More regulations, less protection
Tight regulation vs. digital growth: The US and EU fight over data governance model
Из выпуска мониторинга No. 4 (28), April 2026 · выпуск целиком, PDF · на сайте Института Гайдара

Regulatory burden often hinders the development of technologies. For example, studies show that a less civilized US approach to data regulation marked by more favorable conditions for digital platforms compared to a stricter European regulation model (EU General Data Protection Regulation (GDPR), Digital Market Act (DMA) in terms of competition) resulted in a more intensive development of companies: in terms of capitalization, 7 major technological companies in Europe are 20 times behind 7 US tech giants.
However, now in the US as well, where 75% of the largest companies belong to the technological sector, the introduction of a unified federal law on personal data is being discussed and the SECURE Data Act draft was introduced in April 2026. So far, sectoral laws regulate data (such as Health Insurance Portability and Accountability Act) or local regulations in 23 states.
The draft law has received mixed reviews from American lawyers. On the one hand, it establishes a unified federal set of rights and protection tools for personal data subjects, including the right to access collected data, correct and delete data, receive data in a format suitable for transfer to other operators, refusal to use data for advertising, sale to third parties, for creation of a digital profile of the data subject, and so on.
As in European law, it is proposed to distinguish between the “controller” (who collects data and gives consent to its processing) and the “processor” of data (who stores and processes the data). Data brokers (intermediaries in the sale of data) are required to register with the Federal Trade1 Commission.
Adopting such a federal law would allow the US to reduce the pressure of European regulators on American tech giants operating in the EU: 8 of 10 largest fines in the GDPR history have been issued particularly to the US companies, and the amount of these fines reaches 63% of all fines issued to GDPR breachers.
On the other hand, the law could weaken the level of data protection in those states that already have stricter regulations. As federal law takes precedence over state laws, companies will primarily focus on federal requirements.
For example, the state of California (where personal data protection laws are most developed) has announced that it will lower the bar for data protection: thus, users have the right to prohibit sale of their data once for all websites in their browser settings. However, the federal bill only enshrines the general right to opt out of data sales without establishing a mechanism for its implementation.
Ultimately, the intention to improve data protection in the US as a whole undermines the best practices of the states. Federal law should establish a ”floor”, not a ceiling” on regulation, so that states can retain more detailed data protection rules.
Meanwhile, in April, the EU published a report on the Digital Market Act for the first 2 years of its implementation with regard to 7 major technological companies and their 23 services. It is worth noting that 5 companies are American2 (Alphabet, Amazon, Apple, Meta and Microsoft), whereas Booking is the only company repesenting the EU.
Based on the report data, over 40 companies, mainly SME, due to demands towards major platforms on provision of data portability, have received access to platform data in order to launch their own innovation services. Likewise, users now have the ability to prohibit merging of their data across various company services and transfer their data between platforms and ecosystems (for example, between iPhone and Android devices), which has reduced the practice of unwanted profiling and eliminated binding of users to only one ecosystem.
А что дальше
In Russia, unlike the EU and the US, the state protects data not by expanding data management rights, but by introducing additional instruments of state control over data circulation. In 2025, both turnover-based fines for repeated data leaks and an automated violation monitoring system were introduced, which identified violations of the personal data What is protection law in 84% of conducted inspections , with the number of Roskomnadzor inspections increasing by 40% year-on-year. next? It should be noted that a number of companies’ inspections h as declined in Russia since 2019 by 5.6 times, from 1.52 mn to 275.000 . However, digital sector increased by 1.8 times from 1.32% in 2019 to 2.43% in 2024. Thus, digital sector grows faster where the state reduces excessive administrative burden and makes regulation more predictable.
From the monitoring issue No. 4 (28), April 2026. Download the full issue (PDF) · issue page at the Gaidar Institute