Prof. Dr. Larry AdamsAcademic, Author & Researcher

Chapter 13: South Asia and Southeast Asia

Introduction

South Asia and the Southeast Asia region are among the fastest-growing and most digitally transformative regions globally. These areas have been marked by high and young populations, fast urbanization, high penetration of the Internet and mobile technologies, with a substantial increase in digital participation in the last decade. Data is now a critical asset needed for economic development, efficient government, and social progress (World Bank, 2023), as countries have embraced the era of mobile-first economics, digital financial systems, e-commerce and digitalization of governments.

As usage of digital infrastructure grows, concerns of data protection, cybersecurity, privacy rights and cross-border data flows has grown as well. With millions of new users using the internet each year, governments in both regions have the challenge of developing regulatory systems that are good for users and are conducive to innovation and investment from overseas. In this context, data governance has emerged as a key policy concern, closely connected with national development strategies, digital transformation agendas, and regional competitiveness (UNCTAD, 2024).

South Asia and Southeast Asia have a much more complex and diverse governance landscape, compared to the EU's integrated General Data Protection Regulation (GDPR) framework, or East Asia's diverse but relatively structured approach. Some countries are relatively developed in terms of the data protection laws, like India, Singapore, Thailand, etc., but some countries are still in early stages of the legislation or are dependent upon the sector-specific laws rather than a broad privacy law. The disparity can be attributed to varying legal practices, administrative capabilities, economic interests, and digital readiness in both regions (Greenleaf, 2023).

Countries in South Asia, like India, Bangladesh, Pakistan and Sri Lanka, are beginning to understand the significance of data governance in the growing digital economy. India, notably, has become a leader in the region with the enactment of the Digital Personal Data Protection Act, which provides a clear guideline on how personal data should be processed, how it should be obtained with consent, and how it is subject to regulation. There are however administrative capacity issues, digital literacy issues and issues of regulating a diverse and large population. This implies that the regulation of data protection in South Asia is a continuous process that is yet to reach its final stages in other countries within the region, with a gradual progression of privacy governance (Kshetri, 2022).

Singapore, Malaysia, Indonesia, Thailand and the Philippines in Southeast Asia have seen greater strides in establishing data protection legislation. Singapore's Personal Data Protection Act (PDPA) is known to be one of the most developed and business-friendly privacy legislation in the region, maintaining a balance between effective governance and competitiveness for business. Likewise, the comprehensive Thai and Malaysian data protection laws are based on global best practices, and Indonesia and Vietnam are pressing ahead with the development and strengthening of their legal regimes to keep pace with their ‘rapid digitalization'. While progress has been made, there are still important disparities in levels of capacity and maturity of institutions and regulatory consistency across the region (OECD, 2023).

One of the key features of both South and Southeast Asia is the mobile-first digital ecosystem. Mobile phones in many countries are the main means of accessing the internet, financial services, education, health and government services. This digitalization has made enormous amounts of personal data, introducing a lot of economic possibilities and privacy dangers. This has placed governments under growing pressure to make sure that data governance frameworks can solve problems like data breaches, cyber fraud, digital surveillance, algorithmic decision making, and cross-border data transfers (Zuboff, 2019).

One of the key characteristics of the region is how increasingly digital financial services, including mobile banking, fintech services and digital payment solutions are shaping the region. India and Indonesia have seen a massive expansion of digital payment systems, and a lot of personal and financial data is collected and processed in these systems. These innovations have facilitated greater financial inclusion and economic participation, but they've also sparked concerns about data security, consumer protections and regulatory monitoring. This has led governments to increasingly incorporate data protection into their financial regulation to promote system-wide stability and trust (World Bank, 2023).

Although there are differences, it is a shared challenge for both South Asia and Southeast Asia to reconcile rapid digital innovation with the establishment of strong legal and institutional frameworks. Data protection laws can be constrained by enforcement capacity, technical expertise, regulatory coordination, and other constraints, in many countries. Furthermore, the cross-border nature of digital platforms and cloud services makes it more challenging to regulate, and further cross-border cooperation and regional harmonization have never been more relevant (UNCTAD, 2024).

In response to these problems, mechanisms for cooperation at the regional level have arisen, especially in the Association of Southeast Asian Nations (ASEAN). ASEAN has established frameworks and guidelines aimed at promoting interoperability, improving cooperation on cybersecurity and facilitating cross-border data flows among the member countries. These frameworks are typically not legally binding, but serve as a useful means to promote policy convergence and confidence between countries. The data governance initiative by ASEAN is one of the indicators of the growing awareness that in today's increasingly connected data economy, data governance cannot be only a national responsibility (OECD, 2023).

In conclusion, South Asia and Southeast Asia are a region of dynamic and evolving data governance. The region's environment is one of quick technological uptake and regulatory variety, as well as continued institutional development. Progress has been made in developing laws and regulations and strengthening digital infrastructure, but there are gaps in regulatory consistency, enforcement, and coordination across borders. However, the ongoing progress of data governance systems in these areas will be pivotal to the global digital transformation and will impact future international privacy regulations.

Selected country-level data governance frameworks will be discussed in more detail in the following sections, and regional cooperation mechanisms and their impact on regional data governance trends will be analyzed.

13.1 India

India is home to one of the largest and fastest growing digital economies globally and has been a major contributor to data generation, delivery of digital services and innovation in technology. India has a population of more than 1.4 billion and is one of the largest markets globally for mobile internet adoption, digital transactions, e-commerce, fintech, digital identity and large scale government digital platforms. Data governance has become a key policy priority, especially in the context of safeguarding privacy, cybersecurity, economic development, and national sovereignty, due to the rapid growth of the digital ecosystem (World Bank, 2023).

In the last ten years, digitalization has gained momentum in India with the implementation of large scale government initiatives like Digital India, Aadhaar (digital identity system), Unified Payments Interface (UPI) and the proliferation of mobile broadband services across the country. These efforts have greatly contributed to the production of data by both the public and private sector, leading to new opportunities in financial inclusion, financial service delivery and economic participation. In parallel, the digitalization of society has led to numerous issues and concerns related to the protection of data, surveillance, consent management, and responsible handling of personal data (Kshetri, 2022).

The Digital Personal Data Protection Act (DPDPA) is a significant step towards data governance in India, as it marks the first comprehensive framework in India for personal data protection. The Act represents a huge step forward in moving from sector-specific and patchy regulations to a single ubiquitous law on the processing of personal data. The DPDPA is designed as a framework for managing data, aiming to balance the rights of individuals with the needs of economic growth and technological advancement (Greenleaf, 2023).

Key Features of the Digital Personal Data Protection Act (DPDPA)

The DPDPA establishes a consent paradigm for the processing of personal data, ensuring that organizations process personal information only after obtaining clear, informed, and voluntary consent from those concerned. The purpose of this consent mechanism is to provide individuals with more control over their personal information and to be well-informed about how their information is used.

The Act also adopts the notion of data principals (those whose personal data is being processed) and data fiduciaries (organizations that process, collect and store personal data). The data fiduciaries have to adhere to strict obligations, such as maintaining data accuracy, security safeguards, limiting data use to specific purposes and providing mechanisms to redress grievances (Government of India, 2023).

The other crucial aspect of the DPDPA is its treatment of cross-border transfers of data. India has a more flexible approach to data localization than the more restrictive models in other countries, in which personal data is not allowed to be transferred outside the country, but is allowed to be transferred outside the country, subject to the government's approval of the conditions and restrictions. This is part of India's vision to promote digital trade and foreign investment in the country while ensuring some form of control over sensitive data flows.

