Emerging Privacy Scholars Colloquium
Session I
As artificial intelligence evolves from static generative tools to autonomous “agents” (Agentic AI), the traditional “purpose limitation” principle—a cornerstone of data protection law—faces an unprecedented existential challenge. Unlike conventional AI, Agentic AI possesses the capacity for autonomous reasoning, multi-step goal decomposition, and real-time interaction with external environments. This inherent autonomy creates a “teleological gap”: the specific trajectories and intermediate data processing steps taken by an agent to achieve a high-level objective are often unpredictable at the time of initial data collection. Consequently, the rigid requirement that personal data must be processed only for “specified, explicit, and legitimate purposes” becomes a bottleneck for technological innovation, or conversely, a loophole for unauthorized data expansion. This paper identifies the tension between the fluid operational logic of autonomous agents and the static regulatory framework of existing data protection regimes. It argues that the traditional “notice-and-consent” model is insufficient to capture the dynamic nature of agentic decision-making. To bridge this gap, the research proposes a transition from “static purpose constraint” to “dynamic functional governance.” This framework emphasizes “algorithmic accountability” and “privacy-by-design” as primary regulatory tools. By introducing a risk-based stratification of agentic tasks and implementing real-time technical audits, the paper advocates for a co-regulatory approach. This ensures that while AI agents enjoy the necessary operational flexibility, their actions remain strictly within the “reasonable expectations” of data subjects, thereby safeguarding fundamental privacy rights in an increasingly automated digital ecosystem.
This article examines the data compliance challenges arising from cross-border data flows in the offshore issuance of China-based real-world asset (RWA) tokens. Using the “Two Chains, One Bridge” architecture deployed in the Ant Digital–Guotai Junan International project as its analytical sample, it identifies three concrete regulatory difficulties: the absence of operable criteria for identifying “important data” under the prevailing classification regime; the unworkability of existing personal-information outbound-transfer pathways where token holders are globally distributed and numerically unforeseeable; and the unsettled legal characterization of cryptographically derived data such as hash values and zero-knowledge-proof outputs under the statutory test of anonymization.
The article argues that these difficulties share a common root: a paradigmatic tension between two foundational presuppositions of existing data law — the territorial connecting factor and the centralized accountability structure centered on the personal-information processor — and the distributed, globally circulating logic of on-chain business. The former underlies the important-data and outbound-transfer problems, while the latter underlies the derived-data characterization problem. Drawing on comparative analysis of the European Union and the United States, the article observes that both jurisdictions constrain technical architecture through the enforceability of compliance obligations, rather than evading regulatory choice in the name of technological neutrality. The EU supplies high-density normative tools through MiCA and the 2025 EDPB blockchain and pseudonymization guidelines, whereas the United States demonstrates a methodology of extending existing data law — through the CCPA and CPRA — to bind tokenized business without dedicated legislation. While maintaining a strong-regulation stance, the article proposes restructuring China’s approach into three operable instruments: a tiered RWA-specific classification catalogue, a hybrid on-chain/off-chain architecture coupled with a redefined controller model, and a dedicated Mainland–Hong Kong data corridor operated through a regulatory sandbox, thereby aligning compliance obligations with the on-chain and off-chain division of labor within the existing legal order.
Session II
Generative artificial intelligence, particularly text generation and conversational systems based on large language models, is now widely deployed in areas such as intelligent customer service, educational assistance, financial advisory services, and public administration. In Hong Kong and Singapore, the deployment of such generative AI systems relies heavily on the continuous training of large-scale datasets and ongoing user interactions, giving rise to a range of structural privacy risks. Unlike traditional automated processing technologies, generative AI may trigger novel privacy concerns at multiple stages—model training, real-time inference, and content generation—including risks of personal data re-identification, prompt leakage, and privacy infringements arising from generated content.
This research focuses on text generation and conversational models within generative AI and systematically identifies three core categories of privacy risks emerging from their real-world applications in Hong Kong and Singapore. First, during the model training phase, datasets containing personal data may be “memorized” by the model and subsequently reproduced or indirectly identifiable in generated outputs. Second, in the course of human–AI interaction, user-input prompts may themselves constitute personal data, creating risks of storage, analysis, or secondary use across different purposes. Third, the phenomenon of “hallucination” in generative AI outputs may lead to the erroneous generation of information relating to identifiable individuals, thereby constituting an infringement of privacy rights.
Against this backdrop, the paper undertakes a comparative analysis of the data protection legal frameworks in Hong Kong and Singapore. In the Hong Kong context, the analysis focuses on the Data Protection Principles under the Personal Data (Privacy) Ordinance, with particular attention to purpose limitation, data accuracy, and data security obligations, as well as their applicability to scenarios involving continuous learning and content generation by generative AI systems. The research also examines recent guidance issued by the Office of the Privacy Commissioner for Personal Data on AI and data governance, exploring its regulatory role in addressing generative AI–related privacy risks in the absence of dedicated AI legislation. In Singapore, the analysis centers on the accountability-based governance model under the Personal Data Protection Act, with particular emphasis on the applicability of consent exceptions, legitimate interests, and risk-based compliance tools in generative AI contexts.
By comparing the application of existing data protection laws in Hong Kong and Singapore to generative AI scenarios, this paper analyses the differing legal response logics adopted by the two jurisdictions in addressing the continuous learning characteristics and indeterminate outputs of generative AI systems, as well as the inherent limitations of their respective approaches.
