0% found this document useful (0 votes)
12 views24 pages

Asia Overview

The document provides an overview of data privacy laws across 26 Asian jurisdictions as of October 2019, highlighting the growth and evolution of these laws in response to global standards like the GDPR. It discusses the principles of data privacy, enforcement mechanisms, and the impact of GDPR on Asian countries, noting that 136 countries have established data privacy laws with many more in development. Additionally, it addresses the regional differences in data localization requirements and the establishment of Data Protection Authorities.

Uploaded by

kiara a
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views24 pages

Asia Overview

The document provides an overview of data privacy laws across 26 Asian jurisdictions as of October 2019, highlighting the growth and evolution of these laws in response to global standards like the GDPR. It discusses the principles of data privacy, enforcement mechanisms, and the impact of GDPR on Asian countries, noting that 136 countries have established data privacy laws with many more in development. Additionally, it addresses the regional differences in data localization requirements and the establishment of Data Protection Authorities.

Uploaded by

kiara a
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ASIA OVERVIEW

Asian Data Privacy Laws –


Featured countries (2019)

Professor Graham Greenleaf AM


Professor of Law & Information Systems,
University of New South Wales
Asia-Pacific Editor, Privacy Laws & Business International Report
30 October 2019, Linklaters, London
Relevant materials
1. Greenleaf Asian Data Privacy Laws (OUP, 2014) –
Comprehensive text on all 26 Asian jurisdictions, to early
2014 – available in paperback, at discount (see handout).

2. 2019 Update to ADPL (2014 to 08/19) – Handout for this


course (not yet online)

3. 2017 & 2019 updates

4. News online: Twitter @grahamgreenleaf

5. Articles in Privacy Laws & Business International


Report

6. ABLI Regulation of Cross Border Transfers of


Personal Data in Asia, 2018 – ABLI Privacy Project

7. International Privacy Law Library …

4
International Privacy Law Library

on WorldLII
<[Link]

• free extensive online resources – includes most


Asian Acts, in English, in National Data Privacy
Laws database
• international agreements
• includes cases decided by these Asian DPAs
(and others):
• Hong Kong PCPD
• Korean PIDMC
• Macau OPDP
• Philippines (coming soon)
• many journal articles etc

5
136 Countries w ith data privacy Law s
(to O ctober 2019)

Key
Comprehensive
Public only
Private only
Most Private 6
Bills
Plus 30+ countries with official Bills
(to October 2019)

Key
Comprehensive
Public only
Private only
Most Private 7
Bills
Plus non-European countries with Revision Bills
(to October 2019)

Key
Comprehensive
Public only
Private only
Most Private 8
Bills
How many countries now have a data privacy law?
• Answer: 136 (as at September 2019)
– 2019 Tables and articles on my web pages/SSRN: 132
– Since then, Uganda, Nigeria, Uzbekistan, Barbados: 136
– Since 2014 the majority of global privacy laws are from outside
Europe (now 70%: 89/128); only 20% = EU
• About 30 more countries currently have official Bills
• Growth of new laws globally has not slowed down
• Also many stronger revised laws
(eg Thailand, Korea, Hong Kong, Taiwan, Japan, Australia)
• Others: significant e-commerce/consumer privacy laws
• 90% have a separate Data Protection Authority (DPA)
• Data export restrictions are global

9
What fundamentals
should we look for?

ADPL Ch 2 ‘International’ & Ch 3 ‘Standards’

10
Comparing principles enacted in data privacy
laws [ADPL Chs 2&3]
Data privacy principles – 3 generations:
1. ‘Basic’ principles: CoE Convention 108 1981; OECD Guidelines 1980
2. ‘European’ principles: EU Directive 1995; CoE 108 Protocol 2001
3. New post-GDPR principles:
1. EU GDPR (General Data Protection Regulation) 2016/2018; ‘modernised’ CoE
Convention 108+ (2018)
2. 19 new GDPR principles, 12 shared with 108+

