Abstract

New Media and Society (NMS) was a long time in the making. It involved several colleagues, not all of whom made it to the finish line as well as several contributors from Sage, the publisher. NMS was gestated in that hopeful season when John Perry Barlow’s (1996) Declaration of the Independence of Cyberspace was a subject of conversation and various other utopian dreams were in the air. While referring to Barlow’s definition of cyberspace, the inaugural editorial soberly laid out the state of the field as the co-editors saw it and expressed the hope that the journal would not only be a platform for ongoing research but would also help shape the development of the field (Jankowski et al., 1999).
In 1999, the founding co-editors described the field as “international in scope and interdisciplinary in approach.” There is little question that the object of study transcends national borders and poses challenges both for state and industry actors. The issue is whether scholars habituated to national and disciplinary frames are able to keep up with the rapidly changing phenomena they are seeking to understand. An interdisciplinary approach is easy to prescribe but difficult to do. The present reflections focus on the international and policy dimensions.
Short-wave radio broadcasts jumped national borders, but for the most part, it was not a mass phenomenon and not an essential feature of the business model. Hindi film songs being released in the 1950s on Sri Lanka’s advertising-supported radio channels that reached into India and quack medicines prohibited in the United States being peddled through high-powered Mexican radio broadcasts even earlier were examples of exceptions. Satellites ratcheted up the concerns about nation-states losing control over what their citizens watched and listened to. Smythe (1960) was among the first to discuss their boundary-spanning capabilities, although at that time ground stations allowed for state control. But even with the very small aperture terminals (VSATs) that were introduced later, it was still possible for punitive action to be taken against those who deviated from state-sanctioned behavior (Dalfen, 1970).
With the advent of the Internet and its integration into the everyday functioning of the economy and society, most nation-states have no alternative but to take the international dimensions into account in policy-making related to media and communication. The intertwined issues of data protection, data localization, and cybersecurity illustrate the phenomenon well.
Data protection
Even the world’s largest economy and information and communication technology superpower, the United States, is unable to make rules governing data protection without considering international concerns (Bradford, 2020). The General Data Protection Regulation (GDPR) of the European Union (EU) includes an extra-territorial element, the adequacy certification. Without a form of approval from the EU, companies located in the United States would not be able to seamlessly process data that falls within the scope of the GDPR. The pressures exerted on the countries of the Global South that generate export revenues and jobs by serving as back offices to firms located in Europe (described as Business Process Outsourcing [BPO] or Business Process Management [BPM]) are even stronger.
Data protection is an esoteric subject, but most data protection laws are of general applicability. Therefore, they affect a host of everyday activities and behaviors. All Internet users, even those who have never set foot in Europe, experience the effects of the European data protection laws from the perspective of data subjects while clicking the innumerable cookie banners that keep popping up as they roam the Internet. But its effects on data controllers, the term used to describe those who use data for instrumental purposes, are deeper.
If one keeps a list of invitees to a family event on one’s own computer, it is explicitly exempted from data protection obligations (e.g. Regulation (EU) 2016, Art 2(c)). But that same list sitting on the computer of a free-lance event planner is subject to the full panoply of European-style data protection rules. An example is the requirement to appoint a Data Protection Officer (with qualifications that may be set out in regulations) and inform the Data Protection Authority (e.g. Personal Data Protection Act 2022, section 20). Significant compliance costs are imposed on data controllers, especially on micro, small, and medium enterprises and organizations.
For countries in the Global South wishing to achieve the adequacy certification from the EU, adopting laws that follow the European model, if not the actual GDPR text, appears logical. This appears to be the reason for the data protection laws of countries such as Ghana, Kenya, and Sri Lanka being like the GDPR and predecessor laws in European countries.
Having a law that looks like a European data protection law does not guarantee an adequacy certificate. Only Andorra, Argentina, commercial organizations in Canada, Faroe Islands, Guernsey, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, and the United Kingdom have been certified in the 4 years since the GDPR came into force. Of these, only Argentina may be considered as a country that has not reached the high-income classification. Is adequacy achievable for countries in the Global South?