Data protection is traditionally justified as a means of limiting the concentration and abuse of informational power. In the era of generative AI (“GenAI”), however, this protective logic may produce an unintended governance paradox. This paper argues that data governance rules, while necessary to constrain data exploitation, may also create concentration-enhancing risks in GenAI markets.
The paradox arises from the way GenAI changes the role of data. In traditional digital platforms, data often derives value from observing users, predicting their preferences, and keeping them within a platform’s existing network. In GenAI, by contrast, data becomes part of the process through which models are built, tested, improved, and deployed. Its value depends not merely on collection or exchange, but on the ability to incorporate data into iterative systems of model development. This makes GenAI markets especially sensitive to unequal access to the conditions of model production. When external data becomes harder to obtain or reuse, startups and smaller developers may face greater obstacles, while dominant platforms can draw on data environments and feedback channels already embedded within their own infrastructures.
The paper develops this argument through a selective comparative analysis of three major data governance models: the European Union as the most mature rights-based data protection model, the United States as a fragmented and market-driven model, and China as a state-led model. Although these jurisdictions adopt different regulatory logics, the paper shows how they may converge in their structural effects by strengthening firms that already control extensive data resources, absorb compliance costs, and embed data governance within existing technical infrastructures.
The paper does not argue for weaker data protection. Rather, it calls for a competition-sensitive approach that protects individuals against exploitative or opaque data practices while also examining how data governance shapes market participation and platform power.
Session III
How does the expansion of AI governance reshape the relationship between privacy, state capacity, and public trust? This paper examines the political consequences of AI-enabled data governance in China, situating it within broader debates on privacy and data protection in the age of intelligent systems Governments increasingly deploy AI systems for risk detection, public health monitoring, fraud prevention, and social stability management. These systems rely on large-scale data aggregation and algorithmic profiling, often justified in the name of efficiency and security. While such technologies may enhance administrative capacity, they also expand state access to personal data and intensify concerns over surveillance, transparency, and accountability. Drawing on survey experimental evidence and comparative institutional analysis, I examine whether AI-driven governance strengthens regime legitimacy by improving service delivery or generates privacy concerns that undermine public trust. I conceptualize this tension as a trade-off between administrative performance and perceived intrusion. In the Chinese context, where AI governance operates within a centralized regulatory framework, this balance is politically consequential. This paper contributes to scholarship on AI governance and privacy by linking regulatory design to political incentives and public legitimacy, and by situating China’s approach within broader comparative debates on data protection and global AI regulation.
Can there be a functional privacy governance regime where private plaintiffs face near-certain judicial futility? The influential law and development literature assumes that private enforcement is essential for the protection of individual rights. Yet, individual privacy litigation in China presents a striking paradox: despite the robust legislative framework of the Personal Information Protection Law (PIPL), institutional frictions and remedial deficits render private legal victories both rare and pyrrhic.
This Article investigates why the Chinese state continues to institutionalize a private enforcement regime that appears, on its face, so ineffective. Drawing on a functionalist analysis of China’s digital governance, I argue that the significance of private litigation lies not in individual redress, but in its role as a decentralized informational sensor. By initiating litigation, these plaintiffs transform latent corporate misconduct and systemic patterns of non-compliance into observable judicial cases, effectively mitigating the state’s information asymmetry in the digital realm.
My research also reveals that the rise of Public Interest Litigation (PIL) led by the Procuratorate does not substitute for private action but functions as a power amplifier. The state strategically captures these private signals to overcome regulatory blind spots. By exercising its statutory investigative powers, the Procuratorate overcomes the technical and evidentiary barriers that stymie private individuals. It functions as a strategic lever: through “Procuratorial Suggestions,” the state translates fragmented legal disputes into institutional pressure, fostering a flexible yet potent negotiation with tech giants and local agencies. This mechanism not only compels systemic rectification but also facilitates “rule-making” through individual cases, effectively institutionalizing standards that individual litigants lack the standing or resources to establish.
Finally, I conceptualize this interaction as a “Regulatory Loop.” This selfreinforcing feedback loop demonstrates that the “utility of futility” in private privacy litigation is essential to China’s pursuit of a cost-effective and resilient digital order. China’s approach sheds light on a broader strategy of “governing by distributed signaling,” where the persistent encouragement of “weak” private claims is not a legislative oversight, but a deliberate design to fuel a high-capacity, state-led governance machine.
Session IV
Current accountability frameworks for AI systems, including the EU AI Act’s transparency obligations and the GDPR’s data protection impact assessments, operate within a regulatory compliance paradigm whose inquiry terminates once predetermined requirements are met. When an automated vehicle (AV) causes serious harm despite full regulatory conformity, an accountability vacuum emerges. Responsibility diffuses across manufacturers, developers, and operators, and existing frameworks cannot address it.
This paper argues that criminal law provides a necessary but overlooked dimension of accountability for AI systems. Where regulatory and data protection frameworks verify compliance with specified standards, criminal law evaluates the quality of human judgment: whether those who designed, validated, and deployed a system exercised reasonable care given what they actually knew about its limitations. Criminal law doctrine already possesses the tools for this inquiry, but legal systems risk going awry by tying criminal liability too tightly to regulatory breach, thereby obscuring criminal law’s capacity to evaluate compliant but culpable conduct independently.
