thumbnail image

 

  • Home
  • About APB Forum
  • APB Forum 2026
  • History 
    • 2025
    • 2024
    • 2023
    • 2022
    • 2021
    • 2020
    • Fall 2019
    • Spring 2019
    • Fall 2018
    • Spring 2018
    • Fall 2017
    • Spring 2017
    • Fall 2016
    • Spring 2016
  • Call for Paper
  • Invitation to 2025 Asia Privacy Bridge Forum (APB Forum)

    The artificial intelligence transformation, together with the growing demand for explainable AI (XAI) across sectors, has made coordinated international approaches to AI governance imperative. This year’s APB Forum seeks to address this challenge by bringing together distinguished experts from across the globe.

    The 14th Asia Privacy Bridge Forum, held in conjunction with Privacy Global Edge, convenes under the theme “Behind the Scenes: Enhancing AI Data Governance and Digital Responsibility.” This theme highlights the need to establish governance mechanisms that ensure the development of artificial intelligence strengthens rather than undermines fundamental rights and empowers citizens.

    The APB Forum seeks to advance its mission of fostering international collaboration on AI governance and data privacy, having evolved over 10 years into a platform of exceptional breadth and influence. Since its founding, it has brought together participants from more than 19 countries and engaged in sustained dialogue with international organizations including the OECD and APEC. Its deliberations have drawn on the expertise of 15 national information protection authorities, major research institutes, leading NGOs, and global law firms such as Baker McKenzie. This endeavor has been further enriched by the active involvement of technology leaders including Meta, Microsoft, Google, eBay, NVIDIA, ASML, NAVER, Kakao, NEXON, and NCSOFT, together with senior and young scholars from more than 40 universities worldwide.

    This year’s gathering extends the APB Forum’s distinguished decade-long legacy, welcoming delegates from across Asia who have been dedicated to advancing AI governance and data privacy throughout the region. By convening regulators, policymakers, industry leaders, academics, and civil society, this forum provides a unique venue for collaboration at a moment when the governance of artificial intelligence requires both urgency and vision.

    The insights exchanged here will not only illuminate present challenges but also help forge AI data governance and privacy practices that endure across borders and generations. On behalf of the organizing committee, I extend my sincere appreciation to all participants for joining the 14th APB Forum.

    Beomsoo KIM

    Executive Director, Barun ICT Research Center

    Yonsei University

    “Behind the Scenes: Enhancing AI Data Governance and Digital Responsibility”

    This year, the 14th Asia Privacy Bridge Forum moves beyond the polished facade of artificial intelligence to uncover the critical realities operating “behind the scenes.” Our journey begins within the enterprise itself in Scene 1, exploring how to move Beyond Compliance to the Corporate Culture by embedding genuine Corporate Digital Responsibility (CDR) into the very fabric of an organization. This internal commitment to ethics, however, inevitably confronts a broader societal challenge, leading us directly to Scene 2: The Architect's Dilemma, where we will debate the urgent need to forge a new social contract for data. Solving this dilemma requires more than top-down rules; it demands empowering the individual, pushing us in Scene 3 to look Beyond Governance and harness the transformative power of MyData and user-centric frameworks. With individuals empowered as the foundation, we can then lift our gaze in Scene 4 to The Next Frontier, charting a course for Asia's Collaborative Data Future where trust enables shared prosperity. By connecting these four vital scenes, the APB Forum is dedicated to building a comprehensive roadmap for a future of responsible innovation and genuine digital trust.

  • Keynote Speeches

    Section image

    How AI Agents Could Reshape Digital Privacy

    Jan Ondrus

    Professor ESSEC Business School, Director of Digital Disruption Centre

    Section image

    AI Legal System and the Roles of CPOs and CISOs

    Beomsoo Kim

    Prof. Yonsei University, Executive Director, Barun ICT Research Center

    Section image

    Privacy Protection Policy Directions in the Age of AI

    Cheongsam YANG

    Director-General, Personal Information Policy Bureau, Korea Personal Information Protection Commission

  • Summary of Discussion

    Scene 1: Beyond Compliance to the Corporate Culture: An Implementation Strategy for Corporate Digital
    Responsibility (CDR)

    Chair : Beomsu Kim (Partner, BakerMcKenzie Korea, Republic of Korea)

    Building Trust in Data: Understanding the Challenges of Today’s Technology

    Takaya TERAKAWA
    Founder, CEO, Technica Zen Co., Ltd., Japan

    Building trust in data requires organizations to demonstrate ability, benevolence, and integrity to users willing toaccept technological risks. However, three contemporary data practices undermine this trust foundation. First, organizations construct data warehouses to extract insights from aggregated information, creating inherent conflicts with data minimization and purpose limitation principles while blurring lines between permissible and impermissible uses. Second, international data transfers rely on complex Intra Data Transfer Agreements that stakeholders approve without understanding, enabling unchecked cross-border data flows. Third, businesses rapidly deploy AI systems despite widespread gaps in AI literacy, risking data disparities that disadvantage underrepresented languages and regions. Japan's regulatory response employs pseudonymization and anonymization to legitimize data warehousing, promotes Data Free Flow with Trust (DFFT) frameworks to simplify international transfers, and advances AI guidelines balancing innovation with risk mitigation. This presentation demonstrates how embedding Corporate Digital Responsibility (CDR) principles into organizational culture transforms abstract compliance requirements into operational practices that build genuine consumer trust amid
    technological complexity.

