Intermediaries do matter: Voluntary standards and the Right to Data Portability
Abstract
EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.
Full text
Nebbiai, Matteo Article Intermediaries do matter: Voluntary standards and the Right to Data Portability Internet Policy Review Provided in Cooperation with: Alexander von Humboldt Institute for Internet and Society (HIIG), Berlin Suggested Citation: Nebbiai, Matteo (2022) : Intermediaries do matter: Voluntary standards and the Right to Data Portability, Internet Policy Review, ISSN 2197-6775, Alexander von Humboldt Institute for Internet and Society, Berlin, Vol. 11, Iss. 2, pp. 1-28, https://doi.org/10.14763/2022.2.1639 This Version is available at: https://hdl.handle.net/10419/254292 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by/3.0/de/legalcode
Volume 11 | Intermediaries do matter: voluntary standards and the Right to Data Portability Matteo Nebbiai Scuola Superiore Sant’Anna DOI: https://doi.org/10.14763/2022.2.1639 Published: 12 April 2022 Received: 25 April 2021 Accepted: 25 June 2021 Competing Interests: The author has declared that no competing interests exist that have influenced the text. Licence: This is an open-access article distributed under the terms of the Creative Commons Attribution 3.0 License (Germany) which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. https://creativecommons.org/licenses/by/3.0/de/deed.en Copyright remains with the author(s). Citation: Nebbiai, M. (2022). Intermediaries do matter: voluntary standards and the Right to Data Portability. Internet Policy Review, 11(2). https://doi.org/10.14763/ 2022.2.1639 Keywords: GDPR, Data governance, Big data, EU Data Protection Regulation Abstract: This paper enlightens an understudied aspect of the application of the General Data Protection Regulation (GDPR) Right to Data Portability (RtDP), introducing a framework to analyse empirically the voluntary data portability standards adopted by various data controllers. The first section explains how the RtDP wording creates some “grey areas” that allow data controllers a broad interpretation of the right. Secondly, the paper shows why the regulatory initiatives affecting the interpretation of these “grey areas” can be framed as “regulatory standard-setting (RSS) schemes”, which are voluntary standards of behaviour settled either by private, public, or nongovernmental actors. The empirical section reveals that in the EU, between 2000 and 2020, the number of such schemes increased every year and most of them were governed by private actors. Finally, the historical analysis highlights that the RtDP was introduced when many private-run RSS schemes were already operating, and no evidence suggests that the GDPR impacted significantly on their spread. Issue 2
Introduction In the last decades, the computing advancements of information and communication technologies heavily impacted the economic system through the expansion of states and firms’ capacity to gather, store and transfer digitised data (Shapiro and Varian, 1998; Mayer-Schönberger and Cukier, 2013; European Commission, 2020d). Concurrently, cyberspace emerged as a new domain where traditional state sovereignty can be challenged (Lessig, 2007; Johnson and Post, 1995; Leiser et al., 2016). The creation, manipulation and circulation of personal data are crucial drivers of the expansion of the digital economy (Srnicek, 2017; Posner and Weyl, 2018; Zuboff, 2019; Cohen, 2019). However, the data economy regulatory arena still consists of a complex and dispersed network of public and private initiatives such as data marketplaces (Carnelley et al., 2013; Koutroumpis et al., 2017), data pools (Mattioli, 2017, pp. 147–148), standard certifications (Lachaud, 2018), Personal information management systems (EDPS, 2016) and data collaboratives (Verhulst and Sangokoya 2015). In the European Union, the urgency to regulate the circulation of personal data beyond data protection is increasingly visible from a series of initiatives from EU bodies. The European Commission (2020a, pp. 16-18) Data Strategy aims to create a framework for “EU-wide common, interoperable data spaces in strategic sectors”, while the Business-to-government Data Sharing report by the European Commission (2020b, p. 42) calls for the establishment of “common standards aimed at ensuring interoperability across borders and sectors”. Concurrently, the Data Governance Act proposal (European Commission, 2020c) stresses the need for people, businesses, and the public sector to have control over personal data and introduces a regulatory framework for data intermediation services. Nevertheless, despite the various announcements, the regulation concerning data ownership and access is still a work in progress in the EU, presenting an inconsistent and not fully operable framework (Duch-Brown, 2017; Drexl, 2018; Martens, 2020). At the moment, one of the most relevant pieces of EU legislation regulating personal data access and circulation is the Right to Data Portability (hereafter RtDP), which was introduced by Article 20 of the General Data Protection Regulation (hereafter GDPR) (European Union, 2016). “Data portability” is the ability granted to an individual to port his or her personal data from a certain digital service to another (Article 29 Working Party, 2017, p. 63). As explained by Engels (2016, p. 4), “platforms have an incentive to collect, possess, process and utilise user data in an exclusive manner, since data is a significant asset in platform markets”. Depending on how it is applied, Article 20 could limit the exploitation of this type of competi- 2 Internet Policy Review 11(2) | 2022