However, operationalising criminal accountability for AV harms reveals a significant tension with data protection. Establishing what actors ‘actually knew’ requires evidence – system logs, sensor recordings, and internal risk assessments that reveal what actors knew and when. Yet data minimisation principles may mean that crucial evidence was never retained or has been deleted before any investigation begins. This creates a paradox: the very data protection principles designed to limit surveillance and safeguard privacy may simultaneously undermine the evidentiary basis for holding powerful actors criminally accountable. The question of how much data must be retained, for how long, and under what conditions, sits at the intersection of accountability and privacy. This paper argues that AI accountability frameworks must be reconceived to accommodate not only regulatory and civil liability, but also the evidentiary demands of criminal accountability without undermining the data protection principles they are built upon.
China has designated brain-computer interface (BCI) as one of its six strategic future industries under the 15th Five‑Year Plan, yet the integration of agentic AI has transformed neural data from passive “read‑only” biological records into interactive “read‑write” assets susceptible to real‑time decoding and manipulation. This technological leap exposes the normative fragility of China’s existing legal framework. The Personal Information Protection Law (PIPL) suffers from regulatory hollowing. First, Informed Consent Principle collapses under involuntary neural firing and AI‑driven mental manipulation, with users unable to control what is collected. Second, Purpose Limitation Principle is rendered obsolete by the multidimensional interpretability of brain signals—the same electroencephalogram data can simultaneously reveal disease markers, cognitive traits, and emotional states. Third, the dilemma of full anonymization, algorithmic opacity, and the inseparability of neural data make the data subjects rights of access, rectification, and erasure practically unenforceable.
To remedy these deficiencies, this paper proposes an interpretive and risk‑based approach. First, it advocates reclassifying neural data as a distinct “Ultra‑sensitive Information” category under PIPL, triggering the highest standard of legal protection. Second, it proposes a tiered dynamic consent mechanism tailored to BCI risk scenarios, including layered disclosure and ongoing capacity evaluation. Third, it adopts the contextual integrity framework for purpose compatibility assessment, replacing rigid purpose limitation rules. Fourth, it mandates privacy‑by‑design embedded directly into BCI hardware and algorithmic architectures, employing federated learning, differential privacy, and end‑to‑end encryption to transform abstract legal rights into concrete technical safeguards.
China’s regulatory transition carries significance beyond its borders: as a global leader in BCI application and a critical test case for the Global South and Asia‑Pacificregion, China’s choices in neural data governance will profoundly shape regional data protection norms and inform the global neurorights discourse on reconciling intelligent system innovation with the last frontier of human privacy.
Conference Day 1
Panel 1: Reconfiguring Data Protection and AI Governance
This paper calls for a paradigm shift in the way we view the regulation of new technologies as they arise. Instead of attempting to create purported “technology-neutral” new laws that will survive technological incursions, this paper argues the focus ought to be backwards, not to the laws themselves that regulated earlier technological architectures but, to the fundamental principles that underpinned them. It argues the relevance of these principles ought not to be ignored although the weight accorded them may vary according to the interests that need to be protected under the new technological architecture.
In his latest book, Daniel Solove argues “we should talk about the humans in the machine as well as before the machine and after the machine.” He also argues the “reasonable expectation of privacy” test which has hitherto guided the law’s approach towards privacy is deficient as the proliferation of intrusive technologies tend to shift expectations leading inevitably to reduced legal protections that, in turn, diminish expectations further, a vicious “downward spiral”. He also argues that “The law should focus on the privacy that society desires, not the privacy that society expects.”
The paper tests these assertions through application to selected examples and case studies, including first, second and third generation data privacy laws, the evolving rules on international data transfers as well as laws governing surveillance. It examines whether the fundamental principles underlying these have survived within new architectures such as those relating to artificial intelligence (AI), or if there has been an erosion of fundamental principles contained in earlier laws and their interpretation.
Privacy frameworks such as EU’s General Data Protection Regulation (GDPR) and Hong Kong’s Personal Data Privacy Ordinance (PDPO) are anchored to a foundational assumption: that personal data is data relating to an identified or identifiable natural person. This paper argues that the emergence of persistent, autonomous AI agents exposes a structural gap in this assumption.
Modern AI agents accumulate unique data profiles through continuous operation, including interaction histories, learned preferences, behavioural patterns, and adaptive decision-making tendencies, that are functionally analogous to the personal data of natural persons. These profiles identify and distinguish one agent from another, can be harvested or exploited by third parties, and carry many of the same risks (profiling, manipulation, and unauthorised extraction) that personal data protection regimes were designed to address. However, these data profiles exist in a regulatory vacuum as the definitional gateway of both the GDPR and PDPO requires a natural person. The “natural person” boundary is not as stable as it may appear: legal personhood has proven to be a mutable concept, extended to corporations, natural resources, and, as recent jurisprudence such as Dobbs v. Jackson Women’s Health Organization suggests, detached from any requirement of cognitive capacity or self-awareness. These developments suggest that the assumption that data protection must be tethered exclusively to natural persons deserves re-examination.
