Session
Organizer 1: Timea Suto, 🔒International Chamber of Commerce
Organizer 2: CORIZ Angela, ETNO
Organizer 3: Robyn Greene, Meta
Organizer 4: Berviller Maylis, Business at OECD
Speaker 1: David Pendle, Private Sector, Western European and Others Group (WEOG)
Speaker 2: Maiko Meguro, Government, Asia-Pacific Group
Speaker 3: Bertrand de La Chapelle, Chief Vision Officer, The Datasphere Initiative
Speaker 4: Clarisse Girot, Head of Division, Data Flows, Governance and Privacy, OECD
Speaker 5: Robyn Greene, Director of Privacy and Public Policy, Meta
- Mr Bertrand de La Chapelle, Chief Vision Officer, The Datasphere Initiative
- Ms Clarisse Girot, Head of Division, Data Flows, Governance and Privacy, OECD
- Ms Robyn Greene, Director of Privacy and Public Policy, Meta
Speakers bios
Mr Bertrand de La Chapelle, Chief Vision Officer, The Datasphere Initiative
Bertrand de La Chapelle is the Co-Founder and Chief Vision Officer of the Datasphere Initiative and the Co-Founder and Executive Director of the Internet & Jurisdiction Policy Network. With over 15 years of experience in multi-stakeholder governance processes, he draws on a diverse background as a diplomat, civil society advocate, and tech entrepreneur. Previously, Bertrand served as a Director on the ICANN Board (2010-2013) and as France’s Thematic Ambassador and Special Envoy for the Information Society (2006-2010). He actively participated in the World Summit on the Information Society (2002-2005), fostering dialogue among civil society, the private sector, and governments. He is a frequent speaker at major Internet governance forums, including the Internet Governance Forum. In the 1990s, Bertrand co-founded and served as President of the virtual reality company Virtools, now part of Dassault Systèmes. He is a graduate of Ecole Polytechnique (1978), Sciences Po Paris (1983), and Ecole Nationale d’Administration (1986).
Ms Clarisse Girot, Head of Division, Data Flows, Governance and Privacy, OECD
Clarisse Girot is the Head of the OECD’s Data Governance and Privacy (DGP) Unit, where she focuses on data governance, data flows, and privacy. Before joining the OECD in August 2022, she was a Senior Fellow at the Asian Business Law Institute (ABLI) in Singapore, leading a project on the convergence of data privacy laws across 14 Asian jurisdictions. She also served as Managing Director of the APAC office of the Future of Privacy Forum (FPF) and advised the head of the TMT practice at Rajah & Tann Asia LLC. From 2001 to 2015, Clarisse worked at the French Data Protection Authority (CNIL), including roles as head of the Department of European and International Affairs and senior advisor during the GDPR's development. She was a member of the Jersey Data Protection Authority (JDPA) from October 2018 to June 2022. Clarisse holds a Master's in Private Law and a postgraduate degree in Intellectual Property from the University of Paris Panthéon Assas, a Magister Juris (MJur) from the University of Oxford, and a Doctorate (cum laude) in Comparative Law from the Tilburg Institute for Law, Technology, and Society (TILT) in the Netherlands.
Ms Robyn Greene, Director of Privacy and Public Policy, Meta
Robyn Greene leads Meta’s global privacy policy efforts on cross-border data flows and government access to data. She oversees policy development, research, and coalition building on critical internet governance issues, including Meta’s strategies regarding EU-US data transfers and global data localization requirements. Before joining Meta, Robyn spent five years at New America’s Open Technology Institute as Senior Policy Counsel and Government Affairs Lead, where she focused on policy and legislative proposals related to surveillance and cybersecurity. She also worked at the ACLU's Washington Legislative Office, developing similar policy analyses. Additionally, Robyn served as a subject matter expert on the Data Privacy and Integrity Advisory Committee at the Department of Homeland Security, advising on facial recognition technology. Robyn has testified before Congress on cyber threat information sharing and published the largest publicly available study on US Intelligence Community Section 702 compliance violations. Her work has appeared in prominent media outlets, including the Washington Post, Politico, Lawfare, and Just Security.
