Database

Browse Database

MYANMAR

Since October 2013, last amended in August 2017

Pillar Domestic data policies  |  Indicator Requirement to allow the government to access personal data collected
The Telecommunications Law (The Pyidaungsu Hluttaw Law No. 31, 2013) (ဆက္သြယ္ေရးဥပေဒ (၂၀၁၃ ခုနွစ္၊ ၿပည္ေထာင္စုဥပေဒလႊတ္ေတာ္ဥပေဒအမွတ္ ၃၁။))
Arts. 75 and 77 of the Telecommunication Law allow the government to intercept, suspend, or obtain any information that threatens national security and the rule of law in the country. The broad provision fails to specify which government agents are authorised to do this and what sort of information specifically constitutes the general terms such as national security.
Coverage Telecommunications Sector

MYANMAR

Since April 2004, last amended in February 2021

Pillar Domestic data policies  |  Indicator Requirement to allow the government to access personal data collected
Electronic Transactions Law (The State Peace and Development Council Law No. 5/2004) (အီလက်ထရောနစ် ဆက်သွယ်ဆောင်ရွက်ရေးဥပဒေ)
Art. 4 of the Electronic Transactions Law allows the Government to obtain personal data for purposes related to the stability, tranquillity, and national security of the State. The regulation fails to specify what information constitutes the general terms, such as national security.
Coverage Horizontal

MYANMAR

N/A

Pillar Intermediary liability  |  Indicator Safe harbour for intermediaries for copyright infringement
Lack of intermediary liability framework in place for copyright infringements
A basic legal framework on intermediary liability for copyright infringement is absent in Myanmar's law and jurisprudence. It is reported that the Telecommunication Law does not explicitly hold intermediaries liable for the content, but some provisions are vague and could feasibly be interpreted to justify content removals.
Coverage Internet intermediaries

MYANMAR

N/A

Pillar Intermediary liability  |  Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Lack of intermediary liability framework in place for copyright infringements
A basic legal framework on intermediary liability beyond copyright infringement is absent in Myanmar's law and jurisprudence. It is reported that the Telecommunication Law does not explicitly hold intermediaries liable for the content, but some provisions are vague and could feasibly be interpreted to justify content removals.
Coverage Internet intermediaries

MYANMAR

Reported in 2021, last reported in 2025

Pillar Intermediary liability  |  Indicator User identity requirement
Identity requirement for SIM cards
It is reported that Myanmar’s approach to SIM registration obliges mobile network operators to collect and store users’ personal information, including proof of identity. Furthermore, it is reported that Myanmar requires the submission of biometric data for SIM registration, encompassing both fingerprint and facial recognition data. Failure to register a SIM card results in its deactivation.
Coverage Mobile network operators

MYANMAR

Since January 2025, entry into force in July 2025

Pillar Intermediary liability  |  Indicator Monitoring requirement
Cybersecurity Law (Law No. 1/2025) (ဆိုက်ဘာလုံခြုံရေးဥပဒေ)
Section 31 of the Cybersecurity Law provides that digital platform service providers are required to implement adequate measures to identify relevant information and associated cyber resources in circumstances where particular categories of content arise on their platforms, including material that incites hatred, undermines unity, or disrupts public peace and order; disseminates false news or rumours; is unsuitable for public viewing; contains sexually explicit depictions, including those involving children; contravenes any law in force or involves the commission of unlawful acts; gives rise to complaints concerning intended social or economic harm to an individual; infringes intellectual property rights; or relates to the incitement, commission, attempted commission, or facilitation of terrorist acts. Section 32 further stipulates that, where a digital platform service provider becomes aware of such conduct, whether independently or upon notification by the relevant Department, it must, within the prescribed timeframe, take appropriate steps to prevent, remove, destroy, or suspend the offending content or activity. Pursuant to Section 4, “digital platform services” are defined as a category of business that provides services enabling users to display, transmit, disseminate, or otherwise utilise information online through cyber resources or analogous technologies and associated equipment, while a “digital platform service provider” refers to any person or organisation that offers such services for use within the State. These provisions have been reported as imposing obligations on digital platforms, such as Facebook, effectively requiring them to monitor, identify, and remove broadly and imprecisely defined categories of content.
Coverage Digital platform service providers

MYANMAR

N/A

Pillar Telecom infrastructure & competition  |  Indicator Functional/accounting separation for operators with significant market power
Lack of mandatory functional separation for dominant network operators
It is reported that Malaysia does not require functional separation for operators with significant market power (SMP) in the telecom market. However, since 2015, there has been an obligation for accounting separation.
Coverage Telecommunications sector

MYANMAR

Since October 2013, last amended in August 2017

Pillar Telecom infrastructure & competition  |  Indicator Licensing restrictions to operate in the telecom market
The Telecommunications Law (The Pyidaungsu Hluttaw Law No. 31, 2013) (ဆက္သြယ္ေရးဥပေဒ (၂၀၁၃ ခုနွစ္၊ ၿပည္ေထာင္စုဥပေဒလႊတ္ေတာ္ဥပေဒအမွတ္ ၃၁။))
Chapter 3 of the Myanmar Telecommunications Law stipulates that any person, department, or business organisation, inside Myanmar or from abroad, willing to provide the following facilities and/or telecommunication services shall apply to the Directorate of Communication under the Ministry of Communications and Information Technology for permission and licence for the following services: (i) Network facility services (NFS); (b) Network Services (NS); and (ii) Application services (AS).
It is reported that the government issues tenders upon granting telecommunications licenses. The Government determines from a policy standpoint how many operators to let in. In addition, in 2020, it was reported that the government of Myanmar reportedly threatened to cancel licenses unless their holders complied with demands to block websites, including news outlets. Local government officials also stressed the need for providers to obtain permits to lay fibre-optic cables, build towers, and install Wi-Fi devices.
Coverage Telecommunications sector