The government also has extensive control over the activities of data processors, such as the right to establish guidelines and impose compliance regulations. The measures are intended to guarantee accountability and to safeguard the national interests, including in the case of sensitive or large scale processing.

Ensuring privacy, innovation and sovereignty

India’s data governance model aptly illustrates a number of competing policy goals. The government's goals are on one hand to promote digital innovation, economic growth and technological development. At the same time, it is looking to increase the sovereignty of data, safeguard individual privacy rights, and ensure national security in a today's data-driven world.

India's focus on digital innovation is reflected in its investment in large-scale infrastructure initiatives for digital technologies and its promotion of private sector engagement in technology innovation. In fact, the country's booming fintech sector relies heavily on the development of real-time data and digital identity verification systems that have boosted financial inclusion and economic participation among various groups.

Meanwhile, privacy issues and matters related to data misuse and access to personal information has sparked a constant debate on the extent of governmental surveillance in data governance. In these debates, privacy and rights-based concerns are pitted against the security-based goals of the policy – a conflict shared by many economies that are rapidly becoming digital in nature (Zuboff, 2019).

Challenges arising in the implementation and enforcement of the policy.

Although India has put in place an extensive legislation system, there are still several issues regarding the effective implementation and enforcement of data protection regulations. Institutional capacity is one of the major challenges. Regulatory authorities must have the necessary technical capabilities, budget, and administrative structure to ensure compliance regulation over a wide and varied digital landscape.

One of the other big challenges is the complexity related to enforcement in a very decentralized and dynamic digital environment. Being a large population, along with the general acceptance of digital platforms and services, it is hard to maintain uniformity across all sectors. It can be challenging for small and medium-sized businesses to grasp and adhere to the complex regulatory requirements.

Digital literacy is another significant issue. Although the internet is widely used, there is a significant lack of user awareness about the right to privacy of data, the manner of granting consent, risks to cybersecurity and other issues. This mismatch can hinder the functioning of consent-based regulatory measures, as users might not be aware of the potential effects of data sharing and processing practices.

Further, India needs to balance privacy rights and concerns of surveillance. Access to data by government for security, law enforcement and public administration continues to be a sensitive topic, and there are questions surrounding accountability, transparency, and proportionality regarding data governance (OECD, 2023).

India's Contribution to Data Governance in the World.

India's size, diversity and growing digital economy will be a major influence in the evolution of global norms on data governance. India's regulatory pronouncements will impact regulatory frameworks, international data flows and cross-border digital services, which are one of the largest producers and consumers of digital data.

India's developing regulation will also likely shape the regulations of other developing nations trying to create a harmonious balance between innovation and privacy for data protection. The key principles of consent-based data protection and flexible cross-border data transfer rules could be a blueprint for countries aiming to join the global digital economy while retaining regulatory control and sovereignty.

Also, India's presence at various international digital governance, cybersecurity, and AI regulations forums underscores its prominence in the policy discussions. Data governance in India will continue to be a key reference point in discussions on privacy, innovation and economic development in the digital age as digital transformation continues to gain momentum (UNCTAD, 2024).

Data governance in India continues to undergo rapid development and continues to evolve as the country continues to move towards a fully digital economy. The Digital Personal Data Protection Act is a big step towards establishing a structured and comprehensive privacy framework. This system will be effective, however, if it can be successfully implemented, institutional capacity built and adapted to technological change.

In general, the Indian experience comes across as a complex mix of how difficult it is to govern a large, diverse, and rapidly digitizing society. India is creating a unique approach to data governance that will impact not just the region, but the world's digital ecosystem, where economic growth, technological innovation, data sovereignty, and privacy protection are all balanced.

13.2 Sri Lanka

Sri Lanka is in the initial and transition phases of building a robust data protection and digital governance framework. The growing digital economy in the country, evolving digital transformation in the public sector and penetration of the internet are all driving a rising need for strong data governance. Personal information is being gathered and used in an ever-expanding amount by public and private bodies—particularly in the mobile banking, e-government, digital identity and online commerce sectors. Sri Lanka's move towards a formalized data protection framework is a pivotal development that will help build digital trust, improve cybersecurity, and meet international data privacy regulations (World Bank, 2023).

The rise of data governance in Sri Lanka is part of a country's overall journey towards digitalization and improved governance. In the era of digital transformation, regulators have understood that data protection is a key part of supporting the private right to data and is also vital to foreign investment, cross-border digital trade, and meeting international data regulatory expectations. Sri Lanka is therefore starting to create a legal and institutional basis to structure and control the collection, processing, storage and transfer of personal data in an accountable way (UNCTAD, 2024).

One of the key milestones in this journey is the introduction of the Personal Data Protection Act (PDPA), the main legal framework for data governance in Sri Lanka. The PDPA will be structured according to globally accepted principles and frameworks, such as those outlined in the General Data Protection Regulation (GDPR) of the European Union. The Act establishes fundamental rules of lawful data processing, responsibility, transparency, and individual rights, which contrast with the idea of fragmented or sector based regulation of data protection to a more coherent system of data protection governance (Greenleaf, 2023).

The key features of the Personal Data Protection Act (PDPA) are highlighted.

A key element of Sri Lanka's PDPA is the creation of a Data Protection Authority (DPA) to monitor compliance, enforce the rules, and deliver guidance on data protection practices. The establishment of an independent regulatory body has been an essential institutional step towards boosting the enforcement power and promoting uniformity in the application of data protection regulations.

The PDPA is based on the principle of consent-based data processing, which means that organisations must ask for clear, informed and voluntary consent to use or process the personal information of people before they use it. This principle aims to give people greater power and the means to have control over how their personal data is used, in both digital and real-world settings. Organizations must also clearly communicate why they will be collecting data and keep processing activities to activities that are for those purposes.

The Act also introduces rights of the data subject, including the right to request the right to access the personal data, to ask for rectification, and to receive the deletion of inaccurate or information that has been unlawfully processed. These rights aim to improve transparency and accountability and to reinforce the rights of individual control over their personal data. Furthermore, the PDPA sets out requirements for the implementation of adequate security controls and procedures by organisations to ensure that personal data is kept secure against any unauthorized access, misuse or disclosure.

The other significant aspect of the framework is the rules on cross-border data transfers. The PDPA also adds limitations on transfers of personal data abroad, mandating that such transfers meet certain protections and standards of 'adequacy'. This clause is in line with the trend in the international arena of increasingly acting to safeguard personal data if it is processed in jurisdictions having differing legal systems and enforcement powers (OECD, 2023).

Security and Compliance Obligations

Data security and organizational accountability are a big part of the PDPA. Organizations (including businesses and government agencies) must have technical and organizational security measures in place to safeguard personal data from unauthorized access, cyber threats, and accidental losses. They are of significant importance in the current climate of cybercrime threats and advanced digital attacks on public and private bodies.

Companies also need to have their own data protection compliance governance framework, such as policies, training and risk management, etc. The requirements are designed to encourage an attitude of responsibility, and to ensure that the protection of personal data is considered not as a separate legal requirement, but as an integral part of the decision-making of organizations.

The impact of these measures, however, will rely largely on institutional capabilities, regulatory knowledge and technical capacity. Therefore, Sri Lanka is struggling in implementing them effectively in all areas of the economy (Kshetri, 2022).

Issues related to implementation and enforcement.

While Sri Lanka has made some strides with the PDPA, it still has a number of challenges in its structure and functioning when it comes to establishing an effective data governance system. Limited enforcement capabilities are one of the biggest challenges. Funding, qualified staff and technical capacity are essential for the regulatory institutions to adequately monitor compliance and investigate violations. If there is not enough capacity, it may make it difficult to implement data protection laws.

