Moving Data Around Asia-Pacific. Sam Pfeifle, IAPP Josh Harris, TRUSTe Michael Rose, US Dept. of Commerce

Similar documents
Introduction to the APEC Cross Border Privacy Rules System: Data Privacy in Canada

REPORT OF 31 st APEC ELECTRONIC COMMERCE STEERING GROUP MEETING 9:00 am to 6:00pm, 3 February 2015 Mansion Garden Hotel Subic, Philippines

US-Asian Privacy and Cyber Developments for In-house Counsel

Interoperability effort between APEC CBPR and EU BCR. Malcolm Crompton Managing Director, IIS Google Japan Tokyo, 17 April 2014

Compendium of Excerpts of Ministry Bill Comments for May 16, 2016 Letter to Senator Nunes concerning Senate Bill No. 330:

Preliminary assessment: Potential benefits for APEC economies and businesses joining the CBPR System

APEC CROSS-BORDER PRIVACY RULES SYSTEM JOINT OVERSIGHT PANEL ADDENDUM TO THE RECOMMENDATION REPORT ON APEC RECOGNITION OF JIPDEC

Michael R. Cohen CIPP/US, CIPP/E Gray Plant Mooty. Overview of the EU General Data Protection Regulation (GDPR)

Privacy Culture and Data Protection Laws in Japan

International Tax. international tax developments in the Asia Pacific region. February 2015

ASIA REGION FUNDS PASSPORT

Investment Management Association of Singapore. Annual Conference 2015

Privacy Enforcement Co-ordination at the International Level

Managing data transfers between US and EU and everywhere else

Personal Data Protection Act 2010

INTERNATIONAL SOS. Data Protection Policy. Version 1.8

Privacy Policy. Who we are. Definitions

Bribery and Corruption

Building the Asia Pacific Gateway Economy: The Role of Vancouver-based Professional Services Firms

A world in transition: PwC s 2017 APEC CEO Survey, November APEC CEO Survey. The United States findings.

Privacy Notice under the General Data Protection Regulation (GDPR)

Session 3b Pension system review in Asia Pacific. Billy Wong, FSA

"The Comprehensive Survey on the International Business Strategy in Japan"

Financial Services Opportunities in Asia. By Stan Roche, Senior Adviser Financial Services & FinTech Austrade

Asset & Wealth Management Market Intelligence Digest Thailand. Asset & Wealth Management Market Research Centre Asia Pacific

CHINA S HIGH-TECH EXPORTS: MYTH AND REALITY

WHAT DOES THE GDPR MEAN FOR PENSIONS? HANDY GUIDE

ARE YOU READY FOR THE NEW DATA PROTECTION LAWS?

University of New South Wales

Cross Border Cooperation :

WHAT DOES THE GDPR MEAN FOR PENSIONS?

The Pension and Life Assurance Plan of NG Bailey (Scheme) Privacy notice

Asia Data privacy guide 2014

HSBC GIF Managed Solutions - Asia Focused Conservative Quarterly fund report Q3 2014

tariff global business nontariff barriers multinational corporation quota direct foreign investment trade barriers voluntary export restraints

POST-CRISIS GLOBAL REBALANCING CONFERENCE ON GLOBALIZATION AND THE LAW OF THE SEA WASHINGTON DC, DEC 1-3, Barry Bosworth

Pharmaceutical Regulatory and Compliance Congress

GROUP PRIVACY POLICY. Adopted June 20th, 2017 by each of the Boards of Carnegie Holding AB and Carnegie Investment Bank AB (publ).

A world in transition: PwC s 2017 APEC CEO Survey, November APEC CEO Survey. Malaysia s findings.

A world in transition: PwC s 2017 APEC CEO Survey, November APEC CEO Survey. The Philippines findings.

EU General Data Protection Regulation vs. Swiss Data Protection Act (in the Private Sector 1 )

Asia-Pacific Alternatives & Wealth Management Awards

Privacy in Canada Federal Legislation: Personal Information Protection and Electronic Documents Act

THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL

Employer s Guide. mpf.aia.com.hk

CFRED The Trans Pacific Partnership Impact and Implications. Assessing the content from a business perspective

A world in transition: PwC s 2017 APEC CEO Survey, November APEC CEO Survey. Australia s findings.

