Freedom House
local storage of any “secretive, sensitive, and confidential”
data pertaining to individuals and companies. A new data
protection bill proposed in October 2020 in Bangladesh
would also require domestic data storage.
In some cases, such data localization requirements have
been introduced in the context of content regulation.
Pakistan’s proposed Removal and Blocking of Unlawful
Online Content (Procedure, Oversight and Safeguards)
Rules, the latest version of which was published in
November 2020, outlines requirements for social media
companies to establish one or more data servers in the
country. Similarly, Turkey’s social media law requires
platforms to store data locally and establish domestic legal
representatives or face five stages of escalating penalties,
including fines, an advertising ban, and bandwidth limitations
of up to 90 percent.
Data protection policies may also be used to place stringent
limitations on cross-border data transfers and impose
onerous licensing requirements on companies. Under a data
protection law ratified in Egypt in July 2020, domestic and
foreign entities must obtain a state license and appoint a
local data protection officer to conduct cross-border data
transfers. Unlike the independent commissions formed
in many democracies, Egypt’s data protection agency will
be supervised by a board comprising representatives of
government ministries, including security and intelligence
officials. The law’s exorbitant licensing fees are prohibitive for
many small and medium-sized enterprises.
Continuing pressure on encryption
In addition to requiring data localization, many new
regulations threaten to undermine encryption, which is
essential for data privacy and cybersecurity and a critical
tool for journalists and human rights defenders around the
world. India’s revised Information Technology Rules require
large social media platforms to identify and disclose the “first
originator” of a message if requested by the government
or judiciary in cases related to state sovereignty, security,
public order, and sexually explicit content. Companies would
effectively have to dismantle end-to-end encryption in order
to unmask a message’s originator, undermining the privacy
and security protections on which users, companies, and
governments have come to rely. In May 2021, WhatsApp sued
the government to halt the rules’ implementation, arguing
that the traceability requirements violated constitutionally
guaranteed privacy protections.
@freedomhouse
The proposed Brazilian Internet Freedom, Responsibility,
and Transparency Act includes similar yet more narrow
traceability requirements. Private messaging services would
be required to store for three months the traceability data
of messages that go viral, defined as those forwarded by
more than five users and that reach at least 1,000 accounts.
While this provision is significantly scaled back from one in an
earlier draft, companies would still in practice have to erode
encryption to trace and identify messages that reach the low
virality threshold.
Democratic leaders disparaging endto-end encryption serves the interests
of more authoritarian governments
that seek to undermine the technology
for their own political ends.
Pakistan’s proposed rules have raised alarms about their impact
on end-to-end encryption. The draft requires social media
companies and service providers with more than 500,000
users to hand over personal data in a decrypted and readable
format when requested by the Federal Investigation Agency.
Similarly, amendments to the Nigerian Broadcasting Code
proposed in August 2020 require broadcasters to comply with
decryption orders during moments of emergency.
Over the past year, democratic leaders again disparaged endto-end encryption, serving the interests of more authoritarian
governments that seek to undermine the technology for
their own political ends. For example, in October 2020
leaders from Japan, India, and the Five Eyes—an intelligence
alliance composed of the United States, the United Kingdom,
Canada, Australia, and New Zealand—decried encryption
as an impediment to national security, criminal, and child
sexual abuse investigations. But any weakening of encryption
protocols or requirements for “backdoor” access would
effectively undermine the security of civil society groups,
businesses, and ordinary users, potentially endangering lives.
Contrasting dynamics in China
In China, growing public anger at a series of data scandals has
put authorities under greater pressure to limit companies’
exploitation of user information. This year’s Personal
freedomhouse.org
17