You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 9, 2023

AI, Privacy, and Data Protection: Legal Considerations in Southeast Asia

The significance of artificial intelligence (AI) is rapidly increasing worldwide, and Southeast Asia is no exception, as it plays a leading role in the technological development of many industries. AI has already proven its importance for driving business growth in areas such as e-commerce, finance, and healthcare, but its remarkable potential also raises concerns around privacy. As AI systems are designed to collect and process large amounts of data to improve their operation, it is necessary to balance the development of technology with the protection of individuals’ privacy.

Current Frameworks in Southeast Asia

This concern has been on regional policymakers’ agendas for many years. The ASEAN Framework on Personal Data Protection, which was adopted in 2016, is not legally binding and has no enforcement mechanism, but it serves as a guide for ASEAN member states in developing their own data protection laws and regulations.

Domestic data privacy laws are currently in force in five ASEAN member countries—Indonesia, Malaysia, the Philippines, Thailand, and Singapore—while Vietnam’s Personal Data Protection Decree is scheduled to take effect on July 1, 2023. This presents a challenge for ASEAN members, as adopting AI-related technology can further complicate data protection efforts due to the amount of personal data AI systems collect, as well as the complexity of the data used to train the AI algorithm.

Some ASEAN members have also made progress in regulating AI. For instance, Singapore released the Model AI Governance Framework in 2019 and launched the AI Governance Testing Framework and Toolkit in 2022—the world’s first such framework. Similarly, Thailand issued the Artificial Intelligence Ethics Guideline in 2019 to help government agencies in the development, promotion, and use of AI, and in 2023 adopted the Thailand Artificial Intelligence Guidelines to help the private sector develop AI-related work. These guidelines primarily focus on principles and ethics in developing AI-related technology, but lack a step-by-step implementation process that connects with privacy laws. Despite these early steps by some countries in ASEAN, there are no regional policies or consensus frameworks on how to implement and regulate AI in accordance with privacy laws in ASEAN member countries.

Legal Risks

If AI-related technology is developed without consideration for data protection, there is a risk of breaching personal data and affecting numerous data subjects, potentially resulting in mass litigation. Moreover, the lack of robust privacy laws and frameworks in many ASEAN member countries, coupled with the growing use of AI-related technology, also increases the risk of legal liabilities for companies that make use of this increasingly common technology.

In the event of a data breach or misuse of personal data, affected individuals may seek legal recourse against the companies that collected and processed their personal information. Such legal actions can result in significant financial and reputational damages for businesses, highlighting the need for effective data protection regulations and AI-related technology frameworks in ASEAN countries.

Technology companies with connections to developing AI systems are especially vulnerable. With the vast amount of data required for developing AI systems, these companies will face the challenge of lawfully collecting and processing data from a huge range of sources and data subjects.

Outlook

As AI-related technology continues to evolve and play a crucial role in the growth of many industries in Southeast Asia, it is important to ensure that its development is balanced with the protection of individuals’ privacy. While some ASEAN members have made progress in adopting AI regulations, more needs to be done to enforce data privacy laws and develop consensus frameworks for regulating AI in accordance with privacy laws. Such efforts will not only help protect individuals’ privacy but also mitigate legal risks associated with the use of AI-related technology. ASEAN member countries must continue to work together to achieve a balance between technological development and data protection in support of sustainable and ethical innovation for our digital future.

RELATED INSIGHTS​ 

August 26, 2021
Background In Thailand, bad-faith domain name registrations can present a unique challenge to brand owners. According to the current domain registration policy, Thai domain names can be based on the registered name of a company or organization, or on a registered trademark, depending on the domain name category. When Thailand’s domain name registrar, the Thai Network Information Centre Foundation (THNIC), considers applications for new domain names, it examines only whether the applicant meets these criteria – and not whether the application has been led in bad faith, such as when a registered company uses someone else’s registered trademark without authorization. Domain name registration in Thailand is a first-to-file system, so if all criteria are met, THNIC must allow registration. There are no opposition or cancellation proceedings, making it impossible for an interested person, as well as THNIC itself, to invalidate a Thai-registered domain name. Disputes between two legitimate owners Disputes sometimes arise between trademark owners and Thai-registered companies, such as third-party companies, local distributors, or even authorized trademark licensees who exploit the policy gap identified above. For instance, in a recent case a brand owner found that its Thailand distributor had been able to register a company name containing its registered trademark, and subsequently register such name as a domain name, without the trademark owner’s consent. Fortunately, the two parties had a strong existing business relationship as supplier and distributor; through amicable negotiation, the local distributor agreed to withdraw the disputed domain name. However, if both parties had insisted on their legitimate rights over the disputed name, the case would have had to proceed to court, as THNIC does not get involved in such disputes and offers no dispute resolution mechanisms. Navigating the options Trademark owners facing such a dispute have two options: initiating proceedings with the Intellectual Property
August 18, 2021
On July 15, 2021, Thailand’s Electronic Transactions Development Agency (ETDA) announced a public hearing for their draft royal decree to regulate digital platforms (particularly e-commerce and e-service platforms) that provide services to people in Thailand. The draft royal decree is to be issued under the country’s Electronic Transactions Act B.E. 2544 (2001) and will be of particular concern to digital platform operators, which are defined as operators of intermediary digital platforms that provide a connection space for platform users to offer goods, services, or intangible property via a computer network, regardless of whether a contract is made on the digital platform. The key elements of the current draft royal decree are as follows: Extraterritorial scope. Operators of digital platforms located outside Thailand may be subject to the royal decree if the platform is intended to provide services to people in Thailand (evidenced by actions such as inclusion of Thai language, Thai currency, Thai domain names, and so on). Appointment of a local representative. A foreign digital platform operator that falls under the extraterritorial scope of the royal decree must appoint a local representative in Thailand, without limitation of liability. Notification requirements. Regulated digital platform operators must notify the ETDA of their operations via an online submission channel. The ETDA will also develop an online channel for consumers to check or verify the list of regulated digital platform operators. Further notification requirements and procedures are to be prescribed by the ETDA later. Platform-related requirements. The draft royal decree also sets various platform-related requirements, depending on the size of the digital platform operator (to be specified later). These requirements relate to the following: Terms and conditions; Content display; Content rating; Feedback mechanisms; Dispute settlement; Access and use of data; Control of advertisements; Notice and takedown measures; User verification processes; Suspension of