The restrictive adequacy certification practices of the EU may be explained in multiple ways. One explanation is that the EU is using legislation to erect new forms of protection for its technology firms against the dominant US-based firms and that the countries in the Global South are suffering collateral damage. Increasingly, data protection is being seen as part of international trade law (Gao, 2021). But the most charitable one is that the countries in the Global South are not meeting the European standards of data protection, despite their legislation being modeled on the GDPR.
There are good reasons for the actual practice of data protection falling short of the legislated ideal. After all, it falls short even in Europe. The Chair of German data protection authority, the best funded in Europe, is on record as saying: “We have a lack of enforcement. Most of the European governments don’t give enough resources to the data protection authorities” (Satariano, 2020). Would it not be surprising that under-resourced data protection authorities would have difficulties in ensuring that the complicated provisions of their GDPR emulating laws are fully enforced?
Emulation of the European approach to data protection for most countries in the Global South is unlikely to result in the certification of adequacy and the hoped-for benefits in terms of continued service-export revenues and employment creation. But this does not mean either that people in the Global South do not need data protection or that policy or legislative emulation is wrong.
The problems of data breaches and abuse of sensitive personal data such as those about healthcare are real and require remedies. Adapting solutions that have worked elsewhere is eminently reasonable. It is well established that the appropriateness of regulatory solutions depends on the fit with the local conditions (Levy and Spiller, 1994). The issue in this case is that the commonly emulated solution is not the most appropriate one, and that more effort could have been made to adapt it to local conditions.
Because of the choices made by legislators and their advisors, researchers requiring data to train machine learning algorithms face greater difficulties. Certain innovations will not occur, and others may take different forms. Small firms and organizations will be compelled to incur additional costs or become scofflaws. Instead of bright lines demarcating what is permitted and what is not with regard to personal data, people will continue to have to navigate an ambiguous legal environment.
Data localization
Data flow across national borders. The operations of major processors of data are global. In many countries, attempts are being made to put in place data-localization laws and policies to constrain these flows. In essence, data-localization policies limit the storing and processing of data outside the jurisdiction where the data originated (or falls within the scope of data as defined by the relevant statute).
AWS, Google, and Microsoft Azure have demonstrated the cost-effectiveness of cloud storage of data. Not only do cloud services offer prices that are significantly lower than the costs of storage in hardware that is maintained by the data controller, but they also offer flexibility in terms of adding greater storage capacity when needed and reducing when the need no longer exists. Redundancy can be easily achieved. Risks from cyber-attacks and disasters can be minimized. For Software-as-a-Service (SaaS), cloud storage and processing are optimal, especially because cloud allows flexibility and convenient access for the service provider. It would be against the basic operational model and costly for a company such as Google to process real-time traffic data from the users of its map app in each country.
However, many governments place limitations on the use of cloud services, especially when the service provider is foreign, or the data are stored outside their jurisdictions. China is a prominent example (e.g. Creemers et al., 2018). The reasons may include ease of regulation and lawful access for criminal and civil matters; the concern that when data are stored within the jurisdiction of a foreign government, foreign authorities may gain access to the data; the desire to develop local data centers and cloud services by providing them with captive customers; and assurance of the safety and availability of important data. Increasingly, data localization is becoming a key issue in trade negotiations, with the possible outcome that data regulation will be governed not at the national level, but at the supra-national level (Gao, 2021).
It is understandable that countries such as China and India with large economies and geopolitical ambitions give priority to data localization. But it is puzzling that smaller economies which lack the capacity to manage advanced cloud services that include state-of-the-art defenses against cyber-attacks have also sought to do so, although some have been compelled to moderate imposed restrictions. For example, Indonesia imposed strict restrictions in 2012. Government Regulation 82 of 2012 which imposed them was revoked in 2019 (Basu, 2020). Early drafts of the Sri Lanka Personal Data Protection Act of 2022 included data-localization restrictions for state agencies, state-owned enterprises, and private firms. However, restrictions on state-owned enterprises and private firms were relaxed considerably through floor amendments in the legislature (Samarajiva, 2022).
