Notes

← Back to home

A collection of fragments of understanding in the pursuit of deeper questions.

Antitrust and the Data Economy - Data Sharing and Open Data

Open Data: Regulatory Tools Regulations which applies ex-ante to guide Member States in certain aspects of Data Management, such as Protection and Opening.

Open Data Directive - PSI (2019/1024) The directive on open data and the re-use of public sector information provides a common legal framework for a European market for government-held data(public sector information). It is built around two key pillars of the internal market: transparency and fair competition.

It encourages the Member States to make as much information available for re-use as possible. It addresses material held by public sector bodies in the Member States, at national, regional and local levels, such as ministries, state agencies and municipalities, as well as organizations funded mostly by or under the control of public authorities (e.g. meteorological institutes).

The new rules:

  • Stimulate the publishing of dynamic data and the uptake of Application Programme Interfaces (APIs).
  • Limit the exceptions which currently allow public bodies to charge more than the marginal costs of dissemination for the re-use of their data.
  • Enlarge the scope of the Directive to:
    • Data held by public undertakings, under a specific set of rules. In principle, the Directive will only apply to data which the undertakings make available for re-use. Charges for the re-use of such data can be above marginal costs for dissemination.
    • Research data resulting from public funding - Member States will be asked to develop policies for open access to publicly funded research data. New rules will also facilitate the re-usability of research data that is already contained in open repositories.
  • Strengthen the transparency requirements for public-private agreements involving public sector information, avoiding exclusive arrangements.

French Solution Loi n° 2016-1321, 7 October 2016, pour une République numérique, JO République Française n°0235, 7 October 2016 It put in place provisions that oblige commercial companies to open up - under certain conditions - data they hold for re-use, namely data generated in the context of procurement (article 17), commercial data for the establishment of official statistics (article 19), certain electricity and gas production and consumption data held by transmission and distribution systems operators for re-use by any other party (article 23), and certain data relating to changes in real estate ownership for re-use by certain third parties (article 24). Such data are defined as "public interest data".

PSD2 (2015/2366) (Private Data the respective in Competition Law is EFD) The European Payment Service Directive (PSD2) requires banks to provide access to their customers' accounts in order to enable third parties (Fintech companies) to build financial services on top of banks' data and infrastructure. In this way, banks will not act anymore as gatekeepers of their clients' data: clients will be free to decide to link new Fintech's services to their own traditional bank accounts.

In order to comply with such obligation, in the UK the Open Banking Working Group (OBGW) - set up at the request of HM Treasur and gathering industry experts from the banking sector and Fintechs, business and consumer communities - have developed the first Open Banking Standard Framework, which guides how open banking data should be created and used.

The key word in private data sharing is Voluntary

Models to make Voluntary Data Sharing be easier, because Legal obligations to share private data have significant political implications.

B2B Data Sharing: A Definition The process by which a company makes data available to another company that is interested in these data for its own business purposes (Everis, 2018: iii).

image42

In concrete terms, B2B data sharing consists of the sum of three actions: (i) the making available of data by a company; (ii) the access to said data by other companies; (iii) the re-use of data by a company different from the original data holder (Blackman and Forge, 2017: 9-10). In this scenario, thus, when we deal with data sharing, we consider data not only as an output - i.e. as a product generated through a process - but also as an input, capable of generating and/or improving processes, products and services (Maggiolino, 2018: 20).

The theoretical premise of B2B Data Sharing The non-rivalrous nature of data, making it possible for the same data to support a range of new products or services or new methods of production, suggests that it can become efficient for companies to share more data they hold with other companies so that the value resulting from the data can be exploited to the maximum.

This suggests that questions of data supply and (re-)use ("Data Sharing") need to be addressed in business-to-business (B2B) scenarios... and not only in B2G scenarios.

The 2^nd^ company that re-uses the data can put in place an innovation activity different from the 1^st^ one (additional value from the same data).

The EU Strategy The EU Commission is moving toward incentivizing voluntary B2B data sharing. No Plan for regulations (see public consultation, 2017). Guidance on private sector data sharing - April 2018. The Guidance - Key Principles, as mentioned, the European Union is not considering adopting binding measures in the field public consultation on 'Building a European Data Economy'.

Main raison d'être: levelling the playground among stakeholders, by framing the key principles and providing a toolbox on legal, business and technical aspects of data sharing:

  • Transparency, the relevant contractual agreements should identify in a transparent and understandable manner (i) the persons or entities that will have access to the data that the product or service generates, the type of such data, and at which level of detail; and (ii) the purposes for using such data.
  • Shared value creation, the relevant contractual agreements should recognize that, where data is generated as a by-product of using a product or service, several parties have contributed to creating the data.
  • Respect for each other's commercial interests, the relevant contractual agreement should address the need to protect both the commercial interests and secrets of data holders and data users.
  • Ensure undistorted competition when exchanging commercially sensitive data, the relevant contractual agreements should address the need to ensure undistorted competition when exchanging commercially sensitive data.
  • Minimised data lock-in, companies offering a product or service that generates data as a by-product should allow and enable data portability as much as possible. They should also consider, where possible and in line with the characteristics of the market they operate on, offering the same product or service without or with only limited data transfers alongside products or services that include such data transfers.