tive advantage (Lehtiniemi, 2017). The research aims to describe the understudied variety of voluntary regulatory schemes that set data portability standards, whose provisions are additional and complementary to the ones of the GDPR. Significantly, these regulatory schemes are voluntarily joined by data controllers1 and thus affect their compliance with the RtDP. In particular, the research proposes a theoretical framework to study these schemes and investigates their presence in the EU. These goals are addressed as follows. The first section presents a review of the GDPR Article 20, explaining why its formulation creates some “grey areas” that leave data controllers, data protection authorities and courts many choices concerning the application of the RtDP. It is shown that, instead of creating internal procedures, some data controllers decide to delegate such choices to voluntary regulatory schemes. The second section proposes a theoretical framework to describe such schemes, framing them as regulatory standard-setting (RSS) schemes that are settled by actors with the role of regulatory intermediaries. Firstly, Abbott and Snidal (2009b, 2010) define the “regulatory standard-setting” (RSS) schemes as voluntary standards of behaviour settled either by private, public, or non-governmental actors. Secondly, according to the RIT (regulator-intermediary-target) model developed by Abbott, Levi-Faur and Snidal (2017, p. 26), the actors that possess the “authority to make, interpret, and adapt rules” emanated by another regulator can be defined as “regulatory intermediaries”. The third section analyses the regulatory standard-setting schemes operating in the EU that act as intermediaries in the data controllers’ application of the RtDP. Firstly, the study surveys the RSS schemes implementing data portability that operated in the EU territory between 2000 and 2020. Secondly, the study employs the Abbott and Snidal (2009a) Governance Triangle to highlight if such RSS schemes are governed by private, public or non-governmental actors. Finally, the conclusions propose further areas of research arising from the empirical findings. This work contributes to the law and political science literature by examining the impact of non-state regulation forms on the application of the EU data protection framework. In other words, this paper assesses whether data portability policies 1. According to Article 4(7), “data controllers” means the natural or legal person, public authority, agency or other body which determines the purposes and means of the processing of personal data. 3 Nebbiai
are affected by the dynamics described by the literature on “private regulation” (Graz, 2012; Kobrin, 2002; Cafaggi and Renda, 2012), “decentred regulation” (Black, 2001), “Transnational Private Regulation” (Bartley, 2007; Cafaggi, 2011), “Global Private Regulation” (Büthe, 2010; Büthe and Mattli, 2013), “non-state market-dri- ven governance systems” (Cashore et al., 2004), “Transnational New Governance" (Abbott and Snidal, 2009a, 2009b), etc. Finally, this research relies upon the premise that the analysis of the legal texts is not sufficient to understand how the RtDP is applied. With the words of Raab and De Hert (2008, p. 264), it is necessary to bring “policy actors and their relationships into play... [m]ost ‘tools’ approaches leave these issues out of account, thus losing sight of regulation as a social and political process and not just as a question of what tools do what jobs”. 1. The “grey areas” of the Right to Data Portability Moving from a summary of the rationale and main characteristics of the Right to Data Portability (RtDP), this section shows how the formulation of Article 20 of the GDPR creates many “grey areas” whose interpretation can significantly impact its practical application. Generally, data portability is conceived as “the ability of an individual to port his or her personal data from service A to service B” (Crémer et al., 2019, p. 83). The rationales behind the promotion of data portability practices include the enhancement of data protection and economic efficiency. Particularly, data protection rights can benefit from the strengthened control that the data subjects have on their own personal data, which can discourage unfair and discriminatory practices and the use of incorrect data for decision-making purposes (Article 29 Working Party 2013, p. 47). On the other hand, economic efficiency improvements arise from the reduction of the data-induced lock-in to platform ecosystems by enabling users to switch easily between services (Crémer et al. 2019, pp. 81–87), and the pro-competitive and pro-innovation effects generated by the smoother flow of precious data assets (Graef et al., 2013; Engels, 2016; Drexl, 2017; Furman et al., 2019, pp. 64–71; Martens et al., 2020, pp. 43-45). It follows that the imposition of such a practice has a direct impact on the business sectors where the exclusive control of data has strategic importance. Additionally, some experts are worried that the economic burdens deriving from the compliance to a data portability requirement may harm small and medium enterprises, in front of uncertain economic advantages (OECD, 2014, p. 14) and dangers for data security (Swire and Lagos, 2013). Finally, data portability can be interpreted as a tool to redistribute power: as resumed by the Article 29 Working Party (2013, p. 47) opinion, “allowing data- 4 Internet Policy Review 11(2) | 2022
