10 4. CONTEXT 4.1. OVERVIEW OF INTERNATIONAL, REGIONAL POLICY AND LEGISLATION TRENDS Many jurisdictions across the world do not have data policy, with about a third having no data legislation in place. UNCTAD found in 2020 that 66% of countries in the world have some sort of legislation, 10% have draft legislation, 19% have no legislation, and 5% have no data legislation at all. Globally, a number of instruments have emerged in this context, such as the EU GDPR 2016/679, the APEC Privacy Framework and the Trans-Pacific Partnership (TPP) Agreement. These agreements take slightly different approaches to data protection and may serve as points of reference for Africa’s concerted efforts at data protection. The EU’s GDPR 2016/6 is wide-ranging with an expansive definition of what personal data is. Its broad territorial scope applies within and outside the EU, contains serious penalties for subverting the regulation, requires considerable openness and transparency and, importantly, grants individuals substantial rights that can be enforced against businesses. This approach to data protection is centred around a human rights agenda in the digital ecosystem. The APEC Privacy Framework, which has been applied by APEC member states since 2005, is made up of a set of principles which are set up to ensure the free flow of information in support of economic development. APEC’s framework takes a different approach to data protection by aligning the framework’s mandate with the promotion of trade and investment. An important highlight of the framework is how it emphasises that privacy regulations must take into consideration the importance of business and commercial interests in addition to the cultures and other diversities of member states’ economies. The Comprehensive and Progressive Trans-Pacific Partnership (CPTPP) focuses on open trade and regional integration amongst member states. The agreement allows for the cross-border transfer of information by electronic means, including personal information, when this activity is for the conduct of the businesses, but countries can require protection of data that is transferred. Outside of these multilateral agreements, the public goals of data protection typically centre around protecting the privacy of individuals and communities, safeguarding valuable data from leaks, loss, and theft, and maintaining and increasing public, investor and customer confidence. In a bid to achieve these goals, many countries have included potential barriers to data flow in their domestic laws, such as data localisation requirements and, in some instances, more stringent data processing and collection requirements. These may inadvertently retard or counteract the objects of more far-reaching regional policy frameworks. In the evolution of domestic policies for the digital economy, several strategies have crystallised globally, such as the government-led approach (as championed by the EU), the private sectorled approach (as promoted in the United States), the top-down policy approach (exemplified by Singapore), and the bottom-up approach (for instance, in Hong Kong, China).These approaches have varying complementary effects on policy implementation, deployment, impact, innovation, agility and stability.

Select target paragraph3

Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents