## 1. Introduction

## Source details

**Canonical URL:** [1. Introduction](https://www.imf.org/-/media/files/publications/dp/2019/english/teidea.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/dp/2019/english/teidea.pdf.md)
- [Structured JSON version](/-/media/files/publications/dp/2019/english/teidea.pdf.json)

---

### Overview
- Is data the new oil? Data has taken on a critical role with the rise of the digital economy.
- The paper provides an analytical review integrating perspectives from growth, privacy, competition, inclusion, and financial stability to assess implications of data for macroeconomic growth, equity, and stability.
- Contribution: describes the main trade-offs facing policymakers as they design data policy frameworks for the increasingly complex global data economy.

### Functions of data in the modern economy
- Data functions as:
  - "an input in the production function"
  - "a means of shifting information across agents"
- Two functions elaborated:
  - Data as a factor of production:
    - Data is an input combined with labor, capital, and other factors to produce goods and services and to innovate.
    - Realizing value from data requires costly processing and skilled labor; the agent that aggregates and analyzes data is the data processor.
    - Examples: sensor data for self-driving cars, observational data for weather forecasting or targeted advertising.
  - Data as information that shifts across agents:
    - Data reduces information asymmetries, improving market transactions (e.g., targeted ads, product reviews, retail aggregation).
    - Access to data can create strategic advantages, including price discrimination and improved credit assessment in financial markets.
    - Financial applications: richer customer data can reduce lenders’ uncertainty, lower interest rates, and reduce credit rationing.

### Building blocks of a market for data
- Supply: the decision to produce data
  - Data collector incurs fixed costs (infrastructure) and variable costs (storage, labor).
  - Marginal costs of collecting data can be very low when data is a byproduct of economic activity, but storage and protection remain variable costs.
  - In many platforms (two-sided businesses), data is collected as a barter for services; providing virtual services represents a cost for the collector.
  - Cloud intermediaries have shifted fixed costs into variable costs and reduced economies of scale for individual collectors.
  - Cost of obtaining consent depends on data subjects’ privacy preferences; preferences vary by data type and culture.
- Demand: why data is created and bought
  - A data collector records data if expected revenues exceed costs.
  - Two core roles drive demand: data as an input into production and data as a creator/transfer of information that reduces uncertainty.
  - The price and market for data depend on complementarity/substitutability across data varieties and the value created by merging datasets.

### Three characteristics of data that motivate policy interventions
- Non-rivalry and the associated returns to scale and scope.
- Privacy externalities.
- Partial excludability.

### Four growing concerns that modern data policies must address
- Market opacity that "may be leading to too much data collection and too little privacy." Rights and obligations over data must be clarified; assignment of these will impact growth and equity.
- Incumbent incentives to hoard data, "potentially stifling competition and reducing the social benefits that could flow from wider access." Policies to encourage data sharing can promote competition and innovation.
- Insufficient protection of held data by companies, creating "risks to stability" that require measures to ensure adequate investment in cybersecurity by market participants.
- Risk of international fragmentation without coordination, "impeding potentially large gains from cross-border data activity including trade and finance."

### Economic characteristics of data and policy challenges
- Nonrivalry
  - One agent’s use of data does not diminish others’ ability to use it; duplication and transfer costs are virtually eliminated.
  - Socially, wide sharing maximizes benefits; privately, firms may hoard data to maintain competitive advantage, limiting contestability.
  - Control over data is more about access than ownership; licensing for specific uses is common.
- Privacy externalities
  - Collection, sharing, and processing of personal data can impose costs on data subjects (loss of privacy; potential rent extraction).
  - Markets lacking sufficient user control rights are likely to lead to excessive data collection and too little privacy.
  - Anonymization may allow benefits without identifiability in some tasks, but often reduces the value of data because it fails to reduce information asymmetries.
  - Individual valuations of privacy are inconsistent (the “privacy paradox”): people often accept disclosures (“I agree”) despite expressing high concern in surveys.
  - Policy implication: rights of data subjects must be attributed to internalize privacy externalities; options include strengthening user control or exploring data dividend schemes.
- Partial excludability and cybersecurity
  - Digitized data is only partially excludable: interconnected systems and cyber-attacks make controlling access costly.
  - Greater protection (offline storage, heavy encryption) reduces commercial/social value, especially where real-time access is required.
  - Private incentives to invest in cybersecurity exist (reputation, protecting comparative advantage, liability), but are unlikely to be socially optimal because of externalities and enforcement difficulties.
  - Perceptions of inadequate security reduce trust and willingness to share data, amplifying systemic harm from individual breaches.