The other challenge is institutional development. Data protection is a relatively new regulatory field requiring specialized agencies, legal knowledge and multi-departmental coordination. It takes time and commitment to the policy to build this institutional ecosystem.

There are also significant concerns about cybersecurity infrastructure gaps. But with the growing size of digital systems, the potential for cyberattacks, data breaches and vulnerabilities grows. Thus, enhancing the country's cybersecurity capacities is crucial for the effective governance of data. This encompasses cybersecurity investments, incident response programs, and the development of cybersecurity resilience through the public-private partnership.

Furthermore, there are also gaps in awareness and training which is a big challenge in effective implementation. Many companies, especially small and medium-sized companies, may not be aware of any data protection commitments or compliance standards. Likewise, the protection of privacy rights and data protection concepts are not yet fully understood by the general public and may not be effective in the implementation of consent-based regulatory approaches. Improving digital literacy and skills for professional training will therefore be essential to improve compliance and build the overall data governance ecosystem (World Bank, 2023).

Sri Lanka's role in Regional and Global Data Governance

The ongoing development of Sri Lanka's data protection system is part of a broader initiative to harmonize with international data protection norms and embrace the global digital landscape. Sri Lanka is moving towards a policy framework consistent with global privacy frameworks, which can help build trust in the digital space, bring in more foreign investment, and make digital services more possible. It is especially significant as the multinationals are increasingly demanding high levels of data protection when operating in other countries.

Sri Lanka's development ranks it in the middle of a group of countries in South Asia that are slowly improving the quality of their data. Although it's still in its nascent stage relative to more advanced countries like India or Singapore, Sri Lanka's legislative efforts reflect its efforts to modernize and upgrade the country's digital regulatory landscape and enhance its competitiveness in the global digital economy.

With the ongoing digital transformation, Sri Lanka's data governance framework will need to adapt further, especially to new technologies like artificial intelligence, cloud computing and digital financial services. Continued reforms in enforcement capacity, cybersecurity infrastructure, and institutional development will be essential for ensuring the long-term effectiveness of the PDPA and supporting sustainable digital growth (UNCTAD, 2024).

To sum up, Sri Lanka's data governance system is still a developing yet significant one. The Personal Data Protection Act is a major step towards the creation of a structured legal framework for privacy protection and digital regulation. But sustained investment in institutional capacity, enforcement, cyber security infrastructure and public awareness will be a prerequisite for the effectiveness of this framework.

In summary, Sri Lanka's efforts align with regional trends of enhancing data governance amidst the digital transformation. Despite the challenges, the country's efforts to meet international standards make it an emerging player in the international debates on data governance, and a developing digital economy with great future potential.

13.3 Pakistan

Pakistan is moving toward establishing its digital governance and data protection system in the era of digitalization of society, high internet connectivity and rising cyber threats. The world is becoming increasingly digital and mobile, with e-commerce, fintech services and e-government growing at a rapid rate and the amount of personal and sensitive information being generated is growing rapidly. This swift digital transformation has accentuated the need for thorough legal and institutional frameworks to oversee data processing, safeguard personal data, and enhance cybersecurity resilience (World Bank, 2023).

Pakistan has taken significant steps to improve the legal landscape of digital governance in recent years, including the formulation of draft data protection laws and the application of cybercrime related laws. Although a complete and detailed personal data protection law is still being formally adopted and implemented, the country has been taking significant strides towards creating a regulated framework for the management of digital data. All these developments demonstrate the importance of data for economic development, strengthening governance and national security in the country (UNCTAD, 2024).

One of the current regulatory aspects of Pakistan is the Prevention of Electronic Crimes Act (PECA) that focuses on electronic crimes, unauthorised access to information systems, electronic fraud and misuse of electronic devices. The bill gives law enforcement agencies the power to investigate cybercrime and pursue action against the perpetrators of online crimes, both individuals and groups. Although PECA is not about data protection as broadly, it has an important role in contributing to the overall cybersecurity and cybercrime prevention landscape in the country (Kshetri, 2022).

The Emerging Data Governance Framework in Pakistan has several important features: The key features of the Emerging Data Governance Framework in Pakistan include the following:

An important aspect of the developing data governance system in Pakistan is the introduction of a draft Personal Data Protection bill that will provide a formal legal structure for protecting personal data. This draft bill should bring in concepts like lawful processing of data, consent requirements, rights of the data subjects, responsibilities of organisations processing personal data. It is expected that upon implementation, it would have a profound effect in enhancing the regulatory capability of Pakistan in keeping with the international privacy standards.

Another significant aspect of Pakistan's digital governance system is the rising reliance on government monitoring and regulation of digital platforms. The government maintains a high degree of regulatory oversight of online platforms, telecom and internet service operators. This lack of supervision is mostly due to national security, cybercrime prevention, misinformation control, and public order management concerns. This has led Pakistan's digital platforms to face the hurdles of regulatory compliance and scrutiny over content monitoring and access (Greenleaf, 2023).

Key Focus Areas in Pakistan’s Data Governance

The policy priorities of national security, cybercrime prevention, and regulation of digital platforms are largely responsible for the scope of the data governance approach adopted by Pakistan.The data governance approach for Pakistan is largely influenced by three important policy priorities: national security, cybercrime prevention, and regulation of digital platforms. National security is still a key issue, especially regarding cyber security threats, digital surveillance and safeguarding of critical information infrastructure. The security of digital systems is a strategic priority for the state as digital systems are more and more embedded in governance, financial and communication networks.

Another primary priority is cybercrime prevention. As the internet has become more popular, so has the number of cyber-crimes committed, such as hacking, identity theft, online fraud, and data breaches. To mitigate these risks, the Government of Pakistan has significantly improved its legal and institutional framework for detecting and tackling cybercrime, but the effectiveness is still hampered by limited capacities.

Digital platforms governance is also a major part of the governance framework in Pakistan. Regulatory oversight is in place to ensure compliance with national laws and to prevent misuse of social media platforms, online service providers and digital communication tools. This encompasses oversight of content, dealing with harmful online activity and supporting law enforcement agencies as they may require (OECD, 2023).

Implementation and institutional development challenges.

While significant strides have been made in legal and regulatory measures, Pakistan still has many challenges to overcome in order to create a fully functional data governance system. Its regulatory framework is one of its main challenges due to its immaturity. Draft legislation has been introduced, but the lack of an in-depth and comprehensive personal data protection law diminishes the ability to effectively control the processing of personal data in various sectors.

Institutional capacity constraints are also significant challenges. Well-resourced regulatory bodies are key to effective data governance, as they provide the technical expertise, legal framework, and enforcement mechanisms needed to ensure proper governance. Regulatory institutions in Pakistan are still in the process of building their own capacity to consistently monitor compliance, investigate violations, and enforce penalties in the face of a fast-growing digital ecosystem.

The lack of cybersecurity infrastructure also makes effective data governance more difficult. With digital systems spreading across government agencies, financial systems, and business, so does the requirement for strong cybersecurity policies. The requirement for strong cybersecurity policies is growing as digital systems extend across government, financial systems and business. But not investing in advanced cybersecurity technologies and infrastructure can leave systems vulnerable and open to data breaches and cyberattacks.

Balancing the rights to surveillance and privacy rights is also a big issue. The idea of government surveillance is frequently supported by the arguments of national security and crime prevention, but it also poses significant questions of individual privacy, civil liberties, and transparency. The question of proportionality, accountability, and legal justifications of surveillance, continue to be a policy concern in the digital governance of Pakistan (Zuboff, 2019).