11
1st Gen: Basic data privacy Principles
(EU & OECD hold in common 1-9)
1. Collection - limited, lawful & by fair means; generally with consent or knowledge (OECD 7)
2. Data quality (relevant, accurate, up-to-date) (OECD 8)
3. Purpose specification at time of collection (OECD 9)
4. Notice of purpose and rights at time of collection (OECD ambiguous)
5. Uses (incl. disclosures) limited to purposes specified or compatible (OECD 10)
6. Security through reasonable safeguards (OECD 11)
7. Openness re personal data practices (OECD 12)
8. Access & Correction – individual rights of (OECD 13)
9. Accountable– Responsible data controllers identified (OECD 14)
10. Data export restrictions may [only EU 1995 said ‘must] be limited to (a) countries which
do not substantially observe these basic rules, and (b) do not prevent circumvention by re-
exports (OECD 17)
We will assume these 10 basic principles in laws discussed, and focus on (I) where one
is absent or (II) principles that go beyond these features

12
2nd Gen: 10 ‘European’ standards
EU Directive (1995) & CoE 108 +Add. Protocol (2001)

1. ‘Minimality’ in collection (relative to purposes);


2. Legitimate basis for processing defined;
3. Some prior checking by/notice to DPA required;
4. ‘Deletion’: Destruction or anonymisation after use;
5. Sensitive data additional protections;
6. Limits on automated decision-making;
7. Objections to processing (incl. ‘opt-out’ of direct
marketing).
8. Has a separate independent DPA; (enforcement)
9. Allows remedies via the courts; (enforcement)
10. ‘Border control’ as part of data export restrictions.
On average, new data privacy laws outside Europe include 6 or 7
of these principles, in addition to the minimum OECD principles
13
2nd generation European standards in Asian laws
2nd Gen. – ‘European standards’ EU Directive Asian laws including standard No.

Data retention limits (destruction or EU Dir 6(1)(e) Bhutan, HK, Indonesia, Japan, Korea, Malaysia, Macau, 12
anonymisation) after processing achieved GDPR 5(1)(e) Philippines, Taiwan, Singapore, Thailand, Vietnam
Recourse to the courts to enforce data EU Dir 22, 23 Bhutan, China, HK, India, Indonesia, Korea, Macau, 12
privacy rights (incl. compensation, and GDPR 78, 79, 82 Philippines, Taiwan, Singapore, Thailand, Vietnam
appeals from decisions of DPAs)
Minimum necessary collection for the EU Dir 6(1)(c), 7 Bhutan, China, HK, India, Korea, Malaysia, Macau, 10
purpose (not only ‘limited’) GDPR 5(1)(c) Taiwan, Singapore, Thailand
Restricted data exports based on data EU Dir 25 China, India, Japan, Korea, Malaysia, Macau, Singapore, 9
protection provided by recipient country GDPR 44-49 Thailand, Taiwan
(‘adequate’), or alternative guarantees
Specialised Data Protection Authority(-ies) EU Dir 28 Bhutan, HK, Japan, Malaysia, Korea, Macau, Philippines, 9
(DPA) required GDPR 51-59, 77 Singapore, Thailand
Additional protections for sensitive data in EU Dir 8 Bhutan, China, Japan, Korea, Malaysia, Macau, 9
defined categories GDPR 9, 10 Philippines, Taiwan, Thailand
Rights to object to processing, including to EU Dir 14(a), Bhutan, China, HK, Korea, Malaysia, Macau, Taiwan, 9
‘opt-out’ of direct marketing uses of (b) Thailand, Vietnam
personal data GDPR 21
General requirement, and exhaustive EU Dir 6(1)(a) Bhutan, China, Korea, Malaysia, Macau, Philippines, 8
definition, of legitimate processing’ GDPR 5(1)(a), 6 Taiwan, Thailand
Prior notification to or checking by DPA of EU Dir 20 HK, Japan, Korea, Malaysia, Macau 5
some sensitive processing GDPR 36
Limits on automated decision-making (incl. EU Dir 15, 12(a) China, Macau, Philippines 3
right to know processing logic) GDPR 22
Av. over 14 countries = 6.1/10 principles 86
Standards to compare/assess data privacy laws Enforcement
Standards

• International agreements are less specific on what counts


as effective enforcement
– GDPR has the most specific enforcement requirements yet
seen
• Most widely-agreed necessary element is a specialist
enforcement body (DPA)
– Preferably an independent one
• Theories of ‘responsive regulation’ give the best guide
[see ADPL Chs 2&3]
The idea of ‘responsive regulation’:
What is needed for effective enforcement?

