# Introduction ata has always been an important resource and the main focus of countries' national security. In an extremely connected world, data generated by new technologies became even more important and in great need to be protected. On the other hand, D II. # Mapping Data Protection Worldwide Trends a) The European Model (GDPR) The European Union has been regulating data protection in a very strict way over the years. The General Data Protection Regulation (GDPR) is the current law regulating data protection in EU. It came into effect on the 25 th of May 2018 after being approved by the EU Parliament on the 8 th of April 2016. By approving GDPR, the predecessor Data Protective Directive, which was regulating data protection in EU since 1995, was consequently obsolete [2]. Even though the Data Protective Directive was doing well-protecting data in the EU, the European data was prone in the last years to several violations, which led to developing the GDPR. The new GDPR aims at empowering European citizens to control their personal data in a more effective way, in addition to unifying laws regulating data transfer and protection among all European countries, given the fact that the predecessor Data Protection Directive was today's technologies, which contribute greatly to the worldwide economy, are based on the generation of data that is the basis for the Internet and for the growth of Artificial Intelligence, Big Data, Internet of Things, Cloud Computing and other technologies. Balancing between protecting national security while benefiting from new technologies is an extremely difficult task, especially in light of the security risks presented by new technologies that require transferring data across borders. One of the methods countries resorted to in order to achieve both targets is drafting data protection laws and regulations to protect national data from breaches and disclosure. However, countries took several ways and developed different models of data protection laws, some of which infused international debate. Building upon previously published research about government cloud computing and national security [1], the paper tries to answer a simple research question revolving around how do countries differ in protecting their data and national security. The paper tackles the topic of data protection trends between practice and debate; mapping international models and trends of data protection, shedding light on current debates in this regard, and finally presenting some broad guidelines that can help countries choose the most suited data protection alternative. ? Increased territorial scope: Increasing the law's territorial scope is considered one of the major changes that affected the EU data regulatory framework. This goes back to the fact that the new GDPR applies to all companies working with storing and processing personal data of individuals residing in the EU, irrespective of the place of the company. In fact, this came as a remedy to the situation created by the predecessor Data Protection Directive, which was silent and vague about the territorial applicability of the directive. This led to filing many suits about whether to apply the directive or not in different cases. Therefore, the GDPR came out much stronger, compulsory and very clear regarding the territorial applicability of the law. Additionally, non-European data controllers and processors* 1 ? Penalties: One of the most important modifications that were introduced by the GDPR is imposing penalties for the violators; the penalty could reach a maximum of 4% of annual revenue or 20 million euro (whatever is greater), which is the maximum penalty imposed for the strong violations. The penalties system created by the GDPR follows a tiered approach to fines, according to the type of violation. (Article 83) who process or store European citizens' data are obliged to nominate a representative of the EU, as per Article 3-3 (Official Journal of the European Union: 32,33). ? Consent: The consent of users is firmly regulated in the GDPR, so that the wording of the terms of the agreement should be readable and easily written. Also, the reason for processing data should be clearly stated as well. Most importantly, according to the GDPR, users should have the right to withdraw their consents whenever they want. (Article 7) ? Breach notification: The GDPR considers breach notification, within a maximum of 72 hours of finding out 'without undue delay', as a compulsory activity that should be carried out in response to witnessing data breaches, as it endangers users' data integrity and security. (Articles 33,34) On a side note, it is worth mentioning that the GDPR regulates personal data in the EU. Meanwhile, there is the Regulation on the Free Flow of Non-Personal Data that regulates non-personal data in the European Union. Both of the regulations are being applied side by side to create a unified digital single market. # b) The United States Model The Snowden revelations showed an unstable relationship between IT giant companies and the American security apparatus, based on imposed obligations on IT giant tech companies to reveal users' data so long as data centers are located on the American lands or processed by American companies located outside American territories. This activity is done by means of judicial approval by relevant courts. These acts led many countries to consider the American companies as untrusted and that their citizens' data are unsafe in their hands. Several counterreactions have been taken by countries, as will be clear later in the paper. Additionally, disputes were raised between giant tech companies and the American security apparatus, as companies were trying to find ways out of the diminishing trust they are suffering from, creating pressure on American authorities to amend the laws in this regard. Some tech companies, such as Microsoft, sued American authorities for obligations to reveal users' data in Ireland. Also, following the Snowden revelations scandal, IBM started investing billions of dollars for building more than 15 data centers around the world. [5] No doubt that the American data protection laws are considered loose in comparison to the EU GDPR. In fact; as it is the case with many