Endorsed
16.
The data classification framework is not meant to be an exhaustive or binding
list of data categories. Each category of data will include recommended
measures or protections that should apply to that specific category of data.
These include steps that can be taken to allow data to be processed, shared or
transferred across country borders. The factors that could be considered for the
development of the data classification framework include data sensitivity, risk
assessment, protection impact management, storage and storage standards,
or applicable industry regulations and standards.
Strategic Priority 2: Cross Border Data Flows
17.
Data is regarded as the lifeblood of the digital economy, driven by increasing
technology adoption and digitalisation. As the region moves towards a
borderless, interconnected environment, the Principle on cross border data
flows is intended to guide governments, businesses and consumers in the
region as they navigate their way through managing data flows in this new
phase of digital transformation and integration.
18.
Data flows should be accompanied by assurances that safeguards are in place
to protect and secure the information regardless where the data goes. These
safeguards should be harmonised to prevent the development of fragmented
regulatory regimes, which may negatively impact data flows and increase
business compliance costs.
19.
It should be emphasised that not all requirements imposed on cross border data
flows are detrimental to the economy. Requirements may exist to ensure that
there are safeguards to accord the necessary protection for the data being
transferred. It is important for individual ASEAN Member States to review and
minimise restrictions5 to cross border data flows against the backdrop of its
overall impact to data innovation and the goal of fostering a vibrant data
ecosystem.
D.
20.
Principle on Cross Border Data Flows
The Principle on cross border data flows is intended to maximise the free flow
of data within ASEAN to foster a vibrant data ecosystem but at the same time
ensure that the data transferred is accorded the necessary protection. This
would include:
(i)
Facilitating cross-border data flows within ASEAN by developing clear
and unambiguous requirements and/or criteria and/or circumstances in
which data can be transferred from one ASEAN Member State to
another;
(ii)
Evaluating and ensuring that the requirements on cross border data
flows within ASEAN are proportionate to the risks associated with
5
Restrictions may come in the form of policies requiring organisations to store data within the country (e.g. data
localisation), or regulatory conditions imposed before data can flow out of the country of origin (e.g. consent of the
individual, for purposes of fulfiling contractual obligations).
5