### Macroeconomic implications of data proliferation
- Growth
  - Data can boost growth by improving production, enabling innovation, and reducing financial information frictions.
  - Data sharing in finance (credit bureaus, public registers) is empirically associated with deeper credit markets and lower default frequency.
  - Key unresolved question: do data generate sustained increasing returns to scale?
    - Arguments for decreasing marginal improvements (Varian 2018; machine-learning precision improvements decline with sample size).
    - Arguments for firm-level increasing returns via data feedback loops (Farboodi and Veldkamp 2019) and threshold effects in AI applications (Agrawal, Gans, and Goldfarb 2018).
    - Jones and Tonetti (2018) show nonrival data combined with complementary inputs can yield increasing returns at the firm or economy level, resembling technological change and supporting sustained growth.
    - Other models (Farboodi and Veldkamp 2019) stress decreasing returns where data reduces uncertainty and behaves like capital.
  - Market-structure considerations: data-induced scale/scope economies and network effects can raise concentration and create barriers to entry, though dynamic contestability may mitigate permanence.
- Equity
  - Three claimants to data returns: data subject, data collector, data processor.
  - Distribution of returns depends on whether value comes from individual data points or agglomerated/analysed datasets and on market power.
  - Data can enable price discrimination and rent extraction by firms with market power; data stockpiles can serve as barriers to entry.
  - In finance, broader data can reduce adverse selection and expand credit access, but can also entrench incumbents and bias credit decisions (including discriminatory patterns).
  - Nontraditional data may broaden access but risk excluding those with traits associated with risky behavior; AI “black box” decisions raise transparency and fairness issues.
  - Insurability concerns: granular data can undermine risk-pooling by enabling discrimination on preexisting conditions or behavioral traits; policy limits on permitted underwriting factors may be needed.
- Stability
  - Three channels through which data proliferation affects financial stability:
    - Market-structure effects: data hoarding by incumbents can reduce contestability and increase concentration, affecting risk-taking and the concentration-stability trade-off.
    - Cybersecurity and trust: breaches can undermine public trust in financial institutions; private cybersecurity investment may fall short of socially optimal levels.
    - Operational risk and common systems: reliance on common cloud providers and interconnected systems can create systemic nodes of risk, though cloud adoption may improve standards for weaker institutions and allow geographic diversification of operational risk.

### Policy integration and international coordination
- Data policy frameworks affect objectives for efficiency, equity, and stability, and have implications for cross-border activities and the financial sector.
- An integrated approach to data policy is required "to balance the complex trade-offs that arise across objectives."
- Rights assignment, obligations, and cooperation across domestic and international agencies are central to modernizing policy frameworks.
- Effective data policy requires balancing:
  - Promoting growth and competition via data access.
  - Ensuring incentives to collect and process data exist.
  - Promoting stability via adequate investment in cybersecurity.
  - Respecting individual privacy preferences via user control rights and clear obligations.
- Policy implementation demands national-level cooperation across consumer protection/privacy agencies, competition authorities, ministries of finance and economics, statistics offices, central banks, and financial regulators.
- Because data is inherently mobile, uncoordinated national policies risk fragmenting the global data economy; international coordination is needed to achieve minimum data policy principles compatible with productive cross-border data economies.