areas, there is no one common law that all states should be following, but several laws and acts on the federal level, in addition Data Protection Laws Trends: Practice and Debate *It is worth mentioning that the cloud computing environment allows third parties to work with the data, so the data controller may be the same as the data processor and may be a third party. For more information about the cloud computing environment, please revise previous research published by the author. not compulsory to EU countries, but more of a nonbinding framework. This situation witnessed change with the GDPR, which is binding and compulsory to all EU countries. The GDPR is not only compulsory to European countries but to all other companies and institutions in whatever place, so long as they deal with European citizens' data. The following summarizes main rights guaranteed to European citizens through the GDPR: [3], [4] ? Right to access: The GDPR guarantees the right of the users to get a confirmation from the data controller if their data is being processed or not, and for what reasons. This is in addition to guaranteeing users' rights to get an electronic version of their personal data at the data controller, without any expenses, which is considered a new form of empowering users and securing data. ? Right to be forgotten/Data erasure: The GDPR guarantees the right of users to force the data controller to erase their personal data and to stop collecting more data about them whenever the purpose of collecting data comes to an end, whenever the users withdraw the consent they gave in before collecting their personal data and processing it. to regulations of states pertaining to data protection of citizens inside those states. Some states are considered stricter than others with firm regulations in data protection, such as Massachusetts, which has strong legislation requiring each institution collecting data to provide a detailed plan of securing data. New York has also passed cybersecurity legislation that imposes a minimum requirement of security level. California is also one of the states known for protecting privacy throughout its history. The California Consumer Act has been recently passed and was put in action in 2020. The Act imposes new obligations on companies related to data protection, such as personal data tiering, clarifying how the data will be used, as well as putting restrictions on sharing personal data. The Act involves data subjects' rights such as the right to access data, the right to be forgotten and the right to refuse to share data with a third party. [6] To sum up, in the United States of America, there is no one independent entity responsible for protecting data, and there is no one framework for data protection to resort to as well. This has resulted in a loose data protection environment in the USA, which completely contradicts with the strict data protection environment in the European Union. To close this gap between the USA and the EU, the European Union has regulated protecting European data when transferred, processed or stored in the USA in a separate way, through the Safe Harbor Agreement that was in effect in 2000. However, the EU Court of Justice declared the Safe Harbor Agreement obsolete in October 2015, in the wake of the Snowden revelations and the Max Schrems case (the Austrian activist who sued Facebook for disclosing European data to the US security apparatus). These incidents proved the Safe Harbor was not capable of protecting the European data and was therefore replaced by a new law, which is the EU-US Privacy Shield Law in July 2016, to guarantee the maximum data protection for European data. The main difference between both laws lies in the mechanisms of European data transfer to the USA and the related rights and obligations. Main differences can be outlined as follows: [7], [8], [ It is becoming a matter of fact that the great development in new technologies is imposing threats on national security, and especially with the data revelations cases and incidents. Countries resorted to several ways to protect their data. One of the widest spread techniques is the data and infrastructure localization. Data localization implies passing laws and regulations that confine storing and processing data inside a specific land or geography, or allowing some specific companies to store and process data. [1] Even though the European model is considered one form of data localization, the author prefers to consider the data localization as a separate trend; because it contains several versions and iterations. And despite the fact that the EU GDPR is part of the data localization model, the author believes that the GDPR can be considered as a separate trend given the fact that it is the most looked-upon model and many countries around the world drafted their data protection laws after the GDPR model. Data localization comes in different degrees and forms. Data localization trends can be classified according to the following criteria: [10] i. Scope of Application Some countries impose a clear data localization policy, including all data of the nation, with a 'general scope of application' such as the EU, Russia [11], [12], [13], [14] and some Latin American countries, that impose data localization obligations on all citizens data (i.e. all data should be stored and processed inside the borders of the country). Other countries applied data localization on data of specific sectors that would harm national security, such as the United States that requires storing sensitive data inside its territories, as well as Canada [15]. This last case is closely attributed to the data tiering mechanism that some countries, such as the United Kingdom and the UAE, resort to in order to mitigate the level of data localization; so that data that are classified as highly sensitive would be localized, while data categorized as less sensitive would move Kingdom and the UAE impose data localization obligations on health data, for example, as they classify it as highly sensitive data. Other data and infrastructure localization regulations impose obligations on the importing of IT equipment and require them to be locally produced. # ii. Level of restrictiveness Countries are classified according