    CPO`s AI Privacy Strategy: Designing Trust in the age of AI

    Sueyoung YUN
    Secretary General, Korea Chief Privacy Officers Council, Republic of Korea

    This presentation highlights the role of Chief Privacy Officers (CPOs) in building a trust-based AI ecosystem. Itintroduces KCPO’s AI Privacy Declaration and seven key commitments to balance innovation and privacy through
    CPO-led governance and accountability

    Embedding Corporate Digital Responsibility (CDR) principles into organizational culture and operations for ethical data handling and building consumer trust

    Arpan KAR
    Professor, Department of Management Studies, Indian Institute of Technology Delhi, India

    Corporate Digital Responsibility (CDR) extends corporate social responsibility into the digital realm, requiring organizations to act responsibly in their use of smart technologies and data. To be effective, CDR must focus on internal and external stakeholders, data governance, and sustainability right from planning to execution. For internal stakeholders such as employees, CDR emphasizes creating secure and supportive digital workplaces. This could include protecting staff from cyber threats, and providing opportunities to develop digital skills. Digital well-being is equally important, as organizations must guard against stress and burnout caused by constant connectivity. A responsible organizational culture not only protects employees but also enhances trust and resilience. Externally, CDR builds credibility with customers, partners, regulators, and society. Protecting consumer data, ensuring AI fairness, and designing inclusive digital services are key expectations. External stakeholders increasingly demand transparency around how organizations collect, manage, and use data, making ethical digital practices a competitive advantage. At the heart of CDR lies strong data governance. Companies must establish clear policies for data collection, storage, sharing, and disposal, ensuring compliance with regulations and safeguarding trust. Data governance also underpins responsible use of emerging technologies like artificial intelligence. A CDR culture enhances customer experience and enhances firm productivity. Sustainability adds a further dimension by addressing the environmental impact of digital operations. Reducing energy consumption while utilizing computing infrastructure is essential. By integrating stakeholder interests, ethical data governance, and sustainability, CDR provides a holistic framework for organizations to navigate digital transformation responsibly while building long-term value for society.

  • Scene 2: The Architect's Dilemma: Forging a New Social Contract for Data

    Chair : Beak-Cheol Jang (Professor, Yonsei University, Republic of Korea)

    Beyond Compliance: How Toyota is Shaping the Future of AutomotiveData Governance

    Ken KATAYAMA
    Project General Manager, Department of DigitalTransformation Promotion, Toyota Motor Corporation, Japan

    In an era where vehicles are rapidly evolving from transportation tools into sophisticated, connected dataplatforms, the challenge of safeguarding customer information has become paramount for the automotive
    industry. This presentation will provide a comprehensive overview of the proactive and forward-thinking policies
    the Toyota is pioneering to ensure the highest standards of information quality and data privacy. Moving beyond
    the framework of mere regulatory compliance, the discussion will highlight Toyota's strategic commitment to
    actively shaping the future of data governance. Drawing upon the insights from his involvement in the "Research Project Keio 2040," it will address the emerging "2040 Problem"—a near-future landscape where the proliferation of digital platforms necessitates the formation of a new and ethical "Network space order." Consequently, this session will detail how Toyota is architecting a robust framework that strategically balances groundbreaking innovation in mobility services with an unwavering commitment to customer trust. The presentation will explore the practical formation of this new order, focusing on establishing clear ethical principles for data use, ensuring data integrity is foundational to both safety and security, and building a sustainable data ecosystem where privacy is a core design principle, not a subsequent addition. Ultimately, this session offers a strategic blueprint for how a global leader is navigating the complex intersection of technology, data, and human-centric values to build a trustworthy foundation for the future of mobility.

    Algorithmic Accountability: Building Personal Data Protections into AI Development Lifecycles

    Han WU

    Partner, King & Wood Mallesons, China

    This presentation examines China’s evolving regulatory framework for algorithmic accountability and personal information protection within AI development lifecycles. Against the backdrop of rapid AI commercialization, China has established a multi-layered governance system combining foundational laws such as the Personal Information Protection Law, Data Security Law, and Cybersecurity Law, supplemented by specialized departmental regulations including the Algorithm Recommendation Provisions, Deep Synthesis Provisions, and Generative AI Measures (AIGC Measures). These instruments collectively enforce critical obligations across three dimensions: algorithmic transparency, user rights protection, and ethical risk control.