### Feature: open banking and financial data sharing (box summary)
- Open banking involves regulation requiring banks to share customer information with designated third parties at the customer’s request, typically including granular transactions and balances.
- Rationale: reduce incumbent banks’ monopoly over customer financial data, lower barriers to entry, and spur innovation and competition.
- Considerations:
  - Reciprocity and perimeter: should technology providers be subject to the same sharing requirements?
  - Even with portability, new entrants face disadvantages versus incumbents with large databases and analytic capacity.
  - Policy question: should incumbents be obliged to share anonymized entire customer databases to enhance procompetition outcomes?

### Box 1 — Data Sharing in Banking: From Credit Bureaus to Open Banking (summary)
- Integrated approach and trade-offs
  - Data use offers substantial efficiency gains but can also lead to market concentration and reduced competition; externalities arise for individual privacy, trust, and stability.
  - Reforms should address four broad concerns: market opacity, concentration and market power, financial instability, and international fragmentation.
  - Interventions should clarify rights and obligations over data and enable mechanisms for meaningful consent and transparent transactions.
- Market opacity
  - Key unanswered questions: "Whose data is it, when can it be collected, what can it be used for, and who will have access to it?"
  - GDPR is cited as recognizing and addressing these concerns by granting control rights to the data subject.
  - Consent challenges: users often accept complex terms without understanding them; time-bounded consent and simple language increase transparency and salience.
  - Distributional implications: allocation of access rights affects distribution of rents among data subjects, collectors, and processors; proposals include treating data as labor or varying ownership regimes (user ownership, firm ownership, public).
- Concentration and market power
  - Policy tools to increase access:
    - Data portability: grants users the right to access and transfer personal data; implementing portability imposes costs on processors and may be targeted at dominant firms.
    - Interoperability: require common standards across platforms; often sector-specific (open banking examples in Australia, the United Kingdom, and European Union).
  - Multisided platforms: free services to users monetized via advertisers raise normative questions about rent distribution and adequacy of user compensation.
  - Alternative governance models: public data trusts or data utilities could provide sensitive, valuable data under social-optimum privacy and cybersecurity standards while exploiting returns to scale.
- Financial instability
  - Cybersecurity and breaches: need for adequate investment in client-data security; private incentives may be insufficient.
  - Third-party cloud service providers: rapid increase in use raises systemic concerns; cloud usage may reduce firm-level operational risk but could create system-wide single points of failure.
  - Data-driven credit analytics: benefits for inclusion and credit access, but models may not span full financial cycles and consumer protection risks exist.
- International fragmentation
  - Divergent national data-policy approaches risk fragmenting international data and goods trade.
  - GDPR’s extraterritorial reach generated sizable policy spillovers and influences other jurisdictions’ policy considerations.
  - Strong case for international dialogue and cooperation to avoid fragmentation and preserve benefits of cross-border data sharing.

### Box 2 — The European Union’s General Data Protection Regulation (summary)
- Implemented by the European Union in May 2018.
- Key features:
  - Defines and protects rights of EU residents over their personal data; noncompliance exposes data processors to large fines regardless of country of origin.
  - Principle of data minimization: handle only as much personal data as required for a lawful purpose; data should not be repurposed without further user consent.
  - Expanded individual rights: “right to be forgotten,” “right to erasure,” “right to rectification,” and “right to portability” to retrieve or transfer personal data in an electronic format at no charge.
  - Requires data collectors to anonymize user data they store (for instance, through encryption or tokenization) so that information cannot be readily matched to an identity.
- Economic consequences and trade-offs:
  - GDPR may engender a better-ordered market balancing opportunities and risks by clarifying externalities from privacy and excludability.
  - Concerns:
    - Emphasis on privacy protection may act as a tax on digital technologies; compliance costs for start-ups may be high, potentially reducing competition and adversely affecting consumers.
    - Early evidence suggests GDPR has affected e-commerce firms’ ability to attract users and generate revenue and to raise funding.
  - Further study needed on broader economic implications and trade-offs of strengthening consumer privacy protections.
- Contextual trade-offs of data localization laws:
  - Protectionism: data localization may stifle competition and growth by raising costs of collecting, transferring, and storing data across borders.
  - Sovereignty: localization gives national governments greater control over citizens’ personal data; privacy protection depends on relative protections offered domestically and abroad.
  - Cyber risk: localization may mitigate or amplify cyber and national security risks depending on scale and capacity.

