
As we have seen how UN Cyber Crime Convention has turned into a cartel among state actors ever seeking more surveillance and censorship capacity over their respective constituencies, international treaty negotiations are becoming important fora for and origins of state and inter-state actions affecting people's digital rights around the world.
On the other hand, several Asian countries have suffered from massive data breaches from public and private data controllers, that have not been properly redressed due to the domestic data governance not caught up with the digital age.
Digital consumers in the region are not prioritized by the governments in the region too busy amassing their own surveillance capacities by signing on UNCC, to establish corporate accountability for the most basic consumer harms.
Hence an opportunity and challenge for digital consumers in Asia Pacific.
For instance, the ASEAN Digital Economy Framework Agreement (DEFA), "a landmark, region-wide pact initiated to accelerate Southeast Asia's transition into a premier digital community" is being negotiated. Many digital trade agreements have "data protection chapters" which oblige the parties to maintain strong data protection laws. Asian Pacific consumers can unite to make sure that such treaty chapter does not simply build highways for companies to transfer personal data cross-
border but impose genuine obligations for the state actors to protect digital consumers' data.
Digital trade agreements and the need for Asian Pacific digital consumers to unite
June 9, 2026 (Day 2) 11:30–12:50 (UTC+8)
Meeting Room 1, SMX Aura Convention Centre
KS Park, Open Net
Javier Ruiz, Amnesty International
Shobhit S., IT for Change
Nan Suttisom, Engage Media
Debora Christine, Tifa Foundation
Burcu Kilic, Third World Network
Through this session, we discussed:
- massive data breach incidents in Asia
- treaty negotiations around the world affecting digital consumer rights
- treaty provisions that we can demand from the negotiators for data breach redressability
- various ways of engagement with treaty negotiations
KS Park opened the discussion with the problems of massive data breaches in Asia, data protection chapters in digital trade agreements, and exactly what we need to push for in future digital trade agreements (or demand in exchange for, in case of concluded ones), and other needs for Asian harmonization. Toward that harmonization, KS showcased the South Korean jurisprudence on targeted advertising and whistle blowing on both sides of the spectrum of applying data protection law for consumers.
Shobit noted the emergence of digital governance as an increasingly important frontier for consumer rights and presented India's evolving digital governance ecosystem as a case study. He focused on India's public interest regulatory measures at stake in ongoing trade negotiations with the US (e.g. - conditionalities on outward flows of personal data, policies to promote competition in digital markets, due diligence requirements for intermediaries). Specifically, NTE identifies legitimate measures as barriers such as 20% market cap on digital competition and financial data localization) He concluded on --- A concluding note on what consumer rights advocates in the APAC should guard against, in ongoing and forthcoming trade negotiations. He also said that using trade agreements to strengthen consumer rights seems quite challenging in the current political context. Accordingly, I intend to frame engagement with digital trade negotiations as a "defensive" necessity for consumer groups - to preserve the policy space required for stronger consumer protection.
Nan interjected on how there's very little to no movement/discourse around DEFA in Thailand apart from the government parading their commitment to finalise it (it already is). She pivoted then to talk about concerns from CSO perspectives. No availabiity of DEFA text. Does DEFA violation has remedies. We need to demand transparency.
Debora spoke about the tension between the US-Indonesia ART and Indonesia's PDP Law (pre-designation of the US as an adequate data protection jurisdiction before Indonesia has established its own adequacy assessment mechanism); about the ongoing administrative lawsuit contesting the procedural legality of ART as an advocacy instrument; and the urgency of leveraging the ratification window, finalizing PDPL derivative regulations (which clarifies adequacy assessment and PDPA mandate).
She also pointed out the structural gap that is directly relevant to this coalition, regarding the limited mandate and standing of the ASEAN Committee on Consumer Protection and the ASEAN Consumer Agencies Network which does not extend to trade agreement negotiations.
Javier emphasized the restrictions on algorithms and their implications for AI regulations. In relation to that, he talked about the EU Singapore digital trade agreement and how it clashes with the EU approach but they are just covering their eyes and ears and digging themselves in a deeper hole. For instance, EU Singapore digital trade agreement has source code access restriction when EU AI act allows regulators’ access to source code. In other parts of the world, the consumer-friendly payment systems in Brazil were found discriminatory against US and sanctioned by US. EU is not a model on data protection, especially on redressability, either. In Asia, policies are being developed by governments and businesses. Still, according to him, “consumers” is a good gateway into the meeting rooms because businesses want the consumers to buy the products.
0 Comments