Department of Foreign Affairs and Trade

Entrepreneurs, E commerce, and SMEs in APEC

BINDING CORPORATE RULES

Doing Business in China. Tuesday, May 3, :00 PM - 5:15 PM

Capital Management in Changing Regulatory Environment

Asset & Wealth Management Market Intelligence Digest Taiwan. Asset & Wealth Management Market Research Centre Asia Pacific

Inteum EU or Switzerland Safe Harbor Policy

US Rates Outlook: The Fed s Third Mandate

CROSS-BORDER PRIVACY RULES SYSTEM JOINT OVERSIGHT PANEL RECOMMENDATION REPORT ON THE CONTINUED APEC RECOGNITION OF TRUSTe

Asset & Wealth Management Market Intelligence Digest South Korea. Asset & Wealth Management Market Research Centre Asia Pacific

Advancing Good Corporate Governance by Promoting Utilization of the OECD Principles of Corporate Governance

Chart 2: Fixed Asset Investment (FAI) Year-over-year % change, 3MMA. Chart 1: China Real GDP Growth 12% QoQ Annualized 70% 10% Infrastructure 50%

70% 50% 2017 Rank Survey average

Summary Report - 5 th Experts Group on Illegal Logging and Associated Trade Meeting

Legal Compliance Education and Awareness. Privacy Act (Commonwealth)

Pre-Budget Brief Singapore

2017 APEC CEO Survey Key Findings

Andrew J. Dale Partner

Initial steps on the IPO journey. April 2016

DATA PRIVACY & FAIR PROCESSING NOTICE

THE CPA AUSTRALIA ASIA-PACIFIC SMALL BUSINESS SURVEY 2017

Global Business Expansion Key Strategies for Conducting Business in Foreign Jurisdictions

ESTABLISHING A MANUFACTURING PLANT IN ASIA

Data Protection Cayman Islands

Market Bulletin. China: Still sneezing hard. January 20, 2016 MARKET INSIGHTS. In brief

ESG and Sustainability Risk Advisory Services

The Relative Significance of EPAs in Asia-Pacific

Rina Oktaviani Bogor Agricultural University, Indonesia

CEIOPS-DOC August (former Consultation Paper no. 81)

More bank for your IT buck

Motivation. Optimized Transfer Pricing Model for Asia Pacific. Author: Kelly Liang Advisor: Jonathan Byrnes. MIT SCM ResearchFest.

DATA PROTECTION NOTICE

REGULATORY OVERVIEW. I. Overview of the Laws and Regulations Relating to the Group s Business Operations in Hong Kong

1 Edelman, All rights reserved. EDELMAN TRUST BAROMETER APAC RESULTS

Apple Inc (AAPL) More capital return to shareholders. Global Credit Research GCRE004. FICC Research Dept.

Ximedica, LLC Privacy Shield Policy

BREXIT AND DATA PROTECTION Q & A

Peer Review of Implementation of Incentive Alignment Recommendations for Securitisation Report of Key Preliminary Findings to the G20 Leaders' Summit

The Next-Generation Interactive APEC Tariff Database

Catching up with Corruption in the Asia Pacific Region

Promoting a European Valuation Profession INTERNATIONAL VALUATION STANDARDS COUNCIL

A distinctive local company with national standards. Practical Credit Control & New [GDPR] Data Protection Regulations

Legal Considerations in Negotiating Cloud Contracts

FOUR MONTHLY REPORT OF THE PRIVACY COMMISSIONER FOR THE PERIOD 1 MARCH 2015 TO 30 JUNE 2015

PRIVACY AND CYBERSECURITY ISSUES IN M&A TRANSACTIONS

Environmental Goods Agreement (EGA) negotiations Civil Society Dialogue meeting 13 September 2016

Trade mark applicants in Asia must consider variety of factors

Singapore: A Springboard for your ASEAN Investment. David Chao FDI Advisory UOB Hong Kong

RESULT OF THE SURVEY ON THE PERFORMANCE OF ENVIRONMENTAL, SOCIAL AND GOVERNANCE REPORTING OF HONG KONG LISTED COMPANIES

DKSH Holding Ltd. Presentation Half-year results 2018

The GDPR Possible Impact on the Life Sciences and Healthcare Sectors

Pinsent Masons in the UAE

Globalaw-MCI Webinar Tuesday, 12 July at 4 pm CEST. Featured Speakers. Karin McGinnis Susanne Klein LL.M. Dr. Benno Barnitzke LL.M.

