vix.ing · top · new · best · stats

Data protection in the BRICS countries: legal interoperability through innovative practices and convergence

2022/11/07 by Luca Belli, Danilo Doneda · 1 voice
Computer Science · Economics, Econometrics and Finance · Social Sciences · #Digital Transformation in Law #Law, AI, and Intellectual Property #Privacy, Security, and Data Protection

paper · pdf · doi:10.1093/idpl/ipac019

openalex publication_date 2022/11/07 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/29

Abstract

This article stems from the research elaborated by the CyberBRICS project, which is the first attempt to analyse the digital policies in the BRICS countries (Brazil, Russia, India, China, and South Africa). The article focuses on the ongoing developments and increasing rapprochements of BRICS data protection frameworks and on the emergence of innovative elements in such frameworks. While not renowned for their commitment to data privacy, all BRICS countries undertook major regulatory developments regarding data protection in recent years, elaborating new legislation, updating existing one, or establishing new regulatory agencies, while also introducing innovative institutional and normative elements in their frameworks. This article contextualizes the BRICS and their efforts to cooperate on digital affairs, stresses a tendency towards convergence and ‘legal interoperability’ of several aspects of their national data protection policies, and explores some examples of how BRICS countries are innovating data protection, emphasizing that such innovations could inspire other countries. Lastly, it argues that BRICS should seize the opportunity to further enhance their cooperation on data protection, as the increased convergence and compatibility of their data protection frameworks may be beneficial for both individuals and businesses, while implementing the recent BRICS commitment to enhance intra-BRICS cooperation on digital policies. The BRICS countries—namely, Brazil, Russia, India, China, and South Africa—are an unusual grouping1 and even more unusual is the thought that such countries may be trailblazers regarding a topic such as personal data protection. Indeed, while their economic and geopolitical relevance can hardly be denied, the human rights track record of some of the group members is far from stellar. Several rankings categorize some of them as ‘partly free’, ‘not free’, or even ‘authoritarian regimes’,2 and Russia has recently announced it would no longer participate in the Council of Europe and cease to be a party to the European Convention on Human Rights, after the members of the human rights body voted to suspend the Russian Federation’s rights of representation.3 While the authors of this article are well-aware of the abundant critiques regarding the human rights track records of some BRICS countries, the goal of this article is not to analyse how personal data are or may be misused by BRICS governments, but rather to explore what are the normative and institutional innovations that are emerging in these countries. Indeed, such innovations are already exercising international impact, not only exercising mutual influence among BRICS countries, but also shaping how third countries—either traditionally or more recently influenced by BRICS—are adapting to normative and institutional innovations introduced by the grouping members. BRICS countries act as very influential leaders both in their own regional environments and, to a lesser but increasingly relevant extent, globally, thus stressing the need for carefully studying their policy choices. To understand the relevance of this coalition of emerging powers and why the policies of the BRICS are likely to have a considerable impact, particularly on the Global South, we must briefly analyse how and why these very heterogeneous countries decided to establish their own process of club governance. Originally, the BRICS acronym to some of the and to emerging powers some economic no to of or normative some after the of the acronym by the countries to the by an of governance. this the BRICS club has to a and can be by the Global South, increasing relevance and of countries. The BRICS countries to their on the of the the members of the the relevance of emerging and them their among BRICS countries, their in the process to be a these emerging powers understand the of club and the by this the a as South would their first in on the of that the and the and the this the emerging the to establish their own by a of Russia the first of in as an a international no of has of the which have a among the members a to other such as the and the club a the of South and, in the the and which can be as institutional the the of and and has more BRICS is not an a and a and the is the only existing the the grouping decided the own the and and of to the thus a new for the their the BRICS countries some not only in some of their economic but also in their regarding and very recent of countries, as as the of and such as the and the to understand the it is to that while the existing is by Global South countries, such countries have the of such for very and to existing and further what to be as this the and of the of the and, the BRICS grouping can all be as of the Global South, by the of the to relevance and establish an to what as an and by developments in the BRICS both of the that digital have for the grouping and of the relevance these countries have regarding digital this it is to after European and for several years, the BRICS are to in of data and while a and not from the BRICS are their and and to enhance their cooperation on digital we the BRICS have all or data protection frameworks. should be in countries of as some BRICS members such should also be a of as the BRICS in data protection is not only by an to human rights but rather by or even This is to understand why and how BRICS countries policies as their and may from of be to for the and that Global South countries. such their of data protection frameworks and the of new institutional and normative a very on how and why emerging personal data protection, and why BRICS are and even new leaders in is to understand that such of and normative for emerging an in a BRICS countries have not only some of the countries in the but also leaders in such as This is particularly in the or years, and have the the first and countries