Digital inclusion gaps also exist as a matter of structure. In the past few years, the share of the population with access to the internet expanded, but access to digital services is still unevenly distributed among urban and rural populations and among socioeconomic groups. These differences may hinder the effectiveness of digital governance policies and lead to unequal access to digital rights and protections.

Pakistan's position in regional Digital Governance

In the context of Pakistan, data governance system is a good example of the data governance system of many developing countries which are slowly adjusting to the needs of digital transformation. Pakistan is in a formative phase as compared to the more developed countries of South Asia and South East Asia, but is taking measures to enhance its regulatory framework and build cybersecurity and data protection capabilities.

Regionally, the evolving framework is in line with the broader South Asian context, where countries are increasing their efforts to implement a data governance framework as an asset for their economic growth, digital innovation and national security. With the increasing digitalisation of ecosystems, Pakistan is also likely to continue to strengthen its legal and institutional architecture, especially based on global standards and regional cooperation programs (UNCTAD, 2024).

With the rise in digitalization and regulatory capacities, Pakistan's data governance system is expected to become more structured and comprehensive in the future. Several legislative, enforcement, cybersecurity infrastructure and public awareness reforms will be needed to maintain the long-term impact of data protection and digital governance policies.

To sum up, Pakistan is still at a beginning stage of building a data governance framework. Although there are important advances in the field of cybercrime law and draft data protection law, there are still many challenges regarding institutional capacity, enforcement effectiveness, cyber security infrastructure and regulatory maturity. The continuing work in the country, however, indicates that the country is aware of the value of data governance for the support of digital transformation, economic development and national security.

With the ongoing growth of the digital economy in Pakistan, the data governance framework is poised to undergo substantial transformations, potentially leading to enhanced privacy safeguards, improved cybersecurity strength, and increased compliance.

13.4 Bangladesh

The country is going through a fast and substantial digitalization process with the pervasive connectivity of mobile devices, mobile financial services, e-commerce and increasing adoption of e-government services. The country has taken significant strides towards digital public administration and increased access to digital financial services over the last decade, including mobile financial products and services like bKash and Nagad. These developments have helped to make financial services more inclusive, better and more available, and to gain more access to the digital economy. They have also created a significant volume of personal records being generated, collected, and processed, creating a significant policy challenge for the country with regard to data governance (World Bank, 2023).

The digital ecosystem in Bangladesh has been on a growth spurt with the vision of ‘Digital Bangladesh' encouraging the incorporation of information and communication technologies (ICT) in various aspects of governance, education, healthcare, and financial services. This transformation has positioned digital infrastructure as a key driver of economic development and poverty reduction. Meanwhile, a surge in digital services has created a need for strong legal and institutional structures to safeguard the privacy and security of personal data, and to foster public confidence in digital services (UNCTAD, 2024).

Key Developments in Data Governance

The Digital Security Act is one of the most important legal measures enacted in Bangladesh for the effective control of cybercrime, digital fraud, illegal access to computer systems, and the dissemination of harmful information online. The main aspects of the Act are cybersecurity and national security related and also provide authorities the ability to investigate and prosecute digital offenses. It is important in the fight against cyber threats but has also sparked discussion about its impact on freedom of expression, privacy rights and digital rights governance (Greenleaf, 2023).

Beyond the cybersecurity law, Bangladesh has started considering a comprehensive data protection law and has been involved in discussions regarding it. There is a need for a coherent regulatory regime to tackle consent, limitations on data processing, rights of the data subject and data transfers across borders. While a complete data protection law is in process, there is an increasing concern over harmonizing the current policy with global standards of data governance (Kshetri, 2022).

The other significant advancement is the ongoing growth of digital public services, like on-line government portals, digital identity systems, and electronic service delivery platforms. These efforts are designed to provide more efficient administration, combat corruption and increase access to government services. As digital systems become more prevalent, however, there are growing concerns about how to ensure data security, safeguard privacy and manage vast amounts of data in government databases responsibly.

Bangladesh's Data Governance Approach has the following key characteristics:

The prevailing data governance model is one that prioritizes the safety of cyber security and the development of digital economy instead of a comprehensive data privacy regime. The government's main focus is on the security and stability of digital infrastructure, financial technology systems and the growth of digital services in both urban and rural areas.

Meanwhile, detailed privacy regulations are still weak. Bangladesh is not yet a developed country that has a personal data protection legislation in its own right. Consequently, data governance is currently decentralised with different laws, policies and sector specific regulations. This poses problems when it comes to providing uniform protection of personal data in various sectors and digital networks (OECD, 2023).

The overall direction of the country's policy, however, suggests a moderate move towards privacy governance strength. However, over time, Bangladesh appears to be aligning with international and regional digital initiatives, particularly in terms of engagement with international and regional organizations.

How to implement Data Governance? The challenges of implementing Data Governance

Lack of a specific and thorough data protection law is one of the major issues in Bangladesh. Legislation on cybersecurity provides some protection against digital risks, but not all of the other privacy issues, including lawful processing, data subject rights, accountability and cross-border data governance. The gap in the legal framework may reduce the country's capacity to effectively regulate the modern data economy.

There are also challenges on enforcement. Technical skills, financial resources and institutional capacity are frequently limited for regulatory institutions. Such constraints may make it more difficult to monitor and enforce activities, especially in the context of a constantly evolving digital landscape where new technologies and platforms are continually being introduced.

Another critical challenge is the lack of public awareness of data rights. Digital services users may be unaware of how the organisations they use gather, process or share their personal data. This ignorance can adversely impact the impact of the consent-based governance model, and make it more vulnerable to data misuse, fraud and violations of privacy. Enhancing digital literacy and the public education on data protection is therefore necessary to ensure that future regulatory regimes will have a beneficial impact.

Security online is also an ongoing worry. With the growth of digital systems, cyberattacks, data breaches, and online frauds are a growing threat. Having strong cybersecurity infrastructure, incident response and regulatory coordination is essential to safeguarding both individuals and institutions within the digital ecosystem (Zuboff, 2019).

Bangladesh in the Regional Digital Governance Context

Bangladesh is a country in transition in the South Asian region towards more structured data governance. Although still in its infancy relative to India and other nations, it's beginning to advance in various aspects of developing digital infrastructure and cybersecurity policies. The country's rigorous approach towards digital public services and financial inclusion reflects its commitment to using technology to drive economic and social growth.

At the regional level, Bangladesh's emerging legal framework is part of a wider trend in developing economies which are increasingly aware of the importance of balancing the innovation and use of digital technologies with data protection and cyber security. International data governance principles and norms are expected to continue evolving, and as digital adoption grows, Bangladesh is expected to further enhance its legal and institutional frameworks to meet these evolving risks and expectations.

Bangladesh's data governance system is bound to change a lot in the long run because of the incremental development of regulatory capacity, growing awareness, and the advancement of digital infrastructure. Existing policy reform and international collaboration will be key in helping to pave the way for this shift to a more extensive and robust data protection framework.

To conclude, Bangladesh is in a critical phase of its digital transition journey, with tremendous advancement in digital infrastructure development and provision. Its data governance approach is still in its early stages of development, however, with little privacy governance and a heavy emphasis on cybersecurity and digital advancement. Cybersecurity laws and current discussions on data protection law reflect an awareness of the need for data governance in the context of sustainable digital development.

With the expansion of the digital economy in the country, Bangladesh is likely to further deepen the legal framework, build institutional capacity, and raise awareness of public rights to data. The developments will play a key role in the future in building secure, inclusive, and trustworthy digital ecosystem.

