Prof. Dr. Larry AdamsAcademic, Author & Researcher

Chapter 11: Asia’s Data Protection Landscape

Introduction

Asia is one of the most exciting, varied and dynamic regions in the world for data governance. It has some of the world's largest digital economies, fastest growing technology markets, and most advanced digital infrastructure systems. The region is home to key economic powers like China, Japan, India, South Korea and Singapore, and emerging economies that are fast on the digital upgrade. Asia is home to over 50% of global population and is responsible for a growing proportion of the world's internet traffic, e-commerce, mobile connectivity and digital innovations. (World Bank, 2023).

Rapid adoption of Internet, smartphones, cloud computing, artificial intelligence (AI), fintech innovation, digital payment systems, e-commerce platforms and smart city initiatives have all contributed to the digital transformation of the region. They have created an unprecedented amount of both personal and commercial data, creating data governance as a strategic issue for the government, business and international organisations. The issues of privacy, cyber security, consumer protection, surveillance, cross-border data transfers, and digital sovereignty have risen to the forefront of policy agendas in the region as digital ecosystems expand (Kshetri, 2021).

While most of Europe have come together and converged on the General Data Protection Regulation (GDPR) as a community standard for data protection, Asia has no uniform regional data protection frameworks. Rather, it is composed of a patchwork of legal systems, regulatory philosophies, political structures and cultural approaches toward privacy. To date, some countries have adopted comprehensive privacy statutes that are broadly similar to international standards, others have relied on sector-specific legislation, some have developed new legislation, and a few have established governance models based in the state that overlook and are less protective of privacy amid the priority of national security and economic development (Greenleaf, 2023).

In the case of Japan, South Korea and Singapore, for instance, data protection is well-developed and has integrated several internationally accepted principles of data protection such as transparency, accountability, consent, purpose limitation, and individual rights. Other countries, however, have created unique regulatory frameworks that balance privacy rights with other cybersecurity, digital sovereignty, national security and state supervision goals (Creemers, 2022).

Concurrently, emerging economies are seeking to modernise their privacy regimes to meet the increased digital risks that arise in their economy and to foster economic growth and technological development, including India, Indonesia, Vietnam, Thailand and the Philippines. These reforms are the result of growing awareness that good data governance is critical to the trust of the public, international investment, digital trade and the ability to participate in the global digital economy (UNCTAD, 2023).

There are multiple reasons for the diversity of data protection across Asia. There are many different forms of political system—from liberal democracy to a highly centralized political system. Common law, civil law, socialist law and hybrid law are all legal traditions. There is a wide variation in economic development levels: from advanced industrialized economies to lower income developing countries. Attitudes toward privacy, individual rights, collective interests and government authorities vary greatly across the region, affecting privacy regulatory design and practices (Bennett & Raab, 2020).

Data sovereignty and strategic management of data assets is another hallmark of Asia's data governance landscape. Data is now recognized by the governments across the region as an important national asset with impact on economic competitiveness, technological leadership, cybersecurity resilience, and national security. Consequently, in many countries, legislative and regulatory measures have been taken in the areas of data localization, controls on cross-border data transfers, cybersecurity requirements, and the regulation of digital platforms. The developments are part of a larger world discussion on how to govern data in a world of AI, cloud computing, and geopolitical competition (Aaronson & Leblond, 2018).

AI technologies are also proliferating and adding to the complexity of the regulatory landscape. Countries in Asia are among the top investors and innovators in the development of AI, posing new challenges in relation to automated decision-making, algorithmic accountability, facial recognition systems, biometric data processing, and ethical AI governance. To meet this increasing demand by policymakers, there will be a need to address innovation and technological leadership while maintaining privacy protection, transparency and public trust (Richards & Hartzog, 2022).

Cross-border data transfers are also pivotal in influencing the regulations on privacy in Asia. The region is more tightly connected to the world's supply chains, international trade and digital service ecosystems. This means that governments will have to reconcile their regulatory goals with the realities of allowing international transfers of data to enable trade, investment, research, and innovation. Balancing these is one of the greatest policy challenges in Asia (Kuner, Bygrave, & Docksey, 2020).

In addition, in many countries in Asia, data protection has evolved to cybersecurity. Governments across the world have been taking steps to enhance cybersecurity laws and regulations in tandem with privacy laws to meet the growing threats of cybercrime, ransomware attacks, data breaches, and state-sponsored cyber operations. Today, data protection, cybersecurity and digital governance are understood to be elements of a wider national digital governance framework to safeguard critical infrastructure and promote economic resilience (Kshetri, 2021).

The regulatory developments in Asia will affect not just the region but the world as well as it continues to shape the digital transformation in the world. Regulatory decisions made in Asia will impact the world as much as the region as Asia plays a significant role in shaping the global digital transformation. The policies of Asian states impact multinational corporations, international data flows, technology development, the formation of digital trade agreements, and emerging standards for privacy and data governance around the globe. This is why it is crucial to understand the variety of the regulatory landscape in Asia in order to fully grasp the development of international data protection law in the twenty-first century (Greenleaf, 2023).