    Key operational requirements mandate enterprises to implement robust compliance mechanisms—from algorithm security assessments and filing procedures to data minimization and anonymization techniques. Notably, the AIGC Measures adopt a "prudent and inclusive" governance philosophy, requiring explicit user consent for training data containing personal information while acknowledging innovation imperatives. Significant challenges persist, however, particularly regarding lawful bases for processing publicly available data during model pre-training, where the applicability of "public interest" exemptions remains contested.

    The analysis further unpacks sector-specific compliance demands: algorithm recommender systems must prevent discriminatory outcomes and user addiction, deep synthesis technologies require clear synthetic content labeling, and generative AI services face stringent data sourcing and rights-response obligations. Practical implementation strategies emphasize embedding privacy-by-design through structured workflows—combining automated data identification tools with human oversight, maintaining granular audit trails, and establishing cross-functional review protocols. Ultimately, this regulatory landscape necessitates continuous adaptation as policymakers balance technological advancement against fundamental rights protection in China’s algorithmic governance ecosystem.

  • Scene 3: Beyond Governance: The Power of MyData and User-Centric Frameworks

    Chair: Woongsup Lee (Professor, Yonsei University, Republic of Korea)

    Addressing Cyber Risks and Threats in Agentic AI

    Christopher CHEW
    Technical Leader, Security & Digital Trust - Office of theCTO, CX, Cisco, Singapore

    The burgeoning field of Agentic AI is fundamentally reshaping the digital trust paradigm, simultaneouslypresenting unprecedented opportunities and novel risks. This evolution necessitates a convergence of privacy and cybersecurity principles at the forefront of contemporary data governance, national sovereignty discussions, and the cultivation of user trust. This presentation re-evaluates conventional approaches to risk management within the digital economy, spanning critical e-Government initiatives to widespread consumer digital services. We contend that the expanding attack surface, increasingly exploited by sophisticated scams, phishing campaigns, and pervasive data breaches, is further exacerbated by the rapid integration of AI and other digital technologies. This integration introduces a new class of risks, where systemic misconfigurations and privacy violations frequently compound existing cyber threats, thereby placing digital identities and sensitive data in heightened jeopardy. Consequently, this analysis aims to illuminate strategic pathways for effectively bridging the
    divide between privacy and cybersecurity in the era of Agentic AI, offering a clearer framework for understanding and mitigating these complex challenges. The presentation will give insights into practical considerations for enhancing resilience and maintaining trust in an increasingly autonomous digital landscape.

    Trust but Verify : A Cryptographer’s View on AI Governance and DigitalIdentity

    Kazue SAKO
    Professor Waseda University, Vice Chair of MyData Japan, EU Digital Identity Wallet Advisory Board in Japan, Japan

    Digital identity is a fundamental infrastructure for a trustworthy digital society. People make trust decisions not only based on who you are but, more importantly, on what attributes you can present. At the same time, individuals must retain control over which attributes they disclose in each situation. For this reason, unlinkable selective disclosure is an essential requirement for privacy-preserving digital identity. Conventional cryptographic mechanisms make it difficult to achieve unlinkability. Recent advances in cryptography, however, have introduced new possibilities. Signature schemes such as BBS+ and CL, combined with efficient zero-knowledge proofs, enable users to prove selected attributes without revealing the rest, while also ensuring unlinkability between different transactions. Despite these advances, deployment remains challenging. The new schemes are not yet part of international standards, and there are no certified, off-the-shelf secure hardware modules (such as HSMs or secure elements) capable of supporting them. For this reason, the EU Digital Identity Wallet has taken a pragmatic path: it relies on linkable technologies such as SD-JWT and compensates by issuing multiple one-time credentials to reduce linkability. This approach is compatible with current cryptographic standards and hardware, but it introduces additional credential-management overhead. This talk will present the cryptographic foundations of unlinkable selective disclosure and explain the reasons behind the EU’s current compromise. I will also touch on Google’s recent Longfellow-zk approach and invite reflection on what alternative solutions Asia might.

    Cases of Toss Bank’s use of public MyData

    Jeong-Ha Lee
    Head of Security | CISO | CPO, TossBank, Republic of Korea

    Toss Bank, as a digital-native bank, has innovated its deposit and loan services by utilizing public MyData. Instead of requiring users—the subjects of personal information—to submit handwritten documents, the bank leverages electronic documents from public MyData with the users’ consent. In particular, in the lending sector, it provides customers with fast and accurate loan services, and in tasks such as opening bank accounts, it ensures greater convenience. This presentation will introduce these cases and also highlight the bank’s efforts regarding personal data protection in the use of public MyData.

