{"id":180322,"date":"2023-03-01T14:01:43","date_gmt":"2023-03-01T06:01:43","guid":{"rendered":"https:\/\/www.grab.com\/sg\/?p=180322"},"modified":"2023-06-14T17:40:07","modified_gmt":"2023-06-14T09:40:07","slug":"grab-conversations-on-air-data-protection-in-southeast-asia","status":"publish","type":"post","link":"https:\/\/www.grab.com\/sg\/blog\/public-policy\/grab-conversations-on-air-data-protection-in-southeast-asia\/","title":{"rendered":"Grab Conversations on Air: Data Protection in Southeast Asia"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-180292 size-full\" src=\"https:\/\/assets.grab.com\/wp-content\/uploads\/sites\/4\/2023\/02\/01120430\/5.jpg\" alt=\"Grab Conversations: Data Protection in Southeast Asia Key Takeaways\" width=\"1200\" height=\"627\" srcset=\"https:\/\/assets.grab.com\/wp-content\/uploads\/sites\/4\/2023\/02\/01120430\/5.jpg 1200w, https:\/\/assets.grab.com\/wp-content\/uploads\/sites\/4\/2023\/02\/01120430\/5-250x131.jpg 250w, https:\/\/assets.grab.com\/wp-content\/uploads\/sites\/4\/2023\/02\/01120430\/5-700x366.jpg 700w, https:\/\/assets.grab.com\/wp-content\/uploads\/sites\/4\/2023\/02\/01120430\/5-768x401.jpg 768w, https:\/\/assets.grab.com\/wp-content\/uploads\/sites\/4\/2023\/02\/01120430\/5-120x63.jpg 120w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/p>\n<p><span style=\"font-weight: 400\">Southeast Asia is on its path to becoming a <\/span><a href=\"https:\/\/seads.adb.org\/news\/google-led-study-sees-1-trillion-digital-economy-southeast-asia-2030\"><span style=\"font-weight: 400\">$1 trillion digital economy<\/span><\/a><span style=\"font-weight: 400\"> by 2030 and data is its lifeblood. Naturally, this has led to concerns about how the vast amounts of\u00a0 data being collected are protected from misuse. That begs the questions &#8211; what can individuals, companies, and governments do to develop a trustworthy data protection ecosystem?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">To unpack these pressing questions, the Grab Public Affairs team invited regional experts from local businesses, think tanks, and regulators to our podcast, <\/span><a href=\"https:\/\/open.spotify.com\/show\/0C9x0v19cWGFlkPxwoh6QU?si=7ea7abeecb08458d\"><span style=\"font-weight: 400\">Grab Conversations on Air<\/span><\/a><span style=\"font-weight: 400\">, to discuss the state of data protection in the region, focusing on cross-border data flows and data governance \/ privacy.<\/span><\/p>\n<p><span style=\"font-weight: 400\">You can listen to the four episodes here \u2013 <\/span><a href=\"https:\/\/open.spotify.com\/episode\/34myYu8FDv90aVpCMqaL4S?si=3b3809d2a6d048a8\"><span style=\"font-weight: 400\">The Basics<\/span><\/a><span style=\"font-weight: 400\">; <\/span><a href=\"https:\/\/open.spotify.com\/episode\/5WYsnsGqhefhNFxEQeQYXx?si=720efc0a5ea249fc\"><span style=\"font-weight: 400\">Thailand\u2019s Regulatory Perspective<\/span><\/a><span style=\"font-weight: 400\">; <\/span><a href=\"https:\/\/open.spotify.com\/episode\/2AWOOIAFj3MV1MSVmjoSV6?si=5b4fb69bc7c44935\"><span style=\"font-weight: 400\">Singapore\u2019s Regulatory Perspective<\/span><\/a><span style=\"font-weight: 400\">; <\/span><a href=\"https:\/\/open.spotify.com\/episode\/2eAKmplpuLApylXWyIrlD5?si=163a88a3009c46ca\"><span style=\"font-weight: 400\">Small and Medium Businesses\u2019 Large Challenges<\/span><\/a><span style=\"font-weight: 400\"> and find the transcripts on our <\/span><a href=\"https:\/\/www.grab.com\/sg\/blog\/public-policy\/\"><span style=\"font-weight: 400\">blog<\/span><\/a><span style=\"font-weight: 400\">.<\/span><\/p>\n<p><span style=\"font-weight: 400\">For a summary of the conversations, read on.<\/span><\/p>\n<h1><b>What Data Protection and Free Data Flows Mean in Southeast Asia<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400\">Data privacy and data protection are often referred to as synonymous concepts. However as Josh Lee, MD APAC of the Future of Privacy Forum clarifies in <\/span><a href=\"https:\/\/open.spotify.com\/episode\/34myYu8FDv90aVpCMqaL4S?si=3b3809d2a6d048a8\"><span style=\"font-weight: 400\">Episode 1<\/span><\/a><span style=\"font-weight: 400\">, data protection needs to address the personal interests of users\/consumers as well as the economic interests of companies to ensure that both privacy and innovation are protected.