This chapter examines the framework of data governance in Asia, the complexity of regulatory responses in the region, the economic and technological forces behind the emergence of regulation, and the key challenges faced by policy-makers. Special emphasis is placed on the trade-offs between privacy protection, economic modernization, digital sovereignty, cybersecurity, AI governance and the international flow of data. The chapter showcases how Asia is becoming one of the most influential regions of the future of global data governance.

11.1 Introduction to Asian Data Governance

One of the most significant and dynamic sectors of international privacy law is Asian data governance. This exceptional economic growth, technological advancements and digital transformation in the region have created an unprecedented amount of personal and commercial data that places information resource governance as a strategic priority for governments, businesses and international organizations. Asia has over half of the world's population and some of the biggest digital economies, making Asia a key driver of the future of global data protection, cybersecurity, artificial intelligence governance and digital trade (World Bank, 2023).

The area includes a wide range of countries, each having distinct political, regulatory, legal, economic and cultural frameworks related to privacy. Consequently, there is no uniform regulatory approach in Asia. Rather, it is a wide array of different models, from holistic privacy programs and market-based regulatory regimes to state-centric models focused on cybersecurity, digital sovereignty and state control. Nevertheless, most Asian nations recognise that data has become an essential economic asset, and is a pivotal factor in the competitiveness of a nation in the digital age (Greenleaf, 2023).

The countries like China, India, Japan, South Korea and Singapore have emerged as global leaders in digital innovation, ecommerce, artificial intelligence, cloud computing, fintech development and digital infrastructure development. Their regulatory decisions impact not only the domestic markets but also international technology firms, transborder movement of data and new global trends on data governance (UNCTAD, 2023).

Three key drivers have influenced the development of data governance in Asia as a whole: rapid digitalization, government data policies, and digital economies.

1. Rapid Digitalization

The one thing that brings Asia's data governance landscape to a standstill is the remarkable rate of digital transformation. The internet adoption rates, smartphone penetration, mobile payments, and online service consumption rates are among some of the highest in the world. Digital technologies have become a part and parcel of everyday life in people's lives, impacting their interactions with each other, their business, education, healthcare, transport, entertainment and public administration (Kshetri, 2021).

Several factors have helped in the rapid digitalization:

Increasing the broadband and mobile network footprint.

•Affordable smartphone adoption.

The expansion of e-commerce platforms.

•Increasing use of cloud computing services.

•Increased financial inclusion.

Increased digital literacy of customers.

The mobile-first factor is especially impactful in Asia. Many Asian countries saw growth in the internet via mobile device, whereas in many Western economies the first form of digital growth was via the desktop. This mobile-first approach has led to the fast adoption of digital services by a large population, especially in less developed markets (World Bank, 2023).

This has led to a unprecedented amount of data being generated. All digital transactions, online purchases, mobile payments, social media interactions, biometric logins and location-based services help generate information that is personal and commercial in nature. This puts governments and companies under growing pressure to develop new regulations that can handle the risks to privacy and facilitate ongoing innovation and economic development.

In addition, the implementation of new technologies, including AI, machine learning, Internet of Things (IoT), blockchain and smart city platforms, has greatly complicated data governance issues across the region. Large scale data collection and analysis is essential to these technologies, and there are important privacy, transparency, accountability, and ethical data use considerations (Richards & Hartzog, 2022).

2. Government-Led Digital Policies

The second key characteristic of the Asian data governance experience is the significant impact that governments have on building digital ecosystems. In Asia, governments are more likely than many countries in the West to play an active part in designing, managing, and supervising digital transformation projects, while in many Western jurisdictions, private sector innovation is the source of regulation. (Bennett & Raab, 2020)

Governmentled digital strategies may include:

•National digital transformation programmes.

•Cybersecurity frameworks.

•Artificial intelligence strategies.

•Smart city initiatives.

•Digital identity systems.

•E-government services.

National policies on data governance.

Governments around the world, including Singapore and South Korea, have been actively driving innovation through a coordinated plan of action for the digital economy, while enhancing privacy rights and cybersecurity laws. These efforts are designed to create economic development, while ensuring that digital systems are trusted by these publics (Kshetri, 2021).

By contrast, nations like China have taken a more unified strategy that incorporates the aim of privacy alongside wider goals encompassing cyber security, social management, national security and technological autonomy. The Personal Information Protection Law (PIPL), the Data Security Law (DSL) and the Cybersecurity Law (CSL) of China are examples of how privacy governance can be embedded in broader national data governance programmes (Creemers, 2022).

In the same way, India has also been focussing on the digital governance since last few years with various measures like Digital India, introducing national digital identity programmes, development of fintech and data protection reforms. These are part of an increasing focus on data governance as a means to drive economic modernization and delivery of public services.

As state-led digital transformation is now an integral part of the Asian agenda, data governance is often intertwined with a wider policy agenda, such as economic competitiveness, technological leadership, national security, and social development.

3. Expanding Digital Economies

A third key driver of Asian data governance is the fast growth of the digital economy. Asia has some of the world's most significant and dynamic digital markets that drive economic value in the sectors of digital commerce, financial technology, digital services and technology innovation (UNCTAD, 2023).

