This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
cbdc:public:cbdc_omg:04_doc:15_common:50_international:20_local [2022/04/10 19:58] nick |
cbdc:public:cbdc_omg:04_doc:15_common:50_international:20_local [2022/06/17 18:16] (current) terrance |
||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== 4.6.2 Data Localization ====== | ====== 4.6.2 Data Localization ====== | ||
| - | [[cbdc:private:cbdc_omg:04_doc:15_common:50_international:start | Return to Top]] | + | |< 100% >| |
| + | | [[cbdc:public:cbdc_omg:04_doc:15_common:50_international:start| International Considerations]] | <WRAP> | ||
| + | <html><b> | ||
| + | <a href="mailto:[email protected]?Subject=OMG's CBDC WG Response: | ||
| + | 4.6.2 Data Localization | ||
| + | |||
| + | ">Provide Feedback</a></b> | ||
| + | </html> | ||
| + | </WRAP> | | ||
| [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:d:data_localization | Data localization]] is about jurisdictions adopting policies with an aim to protect the jurisdictions' sovereignty over the data generated from within its geographic boundaries or from its residents. The policies are intended to help protect the jurisdiction and its residents from external entities (private or public). | [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:d:data_localization | Data localization]] is about jurisdictions adopting policies with an aim to protect the jurisdictions' sovereignty over the data generated from within its geographic boundaries or from its residents. The policies are intended to help protect the jurisdiction and its residents from external entities (private or public). | ||
| - | Figure {{ref>dataLocalIncrease}} shows the increase in **Data Localization** measures globally from 1960-2015. This increase indicates that this a problem and that it will only get bigger as time goes by. The CBDC needs to understand and recognize it as a growing international trend. | + | Figure {{ref>dataLocalIncrease}} shows the increase in **Data Localization** measures globally from 1960-2015. This increase indicates that this is a problem that will only get bigger as time goes by. The CBDC needs to understand and recognize it as a growing international trend. |
| <figure dataLocalIncrease> | <figure dataLocalIncrease> | ||
| - | {{ :cbdc:private:cbdc_omg:04_doc:15_common:50_international:screen_shot_2022-04-09_at_1.17.23_pm.png?700 |}} | + | {{ cbdc:04_doc:15_common:50_international:screen_shot_2022-04-09_at_1.17.23_pm.png?600 |}} |
| <caption>Increase in data localization measures globally (1960 - 2015)(( | <caption>Increase in data localization measures globally (1960 - 2015)(( | ||
| Emily Wu, | Emily Wu, | ||
| Line 21: | Line 29: | ||
| * [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:h:hacker&s[]=hacker | Hackers]] engaged in nefarious activities. | * [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:h:hacker&s[]=hacker | Hackers]] engaged in nefarious activities. | ||
| * [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:p:pii | Personal Identifiable Information (PII) ]] | * [[https://www.omgwiki.org/dido/doku.php?id=dido:public:ra:xapend:xapend.a_glossary:p:pii | Personal Identifiable Information (PII) ]] | ||
| - | * Regulators wanting to access the information on participants in cross-boarder transactions | + | * Regulators wanting to access the information on participants in cross-border transactions |
| * External jurisdictions trying to identify individuals engaged in activities it finds illegal or offensive, but that are not considered that way locally | * External jurisdictions trying to identify individuals engaged in activities it finds illegal or offensive, but that are not considered that way locally | ||
| * Unwanted or desired commercial mining | * Unwanted or desired commercial mining | ||
| - | * Public opinion favoring in-country data-storage solutions and strategies | + | * Public opinion favoring in-country data storage solutions and strategies |
| - | And usually takes the form of mandate in the form of laws or regulations that require certain data to be physically stored on servers within the country of origin. | + | This usually takes the form of a mandate and/or a set of laws or regulations that require certain data to be physically stored on servers within the country of origin. |
| Data Localization policies tend to fall into three categories(( | Data Localization policies tend to fall into three categories(( | ||
| Line 48: | Line 56: | ||
