data localisation and data security

Post on 14-Apr-2017

363 Views

Category:

Technology

1 Downloads

Preview:

Click to see full reader

TRANSCRIPT

D A TA L O C A L I S A T I O N A N D

D A TA S E C U R I T YM A R T I N A F R A N C E S C A F E R R A C A N E P O L I C Y A N A LY S T A T E C I P E

Q E D E V E N T O N “ C Y B E R S E C U R I T Y A N D C L O U D C O M P U T I N G ” 2 6 A P R I L 2 0 1 6

A TA X O N O M Y O F D A TA L O C A L I S A T I O N

Definition: a Government imposed restriction that results in the

localisation of data within a certain jurisdiction.

Categorization:

1. Strict data localisation:

• Local storage

• Local storage and processing

• Local storage, processing and access (i.e. ban to transfer)

2. Conditional flow regime.

P R O T E C T I O N I S M 2 . 0

Source: ECIPE Digital Trade Estimates database - To be released in September 2016.

Note: The graph does not include conditional flow requirements and measures whose date of entry into force is unknown.

0"

10"

20"

30"

40"

50"

60"

70"

80"

1961" 1966" 1971" 1976" 1981" 1986" 1991" 1996" 2001" 2006" 2011" 2016"

The$evolu)on$of$data$localisa)on$measures$

DOES DATA LOCALISATION INCREASE SECURITY?

Myth: Data security is a function of where the data is physically located.

DOES DATA LOCALISATION INCREASE SECURITY?

Data can be accessed from any location, independently from where the IP address is located.

DOES DATA LOCALISATION INCREASE SECURITY?

More control of the implementing jurisdiction…

THE COST OF DATA LOCALISATION

Source: The cost of data localisation: Friendly Fire on Economic Recovery. ECIPE Occasional Paper No.8/2014.

THE COST OF DATA LOCALISATION

Source: The cost of data localisation: Friendly Fire on Economic Recovery. ECIPE Occasional Paper No.8/2014.

THE COST OF DATA LOCALISATION

Source: The cost of data localisation: Friendly Fire on Economic Recovery. ECIPE Occasional Paper No.8/2014.

THE COST OF DATA LOCALISATION

Source: The cost of data localisation: Friendly Fire on Economic Recovery. ECIPE Occasional Paper No.8/2014.

1. Market access commitment: any data localisation

measure which imposed a ban to transfer infringes such

commitment.

2. National treatment rules: any data localisation measure

requiring a foreign supplier to build new servers or use

local servers gives a competitive advantage to local

suppliers.

G A T S C O M M I T M E N T S

Exceptions: inter alia, national security, data privacy, fraud

and safety, etc.

—> Necessity test: there is no reasonably available WTO-

consistent alternative (US-Gambling dispute)

—> Burden of demonstration.

G A T S C O M M I T M E N T S

F R E E T R A D E A G R E E M E N T S 2 . 0

Trans-Pacific Partnership:

Art. 14.13: “No party shall require a covered person to use or

locate computer facilities in that Party’s territory as a

condition of conducting business in that territory”

Exceptions:

1. Carve-out on financial services;

2. “Legitimate policy objective”

TTIP?

TiSA?

F R E E T R A D E A G R E E M E N T S 2 . 0

M A R T I N A F R A N C E S C A F E R R A C A N E E M A I L : M A R T I N A . F E R R A C A N E @ E C I P E . O R G

THANK YOU!

top related