You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 9, 2023

AI, Privacy, and Data Protection: Legal Considerations in Southeast Asia

The significance of artificial intelligence (AI) is rapidly increasing worldwide, and Southeast Asia is no exception, as it plays a leading role in the technological development of many industries. AI has already proven its importance for driving business growth in areas such as e-commerce, finance, and healthcare, but its remarkable potential also raises concerns around privacy. As AI systems are designed to collect and process large amounts of data to improve their operation, it is necessary to balance the development of technology with the protection of individuals’ privacy.

Current Frameworks in Southeast Asia

This concern has been on regional policymakers’ agendas for many years. The ASEAN Framework on Personal Data Protection, which was adopted in 2016, is not legally binding and has no enforcement mechanism, but it serves as a guide for ASEAN member states in developing their own data protection laws and regulations.

Domestic data privacy laws are currently in force in five ASEAN member countries—Indonesia, Malaysia, the Philippines, Thailand, and Singapore—while Vietnam’s Personal Data Protection Decree is scheduled to take effect on July 1, 2023. This presents a challenge for ASEAN members, as adopting AI-related technology can further complicate data protection efforts due to the amount of personal data AI systems collect, as well as the complexity of the data used to train the AI algorithm.

Some ASEAN members have also made progress in regulating AI. For instance, Singapore released the Model AI Governance Framework in 2019 and launched the AI Governance Testing Framework and Toolkit in 2022—the world’s first such framework. Similarly, Thailand issued the Artificial Intelligence Ethics Guideline in 2019 to help government agencies in the development, promotion, and use of AI, and in 2023 adopted the Thailand Artificial Intelligence Guidelines to help the private sector develop AI-related work. These guidelines primarily focus on principles and ethics in developing AI-related technology, but lack a step-by-step implementation process that connects with privacy laws. Despite these early steps by some countries in ASEAN, there are no regional policies or consensus frameworks on how to implement and regulate AI in accordance with privacy laws in ASEAN member countries.

Legal Risks

If AI-related technology is developed without consideration for data protection, there is a risk of breaching personal data and affecting numerous data subjects, potentially resulting in mass litigation. Moreover, the lack of robust privacy laws and frameworks in many ASEAN member countries, coupled with the growing use of AI-related technology, also increases the risk of legal liabilities for companies that make use of this increasingly common technology.

In the event of a data breach or misuse of personal data, affected individuals may seek legal recourse against the companies that collected and processed their personal information. Such legal actions can result in significant financial and reputational damages for businesses, highlighting the need for effective data protection regulations and AI-related technology frameworks in ASEAN countries.

Technology companies with connections to developing AI systems are especially vulnerable. With the vast amount of data required for developing AI systems, these companies will face the challenge of lawfully collecting and processing data from a huge range of sources and data subjects.

Outlook

As AI-related technology continues to evolve and play a crucial role in the growth of many industries in Southeast Asia, it is important to ensure that its development is balanced with the protection of individuals’ privacy. While some ASEAN members have made progress in adopting AI regulations, more needs to be done to enforce data privacy laws and develop consensus frameworks for regulating AI in accordance with privacy laws. Such efforts will not only help protect individuals’ privacy but also mitigate legal risks associated with the use of AI-related technology. ASEAN member countries must continue to work together to achieve a balance between technological development and data protection in support of sustainable and ethical innovation for our digital future.