Digital economic growth is driven by the following key players:

E-Commerce

Asia is now a world hub for e-commerce. The era of online marketplaces, digital retail platforms and cross-border ecommerce has created huge volumes of data on consumer transactions, which needs to be regulated effectively. As e-commerce expands, customers are seeking greater protection of their privacy and data, while also being concerned about online fraud and the accountability of platforms.

Fintech and Digital Payments

The landscape of financial inclusion in Asia has undergone a complete overhaul with digital financial services.In many parts of Asia, digital financial services have revolutionized financial inclusion. Mobile banking, digital wallets, P2P payment systems and online lending platforms have made financial services more accessible to millions who did not have a bank. They handle sensitive personal and financial data, making it even more crucial for these services to have strong privacy measures and cybersecurity safeguards (Kshetri, 2021).

Super-App Ecosystems

One trend that has taken hold in many Asian digital markets is the emergence of “super-apps” that bundle multiple services in one app. The applications for messaging, payments, transportation, shopping, food delivery, healthcare services, and entertainment create vast amounts of personal data in many activities.

The integrated ecosystems provide great opportunities for innovation and convenience, but also bring up a host of complex questions about:

Sharing of data between services.

•User consent management.

Profiling and behavioral analytics.

•Algorithmic decision-making.

•Competition and concentration of market.

•Consumer protection.

Data processing volume in super-apps has led to a growing regulatory concern over privacy governance across the region (Richards & Hartzog, 2022).

Artificial Intelligence and Data-Driven Innovation

Artificial Intelligence and advanced analytics are significant strategic investments in many Asian economies to drive the future economy. The reliance on AI systems requires vast amounts of data to be collected, processed, stored, and shared, raising questions about the necessity of transparency and clarity in data handling practices.The use of AI systems relies on large amounts of data to be collected, processed, retained, and shared, which brings up the need for transparency and clarity in data handling practices.

Therefore, policy makers should consider providing support for innovation while protecting against the risks of innovation including:

•Algorithmic bias.

•Automated decision-making errors.

•Excessive surveillance.

•Lack of transparency.

Misuse of biometric information.

The growing importance of AI governance has become a major component of broader data governance discussions throughout Asia.

Data Governance as an economic and geopolitical issue

Data protection is slowly gaining significance among Asia's businesses and organizations as a strategic economic and geopolitical concern, rather than just a legal or compliance matter. Governments understand that data control can impact economic competitiveness, technological leadership, cyber security resiliency and national security. Therefore, data governance policies often overlap with other issues of digital sovereignty, international trade, technological autonomy and geopolitical rivalry (Aaronson & Leblond, 2018).

Data has become a critical resource for:

•Economic development.

•Innovation and research.

•Artificial intelligence systems.

•National security operations.

•Public sector modernization.

•International competitiveness.

The approach of most governments is then to guarantee that Data Governance frameworks provide protection for privacy while also promoting the wider national goals. Many Asian regulatory regimes differ from those which are more focused on the rights of the individual because they also include this dual function.

The regulatory decisions made in Asia will have profound impact on the future of global data governance as cross-border data flows are getting more extensive every day and digital technology is playing a growing role in economic activity. Its technology, economy and regulations are so diverse, it is one of the laboratories where frameworks for privacy and data protection in the twenty-first century will be formed.

11.3 The Development of the New World City.

The diversity of data protection approaches in Asia is one of the most unique aspects of the continent. While the European Union has a fairly consistent set of laws in the form of the General Data Protection Regulation (GDPR), Asia is made up of many countries with varying legal traditions, political systems, economic priorities, cultural values, and levels of technological development. This has resulted in diverse data governance and privacy models specific to the region's context and addressing shared issues like data flows and cybersecurity risks in relation to digital transformation (Greenleaf, 2023).

Such regulatory differences have deep consequences for governments, businesses and people. It provides countries the flexibility to develop data protection regimes to meet their needs and policy goals, but also imposes significant complexity on multinationals doing business in several jurisdictions in Asia. There are often various demands in terms of consent, data transfers, localization duties, breach notification, reporting and enforcement requirements that businesses have to deal with. In this context, it is important to grasp the complexity of the privacy landscape across Asia, as compliance and risk management strategies here can differ significantly from those in other parts of the world (Kuner, Bygrave, & Docksey, 2020).

In general, the regulatory practices in Asia can be divided into three types: all-encompassing regulatory frameworks, state-centric data governance models, and developing hybrid regulatory models.

1. Comprehensive Privacy Frameworks

Some Asian countries have enacted comprehensive privacy laws which are similar to the international laws and include a number of principles included in the GDPR. These principles typically focus on the individual's right to privacy, organizational responsibility, transparency, lawful processing, and regulatory supervision. They aim to strike a balance between safeguarding privacy and promoting digital innovation and global trade (Bennett & Raab, 2020).

Prominent examples include:

Act on the Protection of Personal Information (APPI) in Japan.

Personal Information Protection Act (PIPA) of South Korea.

The Personal Data Protection Act (PDPA) in Singapore.

These laws have assured their respective jurisdictions to be among the most developed privacy regulatory environment in Asia and have been very influential in the international debates on the issue of privacy governance.

The Act on the Protection of Personal Information (APPI) of Japan.

