Volume 8 (2025-2026)

Each volume of Journal of Data Protection & Privacy consists of four 100-page issues published online.

The articles published in Volume 8 are listed below.

Volume 8 Number 4

Editorial
Why synthetic identity fabrication is now at the top of the US national security agenda and what it means for the rest of us
Ardi Kolah, Founding Editor-in-Chief, Journal of Data Protection & Privacy

Papers
The evolution of digital rights in Hong Kong: Balancing innovation and privacy in the age of e-governance
Pooja Shukla, Senior Lecturer, Hong Kong Metropolitan University, and Rosa Pang, Partner, Elsa Law & Co. Solicitors

Abstract ▼

This paper examines the evolution of digital rights in Hong Kong amid the city’s rapid e-governance initiatives. It analyses the Personal Data (Privacy) Ordinance (PDPO) in the context of artificial intelligence (AI), blockchain and big data, highlighting both the opportunities and privacy risks these technologies present, such as data breaches and surveillance overreach. Drawing on case studies of high-profile data breaches1,2,3 and comparing Hong Kong’s approach with the European Union (EU) General Data Protection Regulation (GDPR), China’s Personal Information Protection Law (PIPL) and US frameworks,4 the paper underscores the crucial role of corporate boards in embedding privacy accountability and fostering a culture of trust through robust governance practices. The study also explores Hong Kong’s e-governance milestones, including the Digital 21 Strategy5 and AI ethical frameworks,6 to assess their impact on digital rights. It concludes that while Hong Kong has made important strides, more robust enforcement, mandatory breach notifications7 and cross-border regulatory alignment are needed to ensure that digital innovation enhances rather than undermines individual privacy rights. By proposing actionable recommendations for policy makers and organisations, this paper contributes to the global discourse on privacy law, offering insights for jurisdictions navigating the intersection of technology and human rights in the digital era. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  Hong Kong; data privacy; GDPR; big data; corporate governance; board of directors

Menstrual tracking apps and reproductive privacy: Global perspectives on governing menstrual health data
Maria Jawed, Doctoral Scholar, and Girish R, Head, Academic Affairs and Professor of Law, Gujarat National Law University

Abstract ▼

Menstrual tracking applications (MTAs) are now a routine part of digital life and central to the growing FemTech industry. By turning intimate menstrual and reproductive details into data, they create new risks of privacy invasion, commercial misuse and state surveillance. This paper compares how four jurisdictions — namely the US (post Dobbs), Canada, the UK, the European Union (EU), and India — govern menstrual health data and the predictive claims made by MTAs. Through comparative legal analysis, regulatory gap mapping and doctrinal review, three weaknesses emerge. The first is inconsistent recognition of menstrual and reproductive data as sensitive or special category information requiring heightened safeguards. The second is limited algorithmic accountability for predictive features such as ovulation and fertility forecasts, despite their influence on personal health and reproductive choices. The third is fragmented cross-border enforcement that enables regulatory arbitrage and leaves remedies weak in practice. Case studies, including the Federal Trade Commission’s (FTC) action against Flo Health, the Canadian class action with oversight by the Office of the Privacy Commissioner (OPC), the UK Information Commissioner’s 2023 review of fertility tracking apps and India’s Digital Personal Data Protection Act 2023 read with the Digital Personal Data Protection Rules 2025 and Medical Device Rules 2017, illustrate both progress and persistent gaps. The paper advances a reform agenda built on five priorities: classify reproductive data as sensitive; mandate independent validation and audit of predictive claims; embed privacy by design with granular consent, minimisation and deletion by default; impose distribution safeguards at the platform level; and strengthen cross-border regulatory cooperation. It concludes that protecting reproductive autonomy requires recognising informational self-determination as a core right. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  FemTech; menstrual tracking applications (MTAs); reproductive privacy; informational self-determination; data protection law; algorithmic accountability.

Comparative analysis of AI and privacy laws in Europe and Asia: Identifying regulatory disparities and pathways for harmonisation
Lanx Goh, Global Head of Privacy, and Vinni Kalra Francis, Senior Manager within Group Information Security & Privacy, Prudential

Abstract ▼

This paper provides a comparative analysis of artificial intelligence (AI) and privacy legislations in Europe and Asia, aiming to identify and bridge existing regulatory disparities to facilitate international cooperation and interoperability. The analysis contrasts Europe’s rights-based regulatory frameworks, notably the General Data Protection Regulation (GDPR) and the recently enacted EU AI Act, with pragmatic and innovation-driven models evident in Asian jurisdictions such as India’s Digital Personal Data Protection Act 2023 (DPDP Act), proposed Digital India Act, China’s Personal Information Protection Law (PIPL), Japan’s Act on the Protection of Personal Information (APPI) and Singapore’s Personal Data Protection Act (PDPA). By exploring geopolitical, economic and legal influences shaping these diverse regulatory approaches, the paper delivers critical insights through targeted case studies, illustrating both practical challenges and successes in balancing innovation with robust privacy safeguards. Key issues examined include cross-border data transfer complexities, the necessity for interoperability and the establishment of trust frameworks. The paper critically evaluates ethical considerations, particularly around consent mechanisms, data ownership rights and algorithmic transparency, within each regional context. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  artificial intelligence; AI; privacy laws; data protection; cross-border data transfers; AI governance; regulatory harmonisation; regulatory analysis; AI regulation; GDPR; EU AI Act; PIPL; data privacy comparative Asia Europe

