Introduction and world leaders in data privacy
One world, one internet – many laws. Given the furore over the EU-US Privacy Shield and the GDPR, you could be forgiven for thinking that data protection and privacy is something for the Atlantic power blocs to sort out, with every other country following suit. That's not the case.
"Internet communication has made the whole discussion on data privacy a global interest," says Lillian Pang, Senior Director, Legal, Rackspace. "Data privacy is no longer a local discussion."
Some of the very same emerging economies constantly being talked about as 'tomorrow's markets' (so of critical interest to all international and web-based tech and IT businesses) are legislating around data privacy in drastically different ways. "Rules and regulations vary widely geographically," says Robert Stroud, Director on ISACA's board and Principal Analyst, Forrester Research. "There are no consistent guidelines and rules … even neighbouring legislative regions have different policies."
Who are the world leaders in data privacy?
The European Union's negotiations with the US in recent years has seen the continent of Europe painted as the bulwark of data privacy laws. "It just happens that because of the developed markets in the EU, which has the most progressive laws on data protection globally, and the US, which has the vast majority of the technology industry benefiting from the creation of data, that the data flow between them is particularly under scrutiny," says Ross Woodham, Director, Legal Affairs and Privacy, Cogeco Peer 1.
Europe definitely sets the tone, but it's important to remember that the bloc has defined its reaction to data privacy in relation to the US. That's not an exclusive standpoint.
For example, Canada's Digital Privacy Act came into force in 2015 to help guard Canadians' private data stored by US-based services like Facebook, Gmail, Twitter and YouTube, though individual provinces in Canada do have their own requirements.
"Canada and Europe tend to lead the world in terms of legislating personal data," says Pang, but the rest of the world is catching up fast, though hugely unevenly. "Many countries outside of the EU have enacted data protection laws in recent years, including Malaysia, South Korea, Singapore, and Turkey," says Janine Regan, Associate at Charles Russell Speechlys. "Many of these laws are very similar to the EU Data Protection Directive, although these jurisdictions often carry incredibly heavy sanctions for non-compliance – including prison sentences."
However, the European Commission thinks only Andorra, Argentina, Canada, Faeroe Islands, Guernsey, Israel, Isle of Man, Jersey, New Zealand, Switzerland and Uruguay offer EU citizens adequate protection.
What about Asia?
Some areas of the world have modelled their response to data privacy on the EU's battle with the US, and that certainly applies to Asia, which goes straight to the top of the list of concern for the IT and tech industry. After all, around 28% of the world's middle class already lives in Asia, and that's about to double in just the next 14 years. That's a huge global demographic shift.
In recent years, several Asian countries have undergone a major change in data privacy regulation, and that's mostly due to the Asia-Pacific Economic Co-Operation (APEC) Privacy Framework. "APEC agreed on a privacy framework in 2005," explains Malcolm Harkins, Global CISO from Cylance. Early leaders in Asia Pacific data protection were Australia, New Zealand, and Hong Kong, all of which passed strong data privacy laws in the 1990s."
More recently, China, Taiwan, South Korea, Malaysia, Singapore, and the Philippines have passed comprehensive legislation of their own. "The APEC Privacy Framework has provided some rough signposts for a common approach to principle-based regulation, but priorities for policymaking and enforcement vary significantly by jurisdiction," says Bill Stroud, principal engineer at Covata.
However, there are efforts to harmonise Asia and the EU. "The WP29 is in talks with Asia to see how they can work together to make these two labels become mutually recognised," says Elodie Downing, VP, EMEA general counsel, BMC Software. Still, no harmonisation has happened thus far.
Centralised standards
Lacking centralised standards
It's a view that's confirmed by CipherCloud, whose useful global compliance map gives country-specific information. "As our interactive compliance map demonstrates, Asian privacy laws are country-specific rather than regional," says Willy Leichter, global director of cloud security at CipherCloud. "Singapore has much stricter privacy laws, which likely developed because of its historically vibrant banking sector … but Asia lacks centralised control or standards between data protection authorities."
For example, take India, whose Information Technology Act was passed 15 years ago. "India has passed a principles-based law to protect data privacy," says Harkins. It's a start, but so far it's about specific sectors, not wide-ranging principles.
There's a similar scenario in China, a market of 1.3 billion people. "China is headed for a data localisation model, whereas jurisdictions are aiming for a more cautious approach," says Pang. China has had a national law on the collection of electronic information since 2012.
The model China is chasing is perhaps that of Russia. "All Russian citizen personal data can only be stored in Russia," says Nicky Stewart, Commercial Director at Skyscape Cloud Services. A reaction to NSA snooping, the law effectively makes Western technology companies' data on Russian citizens open to snooping by Russian authorities.
Fast growing economies
Elsewhere in Asia there is a lack of blanket rulings, largely in the 'tiger' economies. "Some countries, such as Indonesia, have offered very particular rules surrounding the country's attitude to data privacy for years now – the old Blackberry requirements are an example," says Penny Jones, senior analyst for European services at 451 Research. In 2011, Indonesia, the world's most populous Muslim nation, forced Blackberry-maker, Canada's RIM, to censor pornography viewed via its handsets.
Another fast growing market, Latin America, is also in flux, with some specific targeted laws, but no blanket protection. "Uruguay, Colombia, Costa Rica and Mexico are all still developing their technological base and face speedy evolution in emerging requirements, meaning legislation and policy is difficult to keep up to date," says Robert Stroud.
A world in flux
When it comes to data privacy law, the world is in flux, and it's unlikely to come to equilibrium any time soon. "As much as an approach based on 'one size fits all' will not be the solution, many countries will continue to observe what the EU does and seek to select parts of the legislation that work well, leaving the not-so-practical elements," says Pang.
"There are 195 countries worldwide, and each may have their own laws and regulations – it is a complex task to be up to date with every country's laws," says Nigel Hawthorn, chief European spokesperson at Skyhigh Networks.
He recommends checking out the resources of law firms like DLA Piper, which give access to all current data protection laws around the world. From there it's straightforward to evaluate an organisation's compliance and gain insights into legal and regulatory compliance with data protection laws around the globe.
Politics will always play a part in data protection – see Turkey's recent banning of PayPal as one example (here's another) of the populist bashing of US technology firms.
Privacy standards may be feeding off each other, and to some extent they are harmonising, but before you do business in a new country check whether you're collecting data legally. In global data collection, less is always more.
No comments:
Post a Comment