Japan was among the first Asian countries to put in place a broad-based privacy regime. APPI has been revised several times to improve individual rights, improve corporate accountability, and ease international data transfers. Japan's privacy regime has been noted for its commitment to converge with global privacy standards, and for its role in facilitating cross-border digital commerce (Greenleaf, 2023).

The APPI features:

Legitimate uses of personal data.

Right to access and correct data.

Notice of data breaches.

Limits on international transfers of data.

Improved accountability measures on organizations.

The regulatory framework in Japan aims to balance good regulation and privacy protection with innovation and international trade.

South Korea – Personal Information Protection Act (PIPA)

South Korea's Personal Information Protection Act is considered one of the most comprehensive privacy laws in Asia and in parts, it can be considered as one of the most rigorous in the world compared to the GDPR. PIPA's scope is broad and its protections are wide-ranging, covering all industries and all personal data. Regulatory authorities are actively enforcing the law and penalties are high for failure to comply with the law. (Kshetri, 2021)

Important features include:

•Strong consent requirements.

General and vague descriptions of personal information.

•Data minimization obligations.

Rights of access, correction and deletion.

Limited ability to transfer data between countries.

•Significant administrative sanctions.

South Korea has a robust privacy regime to uphold consumer rights and to enable one of the world's most technologically advanced digital economies.

Singapore – Personal Data Protection Act (PDPA)

The Singaporean regulatory regime for privacy is pragmatic and business-minded, and is embodied in the country's Personal Data Protection Act. The PDPA's mandate is to ensure the protection of personal information and the promotion of innovation, international trade and economic competitiveness. The Singapore approach is considered as combining privacy with the demands of a global digital economy (World Bank, 2023).

Key components include:

•Consent-based processing requirements.

•Purpose limitation principles.

Data protection requirements for organisations.

•Breach notification requirements.

•A measure of accountability and governance.

•Cross-border transfer safeguards.

As a regional technology hub and financial hub, data governance plays a pivotal role in Singapore's overall digital economy strategy.

There are a number of common characteristics of comprehensive frameworks. The following are some common characteristics of comprehensive frameworks.

While there are differences across countries, both broad and detailed privacy regimes in Asia share a focus on:

•Consent-based data processing.

Notice and transparency requirements.

•Data subject rights.

•Organizational accountability.

•Data security obligations.

Borders and data transfers.

Regulatory surveillance and enforcement.

These principles are becoming increasingly aligned with international norms of privacy and help to enable access to international digital markets.

State-centric data governance models. State-Centric Data Governance Models.

While most countries in Asia have taken more state-centric approaches to data governance, other countries are taking privacy ones that focus on the rights of individuals and corporate accountability. These models highlight national security, cyber security, digital sovereignty, economic growth and governmental regulation, in addition to privacy protection. In addition to the personal rights aspect, data governance is also a strategic issue of national interests and state capacity (Creemers, 2022).

The most obvious example of the method is in China.

China – Integrated Data Governance Framework

China has developed one of the world's most extensive and unique data governance systems, comprising of:

Personal Information Protection Law (PIPL).

Data Security Law (DSL).

•Cybersecurity Law (CSL).

These laws provide an overarching system of laws for personal data, cybersecurity, critical infrastructure protection, and national data management.

China's privacy approach is unique from many Western privacy frameworks in its focus on:

•National security.

•Data sovereignty.

•Strategic economic interests.

•Governmental oversight.

•Cybersecurity resilience.

Regulation of digital platforms.

The Personal Information Protection Law is rich in elements analogous to international privacy laws, such as consent principles, transparency principles, and individual rights. These protections are however part of a larger framework of governance that can provide some level of oversight over data processing operations, and over cross-border data transfers (Creemers, 2022).

Data Sovereignty and Localization

One of the hallmarks of China's model is its focus on data sovereignty. The government considers some types of data to be a strategic national resource and subject to special protection and regulation. As a result, there may be strict requirements on organisations in relation to:

•Data localization.

•Security assessments.

•Government review procedures.

Restrictions that limit transfers of information to and from other countries.

The measures are aimed at maintaining internal regulatory control and national security protection of sensitive data (Aaronson & Leblond, 2018).

Government supervision of the movement of data

Many privacy-oriented jurisdictions give governments less powers to oversee data processing conduct and information flows than do state-centric systems. This echoes the belief that data governance needs to be designed to serve national security, social stability and economic policy goals, as well as privacy.

Data governance is increasingly becoming a topic of discussion in the context of economic and strategic competition, with state-centric models being given more attention.

3. Emerging and Hybrid Regulatory Systems

There are countries in Asia, which are in between these two models, having a hybrid approach that encompasses both aspects of comprehensive privacy framework, sector-specific governance, economic development and cybersecurity oversight. These systems tend to change quickly as governments strive to address innovation, privacy, and economic growth (Greenleaf, 2023).

India – Developing a Hybrid Framework

One of the best examples of a hybrid data governance model in India is the emerging one. India is one of the world's largest digital economy and one of the fastest-growing technology markets, thus having unique challenges with regards to handling large volumes of personal information while moving towards digital inclusion and innovation.

India's privacy regime, in the past, was based on sector-specific regulations and information technology laws. The Digital Personal Data Protection Act (DPDPA), however, marks a significant development in the progress towards a more robust national privacy framework (Kshetri, 2021).