This paper explores three dimensions of this regulatory gap: the absence of any protective framework for agent-generated data profiles, the re-identification risk such profiles pose back to the human principal, and the regulatory silence around agent-to-agent data exchanges where no human is directly involved. It argues that the resolution of the regulatory gap need not await resolution of the broader question of AI legal personhood and concludes with possible reform pathway proposals that extend data protection principles without necessarily extending data subject status.
Chinese legal scholars have been debating whether the personal data protection regime, centred on the Personal Information Protection Law 2021 (PIPL), can meaningfully govern state processing of personal data. One strand argues for a “public law shift” — reconstructing data protection on constitutional foundations and administrative-law constraints on state power, rather than private-law consent mechanisms. A competing position treats the PIPL as essentially a private-law instrument poorly suited to constraining state organs, and prioritises data governance frameworks organised around administrative efficiency, inter-agency coordination, and — where invoked — national security and public order.
This debate has acquired fresh stakes as the Chinese state consolidates its position as the largest aggregator and re-processor of personal data. Recent developments include the 2025 Government Data Sharing Regulations, which integrate previous national guidelines on administrative data, and the National Cyberspace ID system launched in July 2025, which centralises digital identity authentication. Earlier, the Social Credit System and the pandemic-era Health Code system entrenched “sharing as the rule” as the governing principle for inter-agency flows of broad categories of data. Inter-agency sharing is the site where the “public law shift” faces its sharpest test. Data re-use between state organs evades consent and circumvents the PIPL’s general principles of purpose limitation and data minimisation. Public-law constraints appear to be the remaining source of protection for individuals — yet their adequacy is far from established.
The paper examines this interface through recent legislation, administrative measures, and available cases, drawing on Chinese legal scholarship to examine the potential of administrative law in regulating inter-agency sharing of personal data. It considers how current law allocates authority and constraint between the data protection and data sharing regimes, what the regulatory trajectory suggests about the direction of travel, and what the party-state’s other normative systems add to the analysis.
Panel 2: Data Privacy, Vulnerability, and Remedies
This paper examines the challenges of personal data protection in Vietnam’s digital banking sector following the enactment of the Law on Personal Data Protection 2025 and its implementing regulations. While the new framework represents an important step in formalizing data protection rights, its effectiveness remains uncertain in data-intensive financial environments. As banking services increasingly rely on large-scale data processing, automated systems, and platform-based delivery, questions arise as to whether a consent-based approach remains adequate. These concerns are particularly significant in the banking sector, where data governance is complex and closely linked to regulatory compliance, risk management, and operational requirements.
The paper addresses the central research question: To what extent does Vietnam’s legal framework move beyond a consent-based model toward an effective data governance regime in digital banking? It further explores whether existing regulations adequately address risks related to automated decision-making, data sharing within financial ecosystems, and platform-based services.
Adopting a socio-legal and interdisciplinary approach, the study combines doctrinal analysis of Vietnam’s data protection and banking regulations with comparative insights from international frameworks, including GDPR and OECD principles. It also draws on secondary data and policy reports to assess regulatory practices in digital financial services.
The findings suggest that although the 2025 law strengthens individual rights—such as consent, access, and data control—it remains limited in addressing structural risks related to data governance, including algorithmic accountability and third-party data processing. The reliance on formal consent is insufficient in opaque and continuous data environments.
The paper argues for a shift toward a governance-oriented approach, emphasizing accountability, risk-based regulation, and institutional oversight in the regulation of data-driven financial systems.
In May 2025, the Indonesian Ministry of Communication and Digital (Komdigi) suspended an online platform after reports emerged that residents in Bekasi had traded their retinal scans in exchange for substantial cash reward. At the same time, the Indonesian House of Representatives proposed mandatory iris or fingerprint scans for the purchase of 3 kilograms subsidized liquefied petroleum gas (LPG). These reveal a regulatory double standard targeting the vulnerable groups in the governance of biometric data. This study employs a comparative socio-legal analysis, contrasting Indonesia’s enforcement of the Personal Data Protection (PDP) Law with the regulatory frameworks in South Korea and Hong Kong. It evaluates the proportionality and necessity standards in biometric policy and regulation. The research identifies a critical protection void in Indonesia. While South Korea and Hong Kong have utilized robust, independent oversight bodies to impose significant deterrent fines, Indonesia’s response has remained administrative and effectively immeasurable. Furthermore, the study finds that both private-sector and state-led biometric schemes exhibit a recurring pattern of targeting economically vulnerable groups, either by offering cash incentives or by conditioning access to economic assistance on biometric disclosure. In practice, this creates effective pressure for vulnerable groups to relinquish their privacy rights in exchange for material necessity. The findings suggest that, without a centralized and independent Data Protection Authority and a risk-based regulatory approach that recognizes socioeconomic vulnerability, Indonesia risks not only enabling the misuse of personal data but also deepening existing layers of inequality.
When personal data is unlawfully processed to train an artificial intelligence model, deleting the data does not delete its consequences. Model weights that encode the influence of unlawfully processed data persist long after any erasure directed at the input layer, casting “algorithmic shadow”. This phenomenon reveals a structural failure at the heart of contemporary data protection law: its remedial architectures were designed for a world of discrete, retrievable records, not for the distributed statistical representations into which personal data dissolves through machine learning.