subjects/customers to have direct access to their data in a portable, user-friendly and machine-readable format may help empower them and redress the economic imbalance between large corporations on the one hand and data-subjects/consumers on the other”. Before the adoption of the GDPR, data portability options in the EU were offered only voluntarily by data controllers, because no provisions in the EU legislation referred to such a practice. As explained by De Hert et al. (2018, pp. 194-195), the only “ancestors” of the RtDP are the prescriptions about mobile number portability and Open Application Programming Interfaces (APIs) (European Commission 2002a, 2002b). The Right to Data portability is an attempt to institutionalise2 the supply of data portability options by data controllers through the introduction of a legal obligation in the GDPR. The Right to Data Portability was introduced in EU legislation by Article 20 of GDPR and allows a “data subject” to “receive the personal data concerning him or her, which he or she has provided to a controller” from the correspondent “data controller”. Moreover, the data shall be received in a “structured, commonly used and machine-readable format”. According to De Hert et al. (2018, p. 197), in its final wording, the RtDP is fundamentally composed of three different rights: 1. the right to receive (without hindrance from the data controller) data concerning a data subject which he/she has provided (Article 20(1)); 2. the right to transmit (without hindrance from the data controller) those data to another controller (Article 20(1)); 3. the right to have personal data transmitted directly from one controller to another (Article 20(2)). Nevertheless, the formulation of the RtDP generates various “grey areas” concerning the type of granted interoperability, the interpretation of scope limitations, and the interaction with IP law. The following paragraphs detail each of these aspects. 1.1 Interoperability and compatibility Article 20(2) of the GDPR specifies that the data subject has the “right to have personal data transmitted directly from one controller to another, where technically feasible”. In addition, Recital 68 of the GDPR states that “the data subject’s right to transmit or receive personal data concerning him or her should not create an obligation for the controllers to adopt or maintain processing systems which are technically compatible”. Consequently, an obligation to ensure technological compat- 2. “Institutionalisation” is here intended as an attempt to make a feature of social life enduring – i.e., persisting in time and space (Giddens, 1984, p. 24). 5 Nebbiai
ibility between different data controllers does not exist in the GDPR. Rather, Article 20 seems to pursue a more nuanced concept of “interoperability” of systems, intended by the European Union (2009, p. 20; 2017, p. 4) as the ability of disparate and diverse organisations to interact towards mutually beneficial and agreed common goals, involving the sharing of information and knowledge between the organisations, through the business processes they support, by means of the exchange of data between their respective ICT systems. The Article 29 Working Party (2017, p. 17) supports this view, claiming that the Rt- DP “aims to produce interoperable systems, not compatible systems”.3 This prudent approach may be related to the still ongoing technological development and the uncertain economic and innovation impact of a full compatibility requirement (European Commission 2020a, p. 12). However, the vagueness on the actual content of “technical feasibility” may ultimately limit the pro-competitive effects. For instance, Furman et al. (2019, pp. 68–69) emphasise that transfer of data between different services can be interpreted as functioning either on a continuous basis (with automatic updates after a first request from the user) or only when a user makes an expressed request (each exchange of data must be triggered by the user): Although GDPR requires that personal data must be provided in a ‘structured, commonly used and machine-readable format’ there is no explicit requirement for parties to develop technical standards to facilitate the transmission of personal data across suppliers... there is no requirement within GDPR that data portability be made possible on a continuous, rather than discrete, basis. [...] The GDPR data portability provisions formally only relate to personal data which the consumer has provided directly... [a] more pro-competitive approach might involve the sharing of additional personal data. 3. A complete explanation of the difference between interoperability and compatibility in the EU regime is still missing. In the analysis of the Guidelines on the right to data portability by the Article 29 Working Party (2017), the Centre for Information Policy Leadership (2017, p. 13) comments that “[t]he distinction between ‘interoperable’ and ‘compatible’ is not in all circumstances sufficiently clear.” 6 Internet Policy Review 11(2) | 2022
