Cross-border data protection needs less formal, bottom-up approach

Published Wed, Aug 26, 2020 · 09:50 PM

THE Covid-19 crisis has accelerated the take-up of technology across many sectors, with more people working from home, ordering goods and products online, and streaming entertainment using cloud-based solutions. The future 5G mobile network, which promises a host of supercharged AI solutions, will accelerate the use of data transmissions, all of which are dependent on smooth and secure flow of personal data across borders.

Yet Asia, in particular, remains a patchwork of different laws governing the collection, use and transfer of that data, despite drawing on the same sources, like the OECD Privacy Guidelines, the APEC Privacy Framework and Europe's General Data Protection Regulation.

For instance, different rules apply in the regulation of cross-border data transfers in the Asia-Pacific. For example, transfers may be authorised or prohibited by default, subject to exceptions that vary. Some jurisdictions like China, India, Indonesia and Vietnam have, in some circumstances, imposed strict obligations to "localise" their citizens' data, citing digital-sovereignty and national-security concerns. Collecting individual consent is a default condition to transfer data overseas in some, not all jurisdictions. Consent may be understood differently. Not all compliance mechanisms that companies may use to transfer data as alternatives to consent are recognised in all jurisdictions.

A FRAGMENTED LANDSCAPE

Two recent decisions originating outside Asia have made this fragmented landscape even more complex.

On July 16, the European Court of Justice struck down the Privacy Shield, a data-transfer agreement between the EU and the United States, for the lack of individualised protection regarding the use by US intelligence agencies of personal data initially transferred for commercial purposes (in this case by Facebook) from the EU to the US. Because of the interdependence of data-flows frameworks, this decision has major implications for policy and practice of privacy, in Asia and globally.

On Aug 14, US President Donald Trump signed an executive order giving ByteDance 90 days before its TikTok business is banned from the US, on the fear that the company would share the data of US TikTok users with the Chinese government. This decision could signal a new American approach of tech regulation, which some argue might lead to turning the Internet into more of a patchwork of "digital fiefs".

The resulting accumulation of legal uncertainty and inconsistencies weighs heavily on businesses, constrains innovation and eventually limits economic growth across the Asian region in general, and South-east Asia in particular. It further puts limits to regulatory cooperation, creates gaps in protection that are prejudicial to individuals, and thus generates a risk of regulatory inefficiency.

Taken together, this multiplicity of parameters creates the paradox that personal data flows are being restricted in an increasing number of ways at the same time as the pandemic has proven that they have never been so useful for all the sectors of our societies and economies.

Addressing these challenges requires international cooperation and collective action. But in the current geopolitical climate, a top-down approach to international data-flow governance does not work well. Yet despite the political obstacles to the adoption of global solutions, public and private actors urgently need short or medium-term technical and regulatory solutions to protect personal data in a context that will inevitably be ever more international.

To build them, less formal, more agile methods of cooperation are needed.

In November 2020, the work on data privacy of the Singapore-based Asian Business Law Institute (ABLI) will be showcased at the Paris Peace Forum, an international event that provides a platform for detailed discussion of major global challenges and finding practical solutions.

GLOBAL GOVERNANCE GAPS

The project was selected among more than 850 projects, in recognition that soft, bottom-up cooperation actions carried out alongside multilateral cooperation channels can bridge global governance gaps in this complex field of cross-border data protection.

Recently ABLI's project maps the sources of differences, but also identified areas for convergence between the data-transfer frameworks of 14 Asia-Pacific jurisdictions. With inputs received from regulators and industry collected over a year, the report makes recommendations for convergence between those frameworks and puts forward policy considerations and solutions to improve the situation in the short- to mid-term.

The international recognition of ABLI's work is significant in that it vindicates its Asian-centric focus, polycentric and practice-oriented identity, and projects-based strategy for promoting convergence.

It also shows that despite various challenges, Singapore holds the capacity to offer a neutral, globally trusted platform of cooperation to understand and deal with this complexity. This opportunity must be seized by all the stakeholders that want to build a digital world that remains open for business, but also responds to the increasing privacy expectations of the Asian public.