The inability of relatively weak countries to compel big tech companies to follow their rules illustrates the reality of present-day global power relations. China, leveraging both its economic and political power, imposed its will on the tech companies well before their services caught hold with the public. They were compelled to compromise and then withdraw. China’s domestic market size and the purchasing power of its newly prosperous population enabled successful domestic alternatives such as WeChat. But this is a path that is not open to other countries in the Global South, even India which has a massive domestic market.
Once a major part of the populace, especially the youth, have become accustomed to apps that help with everyday life including travel, messaging, and translation, it is difficult for governments in democratic societies to ban the companies offering such conveniences. Myanmar, a closed economy in terms of digital apps just a decade ago, is unable to get rid of the Internet altogether and revert to the conditions prior to the reforms of 2011. The option of becoming like North Korea or Cuba does not appear to be open to Myanmar. It seeks to keep the Internet but uses the fear of surveillance to keep the population under control. The investors in the enabling infrastructure, Telenor and Ooredoo, have exited the country, but it is unlikely that Facebook and YouTube will be compelled to process data within the country. If the Myanmar government was to insist on Google processing the personal data generated by the use of the map app, it is likely that the end result will be the withdrawal of app from the small market that Myanmar is to them. That would be a high price to pay for data sovereignty.
Cybersecurity
Cyber-attacks, including theft and extortion, are increasingly emerging as a major concern in the Global South. In the same way that cyber criminals focused ransomware-based extortion on municipal governments in the United States (Fernandez et al., 2019), it appears likely that government systems in the Global South will be favored targets for cyber-attacks. Both are likely to be seen as lightly defended soft targets.
In February 2016, the Federal Reserve Bank of New York cleared five transactions made by criminals who had hacked into the Bangladesh Bank, that country’s central bank. The US bank’s system sent US$20 million to Sri Lanka and US$81 million to the Philippines. The losses may have reached US$1 billion were it not for happenstance (Das and Spicer, 2016). Most of the money that went to the Philippines could not be recovered. No arrests have been made.
The losses (actual and potential) and the failure to locate the culprits illustrate the enormity of the cybercrime challenges faced by all countries, especially those with weak cyber defense capabilities and weak systems overall. The best defense against these attacks is risk management, which would give weight to redundancy.
Redundancy requires critical systems to not be in a single data center. How likely will this be, if those who are managing vulnerable systems are compelled to store and process data only within the country? Data-localization policies that are being enforced administratively or are being written into legislation, especially by small countries with a limited number of data centers or cloud service providers, appear to be inimical to the objective of reducing the risks of cyber-attacks.
One response to proposals to permit the storing of critical data in the cloud, outside national jurisdiction, is that this would allow other states and external actors to gain access to that data. This response is based on an incomplete understanding of how cloud services operate with users being permitted to partition the segments that they use and to set in place encryption in addition to the defenses offered by the cloud provider. In addition, it is possible to store the data in multiple locations whereby the full dataset is fragmented. Unless multiple external actors collaborate, meaningful access will not be possible.
The experience of countries such as Estonia and Ukraine that have suffered cyber-attacks on critical systems shows that the responders have to bulk up quickly to defend the assets or restore the damage that has been caused. An ideal solution is a trained reserve of cybersecurity professionals who can be activated at short notice, as implemented in Estonia, the first country to be subjected to a concerted cyber-attack (McGuinness, 2017). Another solution is the establishment of mutual assistance agreements among state cybersecurity agencies. For countries with well-developed digital industries such as Estonia, the first solution may be feasible. For others, mutual assistance may be the practical solution.
The smaller the country is and the weaker its digital capabilities are, the less likely it can implement the Estonian solution. What remains is the mutual assistance solution. But this requires a different conceptualization of national security and a recognition of the necessity of international collaboration.