The conventional right to erasure as codified in Article 17 of the GDPR and the right to deletion in Article 47 of China’s Personal Information Protection Law, remain anchored to the act of deletion rather than its practical effect, leaving model-level persistence unaddressed and its “technically infeasible” exception vulnerable to systematic exploitation. The FTC’s algorithmic disgorgement model directly confronts algorithmic shadow by targeting the AI model itself as an object of remedy, yet does so through a blunt, binary destruction order that conflates remediation with punitive confiscation and threatens to impose disproportionate costs on technological innovation. Despite their structural differences, all three frameworks share a common failure: none establishes an adequate mechanism for addressing model-level data persistence.
Building upon an affirmative case for the legitimacy of algorithmic disgorgement as a remedial instrument, this paper reconceptualizes it as a graduated, effect-oriented remedy grounded in prospective risk elimination rather than retrospective deprivation of unlawful gain, thereby seeking to reconcile the competing demands of rights-based remediation, public interest protection, and technological innovation. Particular attention is given to the Chinese legal context, where the intersection of the PIPL deletion framework with emerging AI governance rules presents both distinctive vulnerabilities and reform opportunities that have thus far received insufficient attention in the comparative literature.
AI-enabled data processing has the subversive effects on personal data protection that almost entirely based on data subjects’ informed consent. Data trust system may offer a breakthrough institutional option by constructing a tripartite structure of “trustor-trustee-beneficiary” and introducing strict fiduciary duties to safeguard the interests of the beneficiary (i.e., data subject).
The paper assesses the possibility of establishing personal data trust under specific legal conditions. It emphasizes personal data be capable of becoming trust property (particularly under the Chinese laws) because personal data has the dual nature of unifying proprietary and personal attributes. The trustees shall bear a non-transferable duty to protect the personal interests inherent in the data. In consideration of the automation, scalability, and complexity and other technical characteristics of AI, the paper proposes a personal data trust system with a series of protection mechanisms by design, including but not limited to: setting out a trustee’s duty to audit algorithms to ensure the fairness and transparency of algorithmic decision-making; establishing protocols for data processing to prevent and control aggregation and re-identification risks; introducing technologies such as privacy computation and federated learning to achieve data utility without visibility and to prevent entire auto-decision with material impact on data subject; clarifying the legal relationship between AI system operators and trustees to construct a multi-party collaborative governance framework.
The paper identifies the need to bridge the legal gaps between the Chinese Trust Law and the Personal Information Protection Law through legislative interpretation or specialized legislation, to clarify the legal status and regulatory mechanisms of data trusts. The related supportive system encompassing organizational, technical, and regulatory aspects should also be constructed. This includes establishing professional admission and exit mechanisms for trustees and ensuring effective implementation of the system through cross-departmental collaborative supervision.
Panel 3: Cross-Border Flows and Data Sovereignty
As artificial intelligence (AI) systems increasingly underpin cross‑border digital services, proposals for ex ante, design‑based governance, such as “law‑following AI” (LFAI) that embeds legal norms within system architecture, are gaining prominence. Yet because AI systems rely on extensive personal data processing, embedded compliance inevitably reflects the domestic data protection regimes in which they are developed. These regimes remain markedly divergent: the European Union’s rights‑based and risk‑tiered model under the GDPR contrasts with the United States’ innovation‑oriented, sectoral approach, while China advances a sovereignty‑centred framework grounded in state oversight. When deployed transnationally, an AI system engineered to comply with one jurisdiction’s privacy rules may inadvertently generate non‑compliance in another, transforming ex ante compliance into a source of regulatory friction.
This article argues that LFAI calibrated to fragmented domestic privacy regimes can function as de facto regulatory or technical barriers to trade, particularly where embedded compliance produces effects analogous to algorithmic localisation measures that restrict cross‑border data flows. These dynamics are reinforced by the broad and often self‑judging personal data protection exceptions found in international trade agreements, including GATS Article XIV, Article 25 of the Joint Initiative Statement on E‑commerce, and comparable provisions in recent free trade agreements. Together, they risk constraining the circulation of AI‑enabled services and deepening digital trade fragmentation.
Through doctrinal analysis of WTO law and contemporary digital trade instruments, complemented by transaction cost theory, the article evaluates whether ex ante algorithmic compliance reduces enforcement and monitoring costs or instead amplifies cross‑border compliance burdens. It identifies the conditions under which personal data protection can be reconciled with open digital trade and proposes pathways for regulatory interoperability that prevent privacy‑driven AI design from becoming a new form of trade barrier.
This article traces the evolution of Vietnam’s legal framework governing cross-border data transfer provisions and argues that its advent is primarily driven by external forces rather than domestic drives. Vietnam’s cross-border data transfer regime is shaped by digital trade commitments in PTAs to which Vietnam is a party. Specifically, agreements such as the CPTPP and RCEP have served as regulatory catalysts, with their high-standard rules increasingly encroaching upon domestic data and privacy frameworks. However, rather than simply adopting international rules, Vietnam has progressively recalibrated them to reconcile international obligations with its own regulatory priorities and national objectives. This article argues that Vietnam has developed a distinct model for governing cross-border data transfers, in which the state has a pivotal role in controlling data flows in order to safeguard national security and assert data sovereignty.
