You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 9, 2023

AI, Privacy, and Data Protection: Legal Considerations in Southeast Asia

The significance of artificial intelligence (AI) is rapidly increasing worldwide, and Southeast Asia is no exception, as it plays a leading role in the technological development of many industries. AI has already proven its importance for driving business growth in areas such as e-commerce, finance, and healthcare, but its remarkable potential also raises concerns around privacy. As AI systems are designed to collect and process large amounts of data to improve their operation, it is necessary to balance the development of technology with the protection of individuals’ privacy.

Current Frameworks in Southeast Asia

This concern has been on regional policymakers’ agendas for many years. The ASEAN Framework on Personal Data Protection, which was adopted in 2016, is not legally binding and has no enforcement mechanism, but it serves as a guide for ASEAN member states in developing their own data protection laws and regulations.

Domestic data privacy laws are currently in force in five ASEAN member countries—Indonesia, Malaysia, the Philippines, Thailand, and Singapore—while Vietnam’s Personal Data Protection Decree is scheduled to take effect on July 1, 2023. This presents a challenge for ASEAN members, as adopting AI-related technology can further complicate data protection efforts due to the amount of personal data AI systems collect, as well as the complexity of the data used to train the AI algorithm.

Some ASEAN members have also made progress in regulating AI. For instance, Singapore released the Model AI Governance Framework in 2019 and launched the AI Governance Testing Framework and Toolkit in 2022—the world’s first such framework. Similarly, Thailand issued the Artificial Intelligence Ethics Guideline in 2019 to help government agencies in the development, promotion, and use of AI, and in 2023 adopted the Thailand Artificial Intelligence Guidelines to help the private sector develop AI-related work. These guidelines primarily focus on principles and ethics in developing AI-related technology, but lack a step-by-step implementation process that connects with privacy laws. Despite these early steps by some countries in ASEAN, there are no regional policies or consensus frameworks on how to implement and regulate AI in accordance with privacy laws in ASEAN member countries.

Legal Risks

If AI-related technology is developed without consideration for data protection, there is a risk of breaching personal data and affecting numerous data subjects, potentially resulting in mass litigation. Moreover, the lack of robust privacy laws and frameworks in many ASEAN member countries, coupled with the growing use of AI-related technology, also increases the risk of legal liabilities for companies that make use of this increasingly common technology.

In the event of a data breach or misuse of personal data, affected individuals may seek legal recourse against the companies that collected and processed their personal information. Such legal actions can result in significant financial and reputational damages for businesses, highlighting the need for effective data protection regulations and AI-related technology frameworks in ASEAN countries.

Technology companies with connections to developing AI systems are especially vulnerable. With the vast amount of data required for developing AI systems, these companies will face the challenge of lawfully collecting and processing data from a huge range of sources and data subjects.

Outlook

As AI-related technology continues to evolve and play a crucial role in the growth of many industries in Southeast Asia, it is important to ensure that its development is balanced with the protection of individuals’ privacy. While some ASEAN members have made progress in adopting AI regulations, more needs to be done to enforce data privacy laws and develop consensus frameworks for regulating AI in accordance with privacy laws. Such efforts will not only help protect individuals’ privacy but also mitigate legal risks associated with the use of AI-related technology. ASEAN member countries must continue to work together to achieve a balance between technological development and data protection in support of sustainable and ethical innovation for our digital future.