  • Scene 4: The Next Frontier: Charting Asia's Collaborative Data Future

    Chair: Hyunjoon KWON (Former Director, Korea Internet & Security Agency, Repulic of Korea)

    Korea’s Personal Data Protection Framework: Evolution, Key Features, andPolicy Challenges Ahead

    Jeongsoo LEE
    Deputy Director, Personal Information ProtectionCommission, Republic of Korea

    Over the past decade, Korea has made significant progress in establishing a comprehensive and coherentframework for personal data protection. Since its establishment as an independent authority in 2020, the Personal Information Protection Commission (PIPC) of Korea has worked to align national policies with global standards and to respond flexibly to technological change. This presentation traces the major developments in Korea’s privacy policy, including the integration of previously fragmented legal systems and the policy responses to emerging technologies. It also examines how Korea is preparing for the new challenges introduced by artificial intelligence, where extensive data utilization and algorithmic processing raise complex questions about legal interpretation and enforcement. As AI continues to transform the digital landscape, Korea aims to foster a synergistic relationship between technological innovation and stronger personal data protection. Through initiatives such as the adoption of a riskbased approach, the introduction of generative AI guidelines, and active participation in international dialogue, Korea seeks to establish a forward-looking model for privacy governance in the AI era. This session will share key lessons from Korea’s policy evolution and outline the next steps and strategies to build a more trustworthy and human-centric digital ecosystem.

    Quantum Capital and Civic Values

    JUNG-Gi LEE
    Director of the Network Division, Ministry of Science and ICT, Republic of Korea

    Quantum Information Science, Engineering, Technology (hereinafter referred to as quantum technology) is a field of IT technology that makes possible what was previously impossible with existing technologies. It is divided into three areas: quantum communication, which transmits quantum information; quantum sensors, which collect information previously impossible to obtain; and quantum computers, the next AI. I will present on quantum capital and citizen value based on my experience nurturing quantum technology and industry over the past eight years. 'Changes in Human Capital by Quantum Capital' (same as 'Changes in Human Capital by AI Capital') Countries like Korea, which have driven growth based on education and human capital, are affected in potential economic growth rates by Quantum AI. With the emergence of Quantum AI, human capital becomes replaceable, and humans compete with the state or platform owners. Support is needed for citizens to internalize AI and develop their capabilities. 'Exposure to Asymmetric Risks by Quantum Capital' The acquisition of asymmetric technologies previously impossible with existing technologies reinforces the geopolitical landscape centered on realism. In scenarios where Panopticon-like surveillance is feasible, the balance between governments or platform owners and citizens is disrupted. Attention to social consensus on rules (regulations), democratic deliberation, and consultation is necessary. 'Need for Social Consensus on Access to Quantum Capital' Liberation from disease through quantum MRI and the transformative change in information acquisition. Careful institutional measures are required for citizens’ access to and utilization of information, as well as protection against adversarial actors.

    Financial Artificial Intelligence in Korea: Governmental Support, RegulatoryConstraints, and Supervisory Directions for Safe and Sustainable Adoption

    Bongjun KIM
    Senior investigator, Financial Supervisory Service, Republic of Korea

    This study examines the development, application, and supervisory direction of artificial intelligence (AI) in Korea’s financial sector. It outlines the technological evolution from machine learning and deep learning to generative AI, underscoring their potential to transform financial services through automation and augmentation. Adoption patterns vary across institutional layers: back-office systems enhance fraud detection, document processing, and operational efficiency; middle-office functions strengthen compliance, monitoring, and risk management through financial detection and anti-money laundering systems; and front-office services increasingly use generative AI for personalized investment advisory and customer solutions. Government initiatives, including regulatory sandboxes and AI platform development, aim to broaden the integration of AI within financial institutions. However, regulatory constraints—particularly strict requirements under the Credit Information Use and Protection Act (CIUPA)—remain obstacles to scaling AI agents and personalized services. In response, the proposed supervisory framework emphasizes the balance between fostering innovation and ensuring prudential safeguards. It introduces seven overarching principles—governance, legitimacy, supplementarity, reliability, financial stability, good faith, and security—and outlines an AI risk management framework consisting of risk identification, mitigation, evaluation, and ongoing monitoring. By integrating technological trajectories, institutional practices, and regulatory considerations, this study highlights the dual imperative of enabling innovation while maintaining systemic stability. The findings contribute to ongoing policy debates on AI governance in finance, suggesting that regulatory flexibility combined with robust risk management is essential to achieve safe, reliable, and sustainable AI adoption.

Contact Us

Barun ICT Research Center

50 Yonsei-ro, Seodaemun-gu, Seoul 03722, Korea

 

Tel : +82-2-2123-6694

 

Email : barunict@barunict.kr

    Cookie Use
    We use cookies to ensure a smooth browsing experience. By continuing we assume you accept the use of cookies.
    Learn More