1.2 Scope limitations The scope limitations contained in the RtDP provide another cause of uncertainty. Firstly, Article 20(1) specifies that only personal data can be requested through the RtDP. According to Article 4(1), ‘personal data’ “means any information relating to an identified or identifiable natural person”. However, the notion of “personal data” is not completely stable. On one hand, with the advancements of data analysis and the technical capacity to identify individuals from smaller pools of information, the range of data that can be considered “personal” is expanding (Purtova, 2018). On the other hand, data controllers may increasingly process anonymous or pseudonymised datasets that cannot be linked to data subjects to limit the obligations arising from the RtDP. Secondly, Article 20(1) specifies that the RtDP only concerns personal data processed on the basis of consent or of a contract, thus excluding the personal data processed under all other grounds, including legitimate interest. As argued by Graef et al. (2018, p. 1370), this “raises the question whether controllers will be able to preclude data subjects from relying on the RtDP by invoking a legitimate interest as a ground for processing personal data instead of consent or a contract”. Finally, the interpretation of what data can be considered “provided to the controller” by the data subject is open. The Article 29 Working Party (2017, p. 10) states that these data shall be either “actively and knowingly provided by the data subject” or “observed data provided by the data subject by virtue of the use of the service or the device”.4 About the interpretation of Article 20, De Hert (2018, p. 202), distinguishes a “restrictive approach” (RtDP is applicable only with data explicitly provided by data subjects) and an “extensive approach” (RtDP is applicable with all data provided on the basis of data subject’s consent or within the performance of a contract), while Crémer et al. (2019, p. 81) highlight the difference between “volunteered” (intentionally contributed by the user) and “observed” data (obtained automatically from a user’s or machine’s activity). 1.3 Interaction with IP law Finally, according to Graef et al. (2018, pp. 1374-1375), the interaction between Article 20(4) provisions–claiming that the RtDP “shall not adversely affect the rights and freedoms of others”–and Intellectual Property rights may constitute an emerging “silent conflict”. The GDPR contains no indications on the balance of such a 4. On the contrary, “‘inferred data’ and ‘derived data’… are created by the data controller on the basis of the data ‘provided by the data subject’ (emphasis added)” (Article 29 Working Party, 2017, p. 10). 7 Nebbiai
conflict of interests. Article 29 Working Party (2017, p. 12) employs Recital 63 (on the limitations of Article 15(4) right of access) to claim that the RtDP shall not “adversely affect… trade secrets or intellectual property”. Without additional pronouncements from the Courts or legislation, data controllers will ultimately decide the balance between the RtDP and IP rights. Therefore, behind the claim of defending trade secrets and IP rights in front of the competitors’ reverse-engineering techniques, data controllers may increasingly restrict the pool of data available to portability. *** I have shown that data controllers have various “grey areas” to interpret when they comply with the provisions of the RtDP. First, data controllers can choose whether to develop full compatibility and a continuous data flow between different services. Second, they can select the data processing grounds, anonymise or pseudonymise data, and balance IP rights and the RtDP to engineer the quantity of data falling under the RtDP provisions. Third, they can choose which type of personal data is considered as “provided by” the data subject. This situation of uncertainty can be effectively resumed by the words of Mertens et al. (2020, p. 42), stating that “a problem with Article 20 GDPR… is that it is not (yet) sufficiently operational”. In the future, these “grey areas” might progressively shrink due to the development of forms of soft law, courts’ decisions, or informal standards. Currently, however, many of these decisions are in data controllers’ hands. From the users’ point of view, these choices determine how a data subject can exercise the RtDP using a particular service. From the aggregated point of view, the sum of data controller choices determines whether data portability will become a diffused (institutionalised) option within the economic system and the resulting welfare and competition-im- proving effects. The choices allowed by the RtDP “grey areas” can be independently taken by the data controllers, which establish internal procedures to respond to the users’ requests. Yet, instead of developing independent procedures, some data controllers prefer to join voluntary regulatory schemes to delegate their choices concerning the implementation of data portability. These regulatory schemes guide the participants to interpret in a certain way the described “grey areas”. For this reason, the study of these schemes is crucial to understanding how certain organisations apply the RtDP and how data portability will be institutionalised in the EU. A framing and description of these peculiar regulatory settings are provided in the following section. 8 Internet Policy Review 11(2) | 2022
FIGURE 1: Governance Triangle contained in Abbott and Snidal 2009a. To apply the Governance Triangle to the case of data portability in the EU, the RSS schemes found in the mapping section are placed in the Triangle zones accordingly to their internal rules. I use a formal approach to distinguish the types of actors, where only the formal role of participants as described by the internal rules is tak- en into consideration. For instance, an executive board of directors composed of persons coming from the industry that are mandated to act exclusively as independent representatives of the NGO is considered as an organisation whose governance is only composed of the “NGO” type of actor. To present a practical example, the already mentioned Qiy Scheme has a governance model giving formal independence to the legislative, executive and judiciary branches, that are nominated by the Qiy Foundation (an NGO) (Qiy, 2021b). The internal rules also establish an advisory body called “User Voice”, which is composed of the members of the Qiy Scheme, which are NGOs and firms. The User Voice issues recommendations to the legislative bodies and “enables participating organisations to play an active role in the policy-making process” (Qiy, 2021c). Hence, in the governance of the Qiy Scheme, the power is shared between an NGO (the Qiy Foundation) and the firms and NGOs participating in the RSS scheme (the members represented by the User Voice body). For this reason, the Qiy scheme is placed in Zone 6 of the Governance 15 Nebbiai
