Volume 9 (2026-2027)

Each volume of Journal of Data Protection & Privacy consists of four 100-page issues published online.

The articles in Volume 9 will be listed below as they are published.

Volume 9 Number 1

Is the proposed SECURE Data Act a wolf in sheep’s clothing?
Kolah, Ardi

Practice papers
With regulatory pressure, operational focus: Twelve action priorities for global privacy, AI governance, and cyber security compliance
Determann, Lothar; Doyle, Graham; Urban, Jennifer M.; Will, Michael

Abstract ▼

Global businesses face growing privacy and data protection obligations. Duties can vary by jurisdiction, and many businesses struggle to decide where to direct finite compliance resources. This paper, developed from a panel the authors prepared for the IAPP Global Summit 2026, argues that the European Union’s (EU) General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), the most comprehensive and demanding regimes to which most global businesses are already subject, can serve as a common compliance core whose requirements can be leveraged to satisfy most other data protection regimes. It distils that core into 12 concrete priorities, grouped into five themes: securing the foundation; disciplining the data; respecting the individual; building accountability; and governing automation while anticipating legal change. The paper maps each priority to its anchoring GDPR and CCPA provisions and to the enforcement and litigation exposure that makes it consequential for global privacy, artificial intelligence (AI) governance, and cyber security compliance. The authors conclude that although obligations differ in some details and many organisations face additional sector and jurisdiction-specific rules, businesses that act on these 12 priorities will address the requirements common to data protection laws worldwide and materially reduce risk. The wider implication, underscored by recent deregulatory proposals in the EU and contests between federal and state authorities over AI in the US, is that organisations need a durable, principle-led compliance core and a standing process to monitor change. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: GDPR; CCPA; global data protection compliance; data subject rights; automated decision making; accountability

Assessing the role of mobile banking in promoting sustainable financial inclusion and responsible borrowing practices in Qatar’s digital economy
Singh, Avtar; Mohamed Ali, Amira Omar Mahgoub

Abstract ▼

The adoption of mobile banking and its impact on enhancing financial inclusion and consumer credit in Qatar is the focus of this research. A survey of 600 participants was conducted using a close-end questionnaire to measure variables across five key domains: literacy, mobile banking services, use of information technology, new formation of structures and banking, and clients’ confidence in security measures. The data was analysed qualitatively and quantitatively using descriptive analysis, correlation analysis, and t-tests. It was concluded that although the level of mobile banking is relatively high in the region, it is also associated with certain weaknesses such as financial liberalisation, digital literacy, development of banking structures, and customer confidence. In relation to improving the scale and users of digital financial services, this paper recommends that the government should pay more attention to issues of coverage/container, address specific groups of clients, support the financial value chain, and establish customer trust. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: mobile banking; financial inclusion; digital literacy; banking infrastructure; customer trust; financial accessibility; Qatar

Research papers
Balancing privacy and utility in synthetic data: Insights from Maryland’s State Longitudinal Data System
Woolley, Michael E.; Lachowicz, Mark; Shaw, Terry V.; Bonnéry, Daniel B.; Henneberger, Angela K.; Feng, Yi; Johnson, Tessa L.; Rose, Bess; Stapleton, Laura M.

Abstract ▼

Synthetic data hold strong potential to increase access to administrative data systems while protecting privacy for individuals. This paper details the approach taken to evaluate the synthesis of Maryland’s State Longitudinal Data System (SLDS) using fully synthetic Classification and Regression Tree (CART) models. Results demonstrate low disclosure risk (near zero) and high research utility, validated through robust evaluations. Practical insights and best practices from this case provide valuable lessons for other organisations seeking balanced synthetic data solutions for administrative data. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: synthetic data; research utility; disclosure risk; administrative data

Right to privacy versus right to prosecute: Judicial interpretations of privacy in criminal investigations and trial procedures in India
Saroj, Nidhi

Abstract ▼

The interplay between the right to privacy and the state’s prosecutorial obligations in criminal law presents a legal paradox. Privacy is recognised as a fundamental right under Article 21 of the Indian Constitution; however, the state has a primary obligation to investigate and prosecute crimes in furtherance of justice under the Criminal Procedure Code (CrPC) 1973 (which has been replaced by Bharatiya Nagarik Suraksha Sanhita [BNSS] 2023) and the Indian Evidence Act 1872 (which has been replaced by Bharatiya Sakshya Adhiniyam [BSA] 2023). This paper reports on a study of judicial harmonisation of conflicts between opposing interests, considering evolving judicial doctrine in search and seizure, electronic surveillance, self-incrimination, witness protection, and media trial. Indian courts have thus tried to apply the theory of proportionality to ensure that privacy encroachment is justified, necessary, and minimally intrusive. It is not easy to achieve harmony in enforcing moral and constitutional laws, however, especially in matters such as digital privacy, biometric data collection, and intrusive investigative methods, namely, narcoanalysis and DNA profiling. There is sufficient jurisprudence of court produced in restricting arbitrary state action, but its application under privacy norms continues to be inconsistent, most notably regarding the application of procedural fairness and due process protections. At heart, this study considers judicial oversight as to some degree curbing privacy violations, but the absence of clear legislative frameworks leaves too much room for excessive state discretion. The research shows that by undertaking a comparative analysis with international legal standards, comprehensive statutory guidelines should be formulated to circumscribe privacy in criminal investigations and trials, compromising the competing rights of the data principal and the requirements of criminal justice. This paper critiques the post-Puttaswamy trajectory of Indian jurisprudence in the criminal justice domain, arguing that despite judicial efforts to balance state and data principal interests, the absence of codified safeguards renders privacy protections fragile. It draws on comparative legal frameworks (notably the US Fourth Amendment and the European Union’s [EU] General Data Protection Regulation [GDPR]) to highlight procedural innovations and proposes legislative reforms that prioritise transparency, oversight, and data principal autonomy in prosecutorial practices. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: right to privacy; right to prosecute; criminal investigations; trial procedures; proportionality doctrine; data privacy; electronic surveillance

