“ Free flow of information means that I would continue to enjoy the innovations that have been created elsewhere to benefit me and my neighbors.
The extraterritorial application of the Data Privacy Act of 2012 is a response to the very nature of data in today’s digital economy. Data knows no bounds and transcends all jurisdictions.
In today’s world, everyone will get the chance to step out of their borders in their lifetime, whether it is their physical selves or their digital personas.
Our data will be crossing borders and we would not even be aware of it — crossing borders even while we sleep.
I have never been to Ireland. But I am very sure my digital self has landed on its shores countless times. Ireland is now the hub of digital activity in Europe where multinational companies like Facebook, Yahoo and Google have put up their data centers. Free flow of information allows this to happen.
Free flow of information means that I would continue to enjoy the innovations that have been created elsewhere to benefit me and my neighbors.
But this should happen in a way that is secure for everyone. And it is our job as regulators and authorities to ensure this.
Between 2017 and 2018, the number of countries that have enacted data privacy laws has risen from 120 to 132, a 10 percent increase. These different legislations will somehow enact restrictions on data transfers and can place huge compliance expectations on organizations.
In a growing number of legislative bodies, there is a recognition of the dangers inherent in cross-border data processing. This likewise emphasizes a need for a system that cuts across jurisdictions to provide baseline privacy standards that work with the multitude or patchwork of data protection and data privacy landscapes.
This need for that common standard can be felt most acutely in data ecosystems that are intertwined, where cross-border data transfers form a significant and growing part of the economy. Such is the case with the Asia Pacific Economic Cooperation (APEC) and its 21 member economies.
The APEC Cross Border Privacy Rules System, or the CBPR System, is one such framework.
What is hoped for is that this framework would be the connective tissue that is binding across jurisdictions, binding standards that ensure a safe environment for data processing, and standards that are measurable and predictable, especially for businesses.
The APEC Cross Border Privacy Rule System was endorsed by APEC leaders in 2011. It is an accountability-based approach to facilitate privacy-respecting personal information flows among member economies.
The APEC-CBPR certification serves as a seal of privacy compliance and accountability, creating a competitive advantage in both local and global markets. It also fosters trust among consumers, assured that their personal data is securely transferred. This, by requiring business entities to observe transparency and streamline the customer complaint process.
It is a voluntary system that allows stakeholders operating within its member economies some degree of confidence when transmitting data to an extraterritorial entity because that processing has met an allowable standard recognized by that enrolled jurisdiction.
Next week I will discuss the upside of enrolling to the CBPR system.
If you have questions, feel free to contact the NPC via info@privacy.gov.ph.
Housing is probably the biggest issue affecting people the world over.
Malacañang on Monday called for a more thorough investigation into the questioned flood control projects in Taguig…
The defense on Monday backed the move by senator-judges to exclude a prosecution witness who testified on the firearms…