You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 23, 2021

Myanmar Amends Legislation on the Privacy and Security of Citizens amid State of Emergency

As many are already aware, following the change of government in Myanmar on February 1, 2021, a draft Cyber Security Law was proposed which attracted widespread criticism.

However, less attention has been paid to significant amendments to two existing laws, some of which have a similar effect to parts of the draft Cyber Security Law. In other words, while the draft Cyber Security Law has not progressed further and is under public scrutiny, significant elements of it have found their way into law in Myanmar by other routes. Because these amendments are already law, it is very important that individuals and businesses in Myanmar understand their implications.

Amendments to the Law Protecting the Privacy and Security of Citizens

The Law Protecting the Privacy and Security of Citizens (2017), or the “Privacy Law,” was amended on February 13, 2021, less than two weeks after the military government came into power. These amendments chiefly address the power of the government to conduct searches, seizures, and arrests; to extend detention without judicial oversight; and to carry out broad surveillance and investigation activities that could intrude on individual privacy. The amendments accomplish this by suspending various sections of the Privacy Law for as long as the State Administration Council (the military body now governing Myanmar) is in power. The suspended sections include the following:

  • Section 5: Search, seizure, and arrest without civilian observation

The relevant part of Section 5 of the Privacy Law states, “The responsible authorities shall … when acting in accordance with existing law, not enter into a person’s residence or a room used as a residence, or a building, compound or building in a compound, for the purpose of search, seizure, or arrest, unless accompanied by minimum of two witnesses who should comprise Ward or Village Tract Administrators…”.

The suspension of this section means that government agents can now enter people’s homes for the purposes of search, seizure, and arrest without civilian witnesses.

  • Section 7: Indefinite detention (habeas corpus)

Section 7 of the Privacy Law states that “No one shall be detained for more than 24 hours without permission from a court unless the detention is in accordance with existing law.”

The suspension of this section means that individuals in Myanmar may now be detained in prison indefinitely without the intervention of court proceedings.

  • Section 8: Wide-ranging individual privacy rights

Section 8 of the Privacy Law is the most wide-ranging and covers arrest, search and seizure of property, interception of telecommunications without proper authority, and various other issues of personal privacy:

“In the absence of an order, permission, or warrant issued in accordance with existing law, or permission from the Union President or the Union Cabinet, a Responsible Authority:

      1. Shall not enter into a citizen’s private residence or a room used as a residence, or a building, compound or building in a compound, for the purpose of search, seizure, or arrest.
      2. Shall not surveil, spy upon, or investigate any citizen in a manner which could disturb their privacy and security or affect their dignity.
      3. Shall not intercept or disturb any citizen’s communication with another person or communications equipment in any way.
      4. Shall not demand or obtain personal telephonic and electronic communications data from telecommunication operators.
      5. Shall not open, search, seize or destroy another person’s private correspondence, envelope, package or parcel.
      6. Shall not unlawfully interfere with a citizen’s personal or family matters or act in any way to slander or harm their reputation.
      7. Shall not unlawfully seize the lawfully owned movable or immoveable property of a citizen, or intentionally destroy it either directly or by indirect means.”

Because of the suspension of this section, any of the above actions by governmental authorities now appear to be lawful in Myanmar.

Amendments to the Electronic Transactions Law

On February 15, 2021, the Electronic Transactions Law (2004)—the “ET Law”—was amended to introduce a broad exception allowing government confiscation of personal data, and a prohibition on sharing various types of information online. It is interesting to note that previously—in the draft of the Cyber Security Law—the administration intended to repeal the ET entirely, but this approach appears to have changed, as detailed below.

  • Government access to personal data

The data protection elements of the draft Cyber Security Law have essentially been incorporated into the new Chapter 10 of the amended ET Law. These provisions are brief and not comparable to the standards achieved by personal data protection regimes in other modern legal frameworks.

