You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 23, 2021

Myanmar Amends Legislation on the Privacy and Security of Citizens amid State of Emergency

As many are already aware, following the change of government in Myanmar on February 1, 2021, a draft Cyber Security Law was proposed which attracted widespread criticism.

However, less attention has been paid to significant amendments to two existing laws, some of which have a similar effect to parts of the draft Cyber Security Law. In other words, while the draft Cyber Security Law has not progressed further and is under public scrutiny, significant elements of it have found their way into law in Myanmar by other routes. Because these amendments are already law, it is very important that individuals and businesses in Myanmar understand their implications.

Amendments to the Law Protecting the Privacy and Security of Citizens

The Law Protecting the Privacy and Security of Citizens (2017), or the “Privacy Law,” was amended on February 13, 2021, less than two weeks after the military government came into power. These amendments chiefly address the power of the government to conduct searches, seizures, and arrests; to extend detention without judicial oversight; and to carry out broad surveillance and investigation activities that could intrude on individual privacy. The amendments accomplish this by suspending various sections of the Privacy Law for as long as the State Administration Council (the military body now governing Myanmar) is in power. The suspended sections include the following:

  • Section 5: Search, seizure, and arrest without civilian observation

The relevant part of Section 5 of the Privacy Law states, “The responsible authorities shall … when acting in accordance with existing law, not enter into a person’s residence or a room used as a residence, or a building, compound or building in a compound, for the purpose of search, seizure, or arrest, unless accompanied by minimum of two witnesses who should comprise Ward or Village Tract Administrators…”.

The suspension of this section means that government agents can now enter people’s homes for the purposes of search, seizure, and arrest without civilian witnesses.

  • Section 7: Indefinite detention (habeas corpus)

Section 7 of the Privacy Law states that “No one shall be detained for more than 24 hours without permission from a court unless the detention is in accordance with existing law.”

The suspension of this section means that individuals in Myanmar may now be detained in prison indefinitely without the intervention of court proceedings.

  • Section 8: Wide-ranging individual privacy rights

Section 8 of the Privacy Law is the most wide-ranging and covers arrest, search and seizure of property, interception of telecommunications without proper authority, and various other issues of personal privacy:

“In the absence of an order, permission, or warrant issued in accordance with existing law, or permission from the Union President or the Union Cabinet, a Responsible Authority:

      1. Shall not enter into a citizen’s private residence or a room used as a residence, or a building, compound or building in a compound, for the purpose of search, seizure, or arrest.
      2. Shall not surveil, spy upon, or investigate any citizen in a manner which could disturb their privacy and security or affect their dignity.
      3. Shall not intercept or disturb any citizen’s communication with another person or communications equipment in any way.
      4. Shall not demand or obtain personal telephonic and electronic communications data from telecommunication operators.
      5. Shall not open, search, seize or destroy another person’s private correspondence, envelope, package or parcel.
      6. Shall not unlawfully interfere with a citizen’s personal or family matters or act in any way to slander or harm their reputation.
      7. Shall not unlawfully seize the lawfully owned movable or immoveable property of a citizen, or intentionally destroy it either directly or by indirect means.”

Because of the suspension of this section, any of the above actions by governmental authorities now appear to be lawful in Myanmar.

Amendments to the Electronic Transactions Law

On February 15, 2021, the Electronic Transactions Law (2004)—the “ET Law”—was amended to introduce a broad exception allowing government confiscation of personal data, and a prohibition on sharing various types of information online. It is interesting to note that previously—in the draft of the Cyber Security Law—the administration intended to repeal the ET entirely, but this approach appears to have changed, as detailed below.

  • Government access to personal data

The data protection elements of the draft Cyber Security Law have essentially been incorporated into the new Chapter 10 of the amended ET Law. These provisions are brief and not comparable to the standards achieved by personal data protection regimes in other modern legal frameworks.

