You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 1, 2017

Government Surveillance, Security, and Privacy: Does Security Always Win? (Part 1)

Data Privacy Asia Newsletter

This article was first published in the Data Privacy Asia Newsletter.

In 1949 George Orwell penned a novel that described a world where government surveillance is all pervasive. When we read 1984  today we are struck by the remarkable, and sometimes chilling similarities between the dystopian vision of the author and the pervasive nature of mass surveillance in 2017. However, does this mean that we are faced with an ‘either/or’ proposition? Can there be a reasonable and acceptable balance between the necessity for surveillance in an ever more dangerous world and an individual’s right to privacy?

Can we, as individuals, manage to operate and live in a connected world and still retain some semblance of privacy where our online lives are subject to snooping by criminals, governments and commercial interests? This question is becoming ever more important as we realize that it is no longer feasible to go ‘off the grid’ and still maintain a ‘normal’ life. Governments across the globe cite the ever increasing risk of terrorism and security  as  justification for ever more broad surveillance powers. In these days of big data this question is becoming even more urgent. In the days before big data it was possible to compartmentalize our lives. We all present a persona ( a ‘face’) to the world in our professional lives, a different one in our home lives and perhaps a third social persona in our interactions with friends. We may even have other personas on different social media platforms.

A Single Identity

Today we’re always online and plugged in, creating a stream of continuous data 24/7 and the separation of our personas simply isn’t possible anymore. Your LinkedIn, your Facebook, your Grindr, your Ashley Madison, your E-Harmony, all your tweets, all of your calls, your location data, your Fit Bit/wearables, all the apps that you download and all the data that goes in and out of those apps are recorded and they collectively define you and your life, particularly to governments, to companies and to criminals—and the Internet of things will only make it worse.

Four hundred years ago Cardinal Richelieu reportedly said “if you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him.” When our lives are recorded as an on-going and continuous stream of data that we all generate every day from cradle to grave, how difficult would it be for a current or future government to find something in that stream that ‘violates’ a law? It would seem that that Cardinal’s statement made 400 years ago is more true today than ever before.

The days of predictive intervention (before crime takes place) based on big data may not be far off. How many have seen the Hollywood blockbuster Minority Report? The premise of that movie was the ability to arrest somebody prior to them committing a crime based on a prediction of their behavior. Think about that, if you have enough data about somebody, and enough processing power, you could potentially predict behavior. If you can predict behavior, while you may not make a pre-crime arrest you might, however, target law enforcement and physical surveillance assets on a person/group, or make an arrest if that person/group takes a step towards the completion of the predicted crime -which may not in fact be a crime in itself. We’re not that far off from that day.

Big Data Is Not All Bad

But big data and government access isn’t all bad. Big data provides us with functionality never before possible. Convenience, communication, power, health monitoring, online banking—we experience the benefits of big data every single day. Many, many crimes, very serious crimes, are solved today as a result of lawful government access to cloud and device-based digital information. Electronic and surveillance communications solve many crimes, sometimes even on par with DNA evidence. In our desire to protect privacy, we must not forget that there is a legitimate place for lawful government access of data through lawful process with adequate protection of our rights. The question is where to draw the line, and unfortunately today, we see many examples of governments around the world expanding their powers because technology enables such expansion. Technology should not be the driving factor when it comes to defining the power of governments as this will assuredly lead to the 1984  scenario of George Orwell.

The Transparency Check

Polls indicate that most people would trust their own national government more than they trust foreign governments when it comes to access of their personal data.. That’s natural. The question is how do you allow one government access to data and prevent other governments from getting access? As an example, say you are messaging someone from Singapore, while both parties are in Singapore but one party is a resident of Thailand. The conversation is on the subject of the Thai military and the King. It’s a conversation that is not in any way illegal in Singapore. Let’s assume it would be considered unlawful in Thailand. Should the Thai government, in that instance, have access to those online messages? If that access was granted then it is possible that the person would get arrested on his return to Thailand.

