Each country and region takes its own path
The EU GDPR represents for many companies and others the privacy law gold standard and has the merit of a large European Economic Area market of some 458 million relatively prosperous people compared with some other regions in the world. The “Brussels effect” ripples around the world both explicitly and implicitly.
Each country and region takes its own path. Regulatory innovations are being introduced in several countries which we cover in this edition of PL&B International Report.
The Supreme Court in Argentina, in a case earlier this year, framed consent as a national constitutional requirement, essential to ensuring individuals retain effective control over their personal data. It did not base its decision on the Council of Europe Convention 108, which it could have done as Argentina is a signatory to this convention, but on the EU-influenced national law.
India’s innovation
The most original innovation is the Consent Manager in India a position which exists as a concept (PL&B International Report April 2026) but we have not seen in other laws. The Indian law provides a registration and supervision framework for this new Consent Manager category of regulated intermediary who brokers consent on the individual’s behalf and occupies a position between the data controller and the individual. We will be interested to find out how this role works in practice.
Trade an influencer in south east Asia
We provide contrasting views on international transfers of personal data in the ASEAN region. From a legal perspective, Data Free Flow with Trust (DFFT) appears to lack substance, despite the concept’s embrace by the OECD.
At our Ireland conference in Dublin on 14 May I asked EU Justice Commissioner, Michael McGrath, the question: “Is DFFT something which is still live ….[or has it now] quietly disappeared? He answered my question by stating firmly: “It's certainly not a live issue on my desk.”(1)
Japan: However, there is an initiative in Japan to produce a 2nd version of DFFT recognising the need for a framework that balances law and pragmatism for the ever-increasing proportion of trade based on digital services, such as:
- Aggregation and management of performance and human resources data between headquarters and overseas subsidiaries;
- Supply chain coordination - managing orders and logistics with overseas subsidiaries and business partners;
- Marketing services, such as using cloud services located anywhere for customer analysis, advertisement distribution and payment;
- Remote monitoring and operation of Internet of Things devices in real-time.
As a result, there is pressure to facilitate cross-border data transfers to improve efficiency, creating higher value-added services, and to minimize restrictions.
There is consensus that harmonizing rules under global standards are desirable to maintain interoperability between systems even where differences exist.
The People’s Republic of China is an active participant in this field, hosting the APEC workshop in Shanghai on May 14 this year on In-Depth Study on Digital Trade Provisions of Free Trade Agreements (FTAs) / Regional Trade Agreements (RTAs). Japan’s Ministry of Foreign Affairs served as the project supervisor for this event. Clearly DFFT has a presence in the APEC region, for example, in the Japan-EU Economic Partnership Agreement, which entered into force in 2024. The goal of the workshop was to work towards “rules for digital trade with a view toward the future Free Trade Area of the Asia-Pacific.”(2)
It is inevitable that there are different national approaches.
Singapore has taken a leadership role in in shaping interoperability across south east Asia. ASEAN with its 11 member states does not operate as a single market like the EU, nor does it have a common currency or a centralised regulatory institution. Rather, it is a diverse regional bloc that places significant emphasis on economic development, regional security and cooperation between states. In this context, Singapore does not take a fundamental rights approach, but has several instruments similar to Standard Contractual Clauses which companies can use if they want a legally binding contract.
Hong Kong’s Privacy Commissioner for Personal Data, Ada Chung Lai-ling, presents her office as providing a bridge between the People’s Republic of China and the ASEAN countries, in short, a “super-connector.” She was, for example, a speaker in a panel discussion Governing Personal Data in the Age of Gen AI with Singapore’s Commissioner, Denise Wong at the Asia DPA Exchange in Singapore on 21 July.
Hong Kong’s Commission has produced several policy documents to help organisations, for example, Artificial Intelligence: Model Personal Data Protection Framework and the Checklist on Guidelines for the Use of Generative AI by Employees, which assist organisations in adopting AI technologies in a safe, responsible and privacy-friendly manner, and in establishing an effective AI governance and a risk management framework.(3) It also published in May this year a report on its compliance checks on 60 organisations on the impact of their use of Artificial Intelligence on personal data privacy.
Apparent EU unity masks major contrasts
Despite apparent EU unity, for example, one GDPR and one European Data Protection Board (EDPB), the EU Member States have different approaches to enforcement and appetites for active enforcement. This diversity is shown by research conducted by the University of Warsaw. The author has grouped national Data Protection Authorities into four categories according to their level of activity regarding enforcement on AI and Automated Decision-Making issues. They range from “very active” to “active” to “reluctant enforcers” to “inert enforcers” and she allocates each national DPA to its appropriate category.
The imposition of a fine in Europe is one thing but ensuring that it is paid is another. In Spain, Amadeus paid its €18 million fine with a 20% discount and without admitting liability. In Finland, the Data Protection Ombudsman (also Chair of the EDPB) imposed a €100 million administrative fine on Yango for personal data transfers to Russia. But will the company actually pay this fine or find a way to reduce it?
An attractive summer holiday message
Educational initiatives are not the monopoly of national DPAs. A fine example is the Catalan DPA which has produced information, in Catalan, Spanish and English, for parents and their children in the context of summer holiday leisure activities. They have provided brief messaging in clear language at the right time for the summer holidays.(4) It is an excellent example of how to convey appropriate privacy information in a brief and an easy accessible format for the target audience.
PL&B’s 40th Anniversary Conference, 5-7 July 2027, only 11 months ahead
We at PL&B are delighted by the enthusiasm shown by everyone at our international conference last month in Cambridge. We are already receiving speaking offers and sponsorship enquiries, and noting your new ideas to keep the event fresh next July.
On behalf of Laura Linkomies, Editor, and the rest of our PL&B Team, we look forward to keeping you, the PL&B Community, well informed on privacy law developments over the coming year.
Stewart Dresner
Publisher, Privacy Laws & Business
August 2026
News & Blogs |
August 2026 Report Contents |
Next |