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Southeast Asian governments have also come to recognise the importance of balancing these two sides.<\/span><a href=\"https:\/\/sso.agc.gov.sg\/Act\/PDPA2012\"> <span style=\"font-weight: 400\">Singapore<\/span><\/a><span style=\"font-weight: 400\">,\u00a0 <\/span><a href=\"https:\/\/www.kkd.gov.my\/pdf\/Personal%20Data%20Protection%20Act%202010.pdf\"><span style=\"font-weight: 400\">Malaysia<\/span><\/a><span style=\"font-weight: 400\">, and <\/span><a href=\"https:\/\/www.privacy.gov.ph\/data-privacy-act\/\"><span style=\"font-weight: 400\">the Philippines<\/span><\/a><span style=\"font-weight: 400\"> enacted comprehensive Personal Data Protection Acts (PDPA) in the early 2010s, while <\/span><a href=\"https:\/\/www.dataguidance.com\/sites\/default\/files\/entranslation_of_the_personal_data_protection_act_0.pdf\"><span style=\"font-weight: 400\">Thailand<\/span><\/a><span style=\"font-weight: 400\"> and <\/span><a href=\"https:\/\/www.dpr.go.id\/dokakd\/dokumen\/K1-RJ-20220920-123712-3183.pdf\"><span style=\"font-weight: 400\">Indonesia<\/span><\/a><span style=\"font-weight: 400\"> enacted theirs in 2019 and 2022, respectively. While striving to protect their citizens\u2019 personal data, these countries left space for their digital economy to grow. The region\u2019s digital economy is expected to <\/span><a href=\"https:\/\/economysea.withgoogle.com\/report\/\"><span style=\"font-weight: 400\">grow by 20% <\/span><\/a><span style=\"font-weight: 400\">year-on-year despite the pandemic.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Cross-border data flows partially have contributed to this growth by allowing businesses in the region to access new markets and customers, increasing efficiency, and improving service delivery.<\/span> <span style=\"font-weight: 400\">They also improve delivery of services to citizens.\u00a0<\/span><\/p>\n<blockquote><p><i><span style=\"font-weight: 400\">\u201cThe free flow of data across borders, like blood in somebody\u2019s system, is essential to making this digital economy and the benefits of it possible.\u201d<\/span><\/i><\/p>\n<p><b>Josh Lee, Managing Director Asia-Pacific of the Future of Privacy Forum<\/b><\/p><\/blockquote>\n<h1><b>Data Protection in Singapore and Thailand<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400\">In Episodes <\/span><a href=\"https:\/\/open.spotify.com\/episode\/5WYsnsGqhefhNFxEQeQYXx?si=720efc0a5ea249fc\"><span style=\"font-weight: 400\">2<\/span><\/a><span style=\"font-weight: 400\"> &amp; <\/span><a href=\"https:\/\/open.spotify.com\/episode\/2AWOOIAFj3MV1MSVmjoSV6?si=5b4fb69bc7c44935\"><span style=\"font-weight: 400\">3<\/span><\/a><span style=\"font-weight: 400\">, we study Thailand and Singapore\u2019s approaches to examine how they\u2019ve struck a balance between data protection and data innovation. Singapore enacted its PDPA in 2013 in an effort to safeguard the growing digital economy at the time. In parallel, Singapore positioned itself as a regional hub for data storage, analytics, and governance. According to Francis Zhang, Policy Lead at Singapore Personal Data Protection Commission (PDPC), Singapore is keen on being a data-driven economy and supports cross-border data flows.\u00a0<\/span><\/p>\n<blockquote><p><i><span style=\"font-weight: 400\">\u201cSingapore PDPC focuses not just on data protection but also data innovation. We want businesses to use data, including transferred data, in a safe and legitimate way but also allow them to innovate.\u201d<\/span><\/i><\/p>\n<p><b>Francis Zhang, Policy Lead at Singapore PDPC<\/b><\/p><\/blockquote>\n<p><span style=\"font-weight: 400\">Thailand has taken a similar approach. Dr. Prapanpong Khumon, Adviser to the Secretary-General of the Thailand PDPC, highlighted that Thailand recognised the importance of being able to mobilise data across borders to foster innovation for economic growth. Data mobilisation aligns with the country\u2019s plan to shift the economy from being labour-intensive to data-driven.