to the restrictiveness they impose on the transfer of data to several categories, from the strictest to less strict. Studies differ in the number of categories; some classify them into three categories [16], while others classify countries on a continuum of 5 categories [17]. Despite the difference in the number of categories, the core is very similar. The paper adopts the 5 # A light-touch approach implies that all data, including personal data, can generally flow freely across borders with minimal regulatory requirements (if any). The USA is the prominent advocate of this approach. A prescriptive regulatory approach entails that cross-border data flows are subject to rigorous compliance requirements. The prescriptive approach falls in the middle of the regulatory spectrum, and typically comprises conditional transfer requirements. The EU is the prominent advocate of this approach. A restrictive regulatory approach means a complete or partial ban on cross-border data flows for reasons of national security and establishing political control over the domestic Internet. A guarded approach focuses on regulatory measures directed towards economic gains and considerations. Both the restrictive and guarded approaches tend to focus primarily on localization regulations, although their predominant policy rationales are quite different. In a data-driven world, where technological products and applications produce huge amounts of data, and with the increasing incidents of data revelations, especially from the side of giant tech companies dominated by the USA, countries are held in a tight position trying not to lose neither the economic benefits and power of new technologies and data-driven economy, nor their sovereignty and control over their people and resources. Countries are being overwhelmed by manifestations of neocolonialism in the technological world. From here, countries resorted to data protection laws and data localization obligations in a way to keep their control over their data and resources. Reasons behind data localization stipulations are fear of dependence, fear of losing control and sovereignty as well as technical concerns emanating from the security breaches, especially when breaches occur outside the territory [1]. One of the strong reasons is the absence of a strong international framework, augmented by frequent breaches scandals from U.S. giant tech companies. However, data localization laws and regulations led to a wide debate, skewed towards the idea that data localization is an undesirable trend, leading to negative impacts on the global economy and the development of the Internet. On the one hand, the advocates of the trend believe that through confining storing and processing data within the country borders, nations will be able to protect their data from spying and disclosure and would thereby protect their national security. [5] On the other hand, proponents of this trend believe that these laws usually fail to meet the announced goal and gradually turn to governments spying on their citizens, which impacts democracy and transparency. Most importantly, proponents argue that these kinds of laws negatively impact the growth of the global economy, impede the growth of other technologies that are based on the free flow of data (such as IoT [18], AI and Big Data), as well as threatening the development of Internet and relevant applications. Proponents are afraid that the prevalence of such laws may lead to fragmenting the global Internet infrastructure, which would be a major retreat in the development of the Internet society. [19] In this regard, Internet Society has recently developed some critical principles upon which the foundations of Internet freedom were based. Internet Society provides training in different countries to support the idea that data localization laws hit the critical principles of the freedom on Internet; precisely Critical Property 1 -An open and accessible infrastructure with a common protocol, Critical Property 3 -Decentralized management and a common distributed routing system and Critical Property 5 -A Technology Neutral, General-Purpose network. [20] IV. # Where to Stand Given this hot debate, and the wide diversity of data protection trends worldwide, studies developed some guidelines that can work as assessment criteria for countries to assess where to stand in this wide diversity in practice and controversial debates. The paper presents two frameworks for assessing data protection regulations, fulfilling both contradicting views about data localization; protecting national security and allowing for freedom of the Internet, and allowing for assessing the country's specific particularity and III. interests as well. Countries are supposed to make the most suitable mix and match from all variables, according to each one's interests, views and strategies. # Debate about the Trends The first is a group of elements to be assessed regarding data protection stipulations to ensure de jure privacy control and national security. Countries are expected to draft strong data protection regulations so that the following benchmarks apply: [21] ? Severity of requirements in the law that ensure i) Control: individuals have control over their data. ii) Safety: Personal data is safe in the hands of the organizations. ? Severity of compliance mechanisms that ensure i) Enforcement: mechanisms that increase the likelihood of detection ii) Sanctions: strong penalties that deter violations On the other hand, countries can assess to what extent will data localization benefit the economy through an assessment framework for different localization options. The assessment tool uses scored methodology and takes into consideration several factors for each localization alternative to finally reach a total score for each alternative so as to help the decision-making process [22]. Put simply and concisely, the model measures the impact of data localization alternatives on economic growth and data access, through the following sub-factors: ii) Speed of access: Since speedy access to personal data is very crucial in crime investigations, speed of access is important in this analysis, since delays can drastically reduce the likelihood of success. IV. # Conclusion Data protection