The longstanding partnership between the EU and China in healthcare research is critical to biomedical innovation and global public health governance. For the European research community, China offers an unparalleled collaborative environment characterized by extensive human genetic diversity, the world’s largest genomic sequencing capacity, and significant market potential. However, cross-border flows of genetic data, indispensable for personalized medicine and translational research, face escalating challenges. China’s regulatory framework has substantially strengthened, increasingly conceptualizing human genetic data as national strategic assets beyond data protection. This shift has sparked concerns within the global scientific community that heightened regulatory controls may induce a “chilling effect” on multi-jurisdictional collaborations. The tension was exemplified in March 2025, when the Finnish data protection authority (DPA) investigated a university’s transfer of human genetic data to a Chinese firm, contesting the adequacy of safeguards.
This paper examines the regulatory architecture governing genetic data flows within EU-China scientific collaboration to identify practical barriers. Employing doctrinal and comparative legal analysis, the study examines relevant rules and mechanisms in the EU’ GDPR and China’s evolving data and biosecurity regimes. It identifies critical divergent points: the European approach treats genetic data as a “special category” of personal data that necessitates heightened protection, and GDPR transfer mechanisms embody an extraterritorial logic of “accountability”, requiring exporters to ensure essentially equivalent protection abroad. This threshold is, however, complicated by the landmark 2025 TikTok fine imposed by the Irish DPA, which intensified scrutiny over state data access and judicial independence in the Chinese context. Conversely, China establishes a paradigm of “bio-sovereignty”, viewing genetic data through a dual lens of personal privacy and national security resources. The export pathway is characterized by “government gatekeeping”, where government approvals play a prominent role to prevent resource mis-exploitation. This paper argues that the regulatory obstacles to EU-China genomic research arise not merely from discrete statutory requirements but also from fundamental divergences in legislative philosophies of these two jurisdictions, creating a double sided compliance deadlock.
This paper explores the nature of data protection in the UK following its exit from the EU. Post-Brexit reformers seeking to reform UK law have often looked to the other most developed Commonwealth jurisdictions for inspiration including, most especially, Canada and New Zealand which both have EU adequacy decisions as well as Singapore and Australia. In particular, the Canadian approach to data security and discipline was heavily relied upon in the UK Government’s Data: A New Direction consultation paper. However, its suggestions were not carried forward into the final Data (Use and Access) Act 2025 and, overall, the UK regime remains remarkably similar at a substantive level to that of the EU. Nevertheless, similarly to other old Commonwealth jurisdictions, the UK post-Brexit does not recognise data protection as a fundamental right and nor are the general standards of data protection legally superior to statutory exemptions. In addition, albeit potentially for different reasons, all the old Commonwealth jurisdictions including the UK share a much more limited approach to enforcement compared to that the EU, despite the latter itself having been criticised for a very patchy and often ineffective enforcement stance.
Conference Day 2
Panel 4: Reconceptualising Privacy Frameworks in the Age of AI
The principle of data minimisation, enshrined in Article 5(1)(c) of the GDPR, requires that personal data be “adequate, relevant and limited to what is necessary” in relation to specified purposes. This paper argues that, while foundational in European data protection law, this principle becomes increasingly untenable in the context of contemporary machine learning systems.
In contrast to traditional data processing, the value and necessity of data in machine learning are epistemically indeterminate ex ante. Model performance, robustness, and generalisability – particularly in large-scale and general-purpose AI systems – depend on complex and non-linear relationships within vast datasets. As a result, it is often not feasible to determine in advance which data will be “necessary” within the meaning of the GDPR. Consequently, data minimisation risks operating as a legal fiction, formally maintained but functionally misaligned with the realities of AI development.
In response, the paper proposes a shift from data minimisation to data sufficiency, understood as the calibrated use of data necessary to ensure system performance and reliability, embedded within a framework of ex post accountability, auditability, and risk management. This reconceptualisation aligns with the regulatory logic of the EU AI Act and contributes to broader debates on privacy by design and trustworthy AI governance.
Hong Kong’s Personal Data (Privacy) Ordinance was pioneering in Asia when it was enacted in the 1990s. Since then, however, Hong Kong’s data protection framework has only been incrementally updated. While the Privacy Commissioner has recently issued a series of AI-related guidance documents, including the Model Personal Data Protection Framework for AI, these initiatives rely primarily on soft law and do not create new rights or obligations.
This paper argues that AI and other data-intensive technologies expose important gaps in Hong Kong’s regulatory framework, particularly in relation to AI governance, protection of children and vulnerable groups, cross-border data transfers, and enforcement. The paper develops a reform agenda for modernising Hong Kong’s data protection regime that balances privacy protection, innovation, and data mobility while responding to Hong Kong’s unique position between international privacy norms and Mainland China’s evolving data governance model.
This paper offers an intellectual history of Helen Nissenbaum’s Contextual Integrity (CI) theory in Chinese legal scholarship and draws implications for privacy and data protection in the age of intelligent systems. It combines literature review and intellectual history, building a primary dataset of 171 Chinese Social Sciences Citation Index (CSSCI) journal articles identified through China National Knowledge Infrastructure searches, and comparing English canonical texts with their Chinese manifestations. The core argument is that CI’s Sinicization has shifted from an early interpretive mainstream to a later reflexive mainstream. In the interpretive phase, CI functions mainly as a method to parse positive law and to respond to external regulatory shocks, with China positioned as the object of analysis. In the later phase, CI itself becomes the object of inquiry and Chinese contexts are treated as sources of theoretical revision. A key mechanism in this shift is the emergence of authorized Chinese translations of CI canonical texts, which clarified CI’s notion of social context and corrected over-legalized readings of “Respect for Context” in policy discourse. To make the shift tractable, the paper reconstructs three debates between interpretive and reflexive camps that map directly onto current AI governance problems: (1) how to conceptualize the relationship between privacy and personal information protection, (2) how to regulate the further flow of publicly disclosed personal information across platforms and contexts, and (3) how to categorize sensitive personal information under risk-intensive processing, including biometric collection and AI-enabled inference. The paper concludes by identifying three contradictions shaping CI’s current Chinese trajectory: objective standards versus reflexive evolution, positive law versus plural norms, and theoretical universality versus cultural specificity.