*Source: teidea - Introduction (IMF PDF chapter).*

### 1. Introduction ........................................................................................................

### 1. Introduction

### Overview
- Is data the new oil? Data has taken on a critical role with the rise of the digital economy.
- The paper provides an analytical review that integrates perspectives from growth, privacy, competition, inclusion, and financial stability to assess implications of data for macroeconomic growth, equity, and stability.
- Contribution: describes the main trade-offs facing policymakers as they design data policy frameworks for the increasingly complex global data economy.

### Functions of data in the modern economy
- Data functions as:
  - "an input in the production function"
  - "a means of shifting information across agents"

### Three characteristics of data that motivate policy interventions
- Non-rivalry and the associated returns to scale and scope
- Privacy externalities
- Partial excludability

### Four growing concerns that modern data policies must address
- Market opacity that "may be leading to too much data collection and too little privacy." Rights and obligations over data must be clarified; assignment of these will impact growth and equity.
- Incumbent incentives to hoard data, "potentially stifling competition and reducing the social benefits that could flow from wider access." Policies to encourage data sharing can promote competition and innovation.
- Insufficient protection of held data by companies, creating "risks to stability" that require measures to ensure adequate investment in cybersecurity by market participants.
- Risk of international fragmentation without coordination, "impeding potentially large gains from cross-border data activity including trade and finance."

### Implications for policy frameworks
- Data policy frameworks affect objectives for efficiency, equity, and stability, and have implications for cross-border activities and the financial sector.
- An integrated approach to data policy is required "to balance the complex trade-offs that arise across objectives."
- Rights assignment, obligations, and cooperation across domestic and international agencies are central to modernizing policy frameworks.

_This summary is based on "1. Introduction" from the source PDF._

### Introduction

### teidea - Introduction

### Context and framing: why data matters now
- Two technological trends expanded data’s economic relevance:
  - Dramatically lower costs of collecting and storing data due to widespread digitalization.
  - Advances in analytic techniques, including artificial intelligence and machine learning, enabling greater value extraction.
- For several of the world’s most valuable publicly traded firms, data is central to highly profitable business models:
  - In their report to the US Securities and Exchange Commission from July 2019, Alphabet (GOOGL) reported that advertising revenues—generated by the company’s data-driven ad targeting services—reached $32.6 billion in the latest quarter, making up 83.7 percent of total revenue.
- This paper focuses on the macro-financial implications of data proliferation through its impact on efficiency, equity, and stability, building on existing literature (for example, Jones and Tonetti 2018; Farboodi and Veldkamp 2019; Acquisti, Taylor, and Wagman 2016; Goldfarb and Tucker 2019).

### What data does in the economy (two functions)
- Data as a factor of production:
  - Data is an input combined with labor, capital, and other factors to produce goods and services and to innovate.
  - Realizing value from data requires costly processing and skilled labor; the agent that aggregates and analyzes data is the data processor.
  - Examples: sensor data for self-driving cars, observational data for weather forecasting or targeted advertising.
- Data as information that shifts across agents:
  - Data reduces information asymmetries, improving market transactions (e.g., targeted ads, product reviews, retail aggregation).
  - Access to data can create strategic advantages, including price discrimination and improved credit assessment in financial markets.
  - Financial applications: richer customer data can reduce lenders’ uncertainty, lower interest rates, and reduce credit rationing.

