Curtailing Free Expression, Opinion and Information Online in Southeast Asia EU GDPR and Convention 108+ At the regional level, the European Union (EU) has made efforts towards developing concrete legal guidelines with respect to protection of online personal data. In May 2018, the EU General Data Protection Regulation (GDPR) came into force, providing protections for privacy and data breaches with penalties of up to 4 percent of an organization’s annual global turnover or €20 million (approx. US$22 mil.) for severe infringements.75 Crucially, the GDPR applies extraterritorially to any company processing the data of subjects within the EU, regardless of the location of the company.76 Following the coming into force of the GDPR, in January 2019, Google was fined €50 million (approx. US$55 mil.) by French data protection regulator, CNIL, for failing to obtain consent from its users to use their personal data for targeted advertising.77 In March 2019, the EU also set out a latest draft of its ‘ePrivacy Regulation’, focusing on privacy protections for data processed on electronic communication services.78 While the impacts of these newer, consolidated European data protection laws remain to be seen, their implementation will provide precedential guidance for global efforts to develop laws to protect the right to privacy in the online sphere.79 A key example is the Convention for the Protection of Individuals with regard to Automatic Processing of Personal 75 76 77 78 79 Information on the GDPR is available at: https://eugdpr.org/the-regulation/; In May 2018, the EU Data Protection Law Enforcement Directive also came into force, protecting the right of EU citizens to data protection where personal data is processed by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data. The Directive is available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv%3AOJ.L_.2016.119.01.0089.01. ENG&toc=OJ%3AL%3A2016%3A119%3ATOC GDPR, Article 3, Available at: https://gdpr-info.eu/art-3-gdpr/; One commentary noted that this was “part of a global trend to extend the scope of data protection laws to make them reflect the borderless nature of the Internet”, See Adele Azzi, ‘The Challenges Faced by the Extraterritorial Scope of the General Data Protection Regulation’ (2018) 9 JIPITEC 126, Available at: https://www. jipitec.eu/issues/jipitec-9-2-2018/4723 Klint Finley, ‘EU Privacy Law Snares Its First Tech Giant: Google’, WIRED, 22 January 2019, Available at: https://www.wired.com/story/eu-privacy-law-snares-first-tech-giant-google/; Chris Fox, ‘Google hit with £44m GDPR fine over ads’, BBC, 21 January 2019, Available at: https://www. bbc.com/news/technology-46944696; This was not the first fine to be issued under the GDPR, See Jon Porter, ‘Google fined €50 million for GDPR violation in France’, The Verge, 21 January 2019, Available at: https://www.theverge.com/2019/1/21/18191591/google-gdpr-fine-50-million-eurosdata-consent-cnil Regulation of the European Parliament and the Council concerning the respect for private life and protection of personal data in electronic communications repealing Directive 2002/58/EC. This draft is available at: https://data.consilium.europa.eu/doc/document/ST-7099-2019-INIT/en/pdf In his 2018 report to the UN General Assembly, the Special Rapporteur on the right to privacy noted, “It is likely, in the next five to ten years, that the extraterritorial effects of GDPR with the ever-widening club of Convention 108 countries, will have a significant effect on the deepening world-wide privacy culture. The precise nature of this evolution is still emerging, as is its relevance to the need for further developments such as stand-alone principles for Big Data and Open Data.” See Report of the UN Special Rapporteur on the right to privacy [Advanced Unedited Version], A/73/45712, 17 October 2018 (‘A/73/45712’), para 101. 29

Select target paragraph3