| </caption> | </caption> | ||
| |< 100% 20% 30% 50% >| | |< 100% 20% 30% 50% >| | ||
| - | ^ Localization Category ^ Description ^ Law or Regulation Examples ^ | + | ^ Localization Category ^ Description ^ Law or Regulation Examples ^ |
| ^ Local-only Storing, Transmission, and Processing ^ <WRAP> | ^ Local-only Storing, Transmission, and Processing ^ <WRAP> | ||
| - | This generally means an obligation to locally manage data or as a prohibition of international data transfers. This is the strictest type of localization policy and is more likely to be descriptive of nations seeking broader control over citizen activities. | + | This generally means an obligation to locally manage data or a prohibition of international data transfers. This is the strictest type of localization policy and is more likely to be descriptive of nations seeking broader control over citizen activities. |
| </WRAP> | <WRAP> | </WRAP> | <WRAP> | ||
| Line 57: | Line 65: | ||
| : **China** | : **China** | ||
| - | : Article 37 of the Cybersecurity Law of People’s Republic of China (‘CSL’) requires critical information infrastructure operators (‘CIIOs’) to store personal information and important data generated from critical information infrastructure in China. These requirements are likely to be expanded by the Personal Information Protection Law, the draft of which was released in October 2020. | + | : Article 37 of the Cybersecurity Law of the People’s Republic of China (‘CSL’) requires critical information infrastructure operators (‘CIIOs’) to store personal information and important data generated from critical information infrastructure in China. These requirements are likely to be expanded by the Personal Information Protection Law, the draft of which was released in October 2020. |
| </WRAP> | | </WRAP> | | ||
| ^ Local Copy Required ^ <WRAP> | ^ Local Copy Required ^ <WRAP> | ||
| Line 64: | Line 72: | ||
| : **India** | : **India** | ||
| : Under India’s Personal Data Protection Bill, sensitive personal data (which includes financial information) must be stored in India, but a copy of the data can be transferred internationally if certain requirements are met. These include: | : Under India’s Personal Data Protection Bill, sensitive personal data (which includes financial information) must be stored in India, but a copy of the data can be transferred internationally if certain requirements are met. These include: | ||
| - | * The data principal provides explicit consent, the transfer is made pursuant to a contract or intra-group scheme approved by the Data Protection Authority | + | : 1. The data principal provides explicit consent, the transfer is made pursuant to a contract or intra-group scheme approved by the Data Protection Authority |
| - | * The government has deemed a country to provide adequate protection | + | : 2. The government has deemed a country to provide adequate protection |
| - | * The Data Protection Authority has specifically authorized the transfer | + | : 3. The Data Protection Authority has specifically authorized the transfer |
| </WRAP> | | </WRAP> | | ||
| ^ Narrower, conditional restrictions ^ <WRAP> | ^ Narrower, conditional restrictions ^ <WRAP> | ||
| Line 73: | Line 81: | ||
| : **European Union** | : **European Union** | ||
| : Under the EU’s GDPR, the transfer of personal data outside the European Economic Area is permitted only where: | : Under the EU’s GDPR, the transfer of personal data outside the European Economic Area is permitted only where: | ||
| - | * The recipient is in a territory considered by the European Commission to offer an adequate level of protection for personal data | + | : 1. The recipient is in a territory considered by the European Commission to offer an adequate level of protection for personal data |
| - | * Safeguards are in place, such as binding corporate rules approved by Data Protection Authorities | + | : 2. Safeguards are in place, such as binding corporate rules approved by Data Protection Authorities |
| - | * A legal exemption applies, such as where data subjects provide explicit consent, the transfer is necessary to fulfil a contract or there is a public interest founded in EU or member state law | + | : 3. A legal exemption applies, such as where data subjects provide explicit consent, the transfer is necessary to fulfill a contract or there is a public interest founded in EU or member state law |
| : **Brazil** | : **Brazil** | ||