This chapter provides a new exception (Section 27-C) to the safe management of personal data in the case of “detecting, investigating, organizing of information, verifying the information conducted in accordance with management power on the cyber security and cybercrime matters relating to stability, tranquility, national security of the state.” “Stability,” “tranquility,” and “national security” are not defined in the legislation, but a wide enough interpretation would allow the government sweeping authority to obtain the personal data of any individual in Myanmar whenever it considers it necessary to do so.

  • Internet posts

Posting information on the internet is dealt with in Section 38-C of the amended law: “Whoever, at the cyber space, commits creating false news or fake news with the intention to cause public panic, to lost trust, to lower the dignity by public or to destroy the unity of any association, on conviction shall be punished with imprisonment for a term which may extend from a minimum of one year to a maximum of three years or with a fine not exceeding ten million Kyats or with both.”

This legislation does not  define “false news,” “fake news,” “public panic,” “lost trust,” “lower dignity,” or “destroy unity” which leaves room for wide interpretation and use.

The combined effect of these amendments is that government agents may, without court intervention:

  • Arrest and indefinitely detain anybody in Myanmar;
  • Seize or destroy property;
  • Intercept communications whether electronic or postal;
  • Access personal data wherever located;
  • Demand information from telecommunications service providers; and
  • Arrest and detain individuals for online posting of content deemed undesirable.

As these legal developments represent potentially significant shifts in the legal landscape for Myanmar, all individuals and businesses in Myanmar need to be fully aware of the changes.