From property to power: Why governance, not ownership, will define personal data in the age of AI
Roy Kamp, Legal Director, Central and Northern Europe, UKG, and Noémie Weinbaum, Managing Director, PS Expertise

Abstract ▼

In Pixar’s Finding Nemo, a flock of seagulls gather on a dock, fixating on whatever morsel of food drifts into view, each frantically crying ‘Mine! Mine! Mine!’ This comic scene captures the modern discourse around personal data: corporations, governments and individuals alike stake claims of exclusive ownership. Yet, the analogy quickly unravels. Unlike oil or land, data is non-rivalrous, co-generated and infinitely replicable. Attempts to force it into property categories generate contradictions: who owns a single credit card transaction, or the fragment of a dataset that shapes an artificial intelligence (AI) model’s weights? This paper advances a clear thesis: in the age of AI, property framings collapse; only governance frameworks can reconcile rights, accountability and innovation. From the General Data Protection Regulation (GDPR) to the California Privacy Rights Act (CPRA), Brazil’s Lei Geral de Proteção de Dados (LGPD) to China’s Personal Information Protection Law (PIPL), modern regimes embed rights, lawful bases and accountability mechanisms, not ownership. The challenge intensifies in AI ecosystems where model ‘memory’ resists erasure and generates inferences far beyond original inputs. What endures, and what must guide the future, is governance based on autonomy by design. This paper departs from prior critiques of data ownership1 by situating the shift within a broader redistribution of institutional power across regulators, corporations and individuals, catalysed by the European Union’s (EU) post-2019 data acts. The argument therefore reframes data law not as property’s decline but as the constitutionalisation of governance. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  artificial intelligence; GDPR; data governance; data ownership; privacy by design; privacy compliance

Balancing privacy and explainability in AI: Differential privacy and graph theory as governance tools
Anna Popowicz-Pazdej, Global Senior Data Protection Lawyer, Dentons

Abstract ▼

Anonymisation (particularly the differential privacy method) stands as the most valuable technique for safeguarding individuals’ privacy, especially in an organisational context. Combining graph theory with the differential privacy method ensures that while data remains protected, the explainability of artificial intelligence (AI) models is not compromised, thereby achieving the recommended state of explainable AI. This paper synthesises technical and regulatory analysis to tackle the problem of achieving an optimal relation between privacy protection in AI systems and explainability in computational intelligence, focusing specifically on anonymisation techniques. It concludes that while differential privacy effectively safeguards data subjects, its integration with graph theory can enhance the level of explainability in AI systems, making it a viable solution for AI developers and privacy practitioners. By analysing current regulatory frameworks, including the General Data Protection Regulation (GDPR) and the European Union (EU) AI Act, alongside practical anonymisation methodologies, the study demonstrates how an innovative combination of privacy-enhancing technologies (PETs) and graph theory can align with regulatory compliance and ensure the recommended level of explainability in AI systems. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  anonymisation; personal data; graph theory; artificial intelligence; differential privacy; local differential privacy; homomorphic encryption

Bridging cyber security and privacy: Strategic policy solutions for safeguarding personal data in a digital world
Hrishitva Patel, Graduate Research Assistant, University of Texas at San Antonio, and Suman Garai, Graduate, Kalinga Institute of Industrial Technology

Abstract ▼

Artificial intelligence (AI) is reshaping cyber security by intensifying threats while simultaneously transforming defensive capabilities. This paper examines how AI-driven cyber security practices intersect with data protection, privacy governance and regulatory accountability. It analyses the implications of automated threat detection, large-scale behavioural monitoring and predictive security tools for individual privacy and institutional compliance, drawing on comparative insights from global privacy and AI governance frameworks. The paper argues that effective cyber security in the AI era requires governance models that integrate technical safeguards with enforceable legal and ethical constraints, ensuring that security objectives are pursued without eroding fundamental privacy rights. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  cyber security; data privacy; AI-driven threats; zero trust security; AI governance; generative AI; federated learning; differential privacy; global privacy regulations; post-quantum cryptography; blockchain; cross-border data protection

Volume 8 Number 3

Editorial
The 2030 Pivot: Data protection as industrial policy in the age of agentic AI, fragmented supply chains and a volatile rules‑based order
Ardi Kolah, Founding Editor-in-Chief, Journal of Data Protection & Privacy