13.5 Singapore

Singapore is known as one of the most advanced and sophisticated data governance jurisdictions in the Southeast Asian region, if not the world. Dense, state-led planning, sophisticated technological infrastructure and a well-established regulatory framework have helped the country rapidly turn into a digital economy hub. Hence, data governance is also well connected to Singapore's government's National Strategy on becoming a global hub for finance, technology, and digital services (OECD, 2023).

The Singapore Personal Data Protection Act (PDPA) lays the foundation for Singapore's data governance framework, which offers a comprehensive legal framework for the collection, use, disclosure, and protection of personal data. The PDPA is designed to be a balanced approach to regulation, balancing the rights of individuals with the need to have a competitive and innovative business environment. Singapore's system is more flexible than that of other regimes, as it aims to balance robust data protection principles with economic efficiency and has been especially appealing to multinational corporations and digital service providers (Greenleaf, 2023).

Data protection is handled in a comprehensive and structured manner in Singapore. Singapore’s Data Protection Framework is comprehensive and structured.

One of the key elements of Singapore's PDPA is the robust consent-based approach, which mandates the securing of informed and clear consent from individuals before collecting and processing their personal information by organizations. This principle allows for people to have some control over their own information, and for organisations to be able to process information in an open and accountable way. The consent mechanism is backed by detailed guidelines, which provide clarity on organizational responsibilities and user rights, leading to clearer regulation and operational predictability.

An additional key element is the focus on accountability duties of organizations. The PDPA sets out a framework for businesses to comply with, and includes obligations related to the implementation of internal data protection policies, designating data protection officers and creating governance frameworks. The model of accountability is based on putting data protection into the business' DNA, as opposed to relying on regulatory enforcement alone, which should be more of a safety net if things go wrong (PDPC Singapore, 2023).

The PDPA also contains strong breach notification obligations that require that organizations notify the relevant authorities and affected persons of significant data breaches within certain time limits. This need boosts clearness and enables prompt threat mitigation in case of unauthorised entry, information leaks, or cyberattacks. It also helps to build trust in digital services, as users will be notified if their personal information has been accessed, leaked, or compromised.

Moreover, Singapore has established strong safeguards for cross-border transfers of personal data, which only occur after appropriate safeguards are taken. These measures aim to provide robust protection to data, even when it is processed in countries other than the ones where the data center is located, to ensure that international business operations can be carried out with high level standards in data security and privacy protection.

What makes Singapore's Data Governance Model a good model? What are the key strengths of Singapore's Data Governance Model?

A major asset of Singapore is its well-developed digital infrastructure. Investments in advanced telecommunications and cloud computing systems, cyber security, and digital public services have been made in the country. This robust technological infrastructure helps in the efficient processing of data, secure digital transactions, and broad penetration of digital services in public and private sectors (World Bank, 2023).

Singapore also boasts a robust regulatory enforcement capability. The PDPC actively monitors compliance, provides guidelines, initiates investigations and sanctions when appropriate. The regulatory authority is also known for its clarity, efficiency and participation in its handling with industry actors and international partners. This has helped to build trust and build regulation compliance of the digital ecosystem in Singapore.

A key aspect of Singapore's data governance is its compliance-centric business-friendly approach. The PDPA offers more flexibility for businesses than more prescriptive regulatory models, and still offers robust privacy protections. This reduces regulatory uncertainty and facilitates innovation, which makes Singapore an attractive place to set up a technology business, financial institution or digital start-up.

Moreover, Singapore's role as an international data hub further solidifies its significance in data governance on the global stage. The nation is a major hub for regional data transfers, cloud computing and global multinational digital businesses. Due to its strategic geographical position, robust legal infrastructure and advanced technological infrastructure, it has been identified as a "digital gateway" for digital trade and cross-border data transfer in Asia (UNCTAD, 2024).

Strategic Role in Regional and Global Data Governance

Singapore has a pivotal role to play in establishing standards for data governance throughout Asia and the world. The country actively engages in international forums and regional initiatives to facilitate the development of interoperable data frameworks, cybersecurity cooperation and facilitation of digital trade. The regulatory framework has been considered as a good model of privacy protection and economic competitiveness.

However, Singapore's leadership is most pronounced in its work in the region on digital governance under ASEAN, where it has helped shape digital governance frameworks to drive harmonization of data protection requirements and support secure cross-border data transfers. They contribute to the spread of digitalization throughout the SEA region, taking into account the different regulatory frameworks of member states (OECD, 2023).

At the international level, Singapore's approach is broadly consistent with evolving data governance principles and principles of accountability, risk-based regulation and international interoperability. It provides a good example for countries to modernize their data protection regimes while maintaining robust regulation and promoting business-friendly policies.

The challenges and future considerations.

While Singapore has its advantages, it is also grappling with challenges as data governance evolves. A major challenge is handling cross-border data transfers in the face of different regulations around the world. It is becoming more complex to ensure interoperability and compliance as the jurisdictions start taking different approaches to privacy, security, and data sovereignty.

One of the pressures is the speed at which emerging technologies like artificial intelligence, machine learning and big data analytics are developing. These technologies create new issues on how algorithms are transparent, how data can be biased, how data can be used automatically, and how data is used ethically. The regulatory environment in Singapore will have to keep adapting to the new risks and continue to be pro-innovation (Kshetri, 2022).

The risks of cybersecurity are always a threat as well, especially in light of Singapore's status as a regional digital hub. To become resilient to growing and evolving cyber threats, continuous investment in infrastructure, regulatory revisions and public/private partnerships are crucial.

Singapore is one of the most sophisticated and mature data governance models in the SEA region. Its Personal Data Protection Act offers an effective legal framework for safeguarding privacy with a flexible and innovation-friendly framework. Singapore's digital trust and data governance capabilities are advanced and innovative, having been built through robust enforcement, infrastructure, and a strategic approach to international data flows.

With digital transformation continuing to ramp up, Singapore is set to be a key player in driving regional and global standards of data governance. The experience shows that it is possible to make the privacy protection, the economic competitiveness and technological innovation a part of one coherent regulatory framework.

13.6 Malaysia

Malaysia has put in place a comprehensive and progressively evolving data protection regime that would help to bolster personal data security, improve regulatory compliance, and facilitate Malaysia's overall digital economy transition. Malaysia, as one of the more sophisticated digital economies in Southeast Asia, has been focusing more on data governance as a key pillar of its national development agenda, with a particular emphasis on data governance and ecommerce growth, digital financial services and cross-border digital trade. The rise of digital platforms and cloud-based services has led to a greater amount of personal data being processed and, therefore, more robust legal and institutional protections (World Bank, 2023).

The Personal Data Protection Act (PDPA) 2010 is the cornerstone of Malaysia's data governance system and serves as the main law governing the processing of personal data in business transactions. The Act demonstrates Malaysia's desire to harmonise its regulatory framework with international practice including OECD privacy principles and international data protection standards. In its application, the PDPA has evolved into an important tool for promoting responsible data practices among businesses in Malaysia and continued consumer confidence in digital services (Greenleaf, 2023).

The Data Protection framework in Malaysia consists of the following key features: The key features of Malaysia's Data Protection Framework include:

One of the key pillars of Malaysia's PDPA is the consent-based approach to data processing, which mandates that organizations gain explicit consent from individuals before they can process their personal data, including for collection and disclosure. This principle ensures that people have control over their personal information and that organisations are transparent where the purpose and scope of data is collected. This is informed, voluntary and clearly communicated consent, in line with global standards for privacy governance.

