Cybersecurity Law, digital platform data retention and disclosure duty
Myanmar's Cybersecurity Law (State Administration Council Law No. 1/2025) contains no data-protection framework: its Chapter II definitions define cybersecurity-related terms but no "personal data" or "biometric data" term at all, and the sole use of "personal information" in the entire law is at section 33, which requires a digital platform service provider to retain personal information of a user, usage records, and any data the Department specifies for 3 years, disclosed to an authorised individual or organisation on written request under section 34.
This is a retention and state-access duty, not a protective one: it carries no consent standard, no purpose limitation, no retention ceiling beyond the 3-year floor, and no individual notice or objection right, and it runs toward government access to personal data rather than away from it, reaching a voiceprint or faceprint a covered platform stores exactly like any other user data.
The law's own section 2 commences it only on a date the president appoints by notification; independent trackers converge on State Administration Council Notification No. 113/2025 bringing it into force 30 July 2025, but that notification was not independently read this pass, so this instrument is recorded as enacted rather than in effect.
Enforcement runs through a Central Committee and a Steering Committee on Cybersecurity and a Department with licensing and investigation powers (Chapter III); no private civil right of action exists anywhere in the law's text.