### The building blocks of a market for data
- Supply: the decision to produce data
  - Data collector incurs fixed costs (infrastructure) and variable costs (storage, labor).
  - Marginal costs of collecting data can be very low when data is a byproduct of economic activity, but storage and protection remain variable costs.
  - In many platforms (two-sided businesses), data is collected as a barter for services; providing virtual services represents a cost for the collector.
  - Economies of scale arise when large fixed costs and low marginal costs prevail; cloud intermediaries have shifted fixed costs into variable costs and reduced economies of scale for individual collectors.
  - Cost of obtaining consent depends on data subjects’ privacy preferences; preferences vary by data type and culture.
- Demand: why data is created and bought
  - A data collector records data if expected revenues exceed costs.
  - Two core roles drive demand: data as an input into production and data as a creator/transfer of information that reduces uncertainty.
  - The price and market for data depend on complementarity/substitutability across data varieties and the value created by merging datasets.

### Economic characteristics of data and policy challenges
- Nonrivalry
  - One agent’s use of data does not diminish others’ ability to use it; duplication and transfer costs are virtually eliminated.
  - Socially, wide sharing maximizes benefits; privately, firms may hoard data to maintain competitive advantage, limiting contestability.
  - Control over data is more about access than ownership; licensing for specific uses is common.
- Privacy externalities
  - Collection, sharing, and processing of personal data can impose costs on data subjects (loss of privacy; potential rent extraction).
  - Markets lacking sufficient user control rights are likely to lead to excessive data collection and too little privacy.
  - Anonymization may allow benefits without identifiability in some tasks, but often reduces the value of data because it fails to reduce information asymmetries.
  - Individual valuations of privacy are inconsistent (the “privacy paradox”): people often accept disclosures (“I agree”) despite expressing high concern in surveys.
  - Policy implication: rights of data subjects must be attributed to internalize privacy externalities; options include strengthening user control or exploring data dividend schemes.
- Partial excludability and cybersecurity
  - Digitized data is only partially excludable: interconnected systems and cyber-attacks make controlling access costly.
  - Greater protection (offline storage, heavy encryption) reduces commercial/social value, especially where real-time access is required.
  - Private incentives to invest in cybersecurity exist (reputation, protecting comparative advantage, liability), but are unlikely to be socially optimal because of externalities and enforcement difficulties.
  - Perceptions of inadequate security reduce trust and willingness to share data, amplifying systemic harm from individual breaches.

### Macroeconomic implications of data proliferation
- Growth
  - Data can boost growth by improving production, enabling innovation, and reducing financial information frictions.
  - Data sharing in finance (credit bureaus, public registers) is empirically associated with deeper credit markets and lower default frequency.
  - Key unresolved question: do data generate sustained increasing returns to scale?
    - Arguments for decreasing marginal improvements (Varian 2018; machine-learning precision improvements decline with sample size).
    - Arguments for firm-level increasing returns via data feedback loops (Farboodi and Veldkamp 2019) and threshold effects in AI applications (Agrawal, Gans, and Goldfarb 2018).
    - Jones and Tonetti (2018) show nonrival data combined with complementary inputs can yield increasing returns at the firm or economy level, resembling technological change and supporting sustained growth.
    - Other models (Farboodi and Veldkamp 2019) stress decreasing returns where data reduces uncertainty and behaves like capital.
  - Market-structure considerations: data-induced scale/scope economies and network effects can raise concentration and create barriers to entry, though dynamic contestability may mitigate permanence.
- Equity
  - Three claimants to data returns: data subject, data collector, data processor.
  - Distribution of returns depends on whether value comes from individual data points or agglomerated/analysed datasets and on market power.
  - Data can enable price discrimination and rent extraction by firms with market power; data stockpiles can serve as barriers to entry.
  - In finance, broader data can reduce adverse selection and expand credit access, but can also entrench incumbents and bias credit decisions (including discriminatory patterns).
  - Nontraditional data may broaden access but risk excluding those with traits associated with risky behavior; AI “black box” decisions raise transparency and fairness issues.
  - Insurability concerns: granular data can undermine risk-pooling by enabling discrimination on preexisting conditions or behavioral traits; policy limits on permitted underwriting factors may be needed.
- Stability
  - Three channels through which data proliferation affects financial stability:
    - Market-structure effects: data hoarding by incumbents can reduce contestability and increase concentration, affecting risk-taking and the concentration-stability trade-off.
    - Cybersecurity and trust: breaches can undermine public trust in financial institutions; private cybersecurity investment may fall short of socially optimal levels.
    - Operational risk and common systems: reliance on common cloud providers and interconnected systems can create systemic nodes of risk, though cloud adoption may improve standards for weaker institutions and allow geographic diversification of operational risk.