Elements of‘Responsive regulation’


(Braithwaite, Parker et al)
1. Effective regulation requires multiple types
of sanctions of escalating seriousness
2. It is an enforcement pyramid: sanctions at
the top get used far less than the cheaper
bottom layers
3. All forms of sanctions must be actually
used when necessary
4. Use of each level of sanction must be
visible to those regulated, consumers and
the representatives of both
Enforcement pyramid in a licensing 5. The higher levels are incentives for the
system (Braithwaite 1993) lower levels to be made to work
Regional vs National Structures
Regional Structures Europe Asia
56 countries and 24 countries + 2 SARs
territories
Regional Legislatures EU and CoE None
Permanent bureaucracies Brussels & Strasbourg None (not ASEAN, nor
APEC, nor SAARC)

Common privacy rights EU Charter; Directives; None (only 20/26 are


GDPR; ECHR A8; Conv ICCPR parties; only 5/26
108/108+ accept ICCPR Optional
Protocol)
Regional courts ECtHR; ECJ/CJEU None
Regional DPA groupings Article 29 Working Party; APPA is informal;
with functions/powers EU Data Protection Board APEC CBPR JOP approves
(EDPB); EDPS proposals
17
I have a
feeling
we’re not
in Brussels
anymore

18
Far away – Asia’s 26 jurisdictions
15/26 Asian countries with data privacy laws (1st Gen. min.)

1. Japan 1988 (public sector) + 10. India 2011 (private sector) Draft
private sector 2003; rev. 2015 comprehensive Bill 2018
11. Philippines 2012 (comprehensive)
2. South Korea 1995 (public sector)
12. Singapore 2012 (private sector)
+ private sector 2001
13. Indonesia 2012 + Regulation 2016
3. Hong Kong 1995 (private sector) Comprehensive
(comprehensive); rev. 2012 Bill 2018
4. Taiwan 1995 (public sector + 14. China 2011-19 (most private
limited private sector) sector)
5. Thailand 1997 (public sector) 15. Bhutan 2018 (comprehensive)
Comprehensive Law 2019 + Bills in 16 Pakistan, 17 Sri Lanka
Revised laws
6. Macau 2006 (comprehensive)
1. Taiwan 2011(comprehensive)
7. Nepal (public sector 2007)
2. South Korea 2012+++
(comprehensive 2018)
3. Hong Kong 2012
8. Malaysia 2009 (private sector) 4. Japan 2015
9. Vietnam 2010-19 (private sector) 5. Nepal 2018
6. Thailand 2019
Asia Data Privacy Law Conference

Adrian Fisher and Professor Graham Greenleaf


October 2019
Part 1 – Introduction and Regional Trends

Impact of GDPR

New and Amended Laws

Data Localisation

22
Impact of GDPR

1 Board room level fines (e.g. British Airways, Marriott)


Countries are moving
towards GDPR
2 Extra-territoriality principles through
new laws (e.g. India,
+ Thailand) and
amendments (e.g.
3 Shifting away from consent Singapore, Australia)

4 Breach notification
23
New and amended laws

China’s Implementation Rules + New Laws


in the Pipeline

India’s Draft Personal Data Protection Bill

Thailand’s Personal Data Protection Act

changes to
Singapore’s Personal Data Protection Act

changes to
Australia’s Privacy Act 1988
24
Data localisation

˃ Some regulators:
• are requiring certain data to be kept in
country (e.g. Indonesia, India and China)
• while others remain liberal (e.g. Singapore
and Hong Kong)
˃ Tension between:
1. New laws that require some form of
localisation
2. Growing importance of access to
computing power (with cloud at the core)
25

You might also like