Norton Rose Fulbright Partner Anna Gamvros, CIPP/A, CIPT, FIP, is recognized as a leading privacy expert in the Asia-Pacific region. Her law firm has offices in Hong Kong and Brisbane, Australia, where she advises her clients on the evolving data protection regulations throughout the Pacific Rim.

[caption id="attachment_475443" align="alignright" width="300"] Anna Gamvros, CIPP/A, CIPT, FIP[/caption]

Gamvros was recently named to the IAPP Board of Directors. She previously served on the IAPP’s Asia-Pacific Advisory Board and Board of Women Leading Privacy.

In this IAPP member spotlight, Gamvros spoke to Staff Writer Alex LaCasse about her work, and she previewed the upcoming panel discussion she will lead at the IAPP Global Privacy Summit 2022, “Enter the Dragon: Perspectives on Navigating the New Data Laws in China.�

The Privacy Advisor: From the time you started your career, how have data protection regulations changed across Asia-Pacific over time to where the landscape is today?

Gamvros: It’s been a complete change, really. Twenty years ago, I moved from Australia to Hong Kong. At the time, in the Asia-Pacific region, Hong Kong, was one of the few counties that had a data protection law — sort of a standard data protection law. There were some others in the region that had industry-specific (regulations) or sort of light-touch regimes. Probably in the last 12 years, we've seen a complete overhaul of the data protection landscape in Asia-Pacific. We have many jurisdictions now that have significant omnibus data protection laws, we have regulators who are very active and taking enforcement action. In a number of countries, we have cybersecurity laws and regimes that requires IT and infrastructure around cybersecurity. We also have a breach notification regime in many countries as well, which, when I first moved to region, were completely unheard of.

The Privacy Advisor: Can you please give a general overview of where China’s new data protection laws stand?

Gamvros: There’s kind of interplay with three pillars. There's the cybersecurity law, which came in a few years ago, a data security law, which came into effect last year, and then personal data protection law came into effect last year. The personal data protection law is more what we're used to seeing in the western world around data protection law and it's quite broad. Many people are familiar with the (EU General Data Protection Regulation). Obviously, it has many elements that are similar to the GDPR, but it also has its own nuances and differences. The way the law is written is quite high level, so we are still seeing a lot of regulations and guidelines that will come and fill out the details. So, with anything, the devil is always in the details. We're waiting to see number of terms and number of requirements and more how they'll be filled out, and how those global organizations are going to have to change their existing privacy programs to fit to work in China. There’s a lot of work to be done there.

The Privacy Advisor: Because there is so much international commerce in China, from a compliance standpoint, what provisions in its data protection laws are you finding your clients are most concerned with?

Gamvros: I think the hottest topic for our clients is really looking at data localization and transfer — what, do they need to whether they're impacted by the regime to keep data onshore in China, whether they're going to be restricted in how they can move data in and out of China, and how they can access data from outside within China. That's really the number one concern that our clients have because in any way moving data across borders is becoming increasingly more regulated, and obviously, (is) a big impact for any clients who are running an international business.

The Privacy Advisor: You’re hosting a discussion at GPS about how international businesses can navigate China’s data protection laws. What do you hope attendees takeaway from the panel?

Gamvros: I think we will have a slightly different panel, rather than just a download on what the laws are. It’ll be more talking to those privacy professionals who are in global roles outside of China, and how they're perceiving and operationalizing the new laws, building them into parts of building them into privacy programs, and what they're seeing that their colleagues do. We really want to take a practical look at the challenges that the new laws are putting out and what their key considerations are, with respect to their global programs.

The Privacy Advisor: Throughout the Asia-Pacific region, countries that have data protection regulations and those working to establish their own comprehensive data protection laws, such as India, give their data protection authorities varying degrees of independence. How critical is it for data protection authorities to be independent?

Gamvros: The laws themselves are all stand-alone laws, and they've all kind of grown up in those countries. They were developed for each of the countries in the region for different kinds of geopolitical and economic, reasons. Some may have been drafted following some kind of data incident, so they've all got different drivers for how they've come about. You can see by looking at the different roles in the region, that the drivers and the economic and geopolitical drivers in those countries do come out in those laws, whether it's a country that is trying to create a kind of safe haven for data as kind of a technology hub, or whether they want to be an outsourcing hub, where they're just trying to bring themselves up in line with international standards. They're all different and they all draw differently from the existing laws around the world. We haven't seen any, any country in this region wholesale copy a law and put that in place. What rights do you have for individuals? What fines they put in place? What enforcement regime do they put in place, even the regulator, and the regulator’s powers? So, all of that are kinds of a variations to suit the particular jurisdiction. As a result, we get this huge patchwork of laws in this region.

The Privacy Advisor: You mentioned this patchwork of privacy laws across the Asia-Pacific region, how difficult has it been for your clients to navigate these legal regimes that can vary widely by country?

