This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
|
cbdc:public:cbdc_omg:04_doc:15_common:50_international:20_local [2022/04/09 20:06] nick created |
cbdc:public:cbdc_omg:04_doc:15_common:50_international:20_local [2022/06/17 18:16] (current) terrance |
||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== 4.6.2 Data Localization ====== | ====== 4.6.2 Data Localization ====== | ||
| - | [[cbdc:private:cbdc_omg:04_doc:15_common:50_international:start | Return to Top]] | + | |< 100% >| |
| + | | [[cbdc:public:cbdc_omg:04_doc:15_common:50_international:start| International Considerations]] | <WRAP> | ||
| + | <html><b> | ||
| + | <a href="mailto:[email protected]?Subject=OMG's CBDC WG Response: | ||
| + | 4.6.2 Data Localization | ||
| + | |||
| + | ">Provide Feedback</a></b> | ||
| + | </html> | ||
| + | </WRAP> | | ||
| [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:d:data_localization | Data localization]] is about jurisdictions adopting policies with an aim to protect the jurisdictions' sovereignty over the data generated from within its geographic boundaries or from its residents. The policies are intended to help protect the jurisdiction and its residents from external entities (private or public). | [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:d:data_localization | Data localization]] is about jurisdictions adopting policies with an aim to protect the jurisdictions' sovereignty over the data generated from within its geographic boundaries or from its residents. The policies are intended to help protect the jurisdiction and its residents from external entities (private or public). | ||
| - | Figure {{ref>dataLocalIncrease}} shows the increase in **Data Localization** measures globally from 1960-2015. This increase indicates that this a problem and that it will only get bigger as time goes by. The CBDC needs to understand and recognize it as a growing international trend. | + | Figure {{ref>dataLocalIncrease}} shows the increase in **Data Localization** measures globally from 1960-2015. This increase indicates that this is a problem that will only get bigger as time goes by. The CBDC needs to understand and recognize it as a growing international trend. |
| <figure dataLocalIncrease> | <figure dataLocalIncrease> | ||
| - | {{ :cbdc:private:cbdc_omg:04_doc:15_common:50_international:screen_shot_2022-04-09_at_1.17.23_pm.png?700 |}} | + | {{ cbdc:04_doc:15_common:50_international:screen_shot_2022-04-09_at_1.17.23_pm.png?600 |}} |
| <caption>Increase in data localization measures globally (1960 - 2015)(( | <caption>Increase in data localization measures globally (1960 - 2015)(( | ||
| Emily Wu, | Emily Wu, | ||
| Line 21: | Line 29: | ||
| * [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:h:hacker&s[]=hacker | Hackers]] engaged in nefarious activities. | * [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:h:hacker&s[]=hacker | Hackers]] engaged in nefarious activities. | ||
| * [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:p:pii | Personal Identifiable Information (PII) ]] | * [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:p:pii | Personal Identifiable Information (PII) ]] | ||
| - | * Regulators wanting to access the information on participants in cross-boarder transactions | + | * Regulators wanting to access the information on participants in cross-border transactions |
| * External jurisdictions trying to identify individuals engaged in activities it finds illegal or offensive, but that are not considered that way locally | * External jurisdictions trying to identify individuals engaged in activities it finds illegal or offensive, but that are not considered that way locally | ||
| * Unwanted or desired commercial mining | * Unwanted or desired commercial mining | ||
| - | * Public opinion favoring in-country data-storage solutions and strategies | + | * Public opinion favoring in-country data storage solutions and strategies |
| - | And usually takes the form of mandate in the form of laws or regulations that require certain data to be physically stored on servers within the country of orgin. | + | This usually takes the form of a mandate and/or a set of laws or regulations that require certain data to be physically stored on servers within the country of origin. |
| Data Localization policies tend to fall into three categories(( | Data Localization policies tend to fall into three categories(( | ||
| Line 48: | Line 56: | ||
| </caption> | </caption> | ||
| |< 100% 20% 30% 50% >| | |< 100% 20% 30% 50% >| | ||
| - | ^ Localization Category ^ Description ^ Law or Regulation Examples ^ | + | ^ Localization Category ^ Description ^ Law or Regulation Examples ^ |
| ^ Local-only Storing, Transmission, and Processing ^ <WRAP> | ^ Local-only Storing, Transmission, and Processing ^ <WRAP> | ||
| - | This generally means an obligation to locally manage data or as a prohibition of international data transfers.16 This is the strictest type of localization policy and is more likely to be descriptive of nations seeking broader control over citizen activities. | + | This generally means an obligation to locally manage data or a prohibition of international data transfers. This is the strictest type of localization policy and is more likely to be descriptive of nations seeking broader control over citizen activities. |
| </WRAP> | <WRAP> | </WRAP> | <WRAP> | ||
| : **Russia** | : **Russia** | ||