Panel 5: Protecting Data Privacy in Healthcare AI
As the latest development form of artificial intelligence in the 21st century, embodied intelligence is deeply penetrating into medical and health fields such as medical diagnosis and treatment, rehabilitation nursing, and health management. This paper briefly sorts out the technological development and evolution of embodied intelligence in the medical and health field, and focuses on its typical applications in fields such as surgical robots, intelligent wearable devices, and medical imaging. While technology drives the development of the industry, it also gives rise to unpredictable risks, which are mainly reflected in the risks of privacy leakage and data security, fairness risks caused by algorithms, and the dilemma of subject liability identification. China’s existing regulatory system is difficult to meet the technical characteristics and scenario needs of embodied intelligence. Therefore, on the basis of learning from the regulatory experience of Europe and the United States, this paper puts forward targeted countermeasures. From the aspects of improving laws and regulations to protect patients’ privacy, establishing a standardized safety assessment and regulatory system for embodied intelligence, and constructing a clear liability attribution system, it provides theoretical reference and practical paths for the dynamic balance between technological innovation of embodied intelligence and patient protection.
This paper explores the privacy and data protection issues emerging around the implementation of artificial intelligence (AI) in healthcare in the Guangdong-Hong Kong-Macao Greater Bay Area (GBA). Since the use of AI in applications, including diagnostic systems, predictive analytics, and telemedicine, depends on large-scale health data, it heightens the risks of sensitive data processing, cross-border data transfer, and jurisdictional fragmentation. The article uses a comparative legal approach examining the regulatory systems of Mainland China, Hong Kong, and Macao, and the laws that regulate the protection of personal data, such as the China Personal Information Protection Law (PIPL), the Hong Kong Personal Data (Privacy) Ordinance (PDPO), and the Protection of Personal Data in Macao (PDPA). It also regards recent GBA-specific policy initiatives which enable cross-border data flows. The discussion recognises the major risks that can be presented by AI healthcare, such as re-identification of anonymised health information, biases in the application of algorithms, uncertain consent to use secondary data, and the conflict between data-minimisation principles and the formation of AI. The results indicate a pronounced regulatory difference in the GBA. Mainland China puts strong conditions upon sensitive health data processing and cross-border transfers, whereas Hong Kong has a more liberal approach, with fewer enforceable limits to outbound data transfers. Macao, in its turn, is over-dependent on consent-based systems lacking an overall structure that would address the issue of AI healthcare collaboration across borders. The problem of such fragmentation brings about legal ambiguity and limits the progress of integrated AI healthcare ecosystems within the region. This paper contends that data protection standards should be harmonised gradually in the GBA with the help of interoperable consent models, enhanced accountability frameworks and the introduction of privacy-enabling technologies. This research offers valuable contributions to current discussions on transnational data governance and provides practical information on advancing reliable AI healthcare in the GBA by tackling legal and technological aspects.
AI scribes are sophisticated software tools that automatically generate clinical documentation by ‘listening in’ to consultations and drafting medical notes, discharge summaries, and referral letters. Their adoption has expanded rapidly, with the global market valued in the billions of dollars and some estimates suggesting that up to half of clinicians use scribes. This growth has been accompanied by heightened concern about privacy risks, including secondary data use for algorithm training or disclosure to third parties, and the indefinite storage of consultation recordings. Media frequently warn that ‘AI is increasingly invading our medical privacy’, and that patient data are at risk – despite limited evidence of privacy harms to date.
This paper reports an analysis of publicly-available data governance and privacy policies of the most commonly-used AI scribe products in Australia, conducted in April 2026. Although the analysis began from a position of scepticism, the terms of service of Australia’s leading providers revealed relatively little cause for alarm. Most companies operating in Australia do not retain audio recordings, or retain them only briefly; patient data are typically de-identified before medical notes are generated; and identifiable data are not used to train AI models. Leading providers store data on local servers, although some US-based companies offer products globally while storing data on US servers. Retention periods for medical notes themselves are more variable, ranging from seven days to ‘never delete’, often configurable by clinicians.
These findings highlight four areas requiring closer scrutiny: compliance with published policies (underscoring the need for regulatory oversight); the robustness and legal implications of de-identification practices; the adequacy and ethics of patient consent for scribe use, where ‘de-identified’ data are treated as disconnected from the individuals from whom they originate; and unresolved questions of scribe accuracy and clinician liability in the absence of dedicated medical device regulation.