Triangle, and the “Governance” column in Table 1 contains the letters “N+F” (NGOs + Firms). The empirical section applies the Governance Triangle in two iterations. The first Governance Triangle (Figure 2) depicts the data portability RSS schemes in the EU in 2020 to provide a snapshot of the recent situation. The second application of the model compares three Triangles representing snapshots from different periods. Such comparison aims to show the evolution of data portability RSS schemes in the EU from 2000 to 2020. The goal is to reveal if and how the different groups of actors changed their participation in data portability RSS schemes across the years. Moreover, exploring the RSS schemes operating before the GDPR enforcement (and the existence of the RtDP) is useful to identify long-term trends and because a certain degree of institutional stickiness and path dependence seems plausible. The time spans are 2000-2011, 2012-2015 and 2016-2020 and include each scheme that operated during at least one of those years.9 The time spans were selected on the basis of the GDPR milestones to highlight the potential effect of the Regulation on the establishment of RSS schemes: in 2012, the EU Commission announced the comprehensive reform of data protection rules, while in 2016 the GDPR was finally promulgated. 3.2 Results Table 1 shows the list of RSS schemes affecting data portability in the EU between 2000 and 2020. A total of 23 regulatory schemes have been found. The first apparent feature is that RSS schemes have, in most cases, a global scope, meaning that they accept members without limitations about their country of origin. This can be explained by the fact that the utility of data portability schemes increases with a higher number of participants, because of direct network effects. Hence, there are no incentives to limit the scope of the schemes. One reason to restrict the pool of potential members might be the protection of personal data. This seems confirmed by the fact that two out of three schemes with national scope enact the portability of highly sensitive personal data (medical data in the case of MedMij, financial data in the case of Ockto). Interestingly, only the GAIA-X initiative has a regional scope. On one side, network effects push private initiatives towards a global rather than a regional scope; on the other, schemes that are concerned with personal data seem to rely on a national scope to grant data safety. A speculative hypothesis is that RSS schemes with a regional scope emerge only in presence of strong re- 9. For instance, MiData UK operated from 2011 to 2014 and is included both in the 2000-2011 timespan (even if it was not operating in 2000) and in the 2012-2016 time span (even if it did not survive until 2016). 16 Internet Policy Review 11(2) | 2022
gional political entities (like the EU), that provide large enough network effects but limit the geographical scope for non-economic motives (e.g., data protection, promoting integration in a targeted area). Finally, the dates of foundation and termination of the schemes show that the only scheme that has been closed since its foundation is Midata UK, that was settled by the UK government. Here, a hypothesis could be made on whether politics-driven and business-driven RSS schemes diverge in their “life expectancy”, on the basis that they may have different incentives and goals (where schemes funded by businesses survive as far as their activity is economically sustainable, political actors may shut down regulatory initiatives when certain political goals are reached or when new public servants are elected). In the future, these hypotheses might be tested with new data. To describe the type of actors establishing RSS schemes, we now move to the application of the Governance Triangle model. TABLE 1: Data portability RSS schemes within the EU. In the column “Governance”, “S” means State(s), “F” means Firm(s), and “N” means “NGO(s)”. NAME LIFE PROMOTER GOVERNANCE SCOPE SOURCES aNewGovernance (ANG) 2018- NGO S+F+N Global [1] Bitmark 2014- Firm F Global [1] Data Portability Cooperation (DPC) 2019- Firm F Global [1] Data Transfer Project (DTP) 2018- Firm F Global [1] Digi.me 2009- Firm F Global [1] GAIA-X 2019- State S+F+N Regional [1] HAT-iDataswift (HAT) 2012- Firm F Global [1] [2] HealthBank 2013- Firm F Global [1] ID Ward (IDW) 2020- Firm* F Global [1] [2] iGrant 2017- Firm F Global [1] International Data Spaces (IDS) 2016- NGO N+F Global [1] [2] MedMij 2015- NGO* S+F+N National (Netherlands) [1] [2] Meeco 2012- Firm F Global [1] [2] Midata UK 2011-14 State S National (United Kingdom) [1] [2] MyData 2014- NGO N Global [1] [2] Mydex 2007- Firm F Global [1] [2] Ockto 2017- Firm F National (Netherlands) [1] OneCub 2011- Firm F Global [1] PIMCity 2020- State S+F+N Global [1] 17 Nebbiai
