Upcoming Data Transferability Movement
Balancing Stakeholder Interests: A Discussion on Data Portability
Policymakers are exploring ways to strike a balance between stakeholder interests, consumer privacy, and security, while optimizing data portability in the energy, healthcare, and financial sectors. A discussion moderated by Daniel Castro, Director of the Center for Data Innovation, highlighted the challenges and solutions in implementing data portability policies.
The discussion, held on December 8, 2021, from 12:00 PM to 1:00 PM (EST), featured speakers Ali Lange (Public Policy Manager at Google), Niko Skievaski (Co-Founder and President of Redox), Ben White (Policy Research & Advocacy at Plaid), and Michael Murray (President of Mission:Data).
One of the key strategies proposed was the implementation of comprehensive regulatory amendments, as seen in South Korea’s initiative to expand the MyData ecosystem to healthcare, energy, and finance. This would involve embedding rights in national law with standardized data formats and secure transfer methods like encrypted downloads and API integration.
Another crucial aspect is enforcing strict cybersecurity and privacy controls aligned with sector-specific regulations. For example, in healthcare, this could mean requiring risk assessments, access restrictions, encryption, breach notifications, and staff training to protect sensitive data.
The discussion also addressed conflicts between data portability and data localization mandates. Clear jurisdictional compliance strategies are necessary to allow data to be portable while respecting residency requirements, thus balancing user control with national security and privacy demands.
Strong enforcement mechanisms are essential to ensure compliance with data portability and privacy laws, particularly in sectors like energy where fragmented policies pose challenges. Engaging multiple stakeholders, including regulators, service providers, and certified third-party agencies, can help manage authorized automated data access in a controlled manner, preventing misuse from unregulated third-party requests.
The discussion emphasized the importance of protecting consumer privacy and security in data portability laws and regulations. Policymakers should adapt privacy provisions to evolving conditions, incorporating broad data privacy law frameworks seen in various U.S. states. This ensures businesses meet thresholds for data processing and compliance, which indirectly supports secure data portability provisions through accountability.
The discussion aimed to balance competing interests from different stakeholders, empower consumers, spur innovation, and increase competition. Data portability can give consumers more control over their data, fostering data-driven innovation across various sectors. The discussion was followed on Twitter by @DataInnovation, with the hashtag #ourwebsite.
As policymakers consider new data portability laws and regulations, they should pursue a coordinated, sector-tailored regulatory approach. This would involve embedding data portability rights within comprehensive privacy laws, standardizing data formats and transfer protocols for interoperability, requiring robust security measures aligned with sector-specific risks, ensuring clear legal frameworks for cross-border and multi-jurisdictional data flows, enforcing compliance with meaningful penalties, and facilitating stakeholder dialogue and public consultations to refine policies continuously. This approach seeks to balance consumer empowerment with robust privacy and security protections while optimizing operational feasibility across energy, healthcare, and financial services.
- To enable secure data portability in various sectors, policymakers should consider implementing comprehensive regulatory amendments, as seen in South Korea, featuring rights embedded in national law with standardized data formats and secure transfer methods.
- Enforcing strict cybersecurity and privacy controls aligned with sector-specific regulations is crucial, with healthcare needing risk assessments, access restrictions, encryption, breach notifications, and staff training to protect sensitive data.
- The discussion highlighted the need for clear jurisdictional compliance strategies to allow data portability while respecting residency requirements and balancing user control with national security and privacy demands.
- Strong enforcement mechanisms are needed to ensure compliance with data portability and privacy laws, particularly in sectors like energy, where fragmented policies pose challenges, engaging regulators, service providers, and third-party agencies can help manage automated data access.
- Policymakers must protect consumer privacy and security in data portability laws and regulations, adapting privacy provisions to evolving conditions and incorporating broad data privacy law frameworks like those seen in various U.S. states.