Panel 6: Privacy, Democracy and Children
Research to date on the uses of Artificial intelligence in political campaigns has tended to concentrate on the behavior of nefarious actors, and the spread of misinformation and deep fakes. These trends have inspired understandable concerns over the manipulation of elections by individuals and organizations operating from overseas. But AI (including generative AI) is also being deployed in legitimate ways by parties and candidates in many democratic societies. AI tools enable more personalized voter outreach. They facilitate more precise voter analytics. And they automate and cheapen content creation, through text, images and video. Political campaigns in many societies were already becoming excessively data-driven. AI exacerbates those trends.
This paper builds upon my existing body of work on the privacy implications of data-driven elections. It reviews the existing literature on the deployment of different forms of AI in political campaigns (in North America and Europe). It tries to isolate the existing practices of candidates and parties from the technological and corporate hype. It attempts to understand how AI is being used in political campaigns to facilitate and extend the process of “micro-targeting.” As the creation of ad content becomes significantly cheaper through AI tools, then the ability to deliver that content to ever more precise segments of the electorate, becomes a lot easier, with serious privacy implications.
The body of the paper addresses these privacy challenges in a comparative context. In 2019, I presented a report to the Global Privacy Assembly which addressed the regulatory challenges in comparative perspective (Note 1). In this paper, I apply the same framework to the regulation of political micro-targeting in the age of AI.
The regulation of the processing of personal data by political parties varies among democratic countries. In Europe, political advertising is strictly regulated by the General Data Protection Regulation and by the 2024 Regulation on the Transparency and Targeting of Political Advertising. The paper reviews how these rules impact the uses of AI by European political parties. Other countries, such as Japan, regulate uses of personalised data in campaigns through election law, which contains strict prohibitions on any personalized advertising through social media. In other societies, such as Canada and the U.S., where political parties are still exempted from privacy and data protection law, the use of AI tools for micro-targeting is more permissive. These comparisons will allow some tentative conclusions about voter privacy in the age of AI, and about the intersection of privacy rights and public trust in democratic institutions.
Note 1:
Colin J. Bennett and Smith Oduro Marfo, Privacy, Voter Surveillance and Democratic Engagement: Challenges for Data Protection Authorities. Report presented to the 2019 conference of the Global Privacy Assembly, 2019 at: https://rm.coe.int/report-privacy-voter-surveillance-and-democratic-engagement-2774- 4663-/1680a10852
Global jurisprudence is shifting towards holding technology giants liable for digital addiction, as is evidenced by the landmark verdicts against Meta and Google. However, India’s regulatory landscape remains focused on a traditional and narrow interpretation of data privacy. This paper seeks to reimagine data subject rights for children by moving beyond mere data protection to a framework of algorithmic accountability. We argue that in the age of artificial intelligence (AI), a child’s right should not be limited to privacy but should include cognitive sovereignty; the right to navigate digital spaces free from predatory architecture designed to bypass human agency.
This research examines the Indian Digital Personal Data Protection Act, 2023 (DPDP), highlighting a profound mismatch between the legislative provisions and technical reality. While section 9 of the DPDP prohibits tracking or behavioural monitoring of minors, the Black Box nature of the AI-driven recommender systems makes such violations nearly impossible for the data subjects to prove. Furthermore, this study critiques the parental consent fallacy, arguing that in a deceptive dark pattern and algorithmic nudging era, parental authorisation has become a legal liability shield for corporations rather than a substantive safeguard for the child.
By synthesising recent global litigation on social media addiction with unique socio-economic challenges of India, including low digital policy literacy and lax security enforcement, this research proposes a shift from the notice and consent model to a rebuttable presumption of harm. We argue that this is necessary to ensure that the developmental integrity of India’s youngest citizens is prioritised over algorithmic profits. It concludes that reimagining children’s rights required the law to treat AI-driven engagement not as a neutral service but as a sophisticated tool of behavioural modification.
Recent developments in data protection and privacy regulation have significant implications for schools, which increasingly function as data-intensive institutions in the age of artificial intelligence (AI). In Hong Kong, these challenges are intensified by a distinctive governance structure under the school-based management policy.
This paper explores the implications of privacy regulation for everyday educational practices in Hong Kong’s aided schools, focusing on dilemmas arising from recent guidance regarding the dissemination of students’ and teachers’ images. Drawing on examples from the author’s own involvement in school governance, the paper shows how ostensibly technical privacy guidelines generate uncertainty at the frontline of educational administration. On the one hand, in the context of population decline, schools are increasingly expected to maintain public visibility and market themselves through websites and social media platforms, performing the image of a ‘happy school’ for student recruitment. On the other hand, they are simultaneously being responsibilised for managing privacy risks whose scope and future consequences are rendered opaque by AI-driven data reuse and secondary processing, alongside growing expectations to address cyber-bullying—an area ambiguously positioned between the pedagogic authority of schools and forces beyond their formal remit.
The paper argues that these tensions cannot be understood solely as problems of legal compliance or privacy awareness. Rather, they reflect deeper questions of governance, power, and consent in institutional contexts characterised by dispersed authority. Reviving Basil Bernstein’s concept of framing, the analysis highlights how privacy regulation in the age of AI redistributes control over data practices without clearly allocating decision-making authority or risk. In this sense, Hong Kong schools experience a condition of ‘privacy without sovereignty’, in which consent is required but its meaning and limits remain increasingly indeterminate. The paper concludes by reflecting on the implications of this condition for AI governance, institutional accountability, and public trust in education.


