Regulation of data brokers activity
Special regulation for data brokers has emerged since the mid-2010s. In the digital economy, data brokers (intermediaries between sellers and buyers of data) help to reduce transaction costs (e.g., finding the right data set and its seller), enhance trust between market stakeholders (e.g., by making their activities transparent), and thus develop the data market. At the same time, the emergence of
Из выпуска мониторинга No. 8, August 2024 · выпуск целиком, PDF · на сайте Института Гайдара

Special regulation for data brokers has emerged since the mid-2010s. In the digital economy, data brokers (intermediaries between sellers and buyers of data) help to reduce transaction costs (e.g., finding the right data set and its seller), enhance trust between market stakeholders (e.g., by making their activities transparent), and thus develop the data market. At the same time, the emergence of an intermediary between data owners and users poses additional risks to security of data in transit, such as data leakage risks. Regulation can enhance the benefits of such persons (e.g., through an open register of data brokers) and reduce the risks of their activities (e.g., through liability measures, including fines for information security breaches).
The U.S. experience (Vermont,
California)
In August 2024, California prepared clarifications on the registration of data brokers, including clarifying the criteria for recognizing a company as a data broker: in particular, such criteria include the absence of a “direct relationship” (investor-company, employeeemployer, etc.) between the company and data subjects.1
Among US states, Vermont (2018) and2 California (2019) have adopted regulation of data brokers. In these states, data brokers are professional participants whose function is to lawfully collect personal data from various sources (e.g., websites, businesses), transform it to meet market needs, and sell/transmit it under license. In Vermont, for a company to be recognized as a data broker, the data must be in electronic form and prepared for distribution to third parties. However, both states do not recognize as data brokers companies that sell data of their customers, employees, investors,3 etc., such as an app that sells data of its users.
In both states, data brokers are required to register annually. Registration is done in the period following the activity, i.e., it essentially contains a reporting element. The information provided varies slightly: for example, Vermont requires the number of data security breaches (storage, transmission, etc.), while California requires the number of requests from consumers to exercise their rights (data deletion, etc.) and the reply time.
Vermont also has a requirement for data brokers to have comprehensive information security that includes, but is not limited to, risk assessments, regular review of security measures, and data access controls.
The EU experience
Ita In the EU, the Data Governance Act establishing requirements for data brokering4 services was adopted in 2022. Brokers provide intermediary services between data holders and users (Article 10(a)).
Unlike the US states mentioned above, the registration of data brokers in the EU is carried out once and before the beginning of their activity, at the same time, as in the US, it has a notification character and the information about the broker, including the description of its services, is published in the unified register.
Otherwise, the EU's approach is tougher than that of the US:
1) Provision of services through a separate legal entity: even if a company is already active in the data sector, intermediary services must be strictly separated from other5 activities, both legally and commercially.
2) Generally, data should be exchanged in the format where it is received from the data holder. Related services, such as anonymization, only at the explicit request/approval of the data holder. In other words, the EU restricts functions that are part of the core functions of data brokers in the reviewed US states.
3) Mandatory anti-fraud and abuse procedures - in Vermont, verification of the integrity of data consumers is related to best practices but is not mandatory.
Russia’s experience
In Russia, there is no special regulation for data brokers. This may discourage data sharing in the economy, increasing the costs of finding counterparties and concluding contracts, and not contributing to the development of trust in the data market. For example, it makes it difficult to hold professional data market shareholders liable: when data processing is delegated to a data consumer, the data consumer is responsible for the fulfillment of the operator's obligations. In this regard, it is advisable to define the rights, duties and responsibilities of professional data market stakeholders in the laws on personal data and on information.
- https://www.legifrance.gouv.fr/codes/section_lc/JORFTEXT000000801164/LEGISCTA000006117690/2020-01-01 ↑
- https://legislature.vermont.gov/bill/status/2018/H.764 ↑
- https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201920200AB1202. Сейчас действует редакция 2023 г.: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB362, clarifications to which were issued in 2024: https://cppa.ca.gov/regulations/pdf/data_broker_reg_prop_text.pdf ↑
- https://ago.vermont.gov/sites/ago/files/wp-content/uploads/2018/12/2018-12-11-VT-Data-Broker-Regulation-Guidance.pdf, https://cppa.ca.gov/regulations/pdf/data_broker_reg_prop_text.pdf, ↑
- https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32022R0868 ↑
- Micheli M., Farrell E. et al. Mapping the landscape of data intermediaries. Emerging models for more inclusive data governance. JRC Science for Policy Report. European Commission, 2023, с. 23. ↑
From the monitoring issue No. 8, August 2024. Download the full issue (PDF) · issue page at the Gaidar Institute