The Malaysian PDPA also establishes a framework based on various data protection principles that are similar to the OECD Principles, such as the principles of notice and choice, disclosure, security safeguards, limitation on retention, data integrity and access rights. The principles work together to ensure that personal data is processed fairly, lawfully and securely, and that this brings accountability to data users and increases consumer protection in digital transactions (OECD, 2023).

The other key aspect of Malaysia's framework is the need to register data users, especially organisations involved in the systematic processing of personal data. It registers these entities dealing with massive amounts of private information so that there is a mechanism to keep a check on them and provisions are well-defined and upheld. It also helps to enable monitoring of regulatory governance and increase accountability in the private sector.

The Data Governance Strategy is broken down into various Key Focus Areas in Malaysia.

The government data governance strategy in Malaysia is mainly to tackle data usage by the private sector, enhance cybersecurity and promote the development of the digital economy. The private sector dominates the data processing activities, especially in areas like banking, telecom, healthcare and e-commerce. This means the focus of regulation is primarily on making sure businesses fulfil their data protection duties and implement the necessary security controls to safeguard personal data.

A further policy priority is to enhance cyber security. With the growing digital infrastructure in Malaysia, cyber threats, data breaches, and digital fraud are becoming a growing concern. The government has thus reiterated a need for establishing strong cybersecurity frameworks, strengthening incident response mechanisms, and fostering collaboration amongst public and private sector stakeholders for building national cyber resilience (UNCTAD, 2024).

Moreover, Malaysia has given a high priority to the development of the digital economy. The government is aware of the significance of effective data governance for promoting innovation, foreign investments and global digital trade networks. Consequently, data protection is balanced in the regulatory frameworks with the necessity to keep a competitive and innovation-friendly business environment.

Issues in Data Governance System in Malaysia

Although the Malaysian legal regime to protect data is relatively developed, there are a number of issues in its implementation and enforcement. A difficulty is that there is only a partial coverage of public sector data in PDPA. The Act is mainly targeted at private sector data processing and public sector data governance is subject to other rules and policies. This can lead to a lack of regulatory coverage and to the fact that national data protection measures are not as comprehensive as they could be.

Enforcement capacity constraints is another major obstacle. Governance depends on strong regulatory institutions that are technically knowledgeable, financially powerful and have the investigatory capacity to do effective control. Although Malaysia has made strides in building its regulatory framework, consistent enforcement of all regulations across all sectors continues to be problematic, especially because of the rapid growth of digital services and business models driven by data (Kshetri, 2022).

Modernization of the regulatory regime is also a growing priority. Existing laws and regulations need to be reviewed and modernised to reflect new challenges arising from changes in digital technologies, including artificial intelligence, algorithmic decision-making, the use of big data analytics and data transfers across borders. There is a need for continuous legal reform to ensure that Malaysia's data governance system is in line with global best practices and is able to cater for the new technological risks.

Also, issues of digital literacy and organizational awareness remain. Small and medium sized businesses may not be aware of what data protection requirements they have and therefore may not be compliant in all respects. There is a need for the development of the training programs, guidance and awareness raising activities in order to increase the overall compliance rate and increase the effectiveness of the regulatory framework (Greenleaf, 2023).

The position of Malaysia in the regional and global data governance framework.

Malaysia is strategically situated in the digital governance landscape in Southeast Asia, being one of the countries in the midst of evolving and moving towards more advanced and international data protection measures. It has a PDPA framework, and is considered to have formal privacy legislation, similar to Singapore and Thailand, though there are variations in the capacity to enforce the legislation and the maturity of their respective regulatory regimes.

Malaysia's approach is in line with that of the rest of ASEAN, which is focused on enhancing data protection frameworks and encouraging cross-border data flows through the use of interoperable data protection regimes. Malaysia is likely to assume a more prominent role in forming data governance initiatives at ASEAN level and help to develop harmonized standards at Southeast Asian level as digital trade and regional integration continue to grow (OECD, 2023).

Malaysia's initiative to harmonise its data protection laws with international laws and principles makes the country a more appealing place for digital investment and technology-based industries to locate. The collaboration of Malaysia to streamline its data protection laws with the international laws and principles makes the country more attractive in terms of digital investment and technology-based industries. The adoption of principles similar to those in global privacy regimes bolsters Malaysia's ability to engage in international digital value chains and to facilitate expanded engagement in cross-border data-driven economic activity.

Malaysia has put in place a relatively well-structured and developing data protection regime, which demonstrates its efforts to achieve a proper balance between privacy protection, cyber security and digital economic development. The Personal Data Protection Act offers a robust framework for regulating the use of private sector data, and there is a clear commitment to modernising and enhancing the country's digital governance framework as evidenced by the continued progress of policy development.

Yet, enforcement capacity, scope of the regulation, and technological adaptation are key issues that need to be considered in future reform. Malaysia's digital economy is still growing and ongoing efforts to strengthen institutions, enhance legislation and provide adequate cybersecurity infrastructure will play a key role in sustaining the long-term impact of the data governance system and keeping up with international standards.

13.7 Thailand

Thailand has many steps taken to improve its data governance framework with the introduction and implementation of the Personal Data Protection Act (PDPA) which is one of the most comprehensive privacy laws in Southeast Asia. The Act is in line with Thailand's policy on the modernization of the digital economy, the strengthening of consumer confidence in the use of digital services, and the integration of Thai laws with data protection laws on the international stage. With Thailand's ongoing digital transformation, especially regarding its ecommerce, tourism tech, fintech and smart city projects, the need for strong data governance is becoming more apparent than ever (World Bank, 2023).

Thailand's PDPA is strongly connected to the global regulatory landscape, and specifically the impact of General Data Protection Regulation (GDPR) by the European Union (EU). In order to address the increasing significance of cross-border data transfers and international digital commerce, Thailand has enacted a privacy framework with a focus on robust individual rights, organizational responsibility and transparency in compliance. This alignment is conducive to Thailand's participation in global digital markets and stake in the region's emerging digital economy (OECD, 2023).

The key features of Thailand's data protection framework include: Among the key features of Thailand's data protection framework are:

GDPR-inspired privacy principles form a structured foundation for data protection governance, one of the essential features of Thailand's PDPA. The principles are lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality. Thailand has developed a regulatory framework based on these principles that ensures compatibility with international good practices and thus promotes interoperability with other developed data protection regimes (Greenleaf, 2023).

A key aspect of the PDPA is its robust consent principles, which ensure that personal data can only be collected, processed, or made available if there is explicit, informed, and voluntary consent. In this consent-driven approach, there is a clear emphasis on user control over their personal data and on organizations' transparency on the use of personal data. Additionally, the law mandates proper documentation of consent and allows for users to retract that consent at any point, further ensuring consumer autonomy in digital settings.

Another important aspect is the safeguarding of data subject rights, namely the right to be informed about the processing of personal data, the right to correct inaccurate data, the right to obtain erasure of data under specific circumstances and the right to object to the processing of personal data. The rights bolster personal management over personal information and increase openness in data processing. They also impose a heavy duty on organizations to ensure they are fulfilling their legal obligations and that they have an accurate data management system.

The PDPA also sets forth new regulations for cross-border data transfers, which handle the transfer of personal data outside Thailand. These controls must ensure that the receiving country or organization can offer sufficient data protection, or that suitable safeguards are put in place to ensure that the personal data is still protected. This is in line with Thailand's efforts to harmonize participation in global digital trade with national efforts to safeguard data security and individual privacy rights (UNCTAD, 2024).