the of in the and, even more has the from the in only the of the national digital the this article on the and of the the first to this on the increasingly relevant by the grouping members in the personal data and on the of digital BRICS members. This article stems from the research by the CyberBRICS which is the first attempt to a of digital policies of the BRICS countries. on the ongoing and increasing of BRICS stressing the of a tendency towards that the grouping can be as an of for and stressing the innovative of some of the policy and elements that BRICS are introducing in their frameworks. we to understand the BRICS and their efforts to cooperate on digital affairs, by the existing and relevant data on the While the we explore how an cooperation on the of and has in the BRICS we on the BRICS frameworks. on the research by the CyberBRICS we the of a tendency towards convergence of several aspects of the BRICS national data protection that the of a data protection and increased in on digital ‘legal we explore some examples of how BRICS countries are innovating data protection, new and as as new of data protection that can inspire other countries. Lastly, we that BRICS should seize the opportunity to further enhance their cooperation on data protection, as the increased convergence and compatibility of their data protection frameworks may be beneficial for both individuals and in the To this article that the BRICS of on in the of could a for cooperation and of the recent BRICS commitment to enhance intra-BRICS cooperation on digital policies, and to the new BRICS and which and BRICS in the are to the relevance of the BRICS in and, the that their digital policies and data protection on a countries of the to individuals data or data on the and of the and a of of the of the BRICS and a major opportunity for individuals and in these countries, while also considerable The members of the BRICS grouping have that digital is an for the of their and and that data protection a to digital rights are from and from is or the BRICS are well-aware of the that and of may and that policies are not only to how individuals and to of the this it is to that the by a major as a for the of digital in the BRICS countries. Indeed, the BRICS have elaborated and an of and their own is as is to that the have a particularly and for the personal the of a of members of the is also to the has in is not a the protection of personal data and as increasingly for BRICS countries to their the leaders for the first in even BRICS a the or not even in their first are in the BRICS on the of the BRICS leaders for the first an to the by the in the of and in the BRICS the the BRICS for have for the first in their and an increasing of on from the of on in the grouping the of the frameworks which intra-BRICS and could be we in the this the recent for the of ‘legal frameworks of cooperation among BRICS a BRICS on The process research and policy may be an of what in is to as This has efforts to and data protection frameworks. while elaborating their the BRICS have the of the data protection the European a of while adapting the to their and the of BRICS digital policy cooperation and the towards personal data protection are particularly BRICS countries have from first and thus not only their but also innovating data protection by from the BRICS frameworks are policy convergence and ‘legal to the increasing compatibility of the BRICS normative frameworks the protection of personal an of the BRICS in the Russian of in BRICS of the of and the to human rights and the to privacy, and that the rights that have must also be the the that and protection of personal data should be and BRICS leaders their of and data of individuals all the as as of the of and of human in the to While the be for that such commitment from some countries that have a in of protection, the of the elements is to understand the the policy which all BRICS countries in the To their and enhance their BRICS leaders a BRICS on that could and cooperate to of and on policies and in an The from the to a more regarding stressing the for cooperation among the BRICS countries that could for the of the and of of the process of the of the of and BRICS leaders the a to enhance cooperation in international digital The the of several cooperation on and digital more such as the BRICS and the BRICS the BRICS on the BRICS and the BRICS of The policy and of BRICS and as as the that the of and is a to the that are traditionally policies and in the of an for the BRICS for among of of the BRICS countries, which mutual and the of a to BRICS of the the BRICS the to the of relevant the of an ongoing the new BRICS and and the of a new BRICS and the BRICS an cooperation to the and of BRICS and and to their and their and of BRICS among The and, the recent BRICS the but also the to be to This is not an to the very of BRICS and the of a is no as the is thus increasing the of the of all existing their their of has as a of rather and considerable such as the of the can be this the BRICS the of a new for BRICS as of the of the which BRICS a of BRICS and the for cooperation of Indeed, as by the the and of digital a of economic of the and, for this BRICS countries the of digital in the of and cooperate other in the of digital and have to to and explore to regulatory of digital of The a further as the countries have the of cooperation in these Indeed, the commitment of BRICS of to the of the to of and the of intra-BRICS cooperation in this the of the BRICS of on in the of and the of the BRICS on in the of and also the of establishing frameworks of cooperation among BRICS on this and the towards and of on a BRICS on cooperation on in the of and on among BRICS The towards cooperation and convergence is increasingly and regulatory and The that the recent BRICS data protection developments to how the of their international are an opportunity to BRICS data policies, the of commitment to data protection policy elements are already in the BRICS countries and, this already existing the of their the of a or a may to the for frameworks of and should be as a for the as we in the in their to data protection, BRICS are some innovative elements that should be as to be as by the for BRICS countries would also from studying such innovative as to that are by all countries. To understand why BRICS digital policies and, their data protection frameworks are