RELATED INSIGHTS​ 

July 25, 2022
Vietnam’s current Law on E-Transactions was passed in 2005 and has been effective since March 1, 2006. This law is considered a framework law, developed based on the Model Law on E-Commerce of the United Nations Commission on International Trade Law (UNCITRAL). According to the Ministry of Information and Communications (MIC), over the past 17 years, the implementation and application of e-transactions has shown significant evolution in certain areas demanding high levels of international integration, such as banking and e-commerce, but has faced difficulties in other areas due to a lack of detailed guidance. In addition, with the strong growth and breakthrough development of digital technologies such as artificial intelligence, big data, biometrics, and blockchain, and in the context of the ongoing Industrial Revolution 4.0 and the development of digital government, digital economy, and digital society, the 2005 Law on E-Transactions has revealed its shortcomings. Therefore, the government of Vietnam has entrusted the MIC to take the lead in drafting a new Law on E-Transactions, which will replace the old 2005 law in order to meet the country’s development needs. Accordingly, the MIC published a Draft Law on E-Transactions (“Draft Law”) for public consultation from May 4 to July 4, 2022. The latest accessible version of the Draft Law at the time of writing is Version 4. The effective date of the Draft Law is still not yet determined, though this law is expected to be submitted to the National Assembly for its review and comments in October 2022 and approval in May 2023. The following are some key contents of the Draft Law: 1. Scope of Application Unlike the current law, which explicitly excludes certain areas such as the issuance of certificates of land use rights and marriage certificates from the scope of application, the Draft Law attempts
July 19, 2022
On June 23, 2022, Thailand’s Securities and Exchange Commission (SEC) opened a public hearing period on regulatory controls for initial coin offering (ICO) portals that serve as financial advisors to digital token issuers. The proposed measures aim to prevent conflicts of interest; allow ICO portals to outsource certain functions; and establish additional notification obligations for ICO portals. The public hearing is open for general comments until July 23, 2022, and the new legislation is expected to be issued soon after that. During the public hearing period, any interested parties can comment on the SEC’s proposed principles. The key proposed points are outlined below. Conflicts of Interest Similar to SEC-approved financial advisors for securities offerings, ICO portals must be clear of conflicts of interest when representing issuers in a coin offering. According to the draft regulation, the following conflicts of interest are prohibited: The ICO portal (and certain individuals as specified by the SEC) directly or indirectly holds a prohibited amount of shares in the issuer, its affiliates, or its subsidiaries. If the issuer is not a listed company, any shareholding or portion thereof is prohibited. If the issuer is a listed company on the Stock Exchange of Thailand (SET), the shares held by the ICO platform may not total more than five percent of the total voting rights. The issuer (and certain individuals as specified by the SEC) directly or indirectly holds shares in the ICO portal in any amount if the ICO portal is not a listed company, or totaling more than five percent of the voting rights if the ICO portal is listed on the SET. Any of the ICO portal’s directors or executives, or the head of the department responsible for screening the ICO project, is also a director in the issuer. The ICO portal has
June 30, 2022
On May 30, 2022, Thailand’s Securities and Exchange Commission (SEC) announced that it would start regulating ready-to-use utility tokens, a type of digital token that had previously been exempted from the SEC’s approval and regulatory control. A public forum was open for comments from various stakeholders until June 29, 2022, and the draft regulation is expected to be issued soon. So far, the SEC has only supervised the issuance of not-ready-to-use utility tokens—digital tokens with the underlying right to acquire specific goods or services, which cannot be utilized upon issuance but at a later date. Due to the growing digital asset industry and lack of regulatory control, ready-to-use utility tokens have become more popular and many are listed for trading in digital asset exchanges. The SEC claimed that it is now necessary to regulate ready-to-use utility tokens as some issuers appeared to be exploiting the regulatory loophole to manipulate the price and supply of these tokens in both the primary and secondary markets, while providing insufficient data disclosure to investors. The SEC’s proposed principles include the following key points: Pre-Approval Requirements The same pre-approval requirement applicable to not-ready-to-use utility tokens will apply to ready-to-use utility tokens which an issuer intends to list on a digital asset exchange. This means that the issuer must proceed with the standard formalities, i.e., obtaining prior approval from the SEC, filing a draft prospectus, and offering the approved tokens via a SEC-approved ICO portal operator only. The SEC offers a fast-track (15 days) approval for qualifying ready-to-use utility tokens, which are those with plain-vanilla characteristics; with an offering price corresponding to the value of the underlying goods/services; for which the supply of goods and services does not vary with the price of the tokens (i.e., fixed coins); and which are not intended to be
June 30, 2022
Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) became fully effective and enforceable on June 1, 2022. To ensure that the PDPA will be smoothly and efficiently enforced, the Personal Data Protection Commission (PDPC) is issuing various subordinate regulations. On June 20, 2022, the first set of these regulations was issued and published in the Government Gazette, and according to the Ministry of Digital Economy and Society (MDES), another set of subordinate regulations is expected to be issued by the end of June 2022. The first set consists of the following four subordinate regulations:   1) Notification of the PDPC Re: Exemption to the Record of Processing Activities Requirement for Data Controllers that Are Small Businesses B.E. 2565 (2022) (“ROPA Exemption Notification”) Under the PDPA, data controllers are obligated to prepare and maintain a record of processing activities (ROPA) containing information specified in Section 39 of the PDPA, including the personal data collected, the purposes of the processing of the personal data, the retention period, etc. However, under this ROPA Exemption Notification, a data controller will be exempted from the obligation to prepare and maintain a record of such required information (except information related to the rejection of a request from a data subject to exercise (i) right of access; (ii) right to data portability; (iii) right to object; and (iv) right to rectification), if its business falls within the scope of any of the following: Small or medium-sized business according to the law on small and medium-sized enterprise promotion, defined as follows: Community enterprise or social enterprise, as referred to under the law on community enterprise promotion. Social enterprise, as referred to under the under the law on social enterprise promotion. Cooperative, cooperative union, or agriculturist’s group under the law on cooperatives. Foundation, association, religious body, or