Implications for scholarship on New Media and Society
It is rare to see research and reflection on the issues discussed above in NMS. But data protection, data localization, and cybersecurity have impacts on the everyday lives of people all over the world, with perhaps less direct impact on the relatively less connected, namely the poor in all societies.
It is rare to see research and reflection on the issues discussed above in NMS. The term privacy has appeared 35 times in 1858 titles in the past 25 years. Data protection has appeared in 14, in some instances alongside privacy. Data localization and cybersecurity are absent.
Data protection, data localization, and cybersecurity have impacts on the everyday lives of people all over the world, with perhaps less direct impact on the relatively less connected, namely the poor in all societies. But even they are not insulated. A cyber-attack on an electricity grid or the banking system can affect the everyday lives even of the digitally excluded. They may be excluded from essential services or legal benefits. The examples discussed above have the appearance of macro phenomena and are for the most part addressed as such by decision-makers in the public and private sectors without adequate allowance being made for their capillary manifestations.
For example, all current data protection laws are anchored on Guidelines on the protection of privacy and transborder flows of Personal Data (1980) formulated by the Organisation for Economic Co-operation and Development (OECD) more than 40 years ago, including the cardinal principles of notice-and-consent and purpose specification. They are at the root of the ubiquitous cookie banners that pop up every time we visit a website. But common sense suggests that no normal human being can read all the consent forms and provide adequate informed consent. Research conducted on this topic has been reported in other fora (e.g. McDonald and Cranor, 2008). This is but one example of how research at the capillary level can potentially inform policy at the macro level.
Researchers seeking to illuminate the social implications of new media need not necessarily conduct research on the topics discussed above. After all, they are examples used to demonstrate the international and interconnected nature of new media phenomena. But it is important that researchers working at any level be informed of the qualities of these phenomena.
Fifty years ago, some scholars were pointing to some communication technologies such as satellites being capable of challenging national borders and the capabilities of nation-states to regulate them. Today, business practices and the everyday behaviors of people are not conducive to control by nation-states, at least not those with democratic cultures. China does, but the more important question is why more states do not (or find themselves unable to fully emulate China).
That is not to say that research on these policies or the ways in which they affect, and shape human behavior would not be useful. For example, the continued importance assigned to the notice-and-consent and purpose-specification principles in data protection and privacy regulation has a doctrinal quality. The visitor location registry (VLR) data generated by the pinging of nearby Base Transceiver Stations (BTS) by a mobile device can be analyzed to produce a detailed record of the physical movement patterns of the individual carrying the device (Samarajiva et al., 2015).
Common sense suggests that there should be safeguards on who is entitled to access such records and under what conditions. But should such safeguards be anchored on notice-and-consent, when such consent cannot be practically given for what is essentially machine-to-machine communication, independent of human volition? Even if consent is written into a complicated consumer contract that is a precondition to the provision of service, why would it be wrong to use pseudonymized VLR data for purposes other than locating the mobile device to complete calls or data transfers, such as traffic management? It appears that a fundamental rethinking of the principles developed by the OECD in 1980 is called for. Because the efforts of legal scholars (e.g. Cate et al., 2013) have failed to make headway, it appears that an interdisciplinary and different approach that is informed by research on all aspects of data use and governance is needed.
The references below are illustrative of the interdisciplinary approach advocated in the inaugural editorial. But this is a conceptual article, not a research-based one. The challenges of interdisciplinary research of some depth generally require a team-based approach, as evidenced by the multiple authors common in articles dealing with various aspects of data, such as computational social science and data analytics. Data scientists working in such areas have to know how to communicate with domain experts in whatever field they are working in. For example, the seven authors of an article on dengue propagation (Dharmawardana et al., 2017) included medical researchers and an article on transportation included a transportation specialist (Maldeniya et al., 2015). As NMS lives up to its promise, the lists of co-authors are likely to get longer, making the tables of content less elegant. But it will be for the good.
