Reflections from the 47th Global Privacy Assembly in Seoul

The 47th Annual Global Privacy Assembly (GPA), hosted in Seoul by the Personal Information Protection Commission (PIPC) of the Republic of Korea, provided a great opportunity for the GSMA to engage with a diverse array of global stakeholders, including data protection authorities, academia and policy experts.

The event had a strong focus on agentic AI, and much of the dialogue focused on the need for data protection authorities to align on smart implementation and oversight. In addition to being the perfect launchpad for GSMA’s new Smart Implementation of Data Privacy Laws report, the event also allowed for excellent regional engagement and discussions around much-needed capacity building.

A forum for global dialogue

As technology continues to evolve and becomes more embedded in our lives, cross-border cooperation on data privacy regulation has never been more critical. One of the core themes discussed at GPA 2025 was global regulatory interoperability, the need for data protection authorities (DPAs) worldwide to align on smart implementation and effective oversight.

Commissioner John Edwards of the UK Information Commissioner’s Office captured the essence of this challenge, noting, “We can’t regulate the technology of the future with the tools of the past.” This sentiment underscores the urgency for regulators to modernise their approaches and collaborate more closely across jurisdictions and sectors.

Spotlight on agentic AI

A key focus of the discussions was the increasing prominence of agentic AI. Agentic AI refers to autonomous AI that can make decisions, understand intent, execute complex tasks and act independently with little human intervention. While AI brings enormous promise, it also presents nuanced challenges for data privacy frameworks, particularly around transparency, purpose limitation, data minimisation, and security.

GSMA breakfast briefing: scams prevention and privacy innovation

GSMA’s briefing on scam prevention and privacy protection through innovation brought together DPAs and industry representatives from every region, creating a unique forum for cross-regional dialogue.

The breakfast briefing underscored the need for a shared global commitment to tackle digital threats while promoting privacy-by-design and scalable, secure solutions. It reaffirmed the importance of open, multistakeholder collaboration in developing practical tools that protect consumers and promote digital trust.

The session was a timely opportunity to explore emerging innovations, such as the GSMA Open Gateway, a standardised framework of universal network APIs that enable developers to create scalable digital services, including solutions to combat fraud and scams. Delegates explored how regulatory sandboxes can support responsible innovation by enabling real-world testing of new technologies in a controlled environment.

Smart implementation of data privacy laws

During the GPA, the GSMA’s new report Smart Implementation of Data Privacy Laws was launched.  This report focuses on the key principles of smart data privacy laws and provides learning from around the world to support those looking to implement data privacy laws in their markets.

Building capacity for the future

The GSMA team held several bilateral meetings, during which it became clear that governments, regulators, policymakers, and public sector bodies value a deeper understanding of mobile industry use cases and the broader digital ecosystem. The GSMA remains committed to supporting this learning journey through its capacity building programme, which is designed to help stakeholders make informed decisions that uphold digital rights while fostering innovation.

Thank you to the organisers

This year’s GPA was successfully hosted by the PIPC of the Republic of Korea. We commend them for hosting such a well-organised and thought-provoking event, and we are grateful for the deeper engagement that we have fostered in Seoul. It served as the perfect backdrop for the crucial global conversations advancing the future of data privacy in digital policy and regulation. We look forward to continuing our engagement in the 48th GPA 2026 at Dubai.

For more information on this event and to view key resources, visit our event page.