Ms Maiko Meguro, Director for International Data Strategy, Digital Agency of Japan
Maiko Meguro is the Director for International Data Strategy and International Affairs at Japan's Digital Agency. She represents the Agency in G7, OECD, and other bilateral strategic partnerships, focusing on international data governance and the Data Free Flow with Trust initiative. Previously, as Director at the Ministry of Economy, Trade and Industry (METI), she led the G7 Digital Track and the Data Free Flow with Trust during Japan's G7 presidency. From 2018 to 2021, Maiko served as a legal officer at DG CONNECT in the European Commission. She is also a research fellow in public international law and legal theories at the University of Amsterdam, where she publishes in prominent American, European, and Japanese legal journals on international law, international economic law, and law & technologies.
Mr Dave Pendle, Assistant General Counsel, Law Enforcement & National Security, Microsoft
David Pendle is an Assistant General Counsel, focusing on the field of Law Enforcement & National Security at Microsoft.
Robyn Greene, Private Sector, Western European and Others Group (WEOG)
Berviller Maylis, Intergovernmental Organization, Western European and Others Group (WEOG)
CORIZ Angela, Technical Community, Western European and Others Group (WEOG)
Roundtable
Duration (minutes): 90
Format description: A Round Table format is best-placed for the type of cross-sector, collaborative session that we envisage. It will be optimal for establishing an atmosphere that ensures both participants and panellists can engage in fruitful discussion, and that they can do so on equal footing through a seating arrangement conducive to multi-person dialogue. To allow time for in-depth discussion and also accommodate a constructive Q&A section to address the questions, feedback and thoughts of the audience, 90 minutes is the most suitable timeframe for the session.
1. How can policymakers balance the need for data governance and protection of national interests with the imperative for open and interconnected global data flows? 2. What strategies and mechanisms can be implemented to promote harmonization and policy interoperability in the governance of cross-border data flows across different jurisdictions? 3. How can multistakeholder and international cooperation restore trust in global approaches to data governance?
What will participants gain from attending this session? Participants will gain a comprehensive understanding of the complexities surrounding data governance in a globalized economy. They will acquire insights into the challenges posed by fragmented regulatory approaches and the importance of harmonized policies for facilitating cross-border data flows. Attendees will also gain practical strategies for promoting policy interoperability and fostering collaboration among stakeholders to address concerns related to privacy, security, and economic growth. Furthermore, participants will leave with actionable recommendations for policymakers to develop cohesive frameworks that balance national interests with the imperative for an open and connected digital environment. Ultimately, attendees will be equipped with the knowledge and tools necessary to contribute effectively to the advancement of inclusive and prosperous digital ecosystems on a global scale.
Description:
Data underpins every aspect of today’s global economy, supporting business operations, facilitating the delivery of essential government services, and enabling international and multilateral cooperation. Despite data’s core role in facilitating economic activity and innovation, mistrust continues to grow. This mistrust stems from the difficulty of understanding data, its nature and level of risk its handling carries. Trust is also eroded by concerns that national public policy objectives, including security and privacy could be compromised if data transcends borders. This fuels restrictive data governance policies and regulatory measures such as digital protectionism and localisation, deepening Internet fragmentation. With growth and development driven by data flows and digital technology, disruptions in cross-border data flows have broad reverberations that can lead to reduced potential GDP gains and adverse impact on the local digital ecosystems. To realise the full potential of digitalisation for inclusive socioeconomic growth, policy frameworks should facilitate the adoption of new technologies and the global movement of data while establishing clear rules and enforcing roles and responsibilities to maintain responsibility over compliance irrespective of locality. Numerous national, regional, multilateral, and multistakeholder initiatives have emerged, providing guidelines for data governance and the role of cross-border data flows. However, this proliferation runs the risk of fragmented approaches where harmonization and policy interoperability are necessary. Without cohesive strategies, the potential benefits of data-driven economies may remain elusive, hindered by barriers to cross-border data flows and inconsistent regulatory frameworks. This workshop will delve into these issues, exploring how to navigate the complexities of data governance. Participants will engage in constructive dialogue to identify practical solutions for harmonizing policies, ensuring interoperability, and promoting responsible data stewardship across borders. The workshop aims to pave the way for a more cohesive and inclusive digital landscape that maximizes the benefits of data while safeguarding privacy, security, and economic prosperity.
