You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 9, 2023

AI, Privacy, and Data Protection: Legal Considerations in Southeast Asia

The significance of artificial intelligence (AI) is rapidly increasing worldwide, and Southeast Asia is no exception, as it plays a leading role in the technological development of many industries. AI has already proven its importance for driving business growth in areas such as e-commerce, finance, and healthcare, but its remarkable potential also raises concerns around privacy. As AI systems are designed to collect and process large amounts of data to improve their operation, it is necessary to balance the development of technology with the protection of individuals’ privacy.

Current Frameworks in Southeast Asia

This concern has been on regional policymakers’ agendas for many years. The ASEAN Framework on Personal Data Protection, which was adopted in 2016, is not legally binding and has no enforcement mechanism, but it serves as a guide for ASEAN member states in developing their own data protection laws and regulations.

Domestic data privacy laws are currently in force in five ASEAN member countries—Indonesia, Malaysia, the Philippines, Thailand, and Singapore—while Vietnam’s Personal Data Protection Decree is scheduled to take effect on July 1, 2023. This presents a challenge for ASEAN members, as adopting AI-related technology can further complicate data protection efforts due to the amount of personal data AI systems collect, as well as the complexity of the data used to train the AI algorithm.

Some ASEAN members have also made progress in regulating AI. For instance, Singapore released the Model AI Governance Framework in 2019 and launched the AI Governance Testing Framework and Toolkit in 2022—the world’s first such framework. Similarly, Thailand issued the Artificial Intelligence Ethics Guideline in 2019 to help government agencies in the development, promotion, and use of AI, and in 2023 adopted the Thailand Artificial Intelligence Guidelines to help the private sector develop AI-related work. These guidelines primarily focus on principles and ethics in developing AI-related technology, but lack a step-by-step implementation process that connects with privacy laws. Despite these early steps by some countries in ASEAN, there are no regional policies or consensus frameworks on how to implement and regulate AI in accordance with privacy laws in ASEAN member countries.

Legal Risks

If AI-related technology is developed without consideration for data protection, there is a risk of breaching personal data and affecting numerous data subjects, potentially resulting in mass litigation. Moreover, the lack of robust privacy laws and frameworks in many ASEAN member countries, coupled with the growing use of AI-related technology, also increases the risk of legal liabilities for companies that make use of this increasingly common technology.

In the event of a data breach or misuse of personal data, affected individuals may seek legal recourse against the companies that collected and processed their personal information. Such legal actions can result in significant financial and reputational damages for businesses, highlighting the need for effective data protection regulations and AI-related technology frameworks in ASEAN countries.

Technology companies with connections to developing AI systems are especially vulnerable. With the vast amount of data required for developing AI systems, these companies will face the challenge of lawfully collecting and processing data from a huge range of sources and data subjects.

Outlook

As AI-related technology continues to evolve and play a crucial role in the growth of many industries in Southeast Asia, it is important to ensure that its development is balanced with the protection of individuals’ privacy. While some ASEAN members have made progress in adopting AI regulations, more needs to be done to enforce data privacy laws and develop consensus frameworks for regulating AI in accordance with privacy laws. Such efforts will not only help protect individuals’ privacy but also mitigate legal risks associated with the use of AI-related technology. ASEAN member countries must continue to work together to achieve a balance between technological development and data protection in support of sustainable and ethical innovation for our digital future.