The DPDPA includes many features of thorough privacy programs, such as:

•Consent-based processing.

•Individual rights.

•Accountability obligations.

•Data protection requirements.

•Regulatory oversight mechanisms.

Meanwhile, India is continuing to focus on more comprehensive policy goals like:

•Digital economy growth.

•Innovation and entrepreneurship.

•Digital public infrastructure.

•Artificial intelligence development.

•National initiatives on digital transformation.

This blend of privacy law and economic policy demonstrates a synthesis of concerns for privacy rights and national development interests.

Other EMs in Asia: Other EMs in Asia:

Other Asian countries that are moving towards modernization include:

Thailand as per the Personal Data Protection Act.

Indonesia via recent privacy changes.

We will examine Vietnam's changing policies and laws surrounding cybersecurity and privacy.

The Philippines has adopted the Data Privacy Act.

These jurisdictions are progressively enhancing privacy protections with flexibility to enable digital transformation and economic growth.

Regulatory Diversity is creating challenges.

Regulatory diversity is a benefit to each country in being able to design governance systems to the local context, but it also poses a challenge to organizations that do business across Asia. Multinational companies need to deal with the different requirements concerning:

•Consent standards.

•Data localization.

•Cross-border transfers.

•Data subject rights.

•Breach notification obligations.

•Regulatory reporting.

•Enforcement procedures.

Requirements may differ between jurisdictions and compliance programs may not adequately meet those requirements. As a result, businesses are likely to have more costs, legal requirements and compliance risks if they operate regionally (Kuner et al., 2020).

Additionally, there may be challenges in international data transfers due to divergent regulatory frameworks on privacy, cybersecurity, and data sovereignty. Moreover, fragmented regulations can make cross-border transfers more difficult and hinder digital trade when countries have various approaches to privacy, cybersecurity, and data sovereignty.

One of the unique aspects of the data protection landscape in Asia is the variety of regulatory approaches. Countries like Japan, South Korea and Singapore have thorough privacy frameworks that place a strong focus on individual rights, accountability, and international interoperability. State-centric approaches, especially in China, incorporate privacy safeguards in the context of other goals, like national security, cyber security, and digital sovereignty. At the same time, various emerging economies are creating a hybrid approach that merges privacy protection with economic growth and digital transformation policies.

This diversity is due to the different political systems, legal systems, priorities in the economy and levels of technological development to which the region is subject. While it promotes innovative and flexible regulation, it also poses major challenges for compliance of cross-border companies. The relationship between these various regulatory models is likely to be key to the future of cross-border data governance in Asia and beyond as digital economies continue to grow and cross-border data flows are increasing.

11.3 Economic and Technological Drivers

The region's burgeoning digital ecosystems, technological progress and economic growth have a tremendous impact on Asia's data protection landscape. While the majority of Asia's data governance initiatives are grounded in drivers focused on civil liberties and individual rights, in many parts of the region, there are other underlying motivations such as economic modernization, technological competitiveness, digital innovation and national development. Consequently, privacy policy has become recognized as a governance instrument and a strategy to facilitate engagement in the global digital economy (World Bank, 2023).

The area is now a worldwide hub for digital transformation, with a population of the biggest internet users worldwide, the most innovative technology companies, the fastest growing digital markets and the most advanced technology infrastructures. Governments around the world in Asia understand the importance of effective data governance to ensure the sustainability of digital economies, attract investment, support innovation, and uphold trust with the public, as well as to support digital trade (UNCTAD, 2023).

A number of economic and technological factors have been particularly notable in influencing the development of the data protection frameworks in Asia.

Economic Drivers

1. Digital Economy Expansion

The dramatic growth of the digital economy is one of the biggest factors behind data governance in Asia. It is an important part of the world's e-commerce, online consumer spending, digital services and internet-based business operations. Other countries like China, India, Japan, South Korea, and Singapore have built advanced digital environments that are generating vast quantities of personal and commercial data (Kshetri, 2021).

Growth of the digital economy has been fuelled by:

Online retail/ecommerce sites.

•Digital marketplaces.

•Streaming services.

•Social media networks.

•Mobile applications.

•Digital logistics systems.

Services to children and young people in the field of education and healthcare carried out via the Internet.

These services are expanding, and this has led to more personal data being collected, stored, processed and shared. As a result, governments have enforced privacy laws that aim to provide adequate safeguards to consumer rights and privacy while ensuring that economic growth is supported. Therefore, privacy laws have been enacted by governments to ensure that consumer privacy and rights are protected appropriately alongside the economic growth that is supported.

Moreover, consumer trust is becoming a key component in digital economies. People are more inclined to use digital services when they feel their personal data is secure. Robust privacy laws can thus help to foster trust and digital health and viability.

2. Fintech Growth

Another key economic catalyst that is driving data governance across Asia is the speed at which financial technology (fintech) is maturing. The region has emerged as a pioneer in mobile payments, online banking, online lending, electronic wallets, and financial inclusion. The proliferation of fintech platforms has boosted access to finance for groups that were not served by traditional financial institutions in many countries (World Bank, 2023).

Important progress has been made in:

•China

•India

•Singapore

Indonesia

•Thailand

Fintech services handle a lot of sensitive personal data, such as:

•Financial transaction records.