NAME LIFE PROMOTER GOVERNANCE SCOPE SOURCES QIY 2007- NGO N+F Global [1] Solid 2016- Firm F Global [1] [2] Sovrin 2016- NGO N Global [1] Streamr 2017- Firm F Global [1] *with financial support by public authorities. FIGURE 2: Governance Triangle on personal data portability in the EU in 2020. The abbreviations contained in the labels are explained under the “Name” column in Table 1. The grey area represents the most populated area in the Triangle, evidencing which type(s) of actor(s) has more direct interventions in the governance of data portability RSS schemes. The application of the Governance Triangle model in Figure 2 shows that, in 2020, private companies represented the majority of governors of RSS schemes concerning data portability in the EU. Accordingly, Zone 2 of the triangle is the most populated with 13 RSS schemes, followed by NGOs-States-Firms governance with 4 RSS schemes and NGOs-Firms and NGOs governance both with 2 RSS schemes. 20 out of 22 of the operative schemes are at least partially governed by firms. It is also interesting to notice that usually, where states are involved, also Firms and NGOs 18 Internet Policy Review 11(2) | 2022
participate. This signals the multi-stakeholder standard pursued by initiatives promoted by states such as Gaia-X and PIMSCity. As theorised by Abbott and Snidal (2009b, p. 509), in the New Governance regimes the state actively “incorporates a decentralised range of actors and institutions, public and private, into the regulatory system”, relying on their regulatory expertise and using “soft law” to complement or substitute for mandatory “hard law”. Moving to the second implementation of the Governance Triangle, Figure 3 shows the evolution of the regulatory landscape from 2000 to 2020 in the EU. The Triangles’ gray areas indicate the zones that contain the highest number of regulatory schemes in each time span. As it is evident, the dominance of firm-driven initiatives has been constant since the first decade of 2000, and the initiatives that involve public authorities started to appear only recently. In all the analysed time spans, the most diffused form of governance is the one where firms have full control of the RSS schemes. This also means that when the RtDP was introduced in 2016, the practice of data portability in the EU was already regulated by standards mainly governed by firms. As theorised by Büthe (2010, p. 22), some “private regulators... govern aspects of global markets not previously regulated by public regulators”. In general, public authorities have been very cautious on this topic. As already seen, the EU deliberately adopted a prudent approach (European Commission 2020a, p. 12) and the only relevant early public initiatives have been Midata (United Kingdom) and MyData (Finland).10 FIGURE 3: Evolution of the data portability Governance Triangle in EU. The grey areas represent the most populated areas in the Triangle, evidencing which type(s) of actor(s) has more direct interventions in the governance of data portability. RSS schemes in that time span. The abbreviations contained in the labels are explained 10. Midata was a voluntary programme implemented by the UK Government with industry to give consumers access to their personal data, experimented between 2011 and 2014 (UK Department for Business and Skills, 2014). The MyData initiative is financed by the Finnish government, and its main goal is to build a network of data management services (Langford et al., 2020). 19 Nebbiai
in Table 1. FIGURE 4: Number of data portability RSS schemes available in the EU. The second evident trait emerging from Figure 3 is that the number of operative regulatory schemes is constantly increasing. The time span 2000-2011 presents 5 active RSS schemes, the time span 2012-2015 has 11 active RSS schemes and the period 2016-2020 has 22 active RSS schemes. Figure 4 emphasises the number of operative RSS schemes each year, and an accelerating trend is clear. Many factors may explain such an increase: diffusion of digital technologies involving the manipulation of personal data, increasing demand for personal data control, experimentation of innovative business models, efficiency of this type of coordination in comparison with other forms of partnership between organisations. Another hypothesis is that the institutional environment plays an influential role and public regulation such as GDPR significantly affects the diffusion of data portability RSS schemes. The introduction of a formalised Right to Data Portability in the GDPR might have produced two effects on the diffusion of data portability RSS schemes. On one hand, the obligation for each data controller to introduce data portability options could progressively lead to the development of internal procedures that substitute the reliance on RSS schemes. Instead of joining formalised regulatory schemes, an increasing number of data controllers may adopt internal procedures and multilateral agreements with other organisations to govern data portability and data flows. For this reason, the RtDP introduction could reduce the number of operating schemes. On the other hand, the obligation to develop data portability functionalities might increase the demand for regulatory schemes by the data controllers that cannot or do not want to invest resources to comply with the RtDP. This phenome- 20 Internet Policy Review 11(2) | 2022