This chapter provides a new exception (Section 27-C) to the safe management of personal data in the case of “detecting, investigating, organizing of information, verifying the information conducted in accordance with management power on the cyber security and cybercrime matters relating to stability, tranquility, national security of the state.” “Stability,” “tranquility,” and “national security” are not defined in the legislation, but a wide enough interpretation would allow the government sweeping authority to obtain the personal data of any individual in Myanmar whenever it considers it necessary to do so.

  • Internet posts

Posting information on the internet is dealt with in Section 38-C of the amended law: “Whoever, at the cyber space, commits creating false news or fake news with the intention to cause public panic, to lost trust, to lower the dignity by public or to destroy the unity of any association, on conviction shall be punished with imprisonment for a term which may extend from a minimum of one year to a maximum of three years or with a fine not exceeding ten million Kyats or with both.”

This legislation does not  define “false news,” “fake news,” “public panic,” “lost trust,” “lower dignity,” or “destroy unity” which leaves room for wide interpretation and use.

The combined effect of these amendments is that government agents may, without court intervention:

  • Arrest and indefinitely detain anybody in Myanmar;
  • Seize or destroy property;
  • Intercept communications whether electronic or postal;
  • Access personal data wherever located;
  • Demand information from telecommunications service providers; and
  • Arrest and detain individuals for online posting of content deemed undesirable.

As these legal developments represent potentially significant shifts in the legal landscape for Myanmar, all individuals and businesses in Myanmar need to be fully aware of the changes.