Papers
From fragmentation to interoperability: How the GDPR shapes ASEAN data privacy and cross-border data flows
Minh Hoang Le, Lecturer, Ton Duc Thang University

Abstract ▼

This paper examines how the European Union’s (EU) General Data Protection Regulation (GDPR) has shaped the trajectory of data protection and cross-border data flow regimes across the Association of Southeast Asian Nations (ASEAN). Using a comparative doctrinal method, it systematically assesses the legislative frameworks of Vietnam, Indonesia, Malaysia and Singapore against key GDPR provisions on international transfers, data subject rights and accountability. The findings indicate selective transplantation: ASEAN states internalise core GDPR principles while preserving jurisdiction-specific priorities, exemplified by Vietnam’s security-oriented stance and Malaysia’s enduring ‘data users’ model. This hybridisation generates convergence around concepts such as consent and data portability, alongside divergence in enforcement architectures and restrictions on cross-border data flows. The study contributes to broader regulatory debates by showing that ASEAN’s calibrated adaptation of the GDPR reflects a pragmatic balance between interoperability and regulatory sovereignty. It closes with a policy roadmap calling for clearer adequacy pathways, regionally harmonised transfer standards and strengthened intra-ASEAN cooperation to ease compliance burdens and enable digital trade. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  data privacy; ASEAN; GDPR; legal harmonisation; comparative law; digital economy

India’s emerging data protection framework: A critical analysis of legal reform and global interoperability
Gaurav Mahajan, Partner, The Precept Law Offices

Abstract ▼

This paper discusses the data protection and governance framework in India, catalysed by rapid digitisation and escalating cyber threats, data thefts and data breaches. The central research question is ‘How India’s evolving legislative and regulatory framework specifically the Information and Technology Act, 2000 (IT Act) and the Digital Personal Data Protection Act, 2023 (DPDP Act) and its rules are helping in protecting personal data, ensuring accountability, aligning with global norms on data protection and cross border data transfer and many other related issues?’. The paper posits that while the IT Act laid foundational digital infrastructure, it lacked comprehensive safeguards to protect personal data and user rights gaps, which the DPDP Act aims to bridge through a more comprehensive, rights-based, and principle-driven approach. This paper uses comparative legal analysis, case law review and regulatory gap assessment to show that the DPDP Act represents a significant shift by codifying user rights, establishing an independent Data Protection Board of India (DPB), and imposing stricter duties on data fiduciaries. However, it also points out possible challenges related to practical compliance. The findings of this research may offer vital guidance on emerging compliance requirements, disapprovals and potential exposures/risks. For policymakers, it emphasises harmonised rulemaking and enhanced institutional capacities. For businesses, it provides practical insights into managing user consent, navigating cross-border data transfers and mitigating compliance risks under the evolving regulatory landscape. Ultimately, the true impact of the framework will depend on its effective implementation and enforcement in the near future, paving the way for a transparent, secure, equitable, accountable and globally compatible data governance ecosystem. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  digital legal framework India; data protection India; DPDP Act impact on business; Information Technology Act; data privacy; data protection; artificial intelligence

From clicks to cash: Legal implications of e-commerce data monetisation
Anushtha Saxena, PhD Scholar, Gujarat National Law University

Abstract ▼

The rapid expansion of e-commerce has positioned India as a dominant force in the global digital marketplace. With the proliferation of online platforms employing diverse marketplace models, e-commerce giants entice consumers through substantial discounts and extensive product offerings. While this sector has significantly contributed to India’s economic growth, it simultaneously raises profound legal and regulatory concerns, particularly concerning the monetisation of consumer data. Data-driven strategies enable e-commerce entities to enhance product innovation and amass substantial revenues; however, these practices often encroach upon consumer rights, leading to critical issues such as privacy infringements, unauthorised data exploitation and cross-border complexities in data transfers. This paper critically evaluates the legal implications of e-commerce data monetisation, comparing regulatory frameworks in India and the European Union’s (EU) General Data Protect Regulation (GDPR). It highlights significant legal challenges arising from data-driven marketing strategies, explores consumer rights implications, and assesses the efficacy of India’s Digital Personal Data Protection Act, 2023, against the GDPR standards. By identifying regulatory gaps and suggesting actionable policy enhancements, the study provides strategic insights to policy makers, practitioners and scholars aimed at fostering responsible data monetisation practices and strengthening consumer trust. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  e-commerce; data monetisation; privacy; data abuse; data protection; cross-border data; GDPR 2018; DPDP Act 2023

Strengthening consumer consent in e-commerce: Legal and policy reforms to address dark patterns and AI-driven challenges
Akshay Baburao Yadav, Research Scholar, M. S. Ramaiah University of Applied Science

