Endorsed 16. The data classification framework is not meant to be an exhaustive or binding list of data categories. Each category of data will include recommended measures or protections that should apply to that specific category of data. These include steps that can be taken to allow data to be processed, shared or transferred across country borders. The factors that could be considered for the development of the data classification framework include data sensitivity, risk assessment, protection impact management, storage and storage standards, or applicable industry regulations and standards. Strategic Priority 2: Cross Border Data Flows 17. Data is regarded as the lifeblood of the digital economy, driven by increasing technology adoption and digitalisation. As the region moves towards a borderless, interconnected environment, the Principle on cross border data flows is intended to guide governments, businesses and consumers in the region as they navigate their way through managing data flows in this new phase of digital transformation and integration. 18. Data flows should be accompanied by assurances that safeguards are in place to protect and secure the information regardless where the data goes. These safeguards should be harmonised to prevent the development of fragmented regulatory regimes, which may negatively impact data flows and increase business compliance costs. 19. It should be emphasised that not all requirements imposed on cross border data flows are detrimental to the economy. Requirements may exist to ensure that there are safeguards to accord the necessary protection for the data being transferred. It is important for individual ASEAN Member States to review and minimise restrictions5 to cross border data flows against the backdrop of its overall impact to data innovation and the goal of fostering a vibrant data ecosystem. D. 20. Principle on Cross Border Data Flows The Principle on cross border data flows is intended to maximise the free flow of data within ASEAN to foster a vibrant data ecosystem but at the same time ensure that the data transferred is accorded the necessary protection. This would include: (i) Facilitating cross-border data flows within ASEAN by developing clear and unambiguous requirements and/or criteria and/or circumstances in which data can be transferred from one ASEAN Member State to another; (ii) Evaluating and ensuring that the requirements on cross border data flows within ASEAN are proportionate to the risks associated with 5 Restrictions may come in the form of policies requiring organisations to store data within the country (e.g. data localisation), or regulatory conditions imposed before data can flow out of the country of origin (e.g. consent of the individual, for purposes of fulfiling contractual obligations). 5

Select target paragraph3