•Banking information.

•Identity verification data.

•Biometric information.

•Credit histories.

•Behavioral analytics.

The ubiquity of digital financial services has raised awareness about data security, fraud prevention, cybersecurity and privacy protection. The regulators' challenge, however, is to encourage innovation while at the same time ensuring that financial data is managed in a responsible and secure manner (Bennett & Raab, 2020).

Fintech ecosystems continue to grow and data governance frameworks are playing a more important role in ensuring trust in digital financial systems and protecting consumers.

Cross-Border Trade and Digital Commerce

Asia's deeply connected trade network approach has also sparked a significant impact on privacy regulation across borders. Information flow across countries is vital to modern world trade. Businesses regularly move data from one country to another to provide services, such as customer service, supply chain management, cloud computing, financial transactions, research and for delivering digital services (UNCTAD, 2023).

The following can be supported by cross-border data flows:

•International e-commerce.

•Multinational business operations.

•Cloud computing services.

•Financial transactions.

•Global supply chains.

•Research and innovation.

•Digital platform ecosystems.

With a growing role of data in economic activity, governments are called upon to establish rules for the transfer of information across different countries and protect national interests and individual privacy rights.

The challenge is to reconcile two competing goals:

2.Open markets and innovation.

Regulatory control and protection of privacy.

This tension has resulted in a number of countries in Asia establishing their own requirements for international data transfers, adequacy assessments, contractual safeguards and data localization obligations (Kuner, Bygrave, & Docksey, 2020).

Foreign Investment and International Competitiveness

Well-designed data governance initiatives have emerged as influences on foreign direct investment and on decisions related to international business. The World Bank report (2023) highlights that private companies are taking into account privacy laws, cybersecurity best practices, and regulatory stability as they determine where to invest in technology, data centers, cloud systems, and digital operations.

The following are examples of what a good privacy framework can do:

•Increase investor confidence.

•Improve regulatory predictability.

•Facilitate international partnerships.

Promote digital trade agreements.

•Enhance economic competitiveness.

Established privacy laws may help countries to be more competitive in international digital markets, as they can be able to present compliance with international norms and make cross-border data transfers more manageable.

With increasing rivalry for investments in technology, a number of Asian governments see privacy regulation as a key element within the context of overall economic growth and digital economy policies.

Technological Drivers

Artificial Intelligence (AI)

AI has proven to be one of the key technologies influencing data governance in Asia. The area is one of the world's leading regions for AI research, development, commercialisation and adoption. Governments and private-sector organisations are putting considerable effort into AI technologies to increase productivity, better public services, improve competitiveness and boost economic growth (Richards & Hartzog, 2022).

There are significant investments in AI underway for:

•China

•Japan

•South Korea

•Singapore

•India

AI systems rely on vast amounts of data for training, testing, and performance. This makes AI development timeliest raise important questions of governance with respect to:

•Algorithmic transparency.

•Automated decision-making.

•Bias and discrimination.

•Accountability.

•Explainability.

•Privacy protection.

Use of personal information in an ethical way.

With the continuous advancement of AI technologies, policymakers have begun to pay more attention to the necessity to harmonize the governance of AI with other privacy and data protection regulations.

Big Data Analytics

Asia has huge populations and a large number of digital ecosystems, creating massive amounts of data that can be analyzed by advanced data analytics technologies. Big data are utilized in organizations to detect patterns, forecast behaviour, make better decisions, optimise services and create new products (Kshetri, 2021).

Applications include:

•Consumer behavior analysis.

•Market forecasting.

•Healthcare analytics.

•Financial risk assessment.

•Smart city management.

•Public policy planning.

•Supply chain optimization.

The use of big data has tremendous economic and social value but also potential privacy threats. Aggregation of large amounts of data can raise the risk of profiling, surveillance, privacy intrusion and misuse. Good governance systems are thus vital to ensure innovation is achieved while protecting personal privacy rights.

Cloud Computing

Cloud computing is a staple element of Asia's digital infrastructure. Cloud computing is now widely used across the globe in various sectors of society, including governments, businesses, educational institutions, health care providers, and technology companies to store, process, and manage information (World Bank, 2023).

Cloud computing supports:

•Digital government services.

•Enterprise information systems.

•Artificial intelligence applications.

•E-commerce platforms.

•Remote work environments.

•Data analytics operations.

With the increase in cloud services come the following important regulatory questions:

•Data ownership.

•Security responsibilities.

•Cross-border data transfers.

•Jurisdictional control.

•Data localization requirements.

With its reliance on cloud infrastructure growing, privacy laws are also becoming more attuned to issues raised by cloud service providers and cross-border data hosting arrangements.

Super Apps and Digital Platforms

One of the biggest traits of the digital economy in Asia is the presence of what is being called “super apps” that bundle several services into one app. Super apps are multidimensional, a single application that combines messaging, payments, transportation, shopping, entertainment, healthcare and financial services into “ecosystems” (UNCTAD, 2023).

They are widely used services developed by:

•Tencent Holdings

•Alibaba Group

These platforms handle huge amounts of private data on a range of different areas of life:

•Communication patterns.

•Financial transactions.

•Purchasing behavior.

•Location data.

