Description
In today's data-driven global order, personal data holds significant social, economic and political value. The transnational nature of personal data flows demands effective global data protection governance. While the OECD Privacy Guidelines and the Convention 108 are foundational data protection instruments, the European Union (EU) is a pioneer regulatory actor shaping a global data protection regime. The extraterritorial reach of the European Union's General Data Protection Regulation (EU GDPR) has embedded rules, norms, principles, and decision-making procedures within the apparatus of data protection governance at the national, regional and global levels. However, South Asia represents a distinct case, as no State in the region has adequacy status under Article 45 of the EU GDPR. Despite the absence of a formal adequacy mechanism, South Asian States have adopted data protection reforms influenced by the EU GDPR. This qualitative research draws on primary and secondary data, including interviews with experts, through the lens of Krasner's regime theory. The research study demonstrates that the EU GDPR is an influential regulatory anchor in shaping a data protection regime alongside an evolving regime complex, driven by regulatory fragmentation arising from innovation-led development priorities and sovereignty concerns in South Asia.