Conversely, what if I am in Thailand making statement that might be considered illegal in Singapore but not in Thailand? Should the Singapore government, the Thai government, or if the message goes through a U.S. intelligence collection system some place, the U.S. government, be able to intercept and read my private messages? Would it make any difference if the information is not out there in the cloud but is stored on my phone? Once you let the genie out of the bottle and grant governments access by a lawful legal process, how can we contain it? Governments (by their nature) and law enforcement and intelligence agencies, in particular, want all your information and data. But what keeps them in check? I would argue that one factor is the requirement for disclosure and transparency.

Revisiting Apple vs The U.S. Government

From a bit of a different perspective than what you might have seen or read about in the news, let’s consider what the FBI already had before it tried to compel Apple to compromise its own iPhone security. From Apple, the FBI already obtained all of the data that had been previously backed up to iCloud from the iPhone in question.. The phone was owned by the county of San Bernardino. It was not the suspect’s iPhone. The county of San Bernardino could give consent and, in fact did give consent to search, but the FBI went ahead and got a search warrant as well.

The suspect had turned on the iCloud backup but then turned it off, some time prior to the attack. Apple had already provided the FBI with all of the information that had been backed up to the iCloud. How could Apple do that? Apple holds the encryption keys for the information in iCloud. Therefore, when faced with lawful government access request, i.e. a search warrant, Apple could and did provide that information to the FBI.

From the telecom provider, the FBI already had the call records, the SMS information, the tower location and all the other meta data information. In fact, the only data that the FBI sought in the case was any data that was stored physically in the phone.

Should a company, or for that matter an individual, be permitted to create a digital ‘safe place’ that not even the company could enter even on orders of the government? According to the Director of the FBI, he believes there should be no way to go dark—there should be no safe place.

The  Director’s argument is that before the Internet, before electronic evidence, the entire purpose of the United States 4th Amendment in the Constitution, was to protect individuals from unreasonable and warrantless searches. But that didn’t mean that the government couldn’t access the information, it only meant that it had to have probable cause and obtain a warrant from a judge.

An individual who had some evidence, perhaps documents or perhaps a weapon , might put that evidence in a safe in his house and throw away the key—but that did not mean the government wasn’t able to get that evidence. It meant the government might have to break into the safe or use a locksmith or other mechanism to actually get into the safe. With the proper legal process followed, the FBI’s position is that there is no place where you can go dark.

Of course, today, much of the critical digital data of our lives  is sitting in the cloud or is stored in digital devices. Moreover, today, we are effectively compelled to give that information to third parties to hold and store on our behalf. It’s quite different than if you have some evidence and you are hiding it under the carpet in the floor in your living room. Today you must give your personal  information to third parties, and you are entrusting that information to a third party whether it’s a telephone company or a bank or another party. Under current U.S. law, absent a specific statute, data you provide to a third party (e.g., bank, Waze history, Quicken financial data) has no reasonable expectation of privacy, and is reachable by the government. The world has changed but the law has been slow to keep up—and this is a key area where the tension between privacy and lawful government access arises.

RELATED INSIGHTS​ 

April 3, 2026
Thailand’s Securities and Exchange Commission (SEC) has established a comprehensive governance framework for the use of artificial intelligence and machine learning (AI/ML) in the capital markets. The framework provides guidance to capital market business operators on understanding the risks associated with AI/ML implementation and adopting appropriate practices to build public confidence in Thailand’s capital markets. While the guidelines are principle-based rather than prescriptive, they reflect the SEC’s expectations for responsible AI/ML governance and are likely to inform supervisory activities and industry standards going forward. Scope The framework applies to capital market business operators supervised by the SEC. This includes, for example, securities and derivatives firms, asset management companies, mutual fund and private fund managers, investment advisors and investment consultants (including robo-advisory service providers), derivatives intermediaries, and other licensed intermediaries and market operators in the Thai capital markets that deploy AI/ML in their operations. Core Principles of the Guidelines The framework is presented as a best-practice manual rather than prescriptive regulation, providing guidance that regulated entities may apply to their AI/ML governance and risk management as appropriate. While currently nonbinding, the guidelines signal the SEC’s expectations for the sector, particularly in relation to other binding SEC regulations such as those covering IT risk management and market conduct. The guidelines name four core principles for AI/ML deployment: Fairness: Design and develop AI/ML with consideration for fairness, equality, and social diversity to prevent discrimination against individuals or groups. Legal and ethical compliance: Ensure AI/ML use aligns with applicable laws, ethical standards, and organizational values and policies. Accountability: Establish clear responsibility—both internally and externally—for AI/ML activities and outcomes. Transparency: Provide adequate disclosure to users about AI/ML use, including explainability of decisions and traceability of activities. AI/ML Best Practices The guidelines prescribe best practices across four stages of the AI/ML lifecycle, as described below.
April 2, 2026
Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance. What Has Changed: OIC and PDPC Alignment The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers. Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible. Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors. Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels. DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on
March 30, 2026
On March 24, 2026, the Trade Competition Commission of Thailand (TCCT) published its long-anticipated Guidelines on Multi-Sided Platforms and E-Commerce Businesses in the Government Gazette, following the conclusion of a public hearing conducted last year. The guidelines entered into force on March 25, 2026, and significantly expand the application of Thai competition law to digital platform ecosystems. These rules introduce targeted restrictions on platform conduct, such as price-ranking algorithms and tying and bunding, that leverages network effects, and will have far-reaching implications across Thailand’s digital economy—affecting not only platform operators but also platform participants, including sellers, logistics providers, advertisers, and payment service providers operating on or alongside such platforms. The guidelines clarify how existing prohibitions under the Trade Competition Act B.E. 2560 (2017) (TCA)—including abuse of market dominance, cartel conduct, and unfair trade practices—apply in the context of platform-based business models. While many provisions reflect earlier draft guidelines, the final version delivers more precise definitions and clearer enforcement parameters, increasing regulatory certainty while also raising compliance expectations. Applicability The guidelines introduce core definitions that determine their coverage: Multi-sided platform: A platform that acts as an intermediary connecting two or more groups of users, enabling them to have direct interaction in order to exchange or rely on services from one another. Examples include digital platforms for trading goods or services (e-commerce), as defined below. Digital platform for trading goods or services (e-commerce): A platform that acts as an intermediary connecting the distribution, purchase, sale, or exchange of goods or services. This includes operations carried out to facilitate transactions or interactions between business operators through an electronic transaction system, regardless of whether a service fee is charged. Operator of a digital platform business for trading goods or services: A provider of digital platform services for trading goods or services, as described
March 27, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has publicly indicated that it is preparing a new regulatory framework for data center operators that may introduce foreign-ownership restrictions. In particular, the NBTC is considering reclassifying data center operations from a type 1 telecommunications business license to a type 3 license. If implemented, this change would subject data center operators to a significantly more stringent regulatory regime, especially in relation to foreign ownership and control. The NBTC has indicated that it intends to propose a draft framework to the NBTC board. This would be followed by a public hearing process, with a view to implementing the new rules within 2026. Under the Telecommunications Business Act B.E. 2544 (2001), as amended, telecommunications businesses operating under type 3 licenses are subject to foreign ownership restrictions, including a requirement that less than 50% of the total issued shares be held by foreign shareholders. In addition, type 3 licensees are subject to foreign dominance restrictions, which prohibit arrangements that allow foreigners to dominate the business. These foreign dominance restrictions are broad in scope and may capture various forms of direct and indirect control or influence. This includes circumstances in which a foreign national is able to influence or control the formulation of policy, management, or business operations, or the appointment of directors or senior executives. At this stage, the exact scope of the proposed rules remains unclear. Businesses with existing or planned data center operations in Thailand should therefore monitor upcoming NBTC developments in this regard and prepare for the expected public hearing process.