Gamvros: It can be very tricky. We have to help our clients find a baseline. What is it that suits their business in terms of where they're located, the type of business they do, where their customer base is located? So have to help them find that baseline and to work to that baseline. Then, from there, we look at the different regimes and how they'll affect that baseline. There's no one sir size fits all answer, you have to look at the organization, and then try and kind of fashion a solution for them, while taking into account all of those factors.

The Privacy Advisor: You were just named to IAPP’s Board of Directors this year. What experiences do you think you bring to the board?

Gamvros: I'm really excited about about joining the IAPP Board of Directors. One of the things that I'm bringing is that I’m the only board member coming from the Asia-Pacific region. I can bring some insights from what we've experienced both across Hong Kong, and Australia, and also bring insights from what's going on in this part of the world, and how it’s impacting privacy professionals here.

The Privacy Advisor: You were recognized by Chambers Greater China Region as the region’s top Information Technology expert this year, what does this honor mean to you?

Gamvros: It's great recognition because it comes from clients and peers. So, it's always nice to be recognized from both groups because as they're the most important people in our world. It's a great honor, and I share that with some other great practitioners in the region.

Photo by Keagan Henman on Unsplash

Uncategorized

Politico reports U.S. President Joe Biden is urging private entities to strengthen cybersecurity systems in the face of increased potential for Russian cyberattacks. "The magnitude of Russia’s cyber capacity is fairly consequential and it’s coming," Biden said after releasing a formal statement that called on companies to "harden your cyber defenses immediately." Biden went further in his statement, adding that companies have "the power, the capacity, and the responsibility" to boost defenses over "critical services and technologies on which Americans rely."
Full Story

Uncategorized

The regulatory landscape for privacy and data protection in the U.S. is ever-changing, especially at the state level. The IAPP Resource Center aims to keep privacy professionals in the know with its "US State Privacy Legislation Tracker," which is updated weekly to reflect the latest bill introductions and status updates for existing proposals. The tracker's format was also recently updated to improve user experience.
Full Story

Tracking the latest CCPA, CPRA amendments

While the California Consumer Privacy Act and California Privacy Rights Act continue to preoccupy privacy professionals, there is still much to be decided with both laws. The IAPP's updated "CCPA-/CPRA-Related Legislation Tracker" keeps tabs on bills pending in the California Legislature that would amend the CCPA or CPRA and may otherwise impact how organizations understand or approach each law. The deadline to pass bills is Aug. 31 while the deadline for bills to be signed into law is Sept. 30.
Full Story

Uncategorized

For The New York Times’ “Sway,� host Kara Swisher discusses with U.S. Rep. Ro Khanna, D-Calif., a lack of action by Congress on privacy or antitrust legislation. Khanna and Swisher discussed what legislation could look like, with Khanna saying public and political will is a challenge, adding the discussion extends beyond technology. “This is about our democracy. This is about our economy. And if we get to that point, then we will start to see the reform,� Khanna said.
Full Story

Uncategorized

The Atlantic Council issued a policy brief outlining the need for U.S. and Indian delegations to include discussions on cross-border data flows as they restart the U.S.-India Trade Policy Forum. Atlantic Council Fellow Justin Sherman explained how the two sides have "real opportunities to identify common ground on data policy and work to maximize the mutual benefits therein." The brief laid out key focuses the U.S. and India could explore, including law enforcement's access to data, data processing and localization requirements, and data security.
Full Story

Uncategorized

A federal judge issued an injunction against Texas-based Turbo Solutions at the request of the U.S. Federal Trade Commission and Department of Justice over an alleged deceptive credit repair operation. The company claimed it could delete inaccurate and negative information from customers’ histories within 40 days but failed to deliver. It also allegedly filed false identity theft reports without customers’ knowledge. The agencies’ complaint seeks civil penalties and consumer redress.
Full Story

Uncategorized
  • A report by the State Attorney’s Office said the process for selecting leadership to the Spanish data protection authority, the Agencia Española de Protección de Datos, does not comply with regulations, but the office is endorsing it stating while it is “irregular,â€� it does not invalidate the process, Kiratas reports.
  • An audit report of Argentina’s Agency for Access to Public Information published by the National Auditor General’s Office identified non-compliance in the areas of access to public information, transparency and protection of personal data.
Uncategorized

Following the British College of Policing releasing a live facial recognition guide for English and Welsh officers, civil liberties groups are calling for its outright ban, the Independent reports. The guidance to officers said to make sure use of live facial recognition is, “legal and ethical,� even though a 2020 Court of Appeal decision found the South Wales police use of the technology violated privacy rights and broke equalities law. Critics feared live surveillance would allow innocent people to be put on facial recognition watch lists.
Full Story

Uncategorized