Curtailing Free Expression, Opinion and Information Online in Southeast Asia
EU GDPR and Convention 108+
At the regional level, the European Union (EU) has made efforts
towards developing concrete legal guidelines with respect to protection of
online personal data. In May 2018, the EU General Data Protection Regulation
(GDPR) came into force, providing protections for privacy and data breaches
with penalties of up to 4 percent of an organization’s annual global turnover
or €20 million (approx. US$22 mil.) for severe infringements.75 Crucially,
the GDPR applies extraterritorially to any company processing the data of
subjects within the EU, regardless of the location of the company.76 Following
the coming into force of the GDPR, in January 2019, Google was fined €50
million (approx. US$55 mil.) by French data protection regulator, CNIL,
for failing to obtain consent from its users to use their personal data for
targeted advertising.77 In March 2019, the EU also set out a latest draft of
its ‘ePrivacy Regulation’, focusing on privacy protections for data processed
on electronic communication services.78
While the impacts of these newer, consolidated European data
protection laws remain to be seen, their implementation will provide
precedential guidance for global efforts to develop laws to protect the right
to privacy in the online sphere.79 A key example is the Convention for the
Protection of Individuals with regard to Automatic Processing of Personal
75
76
77
78
79
Information on the GDPR is available at: https://eugdpr.org/the-regulation/; In May 2018, the
EU Data Protection Law Enforcement Directive also came into force, protecting the right of EU
citizens to data protection where personal data is processed by competent authorities for the
purposes of the prevention, investigation, detection or prosecution of criminal offences or the
execution of criminal penalties, and on the free movement of such data. The Directive is available
at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv%3AOJ.L_.2016.119.01.0089.01.
ENG&toc=OJ%3AL%3A2016%3A119%3ATOC
GDPR, Article 3, Available at: https://gdpr-info.eu/art-3-gdpr/; One commentary noted that this
was “part of a global trend to extend the scope of data protection laws to make them reflect the
borderless nature of the Internet”, See Adele Azzi, ‘The Challenges Faced by the Extraterritorial
Scope of the General Data Protection Regulation’ (2018) 9 JIPITEC 126, Available at: https://www.
jipitec.eu/issues/jipitec-9-2-2018/4723
Klint Finley, ‘EU Privacy Law Snares Its First Tech Giant: Google’, WIRED, 22 January 2019,
Available at: https://www.wired.com/story/eu-privacy-law-snares-first-tech-giant-google/; Chris
Fox, ‘Google hit with £44m GDPR fine over ads’, BBC, 21 January 2019, Available at: https://www.
bbc.com/news/technology-46944696; This was not the first fine to be issued under the GDPR, See
Jon Porter, ‘Google fined €50 million for GDPR violation in France’, The Verge, 21 January 2019,
Available at: https://www.theverge.com/2019/1/21/18191591/google-gdpr-fine-50-million-eurosdata-consent-cnil
Regulation of the European Parliament and the Council concerning the respect for private life and
protection of personal data in electronic communications repealing Directive 2002/58/EC. This
draft is available at: https://data.consilium.europa.eu/doc/document/ST-7099-2019-INIT/en/pdf
In his 2018 report to the UN General Assembly, the Special Rapporteur on the right to privacy
noted, “It is likely, in the next five to ten years, that the extraterritorial effects of GDPR with the
ever-widening club of Convention 108 countries, will have a significant effect on the deepening
world-wide privacy culture. The precise nature of this evolution is still emerging, as is its relevance
to the need for further developments such as stand-alone principles for Big Data and Open Data.”
See Report of the UN Special Rapporteur on the right to privacy [Advanced Unedited Version],
A/73/45712, 17 October 2018 (‘A/73/45712’), para 101.
29