Cross-border genomic data protection in Indonesia: Balancing bio-sovereignty, individual rights, and national security
Andika, Tri; Daulay, Zainul; Ferdi,; Dewi, Sinta; Yao, Xuxin

Abstract ▼

This paper examines Indonesia’s legal framework for cross-border transfer of genomic data and evaluates how it balances the rights of data subjects, state sovereignty, and national security. Using a normative juridical method supported by comparative analysis, it reviews the Personal Data Protection Law 2022 and the Health Law 2023, along with their derivative ministerial regulations, in relation to international standards such as the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the World Health Organization (WHO) 2024 Guidelines, and China’s Regulation on Human Genetic Resources (HGR Regulation) 2019. The findings reveal three regulatory weaknesses: the limited recognition and protection of genomic data as sensitive data; the absence of benefit sharing and informed consent as fundamental rights of data subjects; and the lack of binding interstate treaty obligations to protect genomic data outside Indonesia. The paper proposes a ‘treaty-first’ approach in the Material Transfer Agreement (MTA), benefiting data subjects as a right, and a binding international framework designed explicitly for the cross-border protection of genomic data. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: bio-sovereignty; cross-border; genomic; data; Indonesia

Quantum ZKPs and digital inequality: Rethinking privacy governance in the post-quantum era
Mone, Varda; Thommandru, Abhishek; Sobirjonovna, Pulatova Nodirakhon; Bakhriddinovich, Toshkanov Nurbek; Gayratjon Ugli, Pulatov Temurbek

Abstract ▼

This paper assesses the adequacy of technology-neutral privacy frameworks in addressing quantum threats to zero-knowledge proofs (ZKPs) and other privacy-enhancing technologies (PETs) in global data protection regimes. Challenging assumptions that cryptographic innovation inherently bolsters privacy rights, the analysis demonstrates how post-quantum migration, absent binding regulatory duties, risks entrenching a ‘quantum divide’ in access and liability. Grounded in legal frameworks and actual deployments, including Zcash’s classical Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge (ZK-SNARKs) and NantHealth Inc.’s quantum-aware homomorphic encryption systems, the paper contends that access to PETs is becoming ever more determined by institutional capability and geopolitical factors, as illustrated by comparative case studies. This research evaluates the efficacy of statutes such as the European Union’s (EU) General Data Protection Regulation (GDPR) (Article 32), the California Consumer Privacy Act (CCPA) (§ 1798.150), and the Health Insurance Portability and Accountability Act (HIPAA) (45 C.F.R. § 164.308) in imposing liability for quantum vulnerable systems, using the cases to illustrate gaps in mandating equitable post-quantum migration. The conclusion reflects upon legal gaps enabling unequal protections, advocating reforms including mandatory quantum risk assessments. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: post-quantum cryptography; zero-knowledge proofs; privacy-enhancing technologies; regulatory liability; quantum divide; data protection

The public benefit doctrine in the context of surveillance technologies: Towards a new legal model
Sabro, Eyal; Muñoz, Bartolomé Torralbo

Abstract ▼

Existing privacy and surveillance frameworks fail to govern structural democratic harms because their foundational paradigm requires demonstrable individual injury as the threshold for legal intervention. This paper diagnoses that failure through the Israeli constitutional experience, where a 99.3 per cent judicial approval rate for wiretap requests exposes a legal architecture that formally protects privacy while systematically immunising from accountability the institutions most capable of violating it. Drawing selectively on the jurisprudence of the European Court of Human Rights (ECHR) and the General Data Protection Regulation (GDPR) framework, the paper introduces two theoretical innovations. Surveillance Justice Theory reconceptualises privacy violations as structural phenomena with individual, collective, and democratic dimensions, providing courts with a principled basis for recognising constitutional injury without requiring identifiable plaintiffs. The Structural-Dynamic Proportionality Principle reformulates proportionality analysis along institutional and temporal axes, requiring evaluation of oversight architecture and the ongoing validity of authorisation as surveillance capabilities evolve. These innovations are operationalised through the Integrated Constitutional Surveillance Model, a three-tier constitutional framework offering practical tools for courts and policy makers seeking to govern not merely discrete surveillance acts but the systemic conditions that produce structural democratic injury. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: surveillance technologies; privacy law; constitutional proportionality; structural harm; democratic governance; Israeli constitutional law

Book review
Kolah, Ardi

Back to Journal