non would likely increase the number of operating RSS schemes. Therefore, a key factor determining the evolution of the phenomenon is the cost-benefit comparison between developing internal data portability functionalities and joining a RSS scheme. From the data visible in Figure 4, it seems that the adoption of GDPR in 2016 (and its implementation in 2018) did not significantly impact the growth of available RSS schemes. The growth pace of available RSS schemes does not deviate from the trend visible in the preceding years. Thus, neither the positive nor the negative effects of GDPR on the diffusion of RSS schemes are visible. This may be related to a “lag” between the enforcement of the GDPR and the full understanding of the Regulation implications by the targeted organisations. Alternatively, the actors establishing RSS schemes may consider the introduction of Article 20 irrelevant to their operations. It must be noticed, however, that some regulatory schemes which are currently operating (Egan, 2019) or work in progress (GSMA, 2019) explicitly cite the RtDP as a trigger or enabler of their initiative. Also, some actors governing RSS schemes have recently lobbied (MyData, 2020) in favour of a stronger EU regulation of “data intermediaries” in the Proposal for a Data Governance Act (European Commission, 2020c). These events suggest that the EU and the regulatory intermediaries do not interact in a zero-sum power game, with RSS schemes filling the void left by the lack of public regulation. On the very contrary, in the case of data portability, they may act in a complementary way: increasing the supply of public regulation stimulates the supply of regulatory intermediaries by (also) private actors. Conclusion To enlighten an understudied factor of the RtDP application, this study proposed a theoretical framework to analyse the regulatory schemes that set voluntary data portability standards in the EU. The paper analysed the “grey areas” created by the GDPR Article 20 formulation and explained why the data portability voluntary standards can be framed as “regulatory standard-setting (RSS) schemes” settled up by “regulatory intermediaries”. The empirical section surveyed the data portability RSS schemes that operated in the EU between 2000 and 2020 and employed the Governance Triangle model to highlight if such schemes are governed by private, public or non-governmental actors. The results showed that most RSS schemes influencing data portability in the EU have a global scope and are governed by private actors. Moreover, the number of operating schemes is increasing each year. The historical analysis highlights that the regulation of data portability was not 21 Nebbiai
“stolen” from the state by the firms: on the contrary, the GDPR and the RtDP were introduced in a regulatory environment already populated by many RSS schemes. Finally, the empirical analysis presented no evidence to conclude that the introduction of the GDPR impacted the diffusion of data portability RSS schemes. The fact that, within the territory of the EU, private actors play an intermediary role in the application of the RtDP may be worrying for the future development of data markets and infrastructures. According to OECD (2014, p. 38), the lack of interoperability and compatibility between the various standards “could lead to a race to the ‘lowest common denominator’ of standard data sets provided by data controllers”. Another danger is to increase the monopoly power of a few firms, elevating their data portability scheme to the global standard (Thompson, 2018, Cohen, 2019, p. 209). As stated by Gineikytė et al. (2020, p. 56), “[i]f the data portability standards are set by a small number of dominant players (as in the case of the Data Transfer Project, led by Apple, Google, Facebook, Microsoft and Twitter), smaller ones will be forced to follow this standard, carrying the costs of technical implementation that may be especially large for them”. Also, a data portability framework mainly driven by private actors poses serious challenges to regulatory accountability. Cafaggi and Pistor (2015, p. 97) claim that “[f]ar from promoting decentralisation of governance... Transnational Private Regulation re-centralises governance in the hands of powerful private actors”. This power can ultimately “affects domestic polities establishing regulatory standards for sovereign states”, thus binding a fundamental sector of the economic system to the choices of a few unaccountable firms. For these reasons, Curtin and Senden (2011, p. 187), advocate for ‘compensatory mechanisms’ when a certain policy field is regulated only by private actors. On the other hand, the recent proposal of a Data Governance Act (DGA) by the European Commission (2020c) displays growing attention to these subjects by European legislators. The provisions concerning “data sharing services” (Article 9-14) and “data altruism organisations” (Articles 15-22) introduce a variety of binding requirements to data portability RSS schemes. Moreover, the proposal of a European Data Innovation Board (Article 26 and 27) that advises the Commission in developing data sharing and interoperability policies attempts to promote data sharing harmonisation and cooperation across the public and private sectors. Depending on how these provisions will impact the RSS schemes landscape, the DGA could significantly re-shape the stage of RtDP regulatory intermediaries. This paper suggested some tools and hypotheses for studying the role of regulatory intermediaries in the application of the RtDP, but further research is needed to understand 22 Internet Policy Review 11(2) | 2022
