Endorsed 12. 13. (iii) Promoting interoperability of standards by ensuring that data provided is in a structured, commonly used and machine-readable format. B. Principle on Data Use and Access Control The Principle on data use and access control promotes accountability in data processing, which is a key component in data governance. This would include: (i) Using and/or processing data only for purposes that are reasonable and appropriate; and which are not contrary to laws or national policies; (ii) Assigning different access controls and levels of authorisations to personnel for access to different types or classifications of data; and (iii) Ensuring that access to data should be adequate, relevant, and transparent. C. Principle on Data Security The Principle on data security establishes the need to safeguard data, and any storage centres the data sits within, as well as the systems and platforms that handle the data. This would include: (i) Taking appropriate measures, including technical, procedural and physical measures, to ensure that they protect the confidentiality, integrity and availability of any data in their possession, or control against risks such as loss or unauthorised access, use, modification, disclosure, or destruction; and (ii) Addressing data breaches promptly and effectively, by containing the breach and implementing mitigating measures to rectify the breach and where relevant, in accordance with national policies on data breach notifications. Initiative under Strategic Priority 1: ASEAN Data Classification Framework 14. Data governance principles on data life cycle and ecosystem may differ depending on, among other things, the types of data. The level of protection required and accorded under the Principles may apply the same approach and considerations. For example, certain types of data (e.g. sensitive personal data) require higher levels of protection, such as by having stricter access controls or more stringent handling and disclosure requirements compared to data that is publicly available. 15. To afford data the necessary and adequate level of protection, it will be useful to have a common data classification framework, which sets out broad categories of data, descriptions of what each category entails and development of security requirements for each data classification level. 4

Select target paragraph3