Abstract ▼

India’s e-commerce ecosystem increasingly relies on algorithmic personalisation and data-driven business models that depend on consumer consent to legitimise large-scale personal data processing. In practice, however, consent is frequently shaped by interface design choices, bundled permissions and opaque artificial intelligence (AI)-driven profiling, raising concerns about whether user consent remains informed, voluntary and meaningful. This paper critically examines the effectiveness of consent mechanisms deployed by Indian e-commerce platforms under the Digital Personal Data Protection Act 2023 (DPDP Act) and the Digital Personal Data Protection Rules 2025 (DPDP Rules). Drawing on comparative insights from the European Union’s General Data Protection Regulation (GDPR) and the US sector-specific privacy framework, it analyses how dark patterns, fragmented consent flows and automated decision-making (ADM) practices undermine user autonomy in practice. Through doctrinal and platform-level analysis, the paper identifies structural deficiencies in the operationalisation of consent across the e-commerce life cycle. It proposes targeted legal and policy reforms aimed at strengthening granular consent, enhancing transparency and accountability, and addressing AI-driven consent challenges. By repositioning consent as a substantive privacy safeguard rather than a procedural formality, the paper seeks to reinforce consumer trust and support a rights-respecting digital marketplace in India. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  consent mechanism; data privacy; e-commerce; dark patterns; Digital Personal Data Protection (DPDP) Act; consumer

From commitment to implementation : Strengthening privacy and data protection through open government adoption in Lebanon
Jessica Abou Mrad, Assistant Professor, Modern University for Business and Science, et al

Abstract ▼

Open government (OG) initiatives can strengthen transparency, participation and accountability, but they can also expand privacy and cyber risk where personal data governance is weak. This paper examines the tension between OG adoption and privacy protection in Lebanon, focusing on whether Lebanon’s current legal, institutional and technical arrangements can support ‘open by default’ practices without exposing citizens and public officials to misuse, breach or unlawful surveillance.1 The paper maps Lebanon’s data protection gaps against international and regional comparators and identifies practical vulnerabilities relevant to OG implementation, including fragmented privacy rules, limited enforcement capacity, inconsistent cyber security maturity, low levels of public sector training and weak citizen awareness.2 It then proposes a prioritised roadmap for integrating privacy safeguards into Lebanon’s OG trajectory through: (i) comprehensive, modern data protection legislation; (ii) independent oversight and complaint-handling capacity; and (iii) operational controls including privacy-by-design, data protection impact assessments (DPIAs) for high-risk data releases, tiered access models, anonymisation standards and breach preparedness.3 The central argument is that OG credibility depends on making privacy safeguards measurable, enforceable and operational, ensuring that transparency gains do not come at the expense of individual rights. This article is also included in The Business and Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  open government; Open Government Partnership (OGP); Lebanon; transparency; accountability; data protection; digital governance

Data protection as competitive advantage: Leveraging ISO standards to accelerate digital growth in Morocco
Khouloud Rifky, Junior Compliance Consultant, Consilium

Abstract ▼

As Morocco accelerates its digital transformation, robust data protection has become a prerequisite for sustaining digital trust, ensuring economic resilience and enhancing global competitiveness. This paper argues that Morocco must transition from a compliance-based approach to proactive data governance, aligning its legal and operational frameworks with international standards such as the General Data Protect Regulation (GDPR) and International Standards Organization (ISO) certifications. The study proposes two complementary sets of recommendations. For businesses, it advocates the adoption of ISO standards (ISO/IEC 27001, 27701, 31000, 27005, 22301 and 37301), the appointment of qualified data protection officers (DPOs), integration of privacy-by-design principles and the implementation of structured data audits and risk management frameworks to foster a culture of cyber security and compliance. For regulators, the paper recommends reinforcing the investigative and sanctioning powers of the National Commission for the Control of Personal Data Protection (CNDP), introducing mandatory breach notification requirements, enhancing transparency through regular compliance reporting, and promoting a risk-based regulatory approach aligned with GDPR standards. Through a comparative legal analysis of Morocco’s Law 09-08, the European Union’s (EU) GDPR, and key African data protection frameworks, such as South Africa’s Protection of Personal Information Act 2013 (POPIA) and Nigeria’s Data Protection Regulation (NDPR), the paper identifies critical gaps in enforcement mechanisms, regulatory convergence and cross-border data governance. These findings are reinforced by qualitative insights gathered from interviews with leading Moroccan experts in compliance and cyber security, namely Mounim Zaghloul, Taieb Debbagh and Mohamed Achor Zyad, who highlight systemic challenges, particularly for small and medium-sized enterprises (SMEs), in implementing international data governance standards and provide targeted recommendations to bridge these gaps. To address these challenges, the paper introduces a Data Protection Maturity Model, providing a structured framework for assessing the readiness of Moroccan organisations and institutions in data protection governance. The study concludes that transforming data protection into a strategic asset is essential to position Morocco as a trusted digital hub in Africa and globally. Implementing these recommendations will not only strengthen national cyber security resilience but also enhance Morocco’s attractiveness for foreign investment and digital trade partnerships. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  personal data protection; data privacy; digital governance; Law 09-08; GDPR compliance; ISO standards; Maroc Digital 2030; trust and competitiveness; risk management