The session will deepen participants’ understanding of the challenges surrounding data governance in an interconnected world and the necessity for harmonized policies to enable trusted cross-border data flows. Participants will identify practical strategies for promoting policy interoperability and fostering collaboration among stakeholders to address concerns related to privacy, security, and economic growth. The session aims to generate momentum for ongoing dialogue and collaboration among stakeholders to develop a global data governance framework that ensures the realization of a more inclusive and prosperous digital landscape.
Hybrid Format: Prior to the session: to ensure speakers and attendees get the most out of the session, regardless of their chosen way of participation, organizers will make use of the session’s page on the IGF website and social media channels to share preparatory material and kick-start a dialogue. A preparation call will be organised for all speakers, moderators and co-organisers so that everyone has the chance to meet and prepare for the session. During the session: the moderators are experienced in animating multistakeholder discussions and will complement each other in merging onsite and online speakers and attendees. Onsite participants will be encouraged to connect to the online platform to stay informed and engage with discussions in the chat. Following the session: moderators will encourage participants to make use of the IGF website and social media channels to share further comments and contribute to the session’s report.
Report
Key Takeaways
The session tackled some of the many elements that are important to take into consideration when discussing data governance in the globalized economy we have today. Participants of this roundtable session kicked off the discussion by exchanging on the importance of having a dialogue about data, as well as on perceptions of data and cross border data flows. Participants reflected on the difficult balance between the free flow of data and data sovereignty. They stressed the reality of fragmentation, also in the legal landscape surrounding it, in contrast with the fact that the technical infrastructure of the internet is, by default, the free flow of data. A binary perspective on data – i.e. seeing data as either not accessible or completely open – is incorrect, as there are many areas in between. The concept of data free flow with trust (DFFT) was also discussed at length; a principle aiming to promote the free flow of data while ensuring trust in privacy, security, and intellectual property rights. Panelists argued that DFFT can pull people out of their ‘sectoral silos’, changing the overall perception of data flows. They also noted that there have been balances between privacy while enabling growth and DFFT for years. Combining the use and the need of data can also be country or culture dependent, so there should not be single international rules on this. Panelists also discussed restrictive data policies, noting the obligation for the government to protect its citizens, but also that this can turn into an expansion in surveillance. There is relevance, in some cases, for governments to seek access to cross-border data; for example, in cases of child safety. Additionally, concerns about third countries accessing sensitive data often result in requirements for controls and restrictions, along with competition concerns. This led into an overview of the consequences of taking a restrictive approach, where panelists detailed the main impediments to data flows, including data localization requirements, de facto localization, regulation and the restriction of the physical movement of data. The risks of such impediments include internet fragmentation, which can result in regional or national silos, and would pose a grave threat to the IGF’s goals of an open and free internet, as well as negatively affect human rights and privacy. The speakers then discussed tangible solutions, including issues in electronic evidence and criminal investigations, where data is most often stored in a country outside of the territory where the crime was committed. Accessing this information can be a long and arduous process today, which should be considered. Zeroing in on policy frameworks related to non-personal data, participants discussed its importance for cybersecurity, and that its usefulness depends upon its ability to flow across borders. Restrictions need to be balanced, harmonized, multilateral, and interoperable, and policies should be evidence-based. Further, rights and enforceability of obligations should be attached to the data and not the data subject. On the globalization of criminal evidence, it is key to have the right people in the room for discussions. The speakers responded to a few further questions elaborating on the distinction between personal and non-personal data and on existing and potential regulation on data. Participants said that there could be further discussions on our understanding of interoperability, particularly in the legal sense. They also spoke positively about ASEAN model contractual clauses, and about the potential of health data. Participants in general reiterated the need to continue multistakeholder discussions, concentrate on trust, and keep in mind technical limitations.
Call to Action
Participants spoke about the need to aim for having a maximum capacity to share access to data, along with the need for a common objective to responsibly unlock data for all. Discussions on data free flow should take the multifaceted concept of data into account, while recognizing the necessity of cross-border data transfers. Overly restrictive data policies can have undesirable effects, and can even pose a threat to the free and open internet; there should be a balance between business interests and protecting individuals. There should be a more holistic view on data, and differences between the sources of impediments should be reviewed. It is important to involve the private sector in discussions on data flows, as experts and government should be in dialogue with one another to come to better solutions; the IGF is fundamental in this respect.