MYANMAR

N/A

Pillar Telecom infrastructure & competition  |  Indicator Signature of the WTO Telecom Reference Paper
Lack of appendment of WTO Telecom Reference Paper to schedule of commitments
Myanmar has not appended the World Trade Organization (WTO) Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector

MYANMAR

Reported in 2017, last reported in 2024

Pillar Telecom infrastructure & competition  |  Indicator Presence of an independent telecom authority
Lack of an independent telecom authority
Myanmar lacks a telecommunications regulator that operates independently of the government in its decision-making processes. Regulatory authority over the sector rests with the Posts and Telecommunications Department (PTD) within the Ministry of Transport and Communications (MoTC). As a ministerial body reportedly administered by former military officials, the PTD is devoid of both legal and practical safeguards to ensure its independence in regulatory and operational matters. It is reported that the military exercises control over the PTD’s oversight of telecommunications companies and licensing procedures. Furthermore, the PTD’s decisions are characterised by a lack of transparency and appear to exhibit a consistent bias in favour of the military’s interests.
Coverage Telecommunications sector

MYANMAR

Since April 2004, as amended in February 2021
Since February 2021

Pillar Cross-border data policies  |  Indicator Conditional flow regime
Electronic Transactions Law (The State Peace and Development Council Law No. 5/2004) (အီလက်ထရောနစ် ဆက်သွယ်ဆောင်ရွက်ရေးဥပဒေ)

Law Amending the Electronic Transactions Law (State Administrative Council Law No. 7/2021) (အီလက်ထရောနစ် ဆက်သွယ်ဆောင်ရွက်ရေးဥပဒေကို ပြင်ဆင်သည့် ဥပဒေ နိုင်ငံတော်စီမံအုပ်ချုပ်ရေးကောင်စီ ဥပဒေအမှတ် (၇/၂၀၂၁))
Section 27-A(ii) of the Electronic Transactions Law, as amended in 2021 by Law No. 7/2021, mandates the personal data administrator to seek the consent of the owner of data before any data transfer. However, the law does not further regulate the ways in which the owner's consent is sought.
Coverage Horizontal

MYANMAR

N/A

Pillar Cross-border data policies  |  Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
Myanmar has not joined any agreement with binding commitments to open transfers of data across borders. Art. 12.15 of the Regional Comprehensive Economic Partnership (RCEP) recognises that each party may maintain its own regulatory requirements governing cross‑border transfers of information by electronic means and stipulates that such transfers shall not be restricted when undertaken for the conduct of business by a covered person; however, the article simultaneously allows parties to adopt or maintain any measures they themselves deem necessary to achieve a legitimate public policy objective, as well as any measures necessary to protect essential security interests, with the parties expressly affirming that the determination of such necessity lies solely with the implementing party and that such measures shall not be subject to dispute. It is reported that this formulation enables the parties to preserve their domestic data‑control regime under the rubric of national security without risking inter‑state disputes, and that the relative weakness of Chapter 12 renders its provisions largely ineffectual in facilitating the liberalisation of cross‑border data flows, particularly because the clause entrusting necessity assessments to the implementing party effectively permits any measure to be characterised as legitimate at that party’s discretion.
Coverage Horizontal

MYANMAR

N/A

Pillar Domestic data policies  |  Indicator Framework for data protection
Lack of comprehensive legal framework for data protection
Myanmar does not have a comprehensive regime in place for all personal data. However, the Constitution of the Republic of the Union of Myanmar and the Law Protecting the Privacy and Security of Citizens set out provisions for the protection of privacy and security of communications. These are supplemented by sectoral legislation, such as the Telecommunications Law 2013, which contains provisions related to the confidentiality of personal information.
Coverage Horizontal

MYANMAR

Since April 2004, last amended in February 2021

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Electronic Transactions Law (The State Peace and Development Council Law No. 5/2004) (အီလက်ထရောနစ် ဆက်သွယ်ဆောင်ရွက်ရေးဥပဒေ)
Art. 27 of the Electronic Transactions Law requires personal data administrators to retain personal data for a specified period before destruction. However, the regulation does not define the exact duration for which the data must be retained.
Coverage Horizontal

MYANMAR

Since January 2025, entry into force in July 2025

Pillar Domestic data policies  |  Indicator Minimum period for data retention
Cybersecurity Law (Law No. 1/2025) (ဆိုက်ဘာလုံခြုံရေးဥပဒေ)
Section 33 of the Cybersecurity Law provides that a digital platform service provider shall retain, for a period of three years, specified categories of data relating to users of the service, namely: (a) the personal information of users accessing the service; (b) records of users’ utilisation of the service; and (c) such additional data as may be prescribed by the Department from time to time. Section 34 further stipulates that where any individual or organisation duly authorised under any law in force submits a written request for any or all of the data referred to in Section 33, the digital platform service provider is obliged to furnish such data in the prescribed manner. Pursuant to Section 4, “digital platform services” are defined as a category of business that provides services enabling users to display, transmit, disseminate, or otherwise utilise information online through cyber resources or analogous technologies and associated equipment, while a “digital platform service provider” refers to any person or organisation that offers such services for use within the State.
Coverage Digital platform service providers

Report issue     Report new measure