RELATED INSIGHTS​ 

June 19, 2026
For the first time, Thailand’s Food and Drug Administration (FDA) has published a consolidated list identifying all substances that have successfully passed its novel food safety evaluation process. The list is a step forward in regulatory transparency, but it also highlights a feature of the Thai regime that food companies often overlook: each approval is tied exclusively to the company that applied for it. A substance’s appearance on the list does not give other companies the green light to use it. This article examines the structure of Thailand’s novel food approval framework, the implications of applicant exclusivity, and the strategic choices it requires of food companies looking to bring novel ingredients to the Thai market. Thai FDA Food Safety Evaluation Framework Notification No. 376 of the Ministry of Public Health requires novel food substances to undergo a food safety assessment, with an exemption only for novel foods manufactured exclusively for export. The framework also encompasses “foods that do not qualify as novel foods” but which present characteristics warranting a safety evaluation, such as differing quality standards, increased serving sizes, or applications in specific food categories, where such changes affect consumption levels, nutritional value, or consumer safety. The recently published list of foods that passed the safety evaluation by the Thai FDA is structured by substance category and identifies the approved company (domestic manufacturer or importer), country of origin, substance name and trade name, approved purpose of use, and date of the Thai FDA’s approval notification certificate. A notable feature of Thailand’s novel food regime is that the approval result is tied exclusively to the company that submitted the application. Publication of the consolidated list does not constitute a general authorization to use the approved substances. The Thai FDA’s approval certificate specifies the approved conditions of use and the requirements
June 17, 2026
Thailand’s new labeling requirements for medical devices, which include for the first time a unique device identification (UDI) requirement for software as a medical device (SaMD), take effect on June 20, 2026. The Notification of the Ministry of Public Health regarding Criteria, Methods, and Conditions on Labeling and Instructions for Use for Medical Devices 2025, which replaces a similar notification from 2020, was published in the Government Gazette on December 22, 2025. To ensure clarity, modernity, and patient safety, the regulation requires domestic manufacturers and importers to provide labels and instructions for use (IFU) that are clearly legible, complete, and free of false or misleading claims. It also permits IFU to be provided in electronic format, such as via QR codes, websites, or other digital channels—directly relevant to SaMD, where physical labels are impractical and electronic presentation is the natural medium. The notification distinguishes two categories for labeling language. Home-use medical devices (for lay users outside healthcare facilities) must have labels and IFU in Thai. Professional-use medical devices may display labels and documentation in either Thai or English. This distinction is significant for SaMD developers: software intended for clinical professionals may use English-language interfaces and IFU, while consumer-facing health applications must provide Thai-language content. Labeling and UDI Requirements Labels and IFU must include, at a minimum: Product name and intended purpose Quantity or volume Name and address of domestic manufacturer or importer Thai FDA approval number Lot, version, or serial number Manufacturing date and expiry date For SaMD, the version number requirement is particularly relevant. The regulation also mandates display of a UDI code for SaMD in risk category 2 (moderate-risk), category 3 (moderate- to high-risk), and category 4 (high-risk), according to Thailand’s medical device risk classification system (which complies with the ASEAN Medical Device Directive and the EU
June 15, 2026
The surge in AI development has led to a desperate demand for large, high-quality training data. However, real-world data can be expensive to collect, difficult to access, and often subject to strict privacy and regulatory constraints. Synthetic data, which consists of artificially generated records that replicate the statistical properties of real-world data without reproducing specific individuals’ information, provides an appealing solution by generating artificial datasets at scale without relying on identifiable personal information. It combines speed, cost efficiency, and regulatory compliance, making it a sensible alternative for organizations seeking to reduce risks while maintaining data utility. When properly anonymized, synthetic datasets may fall outside the scope of laws such as the EU’s General Data Protection Regulation (GDPR) or Thailand’s Personal Data Protection Act (PDPA), reducing compliance burdens while still supporting high-quality model training. However, relying on synthetic data without rigorous legal due diligence could be a strategic mistake. It replaces one set of known risks (scraping, direct privacy liability) with a new set of complex liabilities. The narrative that synthetic data is a “silver bullet” for privacy and IP compliance is dangerous and could be misleading. While synthetic data addresses data scarcity, it also introduces new legal uncertainties. Legal counsel should anticipate downstream risks arising from compromised data sources. Models trained on unlawfully obtained data may need to be decommissioned, even if their outputs appear lawful. What is synthetic data? Synthetic data refers to artificially generated information created using AI techniques such as deep learning and generative models. Instead of copying real records, it reproduces the statistical patterns and relationships found in the original dataset. Synthetic data generally falls into three categories: Fully synthetic data – Entirely new data points generated from learned patterns. The model studies the structure of the original data and produces records that resemble real-world
June 11, 2026
Thailand’s Electronic Transactions Development Agency (ETDA) has released a revised draft Electronic Transactions Act (ETA) for public hearing from May 12, 2026, to June 15, 2026. This is not merely an amendment to certain provisions of the current ETA, but a comprehensive redrafting of the entire act. The revised draft ETA introduces several significant changes from the current framework, with practical implications for businesses operating in Thailand. Unified Coverage of Public and Private Sectors The current law segregates government transactions into a separate chapter with distinct rules. The draft ETA eliminates this division, defining “transaction” to encompass civil and commercial juristic acts as well as administrative procedures, administrative contracts, and other acts of government agencies. Enhanced E-Signature Definition The definition of “electronic signature” is broadened to expressly include biometric data and refocused on identifying the signatory and demonstrating intent regarding the content of the electronic data. Shift in Burden of Proof When a party challenges the reliability of electronic data created using a “trusted electronic method” or a method prescribed by the ETDA, the burden of proof and the cost of proving unreliability shifts to the challenger. Introduction of New Digital Method Concepts The draft ETA introduces several new digital method concepts that are not currently recognized under the existing ETA framework. These include: Electronic timestamping (e-timestamp) Electronic registered delivery Electronic company seals Electronic stamp duty compliance Electronic identity authentication and verification Electronic transferable records (electronic bills of lading, promissory notes, and similar negotiable instruments) Recognition of Automated Systems and Electronic Contracting The draft ETA expressly recognizes the legal validity and enforceability of contracts formed through automated systems, including contracts concluded entirely between automated systems or between an automated system and a person. A party may not deny the binding effect of such contracts solely because no human review