RELATED INSIGHTS​ 

February 8, 2023
Government Approves Legislative Dossier On February 7, 2023, the Vietnamese government issued Resolution No. 13/NQ-CP (“Resolution 13”) to approve the latest version of the draft Personal Data Protection Decree (“Draft PDPD”)—a draft which has not yet been made public. Similar to Resolution No. 27/NQ-CP issued in March 2022 approving the previous version of the Draft PDPD (“Resolution 27”), Resolution 13 stipulates the different cases where data subjects’ consent is exempted for processing personal data. Most of these lawful bases are similar to those under Resolution 27—except for the fourth case, which is brand new—with some changes for better clarity. According to Article 1 of Resolution 13, personal data can be processed without consent in the following five cases: (1) The processing is to protect the life and health of the data subject or others in an emergency situation. Data Controllers, Data Processors, Parties Controlling and Processing Personal Data, and Third Parties are responsible for proving this case; Remarks: Vietnamese law, including the prior published version of the Draft PDPD, has never used the terms “data controller”, “data processor,” and “parties controlling and processing personal data.” The inclusion of these terms suggests that the latest version of the Draft PDPD has adopted the GDPR-like concepts of “data controller” and “data processor.” However, until the latest version of the Draft PDPD can be assessed, it is uncertain how these concepts are defined and whether they are fully in line with GDPR definitions. (2) The disclosure of personal data is in accordance with the law; (3) The processing of data is performed by competent state agencies in the event of a state of emergency related to national defense, national security, social order and safety, major disaster, or dangerous epidemic; when there is a threat to security and national defense but not to
January 16, 2023
The January–March 2023 issue of Asia Franchise & Business Opportunities magazine features an article by two franchising specialists in Tilleke & Gibbins’ Bangkok office. Written by Alan Adcock, partner, and Sher Hann Chua, consultant, the article provides a summary of the legislative developments of 2022 most relevant to franchisors and franchisees. The update looks especially at amendments to Thailand’s unfair trade practices in franchising, as well as the far-reaching Personal Data Protection Act, which is reshaping the way businesses—including franchises—are handling the personal data of customers, partners, and employees. The article is accompanied by a Chinese-language summary of the developments. The full article can be read online in the January–March 2023 issue of Asia Franchise & Business Opportunities.
January 12, 2023
The year 2022 witnessed a dynamic environment in the development of information and communications technology (ICT) policy in Vietnam. The following are some highlights of remarkable legislative developments in the ICT space from the past year, and some notes on key draft laws and regulations that are in the pipeline for 2023. 1. Telecommunications Although it has helped Vietnam develop modern telecommunications network infrastructure and a diversified and competitive telecom market with a variety of services, Vietnam’s Telecom Law, which has been in effect since 2010, has posed problems and inadequacies in meeting today’s more complex evolution of new service types and new business models as well as the trend of convergence of telecom, information technology, and automation. Accordingly, the Ministry of Information and Communications (MIC) has been working to replace the existing Telecom Law, with a Draft Telecom Law made available for public consultation from October 27 to December 27, 2022 (the Vietnamese version can be accessed here). The primary amendment of the Telecom Law focuses on widening the scope of application to regulate data center and cloud computing services. Data center services include data center space rental services, server rental services, and data storage space rental services. Cloud computing services include services providing server resources, storage capacity, and networks (IaaS services); services that provide the ability to create, develop, manage, and operate software, including applications (PaaS services); and software delivery services, including applications (SaaS services). According to the Draft Telecom Law, it could be interpreted that all providers of data center services and IaaS cloud computing services, whether onshore or offshore, must obtain a permit to provide the services by registration with the MIC via its online portal; while PaaS and SaaS cloud computing services are exempted from this requirement. In addition, the Draft Telecom Law adds
January 10, 2023
The National Assembly of Vietnam promulgated a new Law on Cinema in June 2022 with an effective date of January 1, 2023. To guide the implementation of the new law and the sanctioning of administrative violations thereof, the government of Vietnam issued two related decrees in the final days of 2022. Cinema Decree On December 31, 2022, the government issued Decree No. 131/2022/ND-CP elaborating a number of articles of the Cinema Law (“Cinema Decree”), which took effect with the new law on January 1, 2023. Among the many issues under the Cinema Law guided by the Cinema Decree, one that is critical to over-the-top (OTT) media service providers is the set of conditions for performing the mandatory self-rating of films to be disseminated in cyberspace. According to the Cinema Law, meeting the film self-rating conditions is one of the prerequisites for online dissemination of films. If a film disseminator does not meet these conditions, it would be required to request the Ministry of Culture, Sports and Tourism (MOCST) to perform the rating. The conditions for online disseminators to self-rate their films have now been set out under Article 12 of the Cinema Decree. Accordingly, these conditions include: Having a film rating council or technical software or a mechanism to rate the films according to Vietnamese regulations on film rating and taking responsibility for the results of film rating. Having a plan to amend and update film rating results at the request of the cinematography authority (for most providers, this is the Cinematography Department under the MOCST). Having an administrative tool to support the rating of films according to each of the rating criteria and to flexibly display the updated rating immediately after the rating is changed. Having a technical plan and process for suspending and removing films at the