| - | : Under Russia’s Federal Law No. 242-FZ, operators must ensure the recording, systematization, accumulation, storage, adjustment (update, alteration), and retrieval of personal data of citizens of the Russian Federation will be performed through database serves located in the territory of the Russian Federation.17 Substantial fines are imposed on organizations and individuals that fail to comply with data localization requirements.18 | + | : Under Russia’s Federal Law No. 242-FZ, operators must ensure the recording, systematization, accumulation, storage, adjustment (update, alteration), and retrieval of personal data of citizens of the Russian Federation will be performed through database servers located in the territory of the Russian Federation. Substantial fines are imposed on organizations and individuals that fail to comply with data localization requirements. |
| : **China** | : **China** | ||
| - | : Article 37 of the Cybersecurity Law of People’s Republic of China (‘CSL’) requires critical information infrastructure operators (‘CIIOs’) to store personal information and important data generated from critical information infrastructure in China19. These requirements are likely to be expanded by the Personal Information Protection Law, the draft of which was released in October 2020.20 | + | : Article 37 of the Cybersecurity Law of the People’s Republic of China (‘CSL’) requires critical information infrastructure operators (‘CIIOs’) to store personal information and important data generated from critical information infrastructure in China. These requirements are likely to be expanded by the Personal Information Protection Law, the draft of which was released in October 2020. |
| </WRAP> | | </WRAP> | | ||
| ^ Local Copy Required ^ <WRAP> | ^ Local Copy Required ^ <WRAP> | ||
| - | Companies are required to keep a copy of data in local servers or data centers. This allows for easier access to this data for regulation and law enforcement purposes I.e., it is generally easier for local law enforcement agencies to access data stored locally than it is for them to access data stored in another jurisdiction. | + | Companies are required to keep a copy of data in local servers or data centers. This allows for easier access to this data for regulation and law enforcement purposes, i.e., it is generally easier for local law enforcement agencies to access data stored locally than it is for them to access data stored in another jurisdiction. |
| </WRAP> | <WRAP> | </WRAP> | <WRAP> | ||
| : **India** | : **India** | ||
| - | : Under India’s Personal Data Protection Bill, sensitive personal data (which includes financial information) must be stored in India, but a copy of the data can be transferred internationally if certain requirements are met.21 These include: | + | : Under India’s Personal Data Protection Bill, sensitive personal data (which includes financial information) must be stored in India, but a copy of the data can be transferred internationally if certain requirements are met. These include: |
| - | * The data principal provides explicit consent, the transfer is made pursuant to a contract or intra-group scheme approved by the Data Protection Authority22 | + | : 1. The data principal provides explicit consent, the transfer is made pursuant to a contract or intra-group scheme approved by the Data Protection Authority |
| - | * The government has deemed a country to provide adequate protection23 | + | : 2. The government has deemed a country to provide adequate protection |
| - | * The Data Protection Authority has specifically authorized the transfer24 | + | : 3. The Data Protection Authority has specifically authorized the transfer |
| </WRAP> | | </WRAP> | | ||
| ^ Narrower, conditional restrictions ^ <WRAP> | ^ Narrower, conditional restrictions ^ <WRAP> | ||
| - | Transfers of data outside the country are only permitted if certain conditions are met by the transferee and/or by the recipient country.25 | + | Transfers of data outside the country are only permitted if certain conditions are met by the transferee and/or by the recipient country. |
| </WRAP> | <WRAP> | </WRAP> | <WRAP> | ||
| : **European Union** | : **European Union** | ||
| : Under the EU’s GDPR, the transfer of personal data outside the European Economic Area is permitted only where: | : Under the EU’s GDPR, the transfer of personal data outside the European Economic Area is permitted only where: | ||
| - | * The recipient is in a territory considered by the European Commission to offer an adequate level of protection for personal data26 | + | : 1. The recipient is in a territory considered by the European Commission to offer an adequate level of protection for personal data |
| - | * Safeguards are in place, such as binding corporate rules approved by Data Protection Authorities27 | + | : 2. Safeguards are in place, such as binding corporate rules approved by Data Protection Authorities |
| - | * A legal exemption applies, such as where data subjects provide explicit consent, the transfer is necessary to fulfil a contract or there is a public interest founded in EU or member state law28 | + | : 3. A legal exemption applies, such as where data subjects provide explicit consent, the transfer is necessary to fulfill a contract or there is a public interest founded in EU or member state law |
| : **Brazil** | : **Brazil** | ||
| - | : Under the General Personal Data Protection Law (LGPD) international data transfers are only permitted in certain situations, including when recipient countries ensure an adequate level of data protection, when approved legal mechanisms (such as model contract clauses) are employed or when data subjects have provided their consent.29 | + | : Under the General Personal Data Protection Law (LGPD) international data transfers are only permitted in certain situations, including when recipient countries ensure an adequate level of data protection, when approved legal mechanisms (such as model contract clauses) are employed or when data subjects have provided their consent. |
| </WRAP> | | </WRAP> | | ||
| </table> | </table> | ||