Данные и приватность · 1 октября 2024 · 6 мин чтения

Tightening of personal data circulation

In October 2024, several countries and regions adopted or were considering regulations extending and/or clarifying the processing of personal data, including in the financial sector.

Из выпуска мониторинга No. 10, October 2024 · выпуск целиком, PDF · на сайте Института Гайдара

In October 2024, several countries and regions adopted or were considering regulations extending and/or clarifying the processing of personal data, including in the financial sector.

The US experience

There is no federal law on personal data in the US, but sectoral and regional acts are being adopted.

On October 22, 2024, the Consumer Financial Protection Bureau issued a rule1 requiring financial service providers to transfer personal financial data free of charge to other2 financial service providers upon a consumer's request and to maintain secure interfaces for3 making requests and receiving data.

This is about the right to personal data portability. Consumers will be able to more easily change financial service providers to more suitable ones (e.g. with lower fees or loan rates) without the inconvenience of losing data (payment history, regular payments, etc.).

Such rules will limit the use of “dark patterns”, such as bait-and-switch data harvesting, when customers are attracted to a website by a favorable offer of a non-existent product/service. The rule will be implemented sequentially from large companies to smaller ones from 01.04.2026 to 01.04.2030.

Moreover, the Montana Consumer Data4 Privacy Act came into effect on October 1, 2024. The state residents were granted a number of rights common in other jurisdictions (e.g., EU), such as deletion of their personal data, obtaining a copy of it for transfer to another service provider (e.g., photo hosting), and refusing to have their data processed for the purposes of targeted advertising or profiling for automated decision-making (e.g., of access to credit or healthcare). Data controllers are now required to limit the collection of personal data that is necessary for a specific purpose, among other things.

A characteristic feature of US practice is the direct regulation of the sale of personal data by controllers with the consent of data subjects. In other jurisdictions where the sale of personal data by companies is not directly prohibited (e.g., EU), regulation is usually limited to general principles of personal data handling in the absence of specific rules on the sale of data. Montana law contains special rules: while it does not impose restrictions on the sale of personal data (e.g., purpose of sale, etc.) other than the data subject's consent, the law classifies its sale as a type of data processing with a heightened risk of harm to data subjects and therefore requires a separate data protection assessment of the data processed for these purposes to be conducted and documented. At the same time, the law does not apply to businesses processing personal data of less than 50,000 subjects or 25,000 if the company derives more than 25% of its gross revenue from their sale.

The UK experience

On October 23, 2024, a draft Data (Use and Access) Bill was introduced in the UK5 Parliament. It is expected that the major impact will be on organizations, including international ones, in the spheres of digital, research, medical services and so on.

The bill clarifies regulation in the following areas:

1) Consolidation of the legal status of digital verification services for users of electronic services (online applications, banking, etc.). Providers of such services will be included in the6 register based on a certificate.

2) Availability of personal data for scientific and statistical research. The terms for obtaining the subject's consent to the use of his/her data for these purposes are simplified, including allowing controllers not to formulate precisely the purposes of processing when the purposes of the research itself cannot be accurately interpreted (e.g., at the initial stage of scientific research).

3) Supporting practices of reuse of collected data. The controller may obtain the subject's consent to continue processing their data for new purposes different from the original purpose in the consent form. To do so, the controller must assess the relationship between the original and new purposes of data processing.

4) Decision-making based solely on automated processing of personal data to the explicit consent of the individual. This is relevant, for example, for digital platforms practicing digital profiling of users for the purposes of displaying targeted advertising and personalizing services.

5) The cross-border transfer of personal data receives more detailed regulation. The Secretary of State may regularly assess whether the protection of personal data in third countries is compatible with the level of protection afforded to data subjects in the UK and set standards for cross-border transfers. Consequently, for companies working with personal data from the UK, there are risks of limiting cross-border transfers of data primarily to countries that have not adopted legislation on personal data, such as Cuba, Venezuela, Syria, Sri Lanka and others.

Experience of South Korea

On October 24, 2024, Korea published measures aimed at reducing the illegal7 dissemination of personal data. In 2021, 157,000 cases of illegal disclosure of such data were revealed, and in 2023, it was already 200,000. The number of spam messages on cell phones increased by 40.6% from May to June 2024. Therefore, it is planned to:

1) Introduce an AI-based Internet information scanner that should find both textual data (e.g., email address) and image data (e.g., faces in deepfakes);

2) Block messages that illegally disclose personal data. The objective is to reduce the time required to delete illegally disseminated messages from 24.8 to 18.9 days in 2025, including through cooperation with online platforms;

3) Expand measures for prosecution of those who illegally disseminate personal data, including through information exchange and cooperation with law enforcement authorities;

4) Create database for storage and analysis of information on leakages.

Russia’s experience

Russia has not regulated several issues discussed above, in particular, access to personal data for scientific purposes, dynamic consent to the personal data processing and the right to data portability.

  1. The regulation does not apply to depository institutions with up to $850 million in assets.
  2. The rule relates to the following financial information: transaction data (amount, date, payment type and status, name of payee, rewards, credits and fees or charges), including their history; account balance; payment initiation data, including payee/sender account; fee schedule, account interest rate, credit limit, rewards program, overdraft; scheduled payments (e.g., communication fees); name, address, email and phone number associated with the financial product. However, financial service providers are not required to share with consumers any confidential information, including algorithms used to assign credit scores and risk assessments, or any information collected solely for the purpose of preventing fraud, money laundering, or detecting illegal behavior.
  3. https://www.consumerfinance.gov/about-us/newsroom/cfpb-finalizes-personal-financial-data-rights-rule-to-boost-competition-protect-privacy-and-give-families-more-choice-in-financial-services/; https://files.consumerfinance.gov/f/documents/cfpb_personal-financial-data-rights-final-rule-reg-text_2024-10.pdf
  4. https://archive.legmt.gov/bills/2023/billpdf/SB0384.pdf
  5. https://bills.parliament.uk/bills/3825
  6. Digital Verification Services trust framework.
  7. https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=10702#LINK
  8. Meta's activities are recognized as extremist and banned in the Russian Federation.

From the monitoring issue No. 10, October 2024. Download the full issue (PDF) · issue page at the Gaidar Institute

Читайте также