RELATED INSIGHTS​ 

June 25, 2026
On June 18, 2026, Thailand’s Office of the Personal Data Protection Committee (PDPC) published two notifications in the Government Gazette establishing Thailand’s first formal certification framework for personal data protection standards under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notifications, which took immediate effect, introduce a voluntary certification framework aimed at promoting accountability, strengthening organizational data protection governance, and aligning Thailand more closely with international frameworks that recognize certification as a key compliance tool. Certification Criteria The first notification sets out the assessment criteria for organizations seeking certification. Applicants must undergo an evaluation against a framework comprising four assessment categories, 10 focus areas, and 128 assessment criteria covering key elements of a privacy management program. These include: Organizational oversight and internal policies and procedures. Human resource development, including staff training and awareness programs. Clearly defined operational processes and procedures covering data subject rights, transparency obligations, records of processing activities, and lawful basis management, as well as contractual safeguards such as data-processing and data-sharing agreements and risk assessments, including Data Protection Impact Assessments. Technical measures encompassing data security controls and breach response capabilities Based on the assessment results, organizations may be awarded either a PDPA Compliance Certificate or a higher-level PDPA Certificate accompanied by a certification mark. Application and Assessment Process The second notification establishes the application and assessment process for obtaining certification. Eligible applicants include government agencies and private-sector entities that demonstrate sufficient privacy governance maturity and meet the prescribed eligibility requirements. Applicants must submit their applications along with supporting documentation for review. Upon receiving an application, the Office of the PDPC will conduct a detailed evaluation, which may include both documentary review and on-site inspections. Incomplete applications may be rejected, though applicants are typically given a limited period to correct deficiencies before a final decision
June 24, 2026
Patent enablement requirements are provided under Article 102 of Vietnam’s Law on Intellectual Property (IP Law). In particular, a patent specification must “fully and clearly disclose the nature of the invention to such an extent that, based on the specification, a person having ordinary skill in the relevant art can implement the invention.” In pharmaceutical and biotechnology patents, this requirement is more complicated and subject to more rigorous assessment. The Patent Examination Guidelines (Guidelines) of the Intellectual Property Office of Vietnam (IP Office) were amended in March 2026 to introduce Annexes III and IV for the pharmaceutical and biotechnology sectors, in which Annex III provides detailed guidelines on the assessment of specification requirements. These amendments were made under a project for strengthening capacity in industrial property examination between the Japan International Cooperation Agency (JICA) and the IP Office. Annex III provides detailed instructions on how examiners assess enablement in a pharmaceutical or biotechnology application, and offers examples of acceptable and unacceptable descriptions with regard to the enablement aspect. Enablement Requirements in Pharma and Biotech Patents Article 12.7 of Circular 10/2026/TT-BKHCN (Circular 10) adds to the requirements of Article 102 of the IP Law that the description must demonstrate the novelty, inventive step, and industrial applicability of the technical solution. For pharmaceutical composition subject matters, Article 12.9 of Circular 10 sets out that the description must present the results of clinical trials and/or the pharmacological effects of the claimed pharmaceutical composition, and must include at least the following information: Substance/mixture used. Testing method (system) employed. Information on the test results. Correlation between the pharmacological effects obtained from the tests and the application of the pharmaceutical product in the prevention, diagnosis, and treatment of diseases. The Guidelines note that pharmacological study results should be presented in a quantified manner, and pharmacological
June 23, 2026
On May 26, 2026, Thailand’s Department of Land Transport (DLT) published for public consultation a draft amendment to the Ministerial Regulation on Electronic Ride-Hailing Vehicles that would, for the first time, allow juristic persons (legal entities) to register vehicles as electronic ride-hailing cars—a right that currently belongs exclusively to natural persons, limited to one person per one vehicle. If finalized in its current form, the regulation would significantly expand the supply side of Thailand’s ride-hailing market by enabling corporate fleet operators to enter the space. The public comment period is open through June 24, 2026. Key Principles Under the Draft Regulation Under the proposed amendment, juristic persons that maintain a fleet of at least 50 vehicles will be permitted to register vehicles as electronic ride-hailing cars. This represents a fundamental shift from the current framework, which restricts registration to individual natural persons on a one-person-one-car basis. Vehicle Specifications Corporate-owned ride-hailing vehicles must meet the following requirements: Be brand new from the factory, or no more than two years old from first registration with no more than 20,000 km of use. Not be a vehicle that has been reconstructed or repaired after involvement in a serious accident affecting safety—a standard consistent with public transport vehicles (RorYor. 6). Be classified as small, medium, or large in accordance with ministerial or director-general specifications. The vehicles may be equipped with safety devices such as interior or exterior cameras (video/photo recording) and can retain the original factory color of the vehicle body (no mandatory color change is required). License Plates Corporate ride-hailing vehicles will use license plates of the same size, characteristics, and color as those for private passenger vehicles not exceeding seven seats (RorYor. 1), rather than public transport plates. Potential Impact The government has stated that the regulation is intended to: Promote
June 23, 2026
On May 14, 2026, Thailand published a ministerial regulation in the Government Gazette to prescribe measures for prevention and suppression of technology crimes. The regulation creates a comprehensive procedural framework for returning money and digital assets to victims of technology crimes. It will take effect 90 days after publication (in mid-August 2026), giving affected entities a limited window to prepare. Mandatory Reporting Obligations for Financial Institutions When a deposit account, e-money account, or digital asset wallet is frozen in connection with a technology crime, the relevant financial institution or business operator must report transaction data to the Anti-Money Laundering Office (AMLO) via AMLO’s designated electronic system. Required data elements include account numbers (sender and receiver), names, identification or passport numbers, legal entity registration numbers, phone numbers, remaining balance, damage amount, transaction reference numbers, and the bank case ID. Institutions that already share data through the information-sharing system under the emergency decree are deemed to have satisfied this reporting obligation, creating an incentive for platform participation. When the Royal Thai Police or the Department of Special Investigation seize or freeze assets related to technology crimes, they must provide AMLO with investigation reports, complaint evidence, money-trail data, and account statements. Notification and Claims Process Once the AMLO secretary-general approves verified reports of a technology crime, the account information of persons connected to the crime will be published in the Government Gazette, triggering a 90-day window for victims to file claims and for related persons to file objections. Officers will also publish details on AMLO’s electronic media and send registered mail to identified victims, which will be deemed received after 7 days domestically or 15 days internationally. Victims have 90 days from the date the crime is published in the Government Gazette to file claims through AMLO’s electronic system. Claims must include