Book review
Research Handbook on Human Rights and Digital Technology edited by Ben Wagner, Matthias Kettemann, Kilian Vieth-Ditlmann and Susannah Montgomery
Reviewed by Ardi Kolah, Founding Editor-in-Chief

Volume 8 Number 2

Editorial
Cash is no longer king: How digital wallets and biometrics have eroded our expectations of privacy
Ardi Kolah, Founding Editor-in-Chief, Journal of Data Protection & Privacy

Papers
Data quality, provenance and transparency in real-world data : Aligning quality standards with data governance legal frameworks
Puja Myles, Director, Eleanor Axson, Senior Researcher-Senior Assessor, Clinical Practice Research Datalink, Medicines and Healthcare products Regulatory Agency, and Colin Mitchell, Head of Humanities, PHG Foundation, University of Cambridge

Abstract ▼

There have been numerous papers discussing data quality and data protection independently, but there has been little discussion on how data quality relates to data protection and other data governance regulatory frameworks. This paper is a step towards addressing that gap and makes the case for why data quality is relevant for data protection and legal compliance professionals. Real-world data in the context of healthcare refers to data that is routinely collected in the course of delivering healthcare. From a data protection regulatory perspective, Article 5 of the General Data Protection Regulation (GDPR) lists data accuracy as one of the principles for data processing. The recently adopted European Union Artificial Intelligence Act (EU AI Act) Article 10 outlines requirements for data and data governance, specifically quality criteria for datasets used to train, test and validate high-risk AI models to address concerns around algorithmic bias due to biases in the training data. The Standards for Data Diversity, Inclusivity and Generalisability (STANDING) Together consensus recommendations for dataset curators on transparency in dataset documentation enable an informed assessment of the suitability of data and examination of biases, for development of AI health technologies. This includes information on data provenance, modifications, sociodemographic composition and bias assessment findings. The Clinical Practice Research Datalink (CPRD) database is used to illustrate how these recommendations can be implemented in a practical way using unique identifiers such as digital object identifiers (DOIs), metadata, published data resource profiles with sociodemographic information and data quality assessments using validation and comparability studies. There is considerable alignment between established scientific standards, medical product regulatory and data governance legal requirements on data quality, as well as emerging international consensus which will reduce the compliance burden on curators and users of real-world data. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  data quality; transparency; EU AI Act; data provenance; real-world data; algorithmic bias

Navigating India’s Draft DPDP Rules 2025: Implementation challenges in protecting children’s personal data
Sanya Darakhshan Kishwar, Assistant Professor, Jaskaran Singh Sahani, Student, and Saumya Tyagi, Student, Jindal Global Law School, O.P. Jindal Global University

Abstract ▼

This paper critically examines India’s draft Digital Personal Data Protection Rules 2025, with a particular focus on the protection of children’s personal data. It explores the evolution from earlier legislative frameworks, evaluates the significant changes introduced by the Digital Personal Data Protection Act 2023, and scrutinises the operational, technical and policy-level challenges associated with the implementation of the Draft Rules 2025. Through a comparative approach with global best practices, notably the General Data Protection Regulation (GDPR), the paper identifies gaps, discusses practical implications for businesses, particularly startups, and proposes clear, actionable recommendations for compliance. The analysis aims to provide meaningful insights for policy makers, industry stakeholders and practitioners navigating the complexities of enhanced data protection regulations. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  Digital Personal Data Protection Act 2023; Digital Personal Data Protection Rules 2025; children’s data protection; data fiduciaries; GDPR; parental/guardian consent

Improving data quality and privacy in AI systems used for employee data processing
Noemie Weinbaum, Managing Director, PS Expertise and Roy Kamp, Legal Director, DACH, Northern and Eastern Europe, UKG

Abstract ▼

High-quality data is crucial for the ethical and effective use of artificial intelligence (AI), particularly in the employment context. This paper critically examines global legal frameworks demanding accuracy, fairness and accountability in AI data usage. Analysing key legislation including the European Union (EU) Artificial Intelligence AI Act (AI Act), US federal actions, Japan’s Act on Protection of Personal Information (APPI) and China’s Personal Information Protection Law (PIPL), it highlights international consensus and geopolitical divergences. Recognising limitations in privacy-enhancing technologies (PETs), the authors propose ‘subjective anonymisation’ — a novel, context-sensitive method protecting individual privacy while preserving data utility. The paper argues for dynamic, risk-based data governance as both a compliance strategy and foundation for ethical AI innovation. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  artificial intelligence; privacy-enhancing technology; data governance; employment; anonymisation; privacy; pseudonymisation; de-identification; EU AI Act; GDPR; CCPA; CAIA; LGPD; PIPL; DPDPA

