10
4.
CONTEXT
4.1. OVERVIEW OF INTERNATIONAL, REGIONAL
POLICY AND LEGISLATION TRENDS
Many jurisdictions across the world do not have data policy, with about a third having no
data legislation in place. UNCTAD found in 2020 that 66% of countries in the world have some
sort of legislation, 10% have draft legislation, 19% have no legislation, and 5% have no data
legislation at all.
Globally, a number of instruments have emerged in this context, such as the EU GDPR
2016/679, the APEC Privacy Framework and the Trans-Pacific Partnership (TPP) Agreement.
These agreements take slightly different approaches to data protection and may serve as
points of reference for Africa’s concerted efforts at data protection.
The EU’s GDPR 2016/6 is wide-ranging with an expansive definition of what personal data is.
Its broad territorial scope applies within and outside the EU, contains serious penalties for subverting the regulation, requires considerable openness and transparency and, importantly,
grants individuals substantial rights that can be enforced against businesses. This approach
to data protection is centred around a human rights agenda in the digital ecosystem.
The APEC Privacy Framework, which has been applied by APEC member states since 2005, is
made up of a set of principles which are set up to ensure the free flow of information in support
of economic development. APEC’s framework takes a different approach to data protection by
aligning the framework’s mandate with the promotion of trade and investment. An important
highlight of the framework is how it emphasises that privacy regulations must take into consideration the importance of business and commercial interests in addition to the cultures and
other diversities of member states’ economies.
The Comprehensive and Progressive Trans-Pacific Partnership (CPTPP) focuses on open trade
and regional integration amongst member states. The agreement allows for the cross-border
transfer of information by electronic means, including personal information, when this activity
is for the conduct of the businesses, but countries can require protection of data that is transferred.
Outside of these multilateral agreements, the public goals of data protection typically centre
around protecting the privacy of individuals and communities, safeguarding valuable data
from leaks, loss, and theft, and maintaining and increasing public, investor and customer
confidence. In a bid to achieve these goals, many countries have included potential barriers to
data flow in their domestic laws, such as data localisation requirements and, in some instances, more stringent data processing and collection requirements. These may inadvertently
retard or counteract the objects of more far-reaching regional policy frameworks.
In the evolution of domestic policies for the digital economy, several strategies have crystallised
globally, such as the government-led approach (as championed by the EU), the private sectorled approach (as promoted in the United States), the top-down policy approach (exemplified by
Singapore), and the bottom-up approach (for instance, in Hong Kong, China).These approaches
have varying complementary effects on policy implementation, deployment, impact, innovation,
agility and stability.
Select target paragraph3
Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents