Growth in cross-border data flows is outstripping growth in the flow of goods, services, and people. In a digital economy, cross-border data flows are crucial in enabling improvements in national economies and living standards in developing countries. Thus, the issue of whether and how to regulate cross-border data flows is one of the more critical and contentious issues on the agenda in a number of trade agreements currently under negotiation. The United States has also recently withdrawn its support for proposals concerning strict rules at the WTO’s JSI that would liberalize https://labverra.com/articles/understanding-patient-record-databases/ cross-border data flows, seemingly to re-evaluate how technology companies should be regulated in the public and consumer interest. These provisions significantly limit a country’s ability to implement measures that seek to protect personal data privacy.
These trade secret law updates reflect a significant shift of business attention toward data as a key asset in an information economy and recognition by governments that efficient and effective sharing of commercial secrets requires robust legal frameworks to enforce confidentiality undertakings. As with trade in goods and services and human movement, unregulated cross-border data flows can undermine internal safeguards set up by individual countries to protect their industries, populations, and territories. Another 2020 OECD study concluded that governments can stimulate local production of intangibles that add value by strengthening their country’s appeal for global value chain activities and https://master-your-business.com/how-can-you-implement-iot-in-your-business/ strengthening local production and innovation ecosystems and connections to other countries. A 2020 OECD study found that emerging economy participation in the global value chain enabled by cross-border data flows has increased local wages and attracted investment in local infrastructure, machinery, and equipment, even as the share of value added by local intangibles has diminished. Where data crosses borders, it is exposed to risks beyond such borders, and governments often regulate cross-border data movement to protect their industries, populations, and territories.
This includes exploring the various elements required within the WTO framework to address the policy ramifications of data restrictive measures, focusing on General Agreement on Trade in Services (GATS). Cross-border data flows have become an important component of global digital trade, supporting economic growth and enhancing social welfare. Individuals or organisations who have the need to arrange cross-boundary flow of personal information between Mainland and Hong Kong within the Greater Bay Area are encouraged to adopt the GBA Standard Contract and file with the Digital Policy Office in Hong Kong. The facilitation measure of the GBA Standard Contract is now extended to all sectors of industries, promoting more cross-boundary services to benefit the public and businesses while facilitating data flow throughout the GBA. The relevant facilitation measure will be implemented through administrative arrangements by the Digital Policy Office (DPO) (or the then Office of the Government Chief Information Officer). Organisations must stay informed about emerging requirements and adapt their data transfer practices accordingly.
Cultural Barriers
This rule prohibits or restricts transfers of bulk “sensitive personal data” and “government-related data” from U.S. persons to certain “countries of concern” (e.g., China, Iran, Russia). Australia’s Privacy Act includes APP 8, a rule for cross-border disclosures. Singapore has not issued formal adequacy lists, but many businesses use contractual clauses or certifications (like APEC CBPR, see below). Canada’s federal privacy law, PIPEDA, applies to most private-sector organizations handling personal data in commercial contexts. For example, Canada’s PIPEDA requires organizations to ensure foreign recipients protect data as strongly as Canadian law, and China’s PIPL mandates security assessments or contracts before exporting personal information. For example, if a London company uses a Singapore cloud provider to store customer data, that counts as an international transfer.
Challenges in Cross-Border Data Transfers
Scandals such as Cambridge Analytica, with the invasive and constant tracking and exploitation of people’s data, have eroded people’s trust in cross-border data transfers. Cross-border data transfer has brought with it myriad benefits for not only organizations but also individuals (data subjects) and countries. We reaffirm that cross-border data flows, information, ideas and knowledge generate higher productivity, greater innovation, and improved sustainable development, while raising other challenges. Today, cross-border data regulations are starting to cover a broader array of data, such as personal data, nonpersonal data and other company information, for a diversified range of public policy purposes — national security, artificial intelligence, antidiscrimination/fairness, competition and the like.
- However, adopting a similar provision in the WTO framework will be much tougher and is not recommended because of lack of consensus on whether a risk-based approach is most appropriate to address cyber risks.
- China’s PIPL imposes similarly steep penalties, up to 5 percent of a company’s annual revenue in China, plus the possibility of a suspended business license for repeat or severe violations.
- Under GDPR, personal data cannot leave the European Economic Area unless the destination country has an adequacy decision, the exporter has put contractual safeguards in place, or a narrow exception applies.Since the 2020 Schrems II ruling, organizations must also run a transfer impact assessment for many of these transfers, checking whether the receiving country’s surveillance laws could undermine the safeguards on paper.
- By including SCCs in contracts with third-party data recipients, organisations can ensure that adequate data protection measures are in place and meet the GDPR’s requirements for cross-border transfers.
If a transaction is restricted, the company must implement an extensive set of requirements, including new Cybersecurity and Infrastructure Security Agency (CISA) security requirements, which establish organizational-level, system-level, and data-level requirements. This includes online functions like Google search, which helps businesses develop market intelligence on competitors and learn about foreign laws and regulations. The Internet and cross-border data flows are providing opportunities for small and medium-sized enterprises (SMEs) to participate in the global economy. A recent paper of mine analyzes the importance of the Internet and cross-border data flows for US and E.U trade and investment with each other and globally. As the world’s two largest economies, the U.S. and EU decisions on support for cross-border data flows will also have global implications.
U.S. outbound data transfer restrictions to countries of concern
We welcome the OECD Declaration on Trusted Government Access to Personal Data…as an instrument to increase trust in cross-border data flows among countries committed to democratic values and the rule of law. Including through improved cross-border carbon emissions tracking and predictive climate modeling based on multi-regional data. The geography and nature of the initial third-party recipients are key, as are onward transfer restrictions, which may give rise to data transit across additional borders and to new recipients, thereby potentially creating risk for the original disclosing company. Several elements of these sweeping new regulations will compel disclosure of nonpersonal data and company information to help achieve public policy goals to foster innovation, competition and fairness. Cross-border data transfer outside the EU is regulated by Chapter 5 of the GDPR, “Transfers of personal data to third countries or international organizations.” We can assist you through all your cross border data transfer and general compliance needs.
However, the legal position on access to extraterritorial digital data is unsettled.Footnote 50 Consequently, different governments have adopted measures to increase regulatory control over data including data localisation laws. This section first discusses the most common rationales for imposing data restrictive measures, such as privacy and cybersecurity protection.Footnote 15 It then covers other aspects of data transfer that concern governments, such as illegal and unauthorised data access by foreign countries, trade secrets theft, and consumer risks in electronic transactions. This section also discusses the feasibility of implementing this proposal at the WTO. Finally, the last section proposes a novel WTO framework on data flows by identifying the foundational principles for data regulation and the legal provisions necessary to enable security, predictability and certainty in data flows. This article explores various elements required within the WTO framework to address the policy ramifications of data restrictive measures, focusing on General Agreement on Trade in Services (GATS). Finally, the chapter proposes a novel WTO framework on data flows by identifying the foundational principles for data regulation and the legal provisions necessary to enable security, predictability and certainty in data flows.