RELATED INSIGHTS​ 

July 19, 2024
Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to How the Use of Artificial Intelligence Is Regulated in Southeast Asia, a comparative resource published by Drew Network Asia (DNA). The guide provides an accessible introduction to artificial intelligence (AI) and examines how ASEAN member states are approaching governance, regulation, and responsible deployment of AI technologies. The publication begins by outlining core AI concepts and summarizing the ASEAN Guide on AI Governance and Ethics, which reflects the region’s collective approach to promoting innovation while addressing risks. It then presents a comparative overview of nine ASEAN jurisdictions, highlighting emerging national strategies, regulatory developments, and institutional frameworks. Each country chapter responds to a consistent set of ten practical questions. These cover whether a national AI strategy has been issued; the extent to which dedicated AI laws or sectoral regulations apply; the existence of relevant judicial decisions; available guidelines and government support schemes; regulators responsible for AI oversight; approaches to liability, copyright, and data protection; and key considerations for organizations deploying AI technologies. By consolidating developments across the region, the guide serves as a useful reference for businesses exploring AI-related opportunities or compliance obligations in Southeast Asia. As regulatory approaches continue to evolve, readers seeking jurisdiction-specific advice are encouraged to contact the practitioners listed in each chapter. The full guide is available for download using the button below or directly from the DNA website.
July 10, 2024
The need for privacy and security has grown in tandem with the rapid proliferation of internet-enabled technologies. This is a major concern for consumers and individuals, and governments are increasingly mindful of online threats to their national security and their citizens. All of this represents an imposing challenge for companies—especially now that technology has enabled them to operate with relative ease across jurisdictions throughout the world.
July 5, 2024
The landscape of intellectual property (IP) has transformed alongside advancements in technology, transitioning from traditional methods to modern online approaches. A growing number of IP infringers are moving their illegal activities to the online sphere, particularly through the sale of counterfeit goods on their websites, social media, or e-commerce platforms. In response to these shifting pressures, Thailand implemented the Computer-Related Crime Act B.E. 2550 (CCA) on July 18, 2007, and amended it in 2017, aiming to enhance the effectiveness of combating online infringement by empowering government officials to request that the court block computer data (called “website-blocking”) that infringes upon other parties’ intellectual property rights, as per section 20(3) of the CCA. From 2018 to May 2024, Thailand’s Criminal Court and Central Intellectual Property and International Trade Court have issued 53 orders to block more than 1,779 infringing URLs. One significant recent development is the Criminal Court’s establishment of the Technology Crime Division, which has been operating since April 1, 2024. Its purpose is to address criminal offenses that occur through electronic means, which should then be handled in an effective and prompt manner by judges who have expertise on technological crimes. In addition, several current measures to combat technology crime, including section 20(3) of the CCA, require court orders for the prevention of electronic criminal offenses or online infringement. The Technology Crime Division has the jurisdiction to consider and grant these orders, which will help expedite the approval process and ensure review by specialized judges. Scope of the Technology Crime Division The announcement of the establishment of the Technology Crime Division within the Criminal Court was published in the Government Gazette on March 18, 2024, with operations commencing on April 1, 2024. The Technology Crime Division is empowered to: Consider and adjudicate technology crime cases, except cases falling
July 4, 2024
The rapid development and deployment of artificial intelligence in various industries is increasingly attracting the attention of regulators, who aim to encourage the progression of AI technologies while ensuring their responsible use. Recent regulatory developments around the world, including in the European Union and Southeast Asia, serve as evidence of this emerging trend. Here we shall discuss the effect of AI regulatory approaches in the  EU on Southeast Asian countries. Approach and Action The EU Artificial Intelligence Act has been officially adopted by EU colegislators and will enter into force 20 days after its publication in the EU Official Journal.[1] Most of its provisions will apply two years after its entry into force. The act establishes a harmonized EU legal framework, aiming at ensuring that AI systems placed on and utilized in the EU market are safe, have managed risks, and are aligned with EU fundamental rights and values. Countries in Southeast Asia, predominantly governed by civil law systems, often adopt statutory frameworks similar to those in the EU when addressing new legal matters. In the rapidly developing field of AI, Southeast Asian countries are adopting a wait-andsee approach toward global regulatory trends. This cautious stance allows them to observe and analyze international developments in AI regulation before crafting their own frameworks. Compared to the EU, countries in Southeast Asia are generally more focused on using AI for national development. Common themes include building human resource capability, developing ecosystems and building infrastructure. Some countries emphasize governance and ethics more than others. Over the past five years, governments across Southeast Asia have been focusing on promoting AI by implementing national policies to strengthen AI promotion and governance. While there may be less regional integration in the approach to AI of countries in Southeast Asia, there are some efforts to create