\u00a0<\/span><\/p>\n<blockquote><p><i><span style=\"font-weight: 400\">\u201cThailand&#8217;s economy is made up of a large proportion of small and medium enterprises. Based on research and recent findings, the economic contribution of those enterprises is expected to grow to trillions and lead to economic growth of the Thai economy if SMEs can go fully digital by being able to mobilise data across borders.\u201c<\/span><\/i><\/p>\n<p><b>Dr. Prapanpong Khumon, Adviser to the Secretary-General of the Thailand PDPC\u00a0<\/b><\/p><\/blockquote>\n<h1><b>Region-wide Efforts for Harmonisation of Cross-border Data Flows<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400\">With each country in Southeast Asia enacting their own data protection laws, both \u2013 enforcement authorities and industry \u2013 face challenges. Regulators need to address challenges posed by (1) extra-territoriality of laws, i.e., the legal ability of other governments to exercise authority beyond their national boundaries, and (2) by forum shopping, i.e., organisations exploiting differences in data protection laws to select a country or territory or jurisdiction with a weaker data protection law while still having a presence in other jurisdictions. Industry players, particularly SMEs, suffer from lack of awareness about regulation, language barriers, unclear implementation guidance, and disparate standards and scope of laws across different countries.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Since the maturity of PDP laws varies across countries in the region, there have been concerted efforts to harmonise regulatory requirements across the region. Regional solutions include:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">ASEAN Model Contractual Clauses (MCCs) \u2013 a set of contractual terms that provide baseline requirements for businesses to transfer data among ASEAN member states.\u00a0\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">APEC Cross-Border Privacy Rules (CBPR) \u2013 a government-backed data privacy certification that companies can join to demonstrate compliance with internationally recognised data privacy protections.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">ASEAN Framework on PDP \u2013 consists of principles of personal data protection that member states have agreed on.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">ASEAN Data Management Framework (DMF) \u2013 provides guidance for businesses and particularly SMEs on how to put in place a data management system.\u00a0<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">Additionally, to maintain the privacy and security of data during international transfers, organisations can also use Privacy enhancing technologies (PETs). PETs safeguard personal data using technologies such as differential privacy, homomorphic encryption, federated learning, and multi-party computing, among others.\u00a0 Singapore launched a <\/span><a href=\"https:\/\/www.imda.gov.sg\/How-We-Can-Help\/Data-Innovation\/Privacy-Enhancing-Technologies-Sandbox\"><span style=\"font-weight: 400\">PET Sandbox<\/span><\/a><span style=\"font-weight: 400\"> in 2022 to help businesses experiment with PETs, match them with qualified PET solution providers, and provide regulatory support.<\/span><\/p>\n<h1><b>Practical Challenges for Businesses<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400\">Compliance with data protection laws presents different challenges to small versus large-scale businesses (see <\/span><a href=\"https:\/\/open.spotify.com\/episode\/2eAKmplpuLApylXWyIrlD5?si=163a88a3009c46ca\"><span style=\"font-weight: 400\">Episode 4<\/span><\/a><span style=\"font-weight: 400\">). While large multinational companies generally have sufficient resources to implement comprehensive data protection measures and comply with PDP laws, Small and Medium Enterprises (SMEs) may find it more challenging.