AI-driven surveillance in India: Reconciling privacy, national security and legal oversight
Manu Mariyan Abraham, Research Scholar, and Shampa Dev, Professor, Christ University

Abstract ▼

Artificial intelligence (AI) is having a significant impact on how the surveillance apparatus in India operates. Along with the numerous possibilities, the indoctrination of AI in surveillance mechanisms poses serious privacy concerns. The conflict between state surveillance and the fundamental right of privacy is apparent even at the conceptual level. On the one hand, the rise of advanced surveillance mechanisms has been an abetting factor in this conflict, while on the other hand, many theorists have been at work to find a harmonisation between them. Throughout Indian history, surveillance apparatus has helped thwart threats to national security and maintain the nation’s integrity. The apparent disadvantage of surveillance can be its intrusion into citizens’ right to privacy, which poses several legal challenges. This paper explores how incorporating AI in surveillance mechanisms enhances India’s surveillance apparatus and influences the conflict between national security and privacy rights. The paper examines how revolutionary AI technologies such as predictive policing, facial recognition (FRT) and AI-enhanced monitoring systems aggravate the apparent conflict between national security interests and the fundamental right to privacy, as adjudged in the Puttaswamy judgment. The paper critically analyses the existing legal architecture, which consists of the Telecommunications Act and the IT Act, and highlights its shortcomings. Further, the paper traverses how legal frameworks of other jurisdictions such as the European Union (EU) AI Act, the Canadian AI and Data Act (AIDA) and the US regulatory guidelines could guide India in determining a well-rounded regulatory approach. Additionally, the paper proposes adopting a context-based or risk-based approach to AI regulation and the practical challenges therewith in an attempt to harmonise the state security imperative with citizens’ privacy rights without obstructing technological advancement. The comparative analysis of different regulatory guidelines and legislations and the potential regulations would provide practical insights for the legislature, law enforcement and other stakeholders. The paper ultimately argues that there is an exigence for a comprehensive regulatory framework to conciliate national security and privacy rights in the AI-powered digital landscape. This article is also included in The Business and Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  state surveillance; national security; right to privacy; artificial intelligence

The right to know: Comparative analysis of notification requirements in public space surveillance systems
Bartolome Torralbo Munoz, Profesor Ayudante Doctor de Derecho Penal, Universidad de Córdoba, and Eyal Sabro, Attorney, Israel

Abstract ▼

The proliferation of advanced surveillance technologies in public spaces presents unprecedented challenges to privacy rights and democratic governance. While authorities gain extensive visibility into citizens’ lives through artificial intelligence (AI) and machine learning (ML) capabilities, a critical ‘transparency asymmetry’ has emerged between state surveillance capabilities and citizens’ awareness of such monitoring. This paper employs comparative legal analysis, examining constitutional provisions, legislation, administrative regulations and court decisions across multiple jurisdictions, with a primary focus on the European Union (EU) and the US. The study draws upon primary legal sources, academic literature, policy documents and technical standards to evaluate the effectiveness of various notification approaches. The analysis reveals three fundamental structural failures in existing notification systems: (1) a disconnect between formal notification and substantive understanding of surveillance implications, particularly in systems incorporating AI; (2) ‘consent fatigue’ that undermines notification effectiveness; and (3) fragmented standards creating significant accountability gaps in privacy protection. The EU has developed comprehensive notification requirements through the General Data Protection Regulation (GDPR) framework and court decisions, while the US maintains a more limited ‘notice-and-choice’ approach. This paper proposes a dynamic constitutional notice framework that reconceptualises notification requirements as dynamic constitutional obligations rather than static procedural rules. This framework bridges the European dignity-based and US property-centric approaches while providing flexible implementation mechanisms that can adapt to emerging technologies while preserving democratic oversight. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  surveillance systems; privacy rights; notification requirements; constitutional law; GDPR; Fourth Amendment; data protection; democratic accountability

Volume 8 Number 1

Editorial
Navigating AI‑amplified privacy and data protection risks: from legacy challenges to new and novel threats
Ardi Kolah, Founding Editor-in-Chief, Journal of Data Protection & Privacy

Papers
AI governance and data privacy in cross-border contexts: A comparative analysis of regulatory frameworks
Ahmed Bahgat, ICT Expert and Arbitrator, Bahgat IT Consultancy

Abstract ▼

The implications of artificial intelligence (AI) in cross-border relations include major issues regarding data privacy, jurisdiction, regulatory consistency and accountability. This paper includes a comparative analysis of AI frameworks in four jurisdictions including the US, the European Union (EU), Singapore and the United Arab Emirates (UAE). The paper also analyses the regional AI governance frameworks and cross-border AI governance mechanisms of these regions and their effectiveness in addressing AI-related challenges. This review has gathered data from published articles from different peer-reviewed journals and popular databases including Web of Science, IEEE Springer, Scopus and Google Scholar, from the past six years. The study brings into focus the differences in AI governance approaches, compliance challenges and gaps in privacy protection across these regions, highlighting the importance of harmonised standards, transparency, accountability and ethical considerations in AI deployment. The potential solution includes mutual recognition agreements (MRAs), whereby nations reciprocate one another’s standards of AI regulation if they share similar levels of privacy and risk management. Matching frameworks to the Organisation for Economic Co-operation and Development (OECD) AI Principles, with its focus on transparency, fairness and accountability, can support promoting uniform global standards. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  artificial intelligence (AI); AI audits; cross-border relations; data privacy; governance models; regulatory challenges

