Transferring Personal Data in Asia
Total Page:16
File Type:pdf, Size:1020Kb
Transferring Personal Data in Asia: A path to legal certainty and regional convergence This Comparative Review sets out proposals for how Asian public stakeholders may promote legal certainty and greater consistency between their respective laws and regulations on cross-border transfers of personal data in the region. Despite differences between the philosophies and the regulatory structures of each regime, there exist enough connecting points between national frameworks which lawmakers, governments, and data protection regulators can capitalize on, so as to promote and ensure responsible data flows between jurisdictions. Interoperability would be further enhanced by a common movement to align the standards by which legal grounds, mechanisms, and schemes for data transfers should be assessed. Alignment should be with a similarly high level of data protection so as to improve the situation of individuals and facilitate multi- jurisdictional compliance, as well as regulatory cooperation. Alignment not just to a regional standard but to global standards is a worthwhile goal, especially given the integration of Asian economies in global trade and the increased privacy expectations of the Asian public. This Review is supported by a comprehensive comparative Table of the rules relating to the transfer of personal data in 14 Asian jurisdictions. May 2020 Index Why this Review? ___________________________________________________________ 3 Key Findings _______________________________________________________________ 5 Collective Benefits of Legal Certainty & Convergence ______________________________ 9 Serializing the Causes of Legal Uncertainty & Fragmentation _______________________ 10 Paths of Convergence in a Period of Intensive Law Reform _________________________ 12 Analysis of Asia’s Frameworks & Recommendations for Convergence ________________ 13 Overview of Main Rules & Principles ______________________________________________ 14 Consent _____________________________________________________________________ 22 Status in Asia________________________________________________________________________ 24 ‘Adequacy’ & ‘White Lists’_______________________________________________________ 27 Status in Asia________________________________________________________________________ 29 Self-Assessment by the Exporting Organisation______________________________________ 33 Status in Asia________________________________________________________________________ 33 Contractual Safeguards _________________________________________________________ 37 Status in Asia________________________________________________________________________ 40 Binding Corporate Rules ________________________________________________________ 44 Status in Asia________________________________________________________________________ 45 Certification __________________________________________________________________ 48 Status in Asia________________________________________________________________________ 50 APEC Cross Border Privacy Rules__________________________________________________ 53 Status in Asia________________________________________________________________________ 55 Codes of Conduct ______________________________________________________________ 58 Status in Asia________________________________________________________________________ 60 Exemptions & Additional Legal Grounds for Transfers ________________________________ 63 Status in Asia________________________________________________________________________ 65 Data Transfer Mechanisms & Localisation Laws _____________________________________ 71 Status in Asia________________________________________________________________________ 73 Overarching Policy Considerations ________________________________________________ 76 Acknowledgments _________________________________________________________ 78 2 All the stakeholders which face the challenge of Why this implementing these regulations, primarily industry and data protection regulators, acknowledge this necessity. Legal uncertainty and Review? inconsistency between data protection frameworks have important repercussions on their respective actions—and, directly or Published in May 2018, ABLI’s Compendium of indirectly, on the situation of the individuals reports on the Regulation of Cross-border Data whose personal data is transferred across the Flows in Asia showed how, in this region as Asian borders. elsewhere, national data strategies generally ABLI wrote this Comparative Analytical Review recognise the need for rules regarding cross- and its supporting document—a Comparative 1 border personal data transfers. Table on Laws, Bills, and Regulations on Personal In May 2020, just two years after this first Data Transfers in Asia, on which the Review is publication, law reform or law review has been based—with the ambition to contribute to announced, or is under way in virtually all of the removing such uncertainty and unclarity in the fourteen legal regimes covered in our project. laws of the region. Nearly all Asian Data Protection Laws contain 1. ABLI’s Comparative Analytical Review: specific provisions applicable to cross-border data Promoting Convergence and Interoperability flows, and some jurisdictions are currently This Review was suggested to ABLI by Asian data modifying their data protection frameworks to protection regulators and governments, who clarify their application to such transfers. have expressed an interest in receiving This trend is fuelled by the increasing relevance, comparative information to fuel their efforts to in Asia, of regional or international data increase the compatibility or ‘interoperability’ of protection frameworks with a strong focus on their legal and regulatory frameworks on personal international flows of personal data, including the data flows. Privacy Guidelines of the Organisation for Law practitioners and industry have further Economic Co-operation and Development expressed support to ABLI’s efforts, which (OECD), the European Union’s General Data ‘introduce an additional analytical layer to the Protection Regulation (EU GDPR), Asia-Pacific conversation’ to which Asian Governments are Economic Cooperation (APEC) Privacy currently taking part to identify common Framework, Association of Southeast Asian approaches to data protection between different Nations (ASEAN) Framework for Data Protection, regions.2 and data-related clauses in trade agreements and economic partnerships, among others. ABLI’s Data Privacy Project thus features among the reasons ‘why multinational organisations Yet, the regulation of cross-border data flows have good reason to hope for some measure of remains a key area which requires greater clarity harmonisation of compliance standards, including and consistency between data privacy laws and practical solutions for cross-border data transfers’ regulations in Asia. in the APAC region.3 2 Derek Ho, ‘Mastercard: Dealing with the 1 Clarisse Girot (ed), Regulation of Cross-Border complexity of data protection’, Asia Outlook, Transfers of Personal Data in Asia (Asian October 2019 Business Law Institute, 2018). <https://www.asiaoutlookmag.com/industry- insights/article/775-mastercard-dealing-with- the-complexity-of-data-protection>. 3 Hogan Lovells Asia Pacific Data Protection and Cyber Security Guide 2019 (Hogan Lovells, 2019) at 7. 3 The primary objective of this Review is therefore Primary authority of non-English speaking to provide lawmakers, governments, and countries might be simply lacking or be outdated regulators in Asia who are currently drafting, as laws change rapidly and translations in other reviewing, or implementing data transfer languages do not keep up. Commercial sources provisions in their respective jurisdictions with a are expensive, and translations by government comparative overview and analysis of the transfer entities, when they exist, are still for principles, legal grounds, mechanisms, and informational purposes only. Only the most schemes that operate in the laws of their regional organised business organisations have the partners and neighbours. organisational and financial capacities to follow up on law and rulemaking and make translations In particular, it is hoped that the Review will be to the benefit of their members. useful to those public stakeholders who are seeking constructive ways to enhance the This asymmetric level of information makes it compatibility of their respective frameworks by: particularly difficult for new entrants, in particular for SMEs, whether local or foreign, to assess their • including in Data Protection Laws or compliance risk. It also creates the risk that regulatory guidance the full range of available governments, lawmakers and regulators miss on cross-border transfer mechanisms to enable feedback from lines of business that cannot afford accountable global data flows; the costs of familiarisation through local • permitting existing and widely accepted specialists. It makes it significantly harder for civil exceptions and derogations to such society actors like academics and NGOs to voice restrictions. specific views. As well, it is hoped that it will help to promote the This is why, in addition to this Review, ABLI has need to improve legal certainty in the application decided to publish the entire Comparative Table of personal data transfer restrictions, including on Asian Laws and Regulations on Personal Data data localisation requirements. Transfers which it has drawn up to inform its analysis, for the benefit of all. 2. ABLI’s Comparative