particularly we need to not only that these countries of the but that more of are also from the data to and are by a of of which more is to digital the BRICS grouping the of what is the and a for the of and but also for the of the of individuals not only to the of and data also the of that can the of the BRICS countries. The and the economic and geopolitical relevance of personal data have efforts in all BRICS countries. The in the of and to the of while the BRICS the countries commitment to the of for of data protection and the this in policies has This explores some of the of the research by the CyberBRICS project, regarding the While the BRICS frameworks this some of the the of a of BRICS countries undertook major regulatory developments regarding data protection, in recent years, elaborating new legislation, updating existing or establishing new regulatory The recent the of a new that in in the of a new in and a new Council on and the new to data protection in the and in the a an Russia data protection on after data in the of the the of as a new thus the to the of a new which introduced in the in and by a in is also frameworks and in the of the the new of and of the should be the in new after a new in and also introduced new rights to and to the protection of personal in new in South new to of the of which in after a a very BRICS countries have their data protection introducing major developments in their the of the of their national several regulatory elements are emerging in an The for such convergence is likely the from existing particularly the European the Council of Europe Convention and the on the of and of While the BRICS on data protection a several as we in the it is also to that are considerable it is to the and South frameworks and the European one, as to the and which establishing a more while The of BRICS to have from likely these countries have their data protection efforts in the and Europe an regulatory to data protection. and may also a as in these countries, have from the European and, have a to be influenced by European and and India, on the have decided to their own regulatory which are both the recent and the in the of data protection of the of these countries must also be as a relevant their to an the and of their the their these countries from from and on their on data protection, them to their more on their and and their own rather to and are also to be such as the which can and the regarding the of data protection on the of the CyberBRICS project, we can a but of policy elements which BRICS data protection frameworks are to the recent of the BRICS data protection in these countries have the of their frameworks on existing and, as we also to for that other have not to of convergence is the of personal data in which all BRICS as the to an or the South even more the protection also data to as we in the also the of data and data the may The which the data protection is are also The in BRICS frameworks may be in all data protection and a that is as the first The BRICS data protection and data and BRICS have a of rights BRICS frameworks establishing the rights to of or of personal data the of the data and of BRICS data protection frameworks also a very of for data and the data has in the frameworks. The South the rather The new to a and individuals in personal and This would be the and Russian data while the would the data to the the the of which the to be a to from the of a and The for data in the BRICS to data protection and in to process on the data and the of all personal data their The normative elements in the to innovative that can inspire both BRICS countries and other countries the relevant is the to the from an on personal data to data in This is very in the by a on the which even the by which the is from to Indeed, of data has of a and in BRICS countries in several from their of data frameworks to what to be in India, which is the of data personal and data all BRICS countries have the of international data for the BRICS for international data third are as an of protection, but some of them have data and or are likely to them we can both convergence and regarding international such as data and The and South frameworks no to of personal data national Russia the first to data in national The to the that all personal data must be the the of India, the data to that of personal data to which the is on a or in a data in the The may of personal data as from this on the of or of the but personal data be of international data the of a of protection is heterogeneous from the of on as in the or to data for national or the of or by national the of and the of that BRICS countries to international data we a the to understand and the The a of the international data by the BRICS frameworks. The of is to a of all the that BRICS countries in their frameworks to or data as as to the what are by all or some BRICS countries and which are to some of data in the BRICS data in the BRICS all data protection frameworks in BRICS countries have an the of South which only the party is in the or is in South but not to or data South from all BRICS data protection also to the the as the a powers to the to from the of the for and have a major BRICS data protection frameworks may be is the for of the has a to the European one, as The recent of all as to this the in to data protection a data to the on of of which is to for all BRICS countries to a in a the of the the their national and may be as a of their and institutional frameworks. has a new the by a very innovative body as a and Council very has the an after the of a by the the of this to be by it as an from the and the the Russia, data protection is by the for of and while in the body is the which is not but is as of the have several in other countries, are to such as data protection, or their of has and by and as of the why the Russian and frameworks be as that are to data protection the is The for the of an the not the has Lastly, South the only BRICS to have a only to the and to the and to the this may the the the and body and establish new While BRICS countries are relevant from existing frameworks to their own national data protection it is to that are also introducing considerable this we a of the innovative of the BRICS data protection frameworks. While these elements have only introduced should be carefully as some and innovative that are likely to be by