•Social interactions.

•Service preferences.

The data centralization of integrated ecosystems also presents a number of opportunities for innovation and personalization, while also raising privacy, market power, profiling and cybersecurity issues.

As a result, regulatory oversight and scrutiny of platform governance, competition policy, consumer protection, and data accountability are becoming more focused in Asia.

Opportunities and Risks

Asia's digital transformation offers significant opportunities for growth, innovation and social development, thanks to the economic and technological forces driving the transformation. Digital technologies can be used to boost productivity and financial inclusion, to deliver better public services and to play a role in economic modernization. Concurrently, they create huge privacy, cybersecurity, surveillance, algorithmic bias, and personal information misuse risks (Richards & Hartzog, 2022).

Key opportunities include:

•Increased innovation.

•Economic growth.

•Improved public services.

•Enhanced digital inclusion.

•Greater international competitiveness.

Key risks include:

•Data breaches.

•Cyberattacks.

•Privacy violations.

•Excessive surveillance.

•Algorithmic discrimination.

•Cross-border compliance challenges.

Therefore, good governance of data is crucial for the promotion of trust, protection of individual rights, and for the sustainable development of technological progress and economic growth to happen in a way that is beneficial for all.

11.4 Regional Challenges

While data protection laws and regulations, as well as good governance, have made great progress in Asia, many challenges remain, some of which are complex and interrelated in nature, in the development of effective, harmonised and sustainable privacy frameworks. The region's vast diversity of political systems, legal frameworks, economic growth, technological and information infrastructure, and cultural values poses different challenges for promoting harmonised standards of data protection. These issues need to be tackled by policymakers as digital transformation continues to grow across the developed and developing world at such a rapid pace, while also promoting innovation, growth, and trust in digital ecosystems.

1. Regulatory Fragmentation

The lack of a single region-wide data protection regime that is comparable to the European Union's General Data Protection Regulation (GDPR) poses one of the biggest challenges for Asia. Rather, countries have taken different legal measures, creating a fragmented regulatory landscape. Consider, for instance, that Singapore's Personal Data Protection Act (PDPA), Japan's Act on the Protection of Personal Information (APPI), South Korea's Personal Information Protection Act (PIPA), and China's Personal Information Protection Law (PIPL) all have specific requirements as to consent, data processing, data subject rights, notification of breaches, and regulatory oversight.

Such regulatory diversity presents significant compliance challenges for cross-border companies doing business in the Asian region. Conforming to various legal mandates in each country may cause administrative burden, legal complexity, and operational uncertainty for businesses, as they need to adjust their privacy program for each country. Moreover, the legal definition of personal data differs from region to region, as does the definition of consent and the enforcement mechanisms, making compliance even more complex for organisations that provide cross-border digital services and/or carry out e-commerce activities. The non-harmonization can also prevent regional economic integration and the free flow of data internationally (Greenleaf, 2022; Kuner et al. 2020).

3. Fostering Social and Economic Development

The issue of the government's right to balance privacy concerns with economic development goals is a frequent one in Asia. Digital innovation, artificial intelligence, fintech, e-commerce and business models based on data are seen as key to the economic development and global competitiveness of many Asian economies. Therefore, policymakers have a tendency to try not to impose too many regulations that would make investing or innovating less attractive.

But the focus on economic growth can sometimes lead to conflicts between the economic growth objectives and the privacy protection objectives. Over-collection of data, inconsistent consent processes and inadequate regulatory agencies can erode public confidence and heighten the threat of privacy breaches. The challenge for policy makers is to strike the right balance between the need to promote innovation and respect individuals' fundamental rights. This is especially noticeable in fast-growing economies where governments are keen to increase foreign investment and at the same time reinforce regulatory protection. A desirable balance will only be achieved through flexible regulatory regimes that enable and incentivize responsible innovation while at the same time ensuring high levels of accountability and transparency (World Bank, 2023; OECD, 2022).

Restrictions on the transfer of data across borders

The other significant hurdle in the Asian region is cross-border data transfers. In today's world, where more and more businesses are using cloud computing services and international digital services, and where global supply chains are growing ever more complex, the ability to move personal data across national borders is becoming a key factor of economic activity. But there are a variety of methods in Asian countries for regulating international data transfers.

While some jurisdictions have strict data localization obligations that require that certain types of data be kept in the jurisdiction, others allow transfers under contractual safeguards, adequacy decisions or regulatory authorizations. For instance, China's PIPL provides stringent conditions for the export of personal information, while countries like Singapore tend to allow international data transfers with accountability mechanisms. They engender uncertainty in law and compliance expense for companies that are active in several jurisdictions.

In addition, data transfer limitations can hinder efficiency of operations, access to more sophisticated digital services, and international collaboration. Increasingly interlinked digital economies demand interoperable data governance arrangements for cross-border data transfers, which is a key priority for policymakers and businesses in Asia (UNCTAD, 2024; Asian Development Bank, 2023).

4. Enforcement Limitations

In Asia, there are several countries that have passed comprehensive privacy laws, but enforcement is a problem. While strong legal frameworks are essential, they do not necessarily mean meaningful compliance or regulatory effectiveness. Limitation of institutional capacity, financial resources, technical expertise and regulatory independence remain a challenge in several jurisdictions.

