Menu
Website designed by SA / Build by MMD
  • On 11 December, the Norwegian OECD National Contact Point (NCP) published a Final Statement on a 2021 complaint brought by SOMO on behalf of 474 Myanmar civil society organisations against Telenor regarding its exit from Myanmar.
  • The complaint alleges that Telenor’s exit from Myanmar may have exposed customers to risks of surveillance, torture and death by the Military Junta. The NCP found that Telenor did not carry out appropriate human rights due diligence and that it is probable that Telenor contributed to severe human rights impacts, and therefore should provide remedy proportionate to its contribution to the harm. The NCP’s findings hinged on whether Telenor was justified in systematically prioritising the safety of its own employees over the human rights of customers and other affected stakeholders. 
  • On 11 December, Telenor issued a response to the Final Statement, disputing several key NCP findings and asserting that, under the UNGPs, “an employer cannot give instructions which put employees’ lives at direct risk”.
  • Separately, SOMO is supporting legal action against Telenor brought by Defend Myanmar Democracy, the Myanmar Internet Project and the widow of an executed opposition leader, relating to the transfer of customer data to Myanmar’s military authorities.

Background to the case

  • Telenor entered Myanmar in 2011 following the dissolution of the military junta. After the military coup on 1 February 2021, the company faced escalating security risks, threats to staff and demands to hand over user data. Telenor concluded it could no longer operate safely and sold its Myanmar business to Lebanese investment group M1 for USD 105 million. Final approval was granted on the condition that M1 hold the business jointly with a local partner with close ties to the Military Junta.
  • According to the complaint, requests for historical customer data were common both before and after the coup, and Telenor complied with all such requests from the military authorities following the takeover.

KEY FINDINGS BY THE NORWEGIAN NCP INCLUDE THE FOLLOWING 

  • While Telenor carried out human rights risk assessments, these did not sufficiently account for the foreseeable risk of a return to military rule and had limited relevance post-coup.
  • Telenor set a hard rule that no employee should have to risk their life or health and employee safety was always put first. For example, Telenor considered deleting customer data to protect customers, but “According to Telenor, employees would have been in danger of death penalty and execution without trial if they had deleted data.”
  • Conversely, the NCP found that “it seems improbable to the NCP that the risks to the company’s employees in all circumstances and at all times outweighed and restricted mitigation efforts in regard of other human rights risks with which the company was involved.” Furthermore it states that “it was not in accordance with the expectations of Guidelines to systematically give priority to one set of rightsholders, i.e. Telenor’s own employees.”  
  • Related to the above, despite known risks to customers, Telenor did not inform users about the scope of data being handed over or the resulting security risks, nor did it support mitigation.
  • The sale agreement with M1 included only a general commitment to human rights and should have required specific safeguards appropriate to a conflict-affected context. The NCP found Telenor should have conducted renewed due diligence once authorities required a military-linked local partner.
  • While Telenor claims it engaged extensively with stakeholders, it allegedly did not consult or engage with any of the 474 Myanmar based CSOs supporting the complaint and there is no evidence it consulted with potentially or directly affected stakeholders. 
  • Telenor is expected to take an active role in remediation. The NCP concluded that although the primary responsibility for human rights violations lies with the military authorities, it was foreseeable that Telenor’s disclosure of user data would contribute to harm. While specific cases could not be linked, the NCP found it probable the data formed part of the information used to identify and persecute human rights defenders.
  • Proposed remediation is limited and includes funding an ICT Ecosystem Study (now completed) and a follow-on study exploring options for an independent digital relief mechanism to provide financial and other support to affected individuals.

Additional context

  • SOMO and Telenor initially engaged in mediation, resulting in a memorandum of understanding (MOU) in 2022. Final mediation talks ultimately broke down after over lack of agreement on the scope and purpose of the digital security relief mechanism for clients.
Contact
If you have a project you would like to discuss
email: info@duediligence.design