other countries in the The data protection even only very recently and several to be some very such from and in other of the The and of the in the first this first is the from the of in a economic Brazil, and group on a by of a data protection for the economic not have such a a some to that which a to in by the of This first in and the data protection in Convention of the Council of Europe and of the European the it some of the such as the to and to the The of the even on this to the relevant of in the by the of and the from to which a of and for and The of such process the of several in this but also the of and the as a of the of the as we the which to the of the has the by the The of what is the of an among of which not data protection and from but rather them in a could introducing regulatory and which of the data protection in international on the process are to on some of which we as innovative This is also the in other countries, which their own data protection for a and, the need to their that could international data thus digital Brazil, the to to international data has of the major for the of a data protection of the elements of the commitment of the to the as a which would the of several in the the of a data protection this to some of the which traditionally not to the from the and the in the a relevant to the and this it is not that the would the of a as an body to the and to the protection in both and aspects of the as the a the and Council The Council has and not has or are in article of and and for and, for the of the on the by and and and, data protection and among The Council a of are by the by the by the of by the by the by the among of from and from national from the from the and from and The process to on the group the in is their The have the to and the of of the of and to the of which have a on the and the The of a in the Council the of the a in the of the in the as a that a The the several by the a and in The among even to a coalition of and from several to the and of and of the of these the need to a in the data protection to and a to these in the process of of data protection. Russia, personal data protection is by which in and in and in the Russian data protection is by a particularly and which has for of The to the Russian in and in by and these the a new of personal data that can be and are as data by the data to be the Russian personal data to an of To the the to and from the data The the of this new of personal data the a which to process data to personal data which are by the data to the Russian data protection personal data by the data to be can only be an or them can that the data to the by the the the for Russian of and a of all the of regarding the of personal Lastly, the a new to of the of personal which can be is the only for the and of personal data is by a new in of the as data to which an of have and which is by the data by for the of such in the in the to the new personal data can be only after the of and the or that the of personal data the of personal data to be and the personal data is as the a new for the to the data and to be to personal on of the to process or the for of data and the data must also the to of personal data that can be be it the first the data or personal data the to of the of or other The of the has also the Russian to the for to a to all the of Indeed, to to personal data data can be by the or a to be by This may the by the and in the innovative introduced by the recent of the Russian is the new to of of personal Indeed, that the of personal data can be on from an to from can be to the by the personal data to which the and the of which should be the can also be as a to the of data which has not this the data can the to the that is the personal data or to a of The for the on the of the of of that must as as the is of that need to from the of the or a by a Lastly, it is to Russian policies are not particularly Russia can be a in this as the normative it as as have other BRICS such as and of the the of the to the Russian of the to all personal data from Russian on and the of the personal data of Russian are in of the recent Russian of and the have the already ongoing tendency towards data and which is by Russia as of national the of a of To this several have the relevant of that Russia has the years, the to data and for to a of as while also considerable data has of the not the only the Russian for the of digital on a of policies and is to that this Russian of digital is increasingly and the of the an the digital of the While has very and which is on the of a is a of to as the that is particularly relevant to the that the data protection undertook the of Indeed, the of the is by the as to the of a digital in such as digital and thus While the of is to the elements of the are for and in and is the national digital as of has to more of the it of the of by and to individuals on their has the to the of for the of of in While can be for it to be on a as an for all these other to the for the of the the the the to the of a to in India, which can only be and by the the the the to the of an which to be by the the of the in the policy a article on a new The article of the which in as as the existing of the the already by the is as a data to the of and for data that can individuals their personal The of is particularly as it has to a on all to and the of personal that third may and be a of digital The be on the of to individuals to to of personal by of and and the of that act as a new of has already in the the by the of This is on the of and the of a of which act as the this the of the be to the of personal data from to the of the on the of the are to act as data which a data to and an and are not to personal but rather to be and as a for data is also by as the of the digital data To understand is to a and that is a of the which all them businesses, or the digital to to be in the of the of the to understand how must be this is that it could to the of Indeed, while it is to how can and data it must be that such is while a data protection by and the data protection in to for other of and, in this research on the of in of on the other should be Indeed, the has the to an for both or of data from the on how the is and of the by and must in that the of the be to personal data the of a and to data to and Lastly, it is to the Russian and that may be in the data

Discussions

Related