regulations and data localization trends are some of the most debatable issues in the international arena. The twinning between data protection in the current technological environment and national security is on top of most countries' agendas. The paper presented a mapping of the worldwide trends in data protection, presented the two points of view in this regard, and tried at the end to provide some kind of guidelines for countries to assess the best-suited alternative of data protection. As shown, choosing the optimum level of data security is a tough task, requiring achieving an accurate balance between economic and political considerations to achieve security without harming the economy. ? The third-party who gets the data transferred to orworks with processing European data is totallyresponsible for data and should undergo the samewhole process of accreditation, just as the originalparty.c) Data Localization Model9]? Increasing the European citizens' rights; the PrivacyShield provides several ways for EU citizens to filecomplaints and cases about violations of dataprotection. The Privacy Shield Panel could be asecond resort to file complaints and cases if nothingwas reached using the traditional ways.? Intensifying the rigidity of requirements from American companies to be approved to work with EU data; where companies should get approvals, on individual company basis, to work with EU data according to a list of specifications evaluated by a specific panel. According to the Privacy Shield, Data Protection Laws Trends: Practice and Debate 1ConditionalStrict dataPartial dataConditional transfer:transfer:Free flow oflocalizationlocalizationHardIntermediate/datasoftRestrictive /Guarded approachPrescriptive approachLight-touch approachChinaAlgeriaAzerbaijanAustraliaIndiaArgentinaBahrainCanadaIndonesiaArmeniaBelarusMexicoKazakhstanBrazilGhanaPhilippinesNigeriaColombiaJapanSingaporePakistanCote D'IvoireKyrgystanUnited StatesRussian FederationEgyptNew ZealandRwandaEuropean UnionRepublic of Korea ? Economic growth i) Demand for goods and services: Assessing if building the infrastructure for local storage would create additional demand for goods and services (such as building data centers and the related components) which would consequently lead to creating direct and indirect job opportunities and therefore boost economic growth. However; demand could be affected by the value of imported equipment required for data centers. The overall impact on economic growth would depend on whether the demand would be met through domestic goods or through importing. Weighing those variables would give insights to decision makers about the best option of data protection regulations. ii) Competitive advantage of national firms vs. multinational firms: Countries should assess the costs of data localization from several perspectives. Mandating data localization would require more capital expenditure as a result of the costs of data storage and processing capabilities. Operational expenditure would also increase as a result of the costs of renting or operating data-related infrastructure. ? Data access i) Data Protection Laws Trends: Practice and Debate ## Acknowledgements This paper and the research behind it would not have been possible without the valuable contributions and support of my dad and supervisor, Dr. Nabil Abd Al Ghaffar, PhD in Political Science (Faculty of Economics and Political Science -Cairo University). In the loving memory of my beloved dad who contributed greatly in preparing the original text from which this paper is extracted. * Government Cloud Computing and National Security. Review of Economics and Political Science, ahead of print AbdAl Ghaffar -T-AllahHedaia Nabil 10.1108/REPS-09-2019-0125 2020 * What is the Data Protection Directive? The Predecessor to the GDPR NateLord 2018 Digital Guardian, available at * Key Changes with the General Data Protection Regulation Eu Gdpr Org * /679 Of The European Parliament and of The Council on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data, and repealing Directive 95/46/EC (General Data Protection Regulation) Official Journal of the European Union 2016. 27 April 2016 * The Growth of Data Localization Post-Snowden: Analysis and Recommendations For U.S. Policymakers and Industry Leaders JonahHill Force Lawfare Research Paper Series 2 3 2014 * USA: Data Protection StevenChabinsky FPaulPittman 2019. 2019 * EU-US Data Transfer from Safe Harbour to Privacy Shield: Back to Square One? FabienTerpan European Papers 3 2018. 2018 * COMPARISON Safe Harbor Vs. The EU-US Privacy Shield OTAVA 2019 * Privacy Shield website 2019 * Unctad Cross-border data flows and development: For whom the data flow 2021 2021 * Localization to Fragment Data Flows in Asia Fti Consulting 2017 * Asia-Pacific Data Protection and Cyber Security Guide HoganLovells 2018 * Russian's New Personal Data Localization Regulations: A Step Forward or a Self-Imposed Sanction? AlexanderSauvelyev Computer, Law and Security Review 32 2016 * Internet Iron Curtain Comes Down Across Mother Russia AntonySavvas 2019 * Breaking the Web: Data Localization vs. the Global Internet AnupamChander PUyen Le UC Davis Legal Studies Research Paper Series 378 2014 * Sovereignty and data localization EmilyWu Belfer Centre for Science and International Affairs 2021 * HarvardKennedySchool #:~:text=Data%20localization%20is%20 used%20to%20assert%20data%20sovereignty&text =Generally%2C%20governments%20want%20to%2 0claim,by%20whom%20it%20is%20stored.&text=It %20is%20generally%20a%20policy 20 * South Africa and Data Flows: How to Fully Exploit the Potential of the Digital Economy MartinaFFerracane Global Economic Governance Africa, Discussion Paper 2018 * Cross-border data flows: The impact of data localization on IoT GSMA 2021 cross_border_data_ flows_the_impact_of_data_localisation_on_IoT_Full_ Report.pdf (gsma.com * Understanding Data Localization Laws Big Bang * Internet way of networking use case: Data localization Internet Society 2020 * Quantifying Key Characteristics of 71 Data Protection Laws BernoldNieuwesteeg Journal of Intellectual Property, Information Technology and Electronic Commerce Law 7 2016. 2016 * How would data localization benefit India? AnirudhBurman UpasanaSharma 2021 Carnegie India