Transcription:

Moving Data Around Asia-Pacific Sam Pfeifle, IAPP Josh Harris, TRUSTe Michael Rose, US Dept. of Commerce

Who We Are Sam Pfeifle, Content Director, IAPP Michael Rose, International Trade Specialist, Office of Digital Service Industries, International Trade Administration, U.S. Department of Commerce Josh Harris, Director of Policy, TRUSTe 2

Overview of Privacy Regimes Hong Kong, India, Japan, Singapore (plus South Korea and China)

Hong Kong Personal Data (Privacy) Ordinance, amended 2012 Broad definition of personal data Data User bears responsibility, even if processor loses the data Non-compliance leads first to enforcement action, then prosecution Maximum penalty is HK $50,000 or 2 years in jail Motivated regulator: Privacy Commissioner for Personal Data Stephen Wong 4

Hong Kong Six basic principles Collection: Notice should be given of collection and who else will use Accuracy and retention: Have an obligation to allow correction and data should be destroyed when no longer useful Use: should only be for purpose specified Security: Collector is responsible for loss or erasure Openness: Privacy notice should be clear and accessible Access and Correction: Consumers have a right to know what you know about them 5

India Sensitive Personal Data or Information (SPDI) Passwords Financial information Health information Sexual orientation 6

India General requirements Reasonable security of the SPDI you hold Consent for collection, use only for stated purpose Right to review, amend, and retract Transfer only to countries with equivalent privacy law Disclosure of transfer to third party HOWEVER: It s unclear who the regulator is in many instances. Much of the oversight is done through the courts. 7

Japan Personal Information Protection Act Covers any organization that collects Japanese citizen data Comes into force May 30, 2017 Broad definition of personal data Transfer only to adequate countries, under specific circumstances (we ll get to that), or with express consent Brand-new regulator: No track record yet 8

Singapore Personal Data Protection Act Regulated by the Personal Data Protection Commission Came into effect July, 2014 Broad definition: Whether true or not Basic principles: Consent: Use or disclosure with the consumer s knowledge Purpose: Use it for what you said you d use it for Reasonableness: Surprise minimization 9

China and South Korea China: Privacy via cybersecurity Cybersecurity Law in effect June 1, but still lots of confusion All personal data kept in China, unless government security review Find a lawyer who knows what they re doing here South Korea Act on the Promotion of Information Communication Network Utilization and Information Protection Strictest privacy law in the world? Fines of up to 3X impact on consumers Find a lawyer who knows what they re doing here 10

APEC s CBPRs A universal way to transfer data throughout APAC?

What Are the CBPRs? APEC Cross Border Privacy Rules (CBPR) system Voluntary but enforceable framework of data privacy principles that companies commit to apply to data received under the system Developed through a multi-stakeholder process over six years APEC Leaders committed to CBPR implementation in 2011 and re-affirmed commitment in 2016 Companies must self-certify to an accountability agent, an approved independent third party verifier

What Are the Benefits of CBPRS? For Businesses Facilitates legal compliance Enables cross-border transfers Demonstrates accountability Builds consumer trust For Consumers Enhances privacy protections and improve trust Streamlines complaint process For Government Facilitates Trade and Establishes Credibility in Privacy Coordinates Enforcement Streamlines Investigations

Who Participates? Economies Accountability Agents (AAs) Companies IBM HP IntaSect Communications Merck Apple Cisco

What s happening now: Hong Kong Active participant in the development of the CBPR system Member of the Cross Border Privacy Enforcement Arrangement (CPEA) Developing local certification (P-Mark) that could be compatible with CBPRs May offer a basis for transfer upon implementation of the transfer limitation principle

What s happening now: India Data Security Council of India is interested in developing a certification system similar in scope to CBPRs India is not an APEC member economy May develop a comparable certification system that could be crossed recognized with CBPR-participating economies Enforceability not necessarily dependent on new law - existing state authority may suffice

What s happening now: Japan Has joined the CBPR system Has appointed an Accountability Agent (JIPDEC) and begun certifying companies Specifically calls out CBPRs as a basis for transfer (due diligence) under the new Japanese Privacy law that goes into effect at the end of May

What s happening now: Singapore Announced intention to join the CBPR system at the most recent APEC meetings in Nha Trang, Vietnam (February) Developing a local certification system through PDPC - also likely to be compatible with CBPRs Ideally, CBPRs recognized in a similar manner to BCRs

What s happening now: South Korea Has submitted its application to join CBPRs Anticipates appointing KISA as its first Accountability Agent Likely to begin certifying companies later this summer or early fall

What s Next? Expansion to additional APEC economies Privacy Recognition for Processors (PRP) APEC-EU interoperability Website Enhancements

Additional Resources APEC Privacy Framework: http://publications.apec.org/publicationdetail.php?pub_id=390 Information Integrity Solutions Report on CBPR Benefits: http://unctad.org/meetings/fr/contribution/dtl_eweek2016_iis -APEC_en.pdf APEC Report on Readiness for CBPRs: http://publications.apec.org/publicationdetail.php?pub_id=1800 Questions? Email andrew.flavin@trade.gov

Questions? Sam Pfeifle: sam@iapp.org Michael Rose: michael.rose@trade.gov Josh Harris: jharris@truste.com 22