AI Governance Library

Global Frameworks and Standards Working Group Annual report – July 2024

Annual report of the Global Privacy Assembly's Global Frameworks and Standards Working Group covering its 2023-24 work on promoting global data protection standards and on cross-border transfer mechanisms, with comparative tables of contractual clauses.
Cover of Global Frameworks and Standards Working Group Annual report – July 2024

⚡ Quick Summary

Published by the Global Frameworks and Standards Working Group (GFSWG) of the Global Privacy Assembly, with the UK Information Commissioner's Office as chair authority, this annual report reviews the group's 2023-24 work and sets out its plan for 2024-25. It is submitted for adoption at the GPA2024 Closed Session.

The report covers two workstreams. The first promotes the Resolution on Achieving global data protection standards: principles to ensure high levels of data protection and privacy worldwide, adopted in 2023, through presentations to GPA working groups and international organisations, government meetings, a GPA newsletter article on "Resolutions with lasting impact" and a published set of FAQs. The second addresses cross border transfers: an updated factual comparison of standard contractual clauses across seven frameworks (ASEAN, Council of Europe, EU, RIPD, Argentina, New Zealand and the United Kingdom), a draft resolution on Data Free Flow with Trust (DFFT) for adoption at the GPA2024 conference, and a GPA member survey on transfers that received 37 responses. A third table on processor-to-processor clauses is in preparation, and the survey analysis is still underway.

🧩 What’s Covered

  • Executive Summary and Introduction: sets the work in the context of the GPA Vision of "moving towards a higher level of global data protection and privacy" and the GPA Strategic Plan 2023-25, lists the two high-level work items for the year and names the working group's members, including UK ICO as chair plus 27 member authorities and observers such as the Council of Europe, EDPS, European Commission, OECD and US FTC.
  • Working group activities – promoting the resolution: describes the 2023 resolution's common principles, rights and key practical elements, including transparency, proportionality, accountability, enforceable rights, protections for children, and privacy by design and default, together with the implementation plan and outreach actions, including reference to the resolution in the UN Special Rapporteur on the right to privacy's report to the 55th session of the UN Human Rights Council.
  • Comparative work on contractual clauses: a detailed comparison of standard contractual clauses in the ASEAN, Council of Europe, EU, RIPD, Argentina, New Zealand and UK frameworks, producing two tables (controller-to-controller and controller-to-processor), updated with amended Council of Europe clauses, with a third processor-to-processor table underway.
  • Data Free Flow with Trust (DFFT): a draft resolution to be presented to the GPA for adoption at the 2024 conference, setting out the key essential elements of DFFT and aligning with work in other fora such as the G7 and OECD.
  • GPA member survey on cross border transfers: developed around the context authorities work in, their issues, concerns and needs, the complaints they receive and possible practical GPA activities; circulated in May-July 2024 with 37 responses received and analysis ongoing.
  • Forward looking plan 2024-25: the three overarching actions allocated by the GPA Strategic Plan 2023-25 and the proposed work items, including promoting high standards, updating and promoting the comparative tables, implementing any adopted DFFT resolution and completing the survey analysis.
  • Conclusion: summarises progress against the work plan and thanks working group members and observers.
  • Annexes: two sets of comparative tables, Annex 2 on controller-to-processor transfers and Annex 1 on controller-to-controller transfers, each organised under 18 headings covering structure and variability of the clauses, third-party beneficiaries, interpretation, key data protection principles, security, organisational obligations, onward transfers, sub-processors, data subject rights, redress, liability, supervision, local laws, public authority access, non-compliance and termination, governing law and jurisdiction.

💡 Why it matters?

The report and its annexes give transfer compliance teams a side-by-side view of how seven contractual clause regimes allocate obligations on purpose limitation, security, breach notification, onward transfers, sub-processors, data subject rights, liability and supervision, which supports the design of clauses that work across systems. For regulators and policy staff it documents how one international forum is building common ground on data protection standards and on Data Free Flow with Trust, and shows where the seven systems diverge. The document states plainly that it is an informal comparative tool and not legal advice, and that it does not aim at mutual recognition of the seven systems.

❓ What’s Missing

The subject matter is data protection, privacy and cross-border transfers; AI systems and AI-specific governance obligations are not addressed. The survey results and their recommendations are not yet available, the DFFT resolution is still in draft so its final essential elements are not settled, and no date is given for publishing the updated comparison tables. The tables cover only the content of the clauses themselves, so they are not an exhaustive list of obligations, and greyed-out boxes indicate the absence of provisions within the clauses rather than the absence of legal obligations, which may arise from national or regional law.

👥 Best For

Privacy regulators and data protection authority staff tracking GPA positions; compliance, legal and privacy teams mapping contractual clauses across ASEAN, Council of Europe, EU, RIPD, Argentina, New Zealand and UK transfer regimes; and policy analysts following work on data protection standards and Data Free Flow with Trust.

📄 Source Details

The document is Global Frameworks and Standards Working Group Annual report – July 2024, issued by the Global Frameworks and Standards Working Group with chair authority the UK Information Commissioner's Office, dated July 2024 and running to 127 PDF pages. The extraction supplied covers 80 of those pages: the main report (pages 1-13), Annex 2 on controller-to-processor comparative tables, and the opening pages of Annex 1 on controller-to-controller tables, whose later sections were not available. Language: English. No URL for this document itself is printed in the text.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.