Protecting what matters: Data privacy solutions for Qatar’s expanding mobile banking sector
Avtar Singh, Associate Professor, and Amira Omer Ali, PhD scholar, Mittal School of Business

Abstract ▼

This paper synthesises the current literature on innovation and consumer protection, focusing on data privacy concerns in Qatar’s mobile banking industry. As industry advances, the need for adequate data protection is crucial. The paper critically analyses Qatar’s regulatory position, particularly the Personal Data Privacy Law (PDPL) in the context of financial institutions. It discusses current trends and future threats related to consumer protection strategies based on literature and case studies. The research emphasises the urgency of increasing customer knowledge and trust alongside technological advancements. It highlights the inadequacy of relying solely on legal frameworks when both financial providers and customers lack ownership of personal data protection. Additionally, there is a notable lack of awareness about data privacy risks and consumer responsibilities in protecting data. The study provides policy implications and recommendations for Qatar’s policy makers, financial institutions and consumers. It calls for enhanced regulation, improved technology adoption by financial institutions and better communication to build customer trust. Consumers, too, need more awareness of data privacy best practices. Collaboration among all stakeholders in the mobile banking sector will lead to better data privacy in Qatar, integrated with innovation for the benefit of consumers in a digital world. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  mobile banking; privacy regulations; data security; financial technology; consumer protection

Amendment 13 of Israel’s Privacy Protection Law: A game-changer for data protection compliance
Dalit Ben-Israel, Partner and Chair of IT and Data Protection Practice and Co-Chair of AI, Naschitz Brandes Amir

Abstract ▼

This paper explores Amendment 13 of Israel’s Privacy Protection Law (PPL) and its potential impact on data protection in Israel. It examines how the amendment aligns Israeli privacy law with global privacy standards, particularly the General Data Protection Regulation (GDPR), and provides a framework for imposing new administrative fines. The paper discusses the broader implications of these changes for businesses and government entities, as well as the compliance challenges they present. Key reforms include stronger enforcement mechanisms, new criminal offences, and the introduction of the obligation to appoint data protection officers. The analysis includes actionable recommendations for policy makers, businesses and legal practitioners in adapting to these significant regulatory shifts. This paper is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  Israel; Privacy Protection Law; information security; GDPR; data protection; privacy; controller; processor; consent; administrative fines; DPO

Navigating GDPR challenges in M&A transactions: Practical insights from the Italian legal framework
Tommaso Zeccherini, Senior Consultant, Privacy and Digital Regulation, Deloitte Financial Advisory

Abstract ▼

Mergers and acquisitions (M&A) involving business unit transfers present significant data protection challenges, requiring compliance with the General Data Protection Regulation (GDPR) and national laws. This paper examines the practical obligations of data controllers transferring business units in Italy, considering Italian Civil Code and GDPR requirements. The paper provides a structured approach to ensuring compliance in business transfers, covering key obligations such as data minimisation, privacy notice requirements, legal basis identification, legitimate interest assessments, data processing agreements (DPAs) and security measures for data transfers. The analysis integrates key decisions from the Italian Data Protection Authority along with practical business cases from the banking sector, offering insights into regulatory expectations and enforcement trends. By bridging legal principles with practical implementation, this paper serves as a strategic guide for businesses, legal professionals and policy makers navigating data protection in M&A transactions. The paper concludes with recommendations for best practices in handling personal data during corporate restructuring and acquisitions, ensuring compliance while mitigating legal and operational risks. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  GDPR; data protection; mergers and acquisitions; business unit transfer; Italian law; compliance strategies

The conundrum of personal data protection in Malaysia
Saslina Kamaruddin, Senior Lecturer, Universiti Pendidikan Sultan Idris; Research Fellow, Tashkent State Law University, Islombek Abdikhakimov, Lecturer in Cyber Law, Tashkent State University of Law, Zaiton Hamin, Associate Professor of Law, Universiti Teknologi MARA, and Nadia Nabila Mohd Saufi, Lecturer, Management and Science University

