Skip to content

Menu

LexBlog, Inc. logo
CommunitySub-MenuPublishersChannelsProductsSub-MenuBlog ProBlog PlusBlog PremierMicrositeSyndication PortalsAboutContactResourcesSubscribeSupport
Join
Search
Close

Takeaways from IIC Telecom and Media Forum—Session on Privacy, Cybersecurity, Privacy and Trust (International Panel Discussion)

pexels-photo-72161
By Alan Friel, Ann J. LaFrance, Kristin Bryan & Gicel Tomimbang on January 12, 2022
Email this postTweet this postLike this postShare this post on LinkedIn

On December 9, 2021, Ann LaFrance, SPB Senior Partner and Vice President of the International Institute of Communications (“IIC”), moderated a panel discussion involving U.S. and international stakeholders’ perspectives on privacy and data protection trends and  the value of interoperability in cross-border data transfers at the IIC’s (virtual) annual Telecommunications & Media Forum (“TMF”) in Washington DC.

The panel participants represented a diverse cross-section of international stakeholders, including: Maureen Mahoney, Senior Policy Analyst for Consumer Reports; Sam Schofield, Trade Policy Advisor – Global Data Policy, International Trade Administration (“ITA”); Vitelio Ruiz Bernal, Director General of Investigation and Verification of the Private Sector, Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (“INAI”); and Christopher Calabrese, Senior Director, Privacy Policy, Microsoft.

The panelists discussed a wide range of topics, including the prospects for interoperability between and among national data privacy and protection regimes, data localization, emerging international frameworks, enforcement challenges and consumer trust.  A summary of the major themes covered by the panelists is provided below.

Global Interoperability

Stakeholders in the U.S. and abroad recognize the importance of facilitating cross-border transfers of personal data, and are advocating for interoperable privacy laws,  including agreement on a new framework  to replace the EU-US Privacy Shield (“Privacy Shield”), which the European Court of Justice concluded was invalid from an EU law perspective in 2020.

One emerging framework to facilitate the free flow of personal data is the Asia-Pacific Economic Cooperation (“APEC”) Cross-Border Privacy Rules (“CBPR”) System, which currently has nine participating countries, including the United States and Mexico.  The panelists discussed the conditions for an effective cross-border interoperability regime, including the following principles:

  1. Be transparent so that it is not difficult to comprehend what companies are doing with an individual’s data;
  2. Empower individuals by giving them rights over their own data;
  3. Promote corporate responsibility among companies that collect personal information;
  4. Have a strong enforcement mechanism to ensure that if consumers are granted rights they also have adequate remedies;
  5. Respect national sovereignty but limit data localization where necessary for national governments to protect legitimate state interests; and
  6. Be sufficiently flexible to allow for the evolution of technology and evolving regulatory requirements.

Although there is a consensus on the value of interoperable privacy regimes, there is also a recognition that there are different perspectives on what the critical elements of “interoperability” should consist of, how they should be implemented and what enforcement mechanisms should apply.

Data Localization

Data localization laws place restrictions on where personal information may be stored and processed. The panelists discussed the impact of data localization laws, including:

  1. The obstacles data localization laws create for businesses seeking to serve customers both globally and locally (e.g., significant operational costs), which affects cross-border commerce;
  2. Governments’ national security and law enforcement interests; and
  3. The need to balance the benefits of enabling data to flow freely across borders with the legitimate interests of governments to protect their citizens.

Emerging International Frameworks

Two models of interoperability were the focus of discussion: the APEC CBPR System, and the EU “adequacy” test established under the EU General Data Protection Regulation (the “GDPR”).  The panelists discussed the benefits and challenges of both models and observed that, although the GDPR is generally considered a more stringent regime, the two models are not incompatible and there are countries that participate in both (e.g., Japan, Canada).

Enforcement Challenges

The panelists agreed that establishing a global privacy standard is challenging because privacy is culturally rooted, and each country may have a different understanding of human rights and civil liberties.  Thus, what may be considered “private” in one country may not be so in another, which could affect the enforcement mechanisms included in each country’s privacy regime.  The panelists also identified additional challenges in privacy enforcement, including the:

  1. Importance of allocating sufficient resources and enforcement powers to data protection authorities so they can promote accountability and secure redress for consumers;
  2. Privacy considerations in public and private sectors, which may sometimes be divergent; and
  3. Importance of developing legally enforceable mechanisms that evolve alongside changing technology.

Consumer Trust

From the consumer perspective, ensuring trust in online transactions is an imperative that will require laws designed to protect consumer privacy by default, including strong data minimization requirements, as well as effective opt-out mechanisms, such as global privacy controls that can be activated through browser settings.

There was a general consensus that we are now approaching an inflection point, with new and divergent privacy laws coming into force around the world, such as the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais or LGPD), China’s Personal Information Protection Law (“PIPL”), California’s CCPA/CPRA  and number of other privacy laws at the state level in the U.S.  The panelists agreed that the next five years will be critical to the development of a global consensus on the minimum inter-operability requirements to legitimize cross-border data flows in a world that is ever more reliant on the global internet. 

A recording of this discussion is available here. The IIC/TMF also hosted a panel on U.S. privacy law developments.  A blog post on that is available here.

 

Photo of Alan Friel Alan Friel
Read more about Alan FrielEmail
Photo of Ann J. LaFrance Ann J. LaFrance

Ann LaFrance co-chairs the firm’s global Data Privacy & Cybersecurity Practice and is a senior member of the international Communications Practice.

View full website bio.

Read more about Ann J. LaFranceEmail
Photo of Kristin Bryan Kristin Bryan

Kristin Bryan is a data privacy and cybersecurity litigator experienced in the resolution of complex disputes.

Kristin has deep expertise defending clients in federal class action and multidistrict litigations concerning allegations that their practices violated federal and state privacy laws. This includes in…

Kristin Bryan is a data privacy and cybersecurity litigator experienced in the resolution of complex disputes.

Kristin has deep expertise defending clients in federal class action and multidistrict litigations concerning allegations that their practices violated federal and state privacy laws. This includes in the context of data breach and incident response litigation. As a natural extension of her experience litigating data privacy disputes, Kristin also provides practical, business-oriented privacy advice to a wide range of clients and has represented them in government investigations regarding their privacy practices.

Kristin is CIPP/US certified and routinely publishes and speaks on cutting-edge developments in data privacy and cybersecurity litigation. Kristin is currently the co-chair of the International Association of Privacy Professional (IAPP)’s KnowledgeNet Chapter for Cleveland and on the IAPP’s Privacy Bar Advisory Board. She is a 2020-21 Vice Chair of the ABA TIPS Cybersecurity and Data Privacy Committee and managing editor of Squire Patton Boggs’ data privacy blog Consumer Privacy World.

Prior to joining the firm, Kristin worked at an international law firm in New York, specializing in Data Strategy & Security.

View full website bio.

Read more about Kristin BryanEmail
Show more Show less
  • Posted in:
    Privacy & Data Security
  • Blog:
    Consumer Privacy World
  • Organization:
    Squire Patton Boggs
  • Article: View Original Source

LexBlog, Inc. logo
Facebook LinkedIn Twitter RSS
Real Lawyers
99 Park Row
  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service
  • Products
  • Blog Pro
  • Blog Plus
  • Blog Premier
  • Microsite
  • Syndication Portals
  • LexBlog Community
  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • Resource Center

New to the Network

  • Boston ERISA & Insurance Litigation Blog
  • Stridon News and Insights
  • Taft Class Action & Consumer Insights
  • Labor and Employment Law Insights
  • Age of Disruption
Copyright © 2022, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo