You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 1, 2017

Government Surveillance, Security, and Privacy: Does Security Always Win? (Part 1)

Data Privacy Asia Newsletter

This article was first published in the Data Privacy Asia Newsletter.

In 1949 George Orwell penned a novel that described a world where government surveillance is all pervasive. When we read 1984  today we are struck by the remarkable, and sometimes chilling similarities between the dystopian vision of the author and the pervasive nature of mass surveillance in 2017. However, does this mean that we are faced with an ‘either/or’ proposition? Can there be a reasonable and acceptable balance between the necessity for surveillance in an ever more dangerous world and an individual’s right to privacy?

Can we, as individuals, manage to operate and live in a connected world and still retain some semblance of privacy where our online lives are subject to snooping by criminals, governments and commercial interests? This question is becoming ever more important as we realize that it is no longer feasible to go ‘off the grid’ and still maintain a ‘normal’ life. Governments across the globe cite the ever increasing risk of terrorism and security  as  justification for ever more broad surveillance powers. In these days of big data this question is becoming even more urgent. In the days before big data it was possible to compartmentalize our lives. We all present a persona ( a ‘face’) to the world in our professional lives, a different one in our home lives and perhaps a third social persona in our interactions with friends. We may even have other personas on different social media platforms.

A Single Identity

Today we’re always online and plugged in, creating a stream of continuous data 24/7 and the separation of our personas simply isn’t possible anymore. Your LinkedIn, your Facebook, your Grindr, your Ashley Madison, your E-Harmony, all your tweets, all of your calls, your location data, your Fit Bit/wearables, all the apps that you download and all the data that goes in and out of those apps are recorded and they collectively define you and your life, particularly to governments, to companies and to criminals—and the Internet of things will only make it worse.

Four hundred years ago Cardinal Richelieu reportedly said “if you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him.” When our lives are recorded as an on-going and continuous stream of data that we all generate every day from cradle to grave, how difficult would it be for a current or future government to find something in that stream that ‘violates’ a law? It would seem that that Cardinal’s statement made 400 years ago is more true today than ever before.

The days of predictive intervention (before crime takes place) based on big data may not be far off. How many have seen the Hollywood blockbuster Minority Report? The premise of that movie was the ability to arrest somebody prior to them committing a crime based on a prediction of their behavior. Think about that, if you have enough data about somebody, and enough processing power, you could potentially predict behavior. If you can predict behavior, while you may not make a pre-crime arrest you might, however, target law enforcement and physical surveillance assets on a person/group, or make an arrest if that person/group takes a step towards the completion of the predicted crime -which may not in fact be a crime in itself. We’re not that far off from that day.

Big Data Is Not All Bad

But big data and government access isn’t all bad. Big data provides us with functionality never before possible. Convenience, communication, power, health monitoring, online banking—we experience the benefits of big data every single day. Many, many crimes, very serious crimes, are solved today as a result of lawful government access to cloud and device-based digital information. Electronic and surveillance communications solve many crimes, sometimes even on par with DNA evidence. In our desire to protect privacy, we must not forget that there is a legitimate place for lawful government access of data through lawful process with adequate protection of our rights. The question is where to draw the line, and unfortunately today, we see many examples of governments around the world expanding their powers because technology enables such expansion. Technology should not be the driving factor when it comes to defining the power of governments as this will assuredly lead to the 1984  scenario of George Orwell.

The Transparency Check

Polls indicate that most people would trust their own national government more than they trust foreign governments when it comes to access of their personal data.. That’s natural. The question is how do you allow one government access to data and prevent other governments from getting access? As an example, say you are messaging someone from Singapore, while both parties are in Singapore but one party is a resident of Thailand. The conversation is on the subject of the Thai military and the King. It’s a conversation that is not in any way illegal in Singapore. Let’s assume it would be considered unlawful in Thailand. Should the Thai government, in that instance, have access to those online messages? If that access was granted then it is possible that the person would get arrested on his return to Thailand.

Conversely, what if I am in Thailand making statement that might be considered illegal in Singapore but not in Thailand? Should the Singapore government, the Thai government, or if the message goes through a U.S. intelligence collection system some place, the U.S. government, be able to intercept and read my private messages? Would it make any difference if the information is not out there in the cloud but is stored on my phone? Once you let the genie out of the bottle and grant governments access by a lawful legal process, how can we contain it? Governments (by their nature) and law enforcement and intelligence agencies, in particular, want all your information and data. But what keeps them in check? I would argue that one factor is the requirement for disclosure and transparency.

Revisiting Apple vs The U.S. Government

From a bit of a different perspective than what you might have seen or read about in the news, let’s consider what the FBI already had before it tried to compel Apple to compromise its own iPhone security. From Apple, the FBI already obtained all of the data that had been previously backed up to iCloud from the iPhone in question.. The phone was owned by the county of San Bernardino. It was not the suspect’s iPhone. The county of San Bernardino could give consent and, in fact did give consent to search, but the FBI went ahead and got a search warrant as well.

The suspect had turned on the iCloud backup but then turned it off, some time prior to the attack. Apple had already provided the FBI with all of the information that had been backed up to the iCloud. How could Apple do that? Apple holds the encryption keys for the information in iCloud. Therefore, when faced with lawful government access request, i.e. a search warrant, Apple could and did provide that information to the FBI.

From the telecom provider, the FBI already had the call records, the SMS information, the tower location and all the other meta data information. In fact, the only data that the FBI sought in the case was any data that was stored physically in the phone.

Should a company, or for that matter an individual, be permitted to create a digital ‘safe place’ that not even the company could enter even on orders of the government? According to the Director of the FBI, he believes there should be no way to go dark—there should be no safe place.

The  Director’s argument is that before the Internet, before electronic evidence, the entire purpose of the United States 4th Amendment in the Constitution, was to protect individuals from unreasonable and warrantless searches. But that didn’t mean that the government couldn’t access the information, it only meant that it had to have probable cause and obtain a warrant from a judge.

An individual who had some evidence, perhaps documents or perhaps a weapon , might put that evidence in a safe in his house and throw away the key—but that did not mean the government wasn’t able to get that evidence. It meant the government might have to break into the safe or use a locksmith or other mechanism to actually get into the safe. With the proper legal process followed, the FBI’s position is that there is no place where you can go dark.

Of course, today, much of the critical digital data of our lives  is sitting in the cloud or is stored in digital devices. Moreover, today, we are effectively compelled to give that information to third parties to hold and store on our behalf. It’s quite different than if you have some evidence and you are hiding it under the carpet in the floor in your living room. Today you must give your personal  information to third parties, and you are entrusting that information to a third party whether it’s a telephone company or a bank or another party. Under current U.S. law, absent a specific statute, data you provide to a third party (e.g., bank, Waze history, Quicken financial data) has no reasonable expectation of privacy, and is reachable by the government. The world has changed but the law has been slow to keep up—and this is a key area where the tension between privacy and lawful government access arises.

RELATED INSIGHTS​ 

August 10, 2026
On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation. Central Data-Sharing Platform The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures. Five Dimensions of Data Sharing The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C): G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination. G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication. B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary. B2C: Royal decrees may
August 10, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) recently released draft guidance on records of processing activities (ROPA) for personal data controllers and processors under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft guidance, which was presented to the public on July 7, 2026, addresses both controller records of collection, use, and disclosure of personal data and processor records of processing activities carried out on behalf of controllers. If implemented, the guidance will significantly expand organizational expectations for ROPA preparation, maintenance, and use across all sectors. Key Takeaways The draft guidance contains several important implications for organizations subject to the PDPA: ROPA reframed as a core accountability tool. The guidance elevates ROPA from an administrative record to a central accountability mechanism, connecting controller duties with recordkeeping obligations. ROPA as a source for privacy notices and governance documents. ROPA should serve as the primary source for privacy notices and align with consent management, retention schedules, DPIAs, incident response plans, and vendor contracts. Expanded scope across all activities. ROPA must cover all processing activities across the organization—including security, finance, HR, and external contractors—with correct controller or processor classification for each. Ongoing maintenance and auditability. ROPA must be updated for any change to systems, purposes, or processors, reviewed at least annually, and maintained with version control and a designated owner. Enhanced vendor, processor, and cross-border transfer requirements. Organizations must document all processors, external recipients, and cross-border transfers, specifying purposes, access scope, and destination countries. Linkage with risk assessment, DPIAs, and LIAs. ROPA should assign risk levels to each activity and identify when data protection impact assessments (DPIAs) or legitimate interests assessments (LIAs) are required, functioning as a risk-management tool. ROPA and data breach readiness. Incomplete ROPA can delay breach response and notification. Organizations should map data flows, vendors,
August 4, 2026
Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) could soon see some important changes, as a draft bill to amend the PDPA has been introduced in the House of Representatives. The draft amendment is currently in the public consultation phase, with comments accepted from July 16 to August 15, 2026. If enacted in its current form, the amendment would make three key changes: expanding the government exemption to cover anticorruption operations, introducing a statutory definition of “government agency,” and restructuring the lawful bases for personal data processing to align with international standards. Background The PDPA has encountered several enforcement challenges since its implementation, including three core problems identified by the bill’s sponsors: (1) the current exemptions for government agencies do not cover anticorruption and misconduct-prevention operations; (2) the PDPA lacks a clear statutory definition of “government agency,” causing legal uncertainty as to which entities are covered; and (3) the existing framework for lawful bases of data processing does not align with international standards—particularly the multiple-lawful-bases system in the EU’s General Data Protection Regulation (GDPR)—making compliance inflexible for both government and private sector entities. Expanded Government Exemption The current PDPA exempts government agencies performing duties related to national security (including fiscal security), public safety, anti-money laundering, forensic science, and cybersecurity. The proposed amendment adds “prevention and suppression of corruption and misconduct” to this list of exempted functions. This would allow anticorruption bodies—most notably the National Anti-Corruption Commission (NACC), which is identified as a directly affected party—to collect, use, and disclose personal data without being subject to PDPA requirements when carrying out their duties. New Statutory Definition of “Government Agency” Notably, while the current PDPA use the term “government agency” in several provisions, the term is not comprehensively defined, creating potential uncertainty as to its scope. The draft bill therefore
August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must