OTT telecom services, which were not addressed in Decree 25. Regulation of Three New Telecom Services Expanding on the Telecommunications Law’s definitions of data center services, cloud computing services, and OTT telecom services, Decree 163 applies a light-touch management approach to regulate these three new services, as follows: Offshore providers: Cross-border service providers are exempt from signing commercial agreements with licensed local telecom companies. They only need to notify the Vietnam Telecommunications Authority (VNTA) using the prescribed procedures and forms before offering services. Onshore providers: The foreign