Thailand's data governance system has the following key strengths: Thailand’s data governance system is strong in the following aspects:

The modernity of Thailand's legal structure is one of the country's strengths, making it one of the more advanced jurisdictions in Southeast Asia in terms of regulation of data protection. The PDPA offers a comprehensive and structured governance framework for privacy, encompassing various aspects of data collection, processing, storage, transfer, and security. This contemporary approach brings greater certainty and clarity to the legal environment for businesses and contributes to the creation of a secure and trustworthy digital environment.

Another key advantage is that Thailand is compliant with international standards in general, especially those that are influenced by GDPR principles. This alignment improves Thailand’s ability to engage in cross-border data flows, attract foreign investment, and integrate into global digital value chains. It also boosts the nation's image as a reliable place for foreign businesses and digital services.

One of the strengths of Thailand's data governance system is its digital economy support, which is the country's continuous efforts to develop its data economy. Digital transformation initiatives such as smart cities, digital tourism platforms and e-government services are encouraged by the government. Effective data governance is critical to these efforts, as they heavily depend on data-driven technologies to ensure security, efficiency, and public trust in digital systems (Kshetri, 2022).

Problems in Implementation and Enforcement

There are a number of challenges that Thailand needs to address in the implementation of its PDPA framework, although it is well founded in law. Implementing the measures is one of the greatest challenges, as organisations will need to adjust to new compliance rules, create internal data governance processes and ensure workers are properly trained on data protection policies. These necessities can be costly and challenging to execute efficiently for a lot of small and medium-sized businesses.

One of the other challenges is that of meeting organizational compliance readiness. Large corporations have the ability to have more sophisticated data protection systems, but smaller companies might not have technical expertise and the financial resources to reach full compliance. This imbalance can result in different levels of enforcement and compliance in the various parts of the economy.

Consistency of enforcement is another issue. Robust regulatory institutions are essential for effective data governance, as they ensure consistent monitoring, investigations and penalties for data governance violations. A policy challenge with the Thai regulatory system in development is ensuring consistent implementation of policy across industries and regions.

Moreover, technology is so fast that it poses continuous challenges for regulators to adapt. New technology and innovations like artificial intelligence (AI), cloud computing and big data analytics demand ongoing adjustments to legal structures and regulation. If not adapted in time, regulatory systems may become ineffective and outdated in dealing with new data-related risks (OECD, 2023).

Thailand’s Role in Regional Data Governance

Thailand is slowly emerging as a Southeast Asian data governance player. It has adopted a comprehensive PDPA framework, which is at a more advanced level than that of other jurisdictions in the region, such as Singapore and Malaysia. Consequently, Thailand is gradually asserting its voice in regional fora regarding data protection, cooperation in cybersecurity and facilitating digital trade.

Thailand is also supporting ASEAN efforts for harmonisation of data protection laws and fostering interoperability among member states. These regional measures are crucial for facilitating cross-border digital trade, strengthening cybersecurity cooperation, and promoting trust in regional digital ecosystems (UNCTAD, 2024).

Moreover, Thailand's ongoing efforts to build up its data governance framework are expected to further contribute to the country's competitiveness in the digital economy. Through conforming to international standards and building up regulatory capability, Thailand is playing a trusted partner on global digital networks, thus becoming an attractive investment destination for technology-driven investment.

The Personal Data Protection Act of Thailand is a significant effort towards creating a modern and internationally comparable data protection system. The law adopts robust privacy principles, clear consent regulations, rights of the data subject, and data transfer controls for cross-border data transfers, establishing Thailand as a prominent player in the emerging digital governance framework of Southeast Asia.

Implementing the regulations, however, comes with some challenges: complexity, readiness and consistency of compliance, and the need for further institutional strengthening and for capacity building. Thailand's digital economy is expanding, and the continued success of its data governance system will rely on further development of the rules and technologies.

In sum, Thailand provides a valuable case study on how emerging economies in Southeast Asia are moving toward implementing universal privacy principles while developing the region and fostering digital innovation.

13.8 Initiatives of ASEAN Data Governance

The Association of Southeast Asian Nations (ASEAN) is a key player in digital governance in Southeast Asia, fostering cooperation, harmonization, and integration among the members in the region. The far-reaching impact of digitalization in the region, fueled by the development of the e-commerce sector, the fintech industry, cross-border digital services, and mobile-first economies, has heightened ASEAN's awareness of the need to develop coordinated data governance frameworks. The purpose of these frameworks is to reconcile the regulatory flexibility needed in the different member states with the increasing demand for interoperability in an interdependent digital economy (UNCTAD, 2024).

Unlike ASEAN's other instruments, ASEAN's data governance is not defined by a single law, but by a series of soft law instruments, guidelines and cooperative agreements to promote policy alignment and mutual trust among member countries. This flexible stance is a reflection of the regional diversity in terms of legal systems, development level, regulatory maturity, and political systems. Given this, ASEAN's approach to data governance refers to a gradual convergence process, which involves the country members building their own national data governance frameworks while striving to share data governance objectives at the regional level (OECD, 2023).

ASEAN is implementing several data governance initiatives of significant interest.

The ASEAN Framework on Digital Data Governance is one of the most significant projects, aimed at advancing the harmonization of data protection policies within the ASEAN member states. This framework contains guiding principles such as transparency, accountability, security, and cross-border interoperability, which guide data management. Although the document is not legally binding, it provides a useful guide for the national legislatures when formulating or revising their national data protection laws. It also promotes uniformity in regulatory practices, which is crucial for facilitating digital trade among ASEAN countries and minimizing compliance costs for multinational firms serving ASEAN markets.

Another important one is the establishment of cross-border data flow agreement, facilitating secure and efficient data flow between the ASEAN member countries. Such deals are significant for facilitating international trade, cloud-based computing, and global business activity. The purpose of ASEAN is to ensure a balance between economic integration and data security through smooth data transfers. This is part of a broader trend of understanding that cross-border data flows are crucial to the digital economic development of the region (World Bank, 2023).

Another important milestone in ASEAN's digital governance agenda is the Digital Economy Framework Agreement (DEFA). The purpose of DEFA is to facilitate the development of a single regional digital economy, through the adoption of common principles and rules regarding digital trade, e-transactions, data governance and cooperation in cyber security. The agreement aims to minimize regulatory fragmentation and improve the interoperability of the various ASEAN member states to make ASEAN more competitive in the digital economy. By fostering a more cohesive and stable regulatory framework in Southeast Asia, DEFA is poised to significantly influence the region's digital integration landscape in the years to come.

Cybersecurity cooperation is also one of the key aspects of ASEAN's regional cooperation strategy. Member states share information on cybersecurity risks through various collaborative mechanisms, enhance their capacity to respond to cyber threats collectively, and build national incident response capabilities. Such collaboration is especially vital in the face of the growing frequency and sophistication of cyberattacks on government systems, financial institutions, and critical infrastructure in the region. ASEAN's vision is to develop a more resilient regional digital ecosystem by promoting collective security measures (Kshetri, 2022).

Objectives of ASEAN Data Governance

In general, the goals of ASEAN's data governance efforts are to improve data trade, harmonize regulations, facilitate cyber security collaboration, and foster innovation and economic development. Digital trade is a priority and will allow businesses to better trade across borders and for regional value chains to grow. Harmonization of regulation is also a must, because costs of compliance are lowered and legal certainty is enhanced for companies that have operations in several jurisdictions in ASEAN countries.

Continuous efforts in cybersecurity cooperation are crucial to maintaining a trustworthy cyber environment and safeguarding essential systems against emerging threats. ASEAN member states can build their cyber resilience by learning from one another through knowledge sharing on issues of expertise, resources and best practices. Meanwhile, fostering innovation and economic development is a key priority, and digital technologies are still a catalyst for productivity, job growth and economic diversification in the region (UNCTAD, 2024).