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Many SMEs do not have the resources, or a fully developed system in place for protecting and managing personal data according to the requirements of the PDPA. Such a program would include various elements such as data governance, data protection policies, data protection training, incident management, and regular audits. To add to the complexity, companies have to comply with the plethora of sector-specific regulations in addition to omnibus regulations like PDP laws, all of which differ across countries.<\/span><\/p>\n<blockquote><p><i><span style=\"font-weight: 400\">\u201cEven if you (SMEs) have a DPO designated already, in 80-90% of these places the DPO is not equipped or knowledgeable enough to understand how to synchronise the data protection requirements or regulation or policies for like three or four different countries.\u201d<\/span><\/i><\/p>\n<p><b>Desmond Chow, the Director of P2D Solutions Pte Ltd<\/b><\/p><\/blockquote>\n<h1><b>Solutions to Strike a Balance between Data Protection and Innovation<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400\">Governments may find developing and implementing regulation that balances data protection with promoting innovation challenging.\u00a0 In summary, here are four suggestions made by the expert speakers to help achieve this balance:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">First, regulatory requirements should be harmonised across the region and globally. This will create a level regulatory playing field, reduce compliance burdens, and ensure smooth and efficient data flows.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Second, regulation should be pragmatic and risk-proportionate. Regulators should focus on the risks most relevant to the specific industry and not impose unnecessary burdens on companies that may stifle innovation.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Third, regulation needs to be iterative and keep pace with evolving technologies and socio-economic environments. This can be achieved through multi-stakeholder engagement to understand ground concerns and make informed decisions.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Fourth, two-way education efforts between industry and government are important. Regulators should take the lead in alerting and guiding companies and users about data protection laws, tools, and best practices. Companies should educate regulators about evolving technologies and consult on how to keep regulation relevant.<\/span><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"Southeast Asia is on its path to becoming a $1 trillion digital economy by 2030 and data is its lifeblood. Naturally, this has led to concerns about how the vast amounts of\u00a0 data being collected are protected from misuse. That begs the questions &#8211; what can individuals, companies, and governments do to develop a trustworthy [&hellip;]","protected":false},"author":1579,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[480],"tags":[611,613,629,603,657,326,658,600,659,630,608,612,609,605,627,632,602,656,601,631,628,607,626,625,146],"acf":[],"_links":{"self":[{"href":"https:\/\/www.grab.com\/sg\/wp-json\/wp\/v2\/posts\/180322"}],"collection":[{"href":"https:\/\/www.grab.com\/sg\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.grab.com\/sg\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.grab.com\/sg\/wp-json\/wp\/v2\/users\/1579"}],"replies":[{"embeddable":true,"href":"https:\/\/www.grab.com\/sg\/wp-json\/wp\/v2\/comments?post=180322"}],"version-history":[{"count":5,"href":"https:\/\/www.grab.com\/sg\/wp-json\/wp\/v2\/posts\/180322\/revisions"}],"predecessor-version":[{"id":180342,"href":"https:\/\/www.grab.com\/sg\/wp-json\/wp\/v2\/posts\/180322\/revisions\/180342"}],"wp:attachment":[{"href":"https:\/\/www.grab.com\/sg\/wp-json\/wp\/v2\/media?parent=180322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.grab.com\/sg\/wp-json\/wp\/v2\/categories?post=180322"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.grab.com\/sg\/wp-json\/wp\/v2\/tags?post=180322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}