the characteristics of supply and demand of data portability RSS schemes. Such enterprise will be increasingly useful to evaluate whether the dominance of private actors in this field is a problematic issue and the policies proposed by the EU are up to the challenge. References Abbott, K. W., Levi-faur, D., & Snidal, D. (2017). Theorizing Regulatory Intermediaries: The RIT Model. The ANNALS of the American Academy of Political and Social Science, 670(1), 14–35. https://do i.org/10.1177/0002716216688272 Abbott, K. W., & Snidal, D. (2009a). Strengthening international regulation through transmittal new governance: Overcoming the orchestration deficit. Vand. J. Transnat’l L, 42, 501. Abbott, K. W., & Snidal, D. (2009b). CHAPTER TWO. The Governance Triangle: Regulatory Standards Institutions and the Shadow of the State. In W. Mattli & N. Woods (Eds.), The Politics of Global Regulation (pp. 44–88). Princeton University Press. https://doi.org/10.1515/9781400830732.44 Abbott, K. W., & Snidal, D. (2010). International regulation without international government: Improving IO performance through orchestration. The Review of International Organizations, 5(3), 315–344. https://doi.org/10.1007/s11558-010-9092-3 Article 29 Data Protection Working Party. (2017). Guidelines on the right to data portability, 16/EN WP 242 rev.01. https://ec.europa.eu/newsroom/document.cfm?doc_id=44099 Article 29 Working Party. (2013). Opinion 03/2013 on purpose limitation, 00569/13/EN. European Commission. https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/ 2013/wp203_en.pdf Auld, G., & Renckens, S. (2017). Rule-making feedbacks through intermediation and evaluation in transnational private governance. The Annals of the American Academy of Political and Social Science, 670(1), 93–111. https://doi.org/10.1177/0002716217690185 Bartley, T. (2007). Institutional Emergence in an Era of Globalization: The Rise of Transnational Private Regulation of Labor and Environmental Conditions. American Journal of Sociology, 113(2), 297–351. https://doi.org/10.1086/518871 Biersteker, T. J., & Hall, R. B. (2002). The emergence of private authority in the international system. Black, J. (2001). Decentring Regulation: Understanding the Role of Regulation and Self-Regulation in a “Post-Regulatory” World. Current Legal Problems, 54(1), 103–146. https://doi.org/10.1093/clp/5 4.1.103 Büthe, T. (2010). Private Regulation in the Global Economy: Guest Editor’s Note. Business and Politics, 12(3), 1–1. https://doi.org/10.2202/1469-3569.1349 Büthe, T., & Mattli, W. (2013). The new global rulers: The privatization of regulation in the world economy. Princeton University Press. Cafaggi, F., & Pistor, K. (2015). Regulatory capabilities: A normative framework for assessing the distributional effects of regulation: Regulatory capabilities. Regulation & Governance, 9(2), 95–107. h 23 Nebbiai
ttps://doi.org/10.1111/rego.12065 Cafaggi, F., & Renda, A. (2012). Public and private regulation: Mapping the labyrinth. DQ, 16. Cafaggi, F., Renda, A., & Schmidt, R. (2013). Transnational private regulation. In OECD, International Regulatory Co-operation: Case Studies, Vol. 3 (pp. 9–58). OECD. https://doi.org/10.1787/97892642005 24-3-en Carnelley, P., Schwenk, H., Cattaneo, G., Micheletti, G., & Osimo, D. (2013). Europe’s data marketplaces—Current status and future perspectives,’. European Data Market SMART, 63. Cashore, B. W., Auld, G., & Newsom, D. (2004). Governing through markets: Forest certification and the emergence of non-state authority. Yale University Press. Centre for Information Policy Leadership. (2017). Comments by the Centre for Information Policy Leadership on the Article 29 Data Protection Working Party’s “Guidelines on the right to data portability” adopted on 13 December 2016. https://www.informationpolicycentre.com/uploads/5/7/1/0/5710428 1/cipl_comments_on_wp29_data_portability_guidelines_15_february_2017.pdf Cohen, J. E. (2019). Between Truth and Power: The Legal Constructions of Informational Capitalism (1st ed.). Oxford University Press. https://doi.org/10.1093/oso/9780190246693.001.0001 Crémer, J., Montjoye, Y.-A., & Schwitzer, H. (2019). Competition Policy for the Digital Era (Report KD-04-19-345-EN-N). Publications Office of the European Union. http://doi.org/10.2763/407537 Curtin, D., & Senden, L. (2011). Public Accountability of Transnational Private Regulation: Chimera or Reality? Journal of Law and Society, 38(1), 163–188. https://doi.org/10.1111/j.1467-6478.2011.00 539.x Cutler, A. C., Haufler, V., & Porter, T. (Eds.). (1999). Private authority and international affairs. Suny Press. De Hert, P., Papakonstantinou, V., Malgieri, G., Beslay, L., & Sanchez, I. (2018). The right to data portability in the GDPR: Towards user-centric interoperability of digital services. Computer Law & Security Review, 34(2), 193–203. https://doi.org/10.1016/j.clsr.2017.10.003 Drexl, J. (2017). Designing competitive markets for industrial data. J. Intell. Prop. Info. Tech. & Elec. Com. L, 8, 257. Drexl, J. (2018). Data access and control in the era of connected devices [Report]. BEUC. https://www.b euc.eu/publications/beuc-x-2018-121_data_access_and_control_in_the_area_of_connected_devices.p df Duch-Brown, Nn., Martens, B., & Mueller-Langer, F. (2017). The Economics of Ownership, Access and Trade in Digital Data. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.2914144 E.D.P.S. (2016). Opinion 9/2016: EDPS Opinion on Personal Information Management Systems [Technical report]. European Data Protection Supervisor. https://edps.europa.eu/sites/edp/files/publ ication/16-10-20_pims_opinion_en.pdf Egan, E. (2019). Data Portability and Privacy [Report]. Facebook. https://about.fb.com/wp-content/upl oads/2020/02/data-portability-privacy-white-paper.pdf Engels, B. (2016). Data portability among online platforms. Internet Policy Review, 5(2). https://doi.or g/10.14763/2016.2.408 European Commission. (2002). Directive 2002/21/EC of the European Parliament and of the Council of 24 Internet Policy Review 11(2) | 2022