Abstract ▼

The issue of privacy and personal data protection has been a protracted conflict between the Malaysian Government and its citizens. Rapid technological progress has created challenges in ensuring that Malaysia’s Personal Data Protection Act (PDPA) is robust enough to protect personal and sensitive data. The Malaysian PDPA faces criticism for failing to adapt to these changes. The PDPA was enacted and implemented in Malaysia in 2010. Despite being in existence for 15 years, the legislation has faced ongoing criticism due to its deficiencies in safeguarding the rights of individuals and the government’s interests. This paper aims to evaluate the dilemma arising in personal data protection due to the gap between existing legal measures and hindrances of the enforcement of personal data. The qualitative research methodology, which includes doctrinal and comparative legal analysis of primary sources, reveals that protecting personal data is an ongoing and formidable challenge. The authors argue that the PDPA 2010 requires a comprehensive overhaul and a greater emphasis on a collaborative approach between private and governmental entities to safeguard the interests of citizens as well as the government’s need to access data for social justice purposes. This paper is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  data protection; privacy; breach notification; data users; regulation; GDPR; Malaysia

Regulating deepfakes and synthetic media: Privacy, policy and global regulatory challenges
Sanya Darakhshan Kishwar, Assistant Professor, Jindal Global Law School, Anjali Tripathi, Student, Jindal Global Law School, Sadqua Khatoon, Student, Faculty of Law, Aligarh Muslim University, Deepali Poddar, Student, Jindal Global Law School, and Bharat Khurana, Advocate, Delhi High Court

Abstract ▼

Deep fake technology presents a profound challenge to data protection, privacy and regulatory frameworks worldwide. By exploiting biometric data without consent, deep fakes pose severe threats to privacy frameworks such as the European Union’s (EU) General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act 2023 (DPDPA). The ability to manipulate digital content using artificial intelligence (AI) raises concerns over identity theft, misinformation and biometric data security. This paper examines regulatory gaps, emerging AI-driven detection strategies and the need for privacy-preserving technological solutions. Through a comparative legal analysis, we identify gaps in existing regulations and propose a privacy-centric framework for mitigating deep fake risks. We further examine AI-driven solutions for authentication and policy interventions necessary for global regulatory alignment. Our findings suggest a multitiered regulatory response integrating technology, governance and privacy laws to counter deep fake threats while protecting individual rights. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  deep fakes; synthetic media; privacy regulation; GDPR; AI ethics; digital misinformation; biometric data

Evaluating the effectiveness of Saudi Arabia’s PDPL in the global digital economy
Hussam O. Haroun Suliman, Legal Consultant, Saudi Electricity Company

Abstract ▼

Saudi Arabia’s Personal Data Protection Law (PDPL) is a major milestone in bringing the Kingdom’s regulatory environment in line with global data protection norms. Although drawing inspiration from the European Union (EU) General Data Protection Regulation (GDPR), the PDPL presents unique provisions aligned with Saudi Arabia’s national interests, such as stringent data localisation requirements and increased regulatory control. This paper critically evaluates the PDPL’s effects on enterprises, compliance with regulations and international investment, with emphasis on the difficulties faced by multinational companies in adjusting to Saudi Arabia’s changing data governance environment. One of the areas of emphasis is enforcement bodies of the Saudi Data and Artificial Intelligence Authority (SDAIA) and the National Data Management Office (NDMO), determining if they have the authority and means to enforce compliance. Further, this research delves into whether the PDPL promotes trust within Saudi Arabia’s digital economy or imposes regulatory impediments that might discourage international cooperation. By locating the PDPL in a larger international context, this analysis yields insights into its efficacy as a model of data protection within the Middle East and its far-reaching implications for digital transformation through Vision 2030. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  data sovereignty; regulatory compliance; GDPR versus PDPL; cross-border data transfers; privacy enforcement

Navigating the legal basis for employment background screening: Global compliance challenges and best practices
Kerstin Bagus, Chief Knowledge Officer, NetForce Global and Andy Hellman, Associate, iQubed Advisors

Abstract ▼

This paper concentrates on the legal basis of processing personal data in the context of the employment background screening role. Although this is a specialised task, it serves as a useful exercise for any enterprise evaluating the legal basis of processing personal information, especially when third parties are involved. When conducting employment background screening, the roles of the parties involved need to be clearly outlined. If a third party screening company is used, they may be a data processor, which requires specific contractual language. If they are a data controller, then joint controller language will need to be completed, as the employer and background screener have entirely separate roles in the data processing. Determining the legal basis of processing is primarily completed by the hiring organisation, as only they know who they are screening and why. Although the term ‘consent’ is commonly used in the background screening process, it is rarely allowable in General Data Protection Regulation (GDPR) or GDPR-like privacy regulations but may be the primary legal basis of processing in other countries. This can set up a conflict of laws for the hiring organisation, which they will have to navigate through. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  GDPR; legal basis; compliance; background screening; vetting; consent; privacy

Book reviews
Research Handbook on Human Rights and Digital Technology edited by Ben Wagner, Matthias Kettemann, Kilian Vieth-Ditlmann and Susannah Montgomery
Reviewed by Ardi Kolah LL.M, FIP, Founding Editor-in-Chief, Journal of Data Protection & Privacy

Back to Journal