In some developing economies, data protection authorities might not have adequate personnel, investigative powers or technological resources to effectively monitor compliance. The complexity of regulation is compounded by the rapid advances in technology such as artificial intelligence, machine learning, blockchain technologies and increasingly advanced cyber attacks. Moreover, courts and legal systems might not be well-versed in the new privacy laws, which can create uncertainty on enforcement results.

If there are weak enforcement tools in place, an organization might believe that it has little to lose from not having a strong privacy management program. Therefore, strengthening regulatory institutions, increasing technical skills, and fostering international cooperation between regulatory authorities are critical to improving privacy protection across the region (Bennett & Raab, 2020; International Association of Privacy Professionals [IAPP], 2024).

5. Cybersecurity Threats

The reason is that the digital economy is booming in Asia, along with the number of internet users, the rise of cloud technologies and the region's rising geopolitical status. Governments, businesses and individuals are still facing significant threats from cyberattacks, ransomware attacks, data breaches, phishing attacks and state-sponsored cyber operations.

In recent years, significant incidents affecting financial institutions, healthcare providers, telecom and government organizations have been among the many exposures of digital infrastructure in the region. With the increasing complexity of cyber threats, organizations need to allocate significant resources to cybersecurity initiatives, incident response planning, and training programs for their staff. Regulators, meanwhile, are constantly trying to keep pace with changing technology risks by revising or improving laws.

There is also a close link between cybersecurity and data protection, with failures in cybersecurity potentially jeopardizing privacy rights. As a result, numerous Asian nations have embedded cybersecurity provisions within their data protection laws, focusing on risk management and notification rules and organizational liability. However, the ability to resist more advanced cyber threats is still a constant challenge (World Economic Forum, 2024; ENISA, 2023).

6. Cultural and Political Differences

Attitudes towards privacy and data governance vary greatly across Asia due to different cultural values, social norms, and political systems. While in some Asian societies privacy is more an individual right, others give more importance to other values like collective welfare and social harmony, national security or economic development. These viewpoints impact legislative agendas, regulatory strategies and public expectations about privacy of personal information.

Central government also varies from liberal democracy to more centralized government systems throughout the region. Therefore, governments can have varying methods of surveillance, access to data by law enforcement, national security concerns and regulatory powers. The variations can make it difficult to establish common and harmonised regional standards, as well as to lead to different interpretations of basic principles of privacy.

Policymakers need to be aware of these cultural and political contexts to foster effective data governance. When regulations are not sensitive to local social and cultural contexts, they can be problematic to implement or have a negative response from the public. Cooperation between regions should thus respect the national diversity and sovereignty, but also universal principles of privacy (Westin, 2015; Greenleaf, 2022).

7. Digital Inequality

There is still a wide divide on the digital front in Asia. Many developing countries still struggle with internet access, technical ability, skill in using the internet and institutional development, while countries like Japan, Singapore, South Korea and China have well-developed digital infrastructures and regulatory frameworks.

Such disparities have an impact on the implementation and enforcement of data protection regulations. Limited technological resources in countries could hinder the creation of meaningful supervisory authorities, the building of cybersecurity capacities, and citizens' knowledge of their privacy rights. Limited financial and technical resources can also make it hard for small and medium-sized enterprises (SMEs) in developing economies to meet complex regulatory requirements.

The lack of digital equality can also increase the risks of privacy breaches, cybercrime and exploitation. These differences call for a significant digital infrastructure, education, capacity development and cooperation with other countries investment. The significance of inclusive digital transformation, with the aim of reaching all countries with technological progress and respecting proper privacy policy in the process, has been growing increasingly in the discourse of regional organizations and development institutions (Asian Development Bank, 2023; United Nations, 2024).

Together, these hurdles illustrate the complexity of data governance in Asia that needs to be addressed for harmonized and effective governance. The regulatory landscape is very dynamic, driven by regulatory fragmentation, competing economic priorities, cross-border data transfer restrictions, enforcement limitations, cyber security threats, cultural diversity and digital inequality. There is a need for long-term partnerships between governments, regulators, industry, civil society and international bodies to solve these problems. Enhancing cooperation between countries in the Asia region and supporting the adoption of interoperable privacy frameworks will be crucial for driving innovation, safeguarding individual rights, and building trust in the digital economy for the future.

Asia is one of the most complicated and the most dynamic data protection markets in the world. It is influenced by advanced digital economies, differences in political systems and maturities of the regulatory landscape.

Some countries have well-established privacy laws, like Japan, South Korea and Singapore, while some other countries take more of a centralized and security-focused approach, like China, and emerging economies are still developing their laws, as in the case of India.

This diversity poses opportunities as well as challenges. While it allows innovation and flexibility, it also makes data governance across borders more complex and burdensome for global organisations.

The regulatory frameworks in Asia will become an important determinant in global data governance going forward, as the region remains the forerunner in digital transformation all over the world. Increased regional cooperation, bolstered enforcement and standardized regulations where feasible will be needed for sustainability and trust in digital ecosystems.

The following chapter will explore future trends in global data governance, such as the regulation of artificial intelligence, digital sovereignty, and the changing nature of privacy regulations around the world.