Models of B2B Data Sharing The supply and the re-use of data in B2B relations can take many forms or combinations thereof:

  • An Open Data approach: whereby the data in question are made available by the data supplier to an open range of (re-)users with as few restrictions as possible and against either no or very limited remuneration. This model is chosen when the data supplier has a strong interest in the data re-use. Examples are providers of services that would like to make use of an ecosystem of third-party application developers in order to reach the final customers.
  • The data monetization approach: It can take place through a data marketplace as an intermediary on the basis of bilateral contracts against remuneration. This can be interesting for companies that do not know potential re-users for their data and aim at engaging in one-off data monetisation efforts. This mechanism appears suitable when either (1) there are limited risks of illicit use of the data in question, (2) the data supplier has grounds to trusts the (re-)user, or (3) the data supplier has technical mechanisms to prevent or identify illicit use. Model contract terms can lower the costs of drawing up data usage agreements.
  • The data exchange approach in a closed platform: a closed platform can be either set up by one core player in a data sharing environment or by an independent intermediary. The data in this case may be supplied against monetary remuneration or against added-value services, provided e.g. inside the platform. This solution allows offering added-value services and thus provides for a more comprehensive solution for more stable data partnerships and allows for more mechanisms of control on the usage made of the data; model contract terms can lower the costs of drawing up data usage agreements. Where the data sharing is exclusive, it would need to comply with the competition rules.

The legal issues: Data Licensing Contracts B2B data sharing is typically implemented on the basis of contracts. In data usage or licensing agreements parties agree on the subject and value of the contract as well as on all other modalities put down in contract terms. The design of the relevant contract terms for data usage or licensing agreements requires special attention so as to both comply with existing legislation. Specific attention:

  • What data shall be made available.
  • Who can access and (re-)use the data in question.
  • What can the re-user do with data.

What data shall be made available. Describe data which you wish to share as concretely and precisely as possible (e.g. R&D data, customer data, diagnostic data), including the levels of updates to be expected in the future. What quality levels can be assured for the data, also over time? Shared data needs to be of good quality, i.e., accurate, reliable and when necessary up-to-date. Ensure that data are not missing, duplicate, unstructured. Specify the source/origin of data and how it was collected/constructed. A mechanism for reporting error in the data should be set up. Is the data sharing about a data set or a data stream? Ensure respect of rights that others may have on the data. Verify rights on content represented by the data (intellectual and industrial property rights). Ensure respect of data protection legislation. Among others verify that there is a legal basis for the processing of personal data in line with the GDPR.

Who can access and (re-)use the data in question. Ensure that the contract defines in a transparent, clear and understandable way who has a right to access, right to (re-)use, and right to distribute data and under which conditions. Specify if and how data may be licensed for re-use and distribution. Sublicensing needs also to be considered: either it should be specifically excluded or the conditions under which it is allowed and for what types of data should be specified. The right to access and (re-)use of data does not need to be unlimited. The agreement may for instance limit the right to access, i.e., only to members of specific professional groups (e.g., farmers) or link it to certain purposes of use of data (e.g., for a limited commercial use).

What can the (re-)user do with the data. In the contract negotiations, the (re-)user should be as open and as clear as possible about how the data is going to be used, including by parties downstream. This will ensure transparency and increase the trust of the supplier of the data. Specify the exact usage that can be made of the data, including rights on derivatives of the data (analytics). Define non-disclosure rules regarding downstream parties.

The Technical Mechanism/Aspects for Data Sharing The data holder makes available selected data directly to a larger number of re-users, e.g., via an Application Programming Interface.

  • TomTom is a Dutch company that produces traffic, navigation and mapping products. Most revenue from the company's activities comes from the data (maps and online services) licensed to other companies. TomTom offers Application Programming Interfaces for developers as a means of data access. According to TomTom this has the following advantages compared to other technical means to share data:
    • Easy and swift access to data.
    • Monitoring the use of data.
    • Verification of breaches of contract.
    • Rapid action on cases of data misuse (i.e., terminate or suspend access to data).

The data holder makes available selected data via an intermediary (a data marketplace) to one or several re-users with limited control over the subsequent use. The term "data marketplace" is employed to designate a specific type of intermediary that may have three essential functions: match-making between potential data supplier and data buyer; the actual transfer of the data (and the agreed compensation); a certification function that the transaction has actually happened.

  • Dawex does not purchase or sell data. It brings together companies interested in monetizing and re-using data and fosters transparency between data suppliers and users by ensuring that they communicate and conduct the transaction directly on the platform. Dawex developed a series of tools to help both data suppliers: data visualization tools sampling tools; messaging tool embedded in the platform; contractual model terms.

The data holder makes available selected data via an intermediary (a data space or platform) to one or several re-users in an environment that allows stronger control and traceability of the subsequent use. Different from data marketplaces, such technical enablers have a strong focus on providing additional features allowing the data supplier to control the use made of the data, in particular the respect of the provisions of the data transfer agreement (this can include forms of track-and-trace of data usage made; self-regulation within the community of users of the data space or platform, possibly including a set of sanctions for data users in violation of individual data transfer agreements).

  • Nallian has developed a cloud-based platform that enables real-time data sharing and supports process synchronization. The platform allows data suppliers to maintain a granular control over who has access to which data and for what purpose. This control is enabled by a rights-granting engine embedded in the platform that allows data suppliers to define roles and sharing rules for the different community members down to field-level, including for app providers. In addition, the platform facilitates data anonymization and aggregation to meet the necessary privacy requirements.