Over 90 countries and jurisdictions around the world have adopted comprehensive data protection/privacy laws to protect personal data held by both governments and private companies. This map shows which countries have adopted laws or have pending initiatives to adopt one. The new version now includes small jurisdictions and island states. Note: This map has been updated- see National Comprehensive Data Protection/Privacy Laws and Bills 2021.
Blue - Comprehensive Data Protection Law Enacted (122:103 UN/19 self gov)
Red - Pending Bill or Initiative to Enact Law (34/3)
White - No initiatives or no information (56)
National Comprehensive Data Protection/Privacy Laws and Bills 2019
David Banisar
April 2019
Mobile health (mHealth) systems empower Community Health Workers (CHWs) around the world, by supporting the provisioning of Community-Based Primary Health Care (CBPHC) – primary care outside the health facility into people's homes. In particular, Mobile Health Data Collection Systems (MDCSs) are used by CHWs to collect health-related data about the families that they treat, replacing paper-based approaches for health surveys. Although MDCSs significantly improve the overall efficiency of CBPHC, existing and proposed solutions lack adequate privacy and security safeguards. In order to bridge this knowledge gap between the research areas of mHealth and privacy, the main research question of this thesis is: How to design secure and privacy-preserving systems for Mobile Health Data Collection Systems? To answer this question, the Design Method is chosen as an engineering approach to analyse and design privacy and security mechanisms for MDCSs. Among the main contributions, a comprehensive literature review of the Brazilian mHealth ecosystem is presented. This review led us to focus on MDCSs due to their impact on Brazil's CBPHC, the Family Health Strategy programme. On the privacy engineering side, the contributions are a Privacy Impact Assessment (PIA) for the GeoHealth MDCS and three mechanisms: (a) SecourHealth, a security framework for data encryption and user authentication; (b) an Ontology-based Data Sharing System (O-DSS) that provides obfuscation and anonymisation functions; and, (c) an electronic consent (e-Consent) tool for obtaining and handling informed consent. Additionally, practical experience is shared about designing a MDCS, GeoHealth, and deploying it in a large-scale experimental study. In conclusion, the contributions of this thesis offer guidance to mHealth practitioners, encouraging them to adopt the principles of privacy by design and by default in their projects.
Data protection and management of personal information has become an integral aspect for organisations and individuals in conducting business in the modern era. It has also become a major issue for legislators, regulators and consumers worldwide due to the widespread repercussions when personal information is negligently or maliciously used. Despite increased attention on personal information and the existence of data protection legislation internationally, data breaches remain a common occurrence. It has become crucial now, more than ever, for organisations to manage and safeguard personal information. As a nation, South Africa has addressed the need for increased protection - the Protection of Personal Information (PoPI) Act was signed into law in November 2013. This paper presents a comparison between the South African PoPI Act and other international data protection laws in order to highlight similarities and differences. These privacy legislations will be compared based on the principles set out by the PoPI Act. Other areas to be considered include data protection officers, enforcement, electronic marketing, online privacy and the year enacted. Data protection compliance is not straightforward and having the correct measurements and procedures in place is of utmost importance. These findings can be applied in future work to examine where South Africans can make use of already established international best practices to best enforce their privacy regulation.
The development of cyberspace as a platform for e-commerce as well as for the interaction between people has given rise to ensure 'cyber security'. In the present information revolution era, there is nothing more costly than the personal data of individuals, companies, and other organizations. The need to talk about cyber security increased further when almost all activities, including business, learning, interaction, entertainment, etc., were confined to cyberspace due to the COVID-19 pandemic. The lack of a data protection law in India adds to the already existing insecurity. The chapter aims to analyze the extent of the right to privacy in the modern cyber-world. It tries to study the concept of cyberspace and the scope and extent of the right to privacy in India-whether the same extends to cyberspace? The chapter also addresses the privacy-related issues and challenges in cyberspace and tries to suggest the way forward.
The article addresses the digital transformation and new power asymmetries and challenges to democracy by the world's seven largest digital platforms. Four different governance models are examined: The Chinese authoritarian model, the libertarian US-model, the European regulatory model, and the Mexican hybrid model. The challenges of digital sovereignty and democratic governance of platform capitalism are explored.
'Right to information' (RTI), 'access to information' (ATI) or 'freedom of information' (FOI) has been adopted by countries around the world, as a manifestation of the rights of citizens to freedom of opinion and expression and a prerequisite for human rights. In 1948, the United Nations Universal Declaration of Human Rights Article 19 stated the fundamental 'right to hold opinions without interference and to seek, receive and impart information and ideas through any media and regardless of frontiers.' In 1966, the International Covenant on Civil and Political Rights declared that '…access to information is inextricably tied to freedom of expression.' The right to information has frequently been linked to trust in public discourse and to enabling accountable and open government. Access to information establishes a right for individuals to seek information held by public authorities, often in a manner defined by the law, and generally subject to exemptions for such things as national security, defence, international relations, police investigations and privacy. Recordkeeping professionals in corporate and public organisations provide access to records for internal business use to support current activities, as well as ensuring access to records needed over the longer term for the study of cultural heritage and the history of communities and families. In addition, in the accountability domain, records can be used to hold individuals, officials and corporations to account, both internally and externally. Providing access to reliable records is commonly cited as a necessary prerequisite for accountability, transparency, and good governance. Transparency International (Pope, 2003) asserted that 'when we campaign for greater access to information we must at the same time campaign for improved records management. There seems little point in having access to information that is chaotic and unreliable'. Archives have been called 'arsenals of democratic accountability' (Eastwood, 1993; Iacovino, 2010) and this chapter will examine the recordkeeping role in providing access to records so that individuals can exercise their 'right to information'. It will consider four different aspects of access to information: national archives and records legislation; secrecy and privacy; responsive release of information by governments under freedom of information; and proactive release of information under open government policies. It will reflect upon whether these aspects together provide citizens with 'a right to information' and therefore whether such a right can be said to exist in practice. Unofficial routes to information access, such as whistleblowing or unauthorised disclosure by activists, will not be covered in this chapter.