The ASEAN Data Governance Integration Challenges

While substantial strides have been made, ASEAN still struggles with a number of structural and institutional issues to ensure the integration of data governance. The main difficulties arise from the differences in legal systems among member states. The variety of legal systems in ASEAN countries (common law, civil law or hybrid) often hinders the harmonisation of regulations.

Another significant challenge is the differences in regulatory maturity. Singapore, Malaysia and Thailand have well established data protection regimes but others are at an early stage of development. This uneven progress results in imbalances in the region in terms of their enforcement capacity and effectiveness.

The disparity of infrastructures is also a great challenge. Regional data governance efforts can be hindered by disparities in digital infrastructure development, internet connectivity, and technological capabilities. The more sophisticated the digital system in a country, the more likely it is to be able to have a more sophisticated regulatory framework, and, the less developed, the more difficult it is for the system to be enforced and complied with.

Moreover, the different political agendas of member states can have an impact on the process and direction of integration. Some governments might focus on data sovereignty and national control over data flows, others on openness and digital trade facilitation. These variations can make it harder to reach deeper levels of regulatory convergence. These differences can make it more difficult to achieve deeper levels of regulatory convergence at the regional level (OECD, 2023).

The strategic significance of ASEAN Data Governance

Despite these hurdles, the ASEAN data governance initiatives are a step in the right direction for ASEAN integration and economic cooperation in the digital era. ASEAN is helping to cement the basis of a more unified and competitive digital economy through the promotion of a set of ASEAN principles, policy alignment and cross-border cooperation.

The significance of these efforts is further magnified by the global transition to data-driven economic systems in which digital trade, artificial intelligence and cross-border data flows are increasingly playing a key role in economic competitiveness. ASEAN's work on building interoperability in governance frameworks enables the region to play a more active role in the global digital value chain and remain flexible with policy agendas.

Going forward, ASEAN is poised to further develop its data governance framework through enhanced regional cooperation and regional member countries' efforts to improve their national legal systems. Further improvements in this area will be critical to sustain Southeast Asia's competitiveness in the global digital economy and to handle the opportunities and risks of digital transformation (World Bank, 2023).

ASEAN is playing a major, critical and increasingly influential role in data governance in the region of Southeast Asia. ASEAN is pursuing regional integration with due consideration of differences through various efforts, such as the Digital Data Governance Framework, cross-border data flow agreements, the Digital Economy Framework Agreement, and cooperation in cybersecurity.

While legal, regulatory and infrastructure issues as well as political variation are still crucial, ASEAN's stance is an example of flexible and cooperative regional governance. The role of ASEAN in fostering harmonised, secure, and innovation friendly governance of data will gain significance in the region's development and integration with the world in the age of digital transformation.

South Asia and Southeast Asia are among the most dynamic, diverse and evolving areas in the world with regard to data governance. Together these areas are undergoing the greatest digital transformations ever seen, with an increasing number of regions experiencing a surge in internet access, mobile-first economies, fintech innovation, ecommerce growth and systems of digital public service delivery on a large scale. With the growth of digital ecosystems, the amount, speed and sensitivity of data collected in both regions is also growing at a considerable rate, and data governance is a key element of economic growth, cybersecurity resilience and institutional trust in digital systems (World Bank, 2023).

Countries in South Asia have varied levels of regulatory maturity, ranging from well-developed regulations in some (India, Pakistan, Sri Lanka, Bangladesh) to underdeveloped regulations in others. India's Digital Personal Data Protection Act, which was enacted as a regional leader, and Sri Lanka's current state of regulatory consolidation during transition stand in contrast in their status. India’s Digital Personal Data Protection Act has been enacted as a regional leader, whereas Sri Lanka's current status of regulatory consolidation is in the process of transition. In Pakistan, the data protection laws are still formulating a comprehensive framework, while in Bangladesh, extensive measures have been taken to enact data protection laws, with a high reliance on cybersecurity-focused laws and draft regulatory proposals. These differences reveal the unevenness of the regulatory process in the region, as the uptake of digital technologies has often been faster than the creation of developed governance systems (Kshetri, 2022).

In Southeast Asia, countries like Singapore, Thailand, Malaysia, and more recently, Indonesia and Vietnam, are making progress in developing more formal and international data protection regimes. Singapore is a leader in digital trust and regulatory innovation, and Thailand and Malaysia have legal frameworks that are similar to GDPR, with a focus on consent, accountability and cross-border data governance. The developments are part of a wider trend in the region to formalize privacy rights and increase the institutional control over data processing activity. Meanwhile, the level of enforcement capacity, and the sophistication of the regulation, varies across the region and so does the overall level of governance (OECD, 2023).

Yet there are commonalities between both regions: the increased understanding of data as a strategic economic and national resource. Data is no longer just a privacy issue, it is also becoming an important enabler of innovation, competitiveness and national security for governments. This dual view has resulted in regulatory measures that seek a balance between privacy protection and economic growth goals, digital transformation priorities, and cross-border data flows. This means data governance models in these areas may be more hybrid, incorporating aspects of rights-centric protection and government policy-making for economic planning and cybersecurity enforcement (UNCTAD, 2024).

The growing role of regional cooperation and digital integration mechanisms, especially in ASEAN in the Southeast Asian region, is another important development. ASEAN efforts, like the Digital Economy Framework Agreement, cross-border data flow arrangements, and the ASEAN Framework Agreement on Cooperation in the Security Field, are contributing significantly to the push for digital ecosystem regulation and fostering trust in digital ecosystems. SEAN programmes, such as the Digital Economy Framework Agreement, cross-border data flow arrangements, and the ASEAN Framework Agreement on Cooperation in the Security Field, are making significant contributions towards the regulation of digital ecosystems and building trust in digital ecosystems. Addressing the problems of legal fragmentation, infrastructure gaps and differing degrees of regulatory maturity among member states, these initiatives are of particular importance. Through facilitating interoperability and harmonising standards, ASEAN is contributing to the development of an integrated and competitive regional digital economy (World Bank, 2023).

But, notwithstanding the improvement, there are still structural troubles in South Asia and Southeast Asia that could shape data governance for the near future. These encompass lack of institutional capacity, inadequate enforcement structures, uneven digital infrastructure development and the lack of public awareness of data rights. What's more, the rapid emergence of cutting-edge technologies like artificial intelligence, cloud computing, blockchain and big data analytics is creating more pressure on current regulatory frameworks, demanding constant adjustment of legal frameworks and innovation of policy to be effective and relevant (Kshetri, 2022).

With the pace of digital transformation rising, these areas will be key drivers in the future of global data governance. The sheer size of their populations, their digital economies, and the increasing role and volume of their involvement in international digital trade make them important players in the international debate on privacy, cyber security, data sovereignty, and digital regulation. The transformation of their governance structures will thus have important ramifications not only at the regional level, but also for global standards and practices in the digital economy (UNCTAD, 2024).

Overall, the experience of South Asia and Southeast Asia highlights the challenges and opportunities of data governance in dynamic digital contexts. Overall, however, the pace of change is uneven, but the direction is clear: towards better regulation, more regional cooperation, and a greater understanding of the importance of data as a strategic and economic asset. Future reforms, capacity development, and international cooperation will be vital keys to ensuring that these areas will be able to cope with the challenges and opportunities of the digital age.

The next Chapter will explore future trends of data protection, such as AI governance, international regulatory harmonisation, and how new technologies are shaping data governance systems around the world.