### Policy integration and international coordination
- Effective data policy requires balancing:
  - Promoting growth and competition via data access.
  - Ensuring incentives to collect and process data exist.
  - Promoting stability via adequate investment in cybersecurity.
  - Respecting individual privacy preferences via user control rights and clear obligations.
- Policy implementation demands national-level cooperation across consumer protection/privacy agencies, competition authorities, ministries of finance and economics, statistics offices, central banks, and financial regulators.
- Because data is inherently mobile, uncoordinated national policies risk fragmenting the global data economy; international coordination is needed to achieve minimum data policy principles compatible with productive cross-border data economies.

### Feature: open banking and financial data sharing (box summary)
- Open banking involves regulation requiring banks to share customer information with designated third parties at the customer’s request, typically including granular transactions and balances.
- Rationale: reduce incumbent banks’ monopoly over customer financial data, lower barriers to entry, and spur innovation and competition.
- Considerations:
  - Reciprocity and perimeter: should technology providers be subject to the same sharing requirements?
  - Even with portability, new entrants face disadvantages versus incumbents with large databases and analytic capacity.
  - Policy question: should incumbents be obliged to share anonymized entire customer databases to enhance procompetition outcomes?

*Source: teidea - Introduction (IMF PDF chapter).*

### Box 1. Data Sharing in Banking: From Credit Bureaus to Open Banking

### Box 1. Data Sharing in Banking: From Credit Bureaus to Open Banking

### Integrated approach and trade-offs
- Data use offers substantial efficiency gains but can also lead to market concentration and reduced competition; externalities arise for individual privacy, trust, and stability.
- Policy frameworks that address only a single facet of data risk suboptimal outcomes: tightening privacy can protect consumer rights but harm efficiency and competition; granting extensive rights to collectors can incentivize data generation and hoarding, undermining broader efficiency gains and privacy.
- Reforms should address four broad concerns: market opacity, concentration and market power, financial instability, and international fragmentation.
- Interventions should clarify rights and obligations over data and enable mechanisms for meaningful consent and transparent transactions.

### Market opacity
- Key unanswered questions: "Whose data is it, when can it be collected, what can it be used for, and who will have access to it?"
- Lack of clarity over control and access rights likely leads to overuse of data and insufficient respect for privacy; Zuboff (2019) describes online data markets as “one-way mirrors.”
- Coase (1960) theorem requires well-defined and respected property rights, but literature suggests Coase is unlikely to apply to data due to market power and asymmetric information (Acquisti, Taylor, and Wagman 2016).
- Nonrivalry creates economies of scope for data collectors, encouraging reuse and repurposing of data; socially efficient decisions require data subjects to have control over each usage.
- GDPR is cited as recognizing and addressing these concerns by granting control rights to the data subject.
- Consent challenges:
  - Users often accept complex terms without understanding them; complex transactions reduce likelihood of meaningful consent.
  - Trust and reputation matter; simple language, limited-use transactions, and time-bounded consent (for example, the “right to be forgotten”) increase transparency and salience.
- Distributional implications:
  - Allocation of access rights affects distribution of rents among data subjects, collectors, and processors (Acquisti, Taylor, and Wagman 2016).
  - Arrieta-Ibarra and others (2018) propose treating data as labor, where processors pay subjects for data-processing rights.
  - Jones and Tonetti (2018) model welfare under regimes where users own data, firms own data, or data is public:
    - Firm ownership: firms hoard data, collect too much from users, and under-share across firms → limits economies of scale, erects barriers to entry, stifles competition.
    - User ownership: users trade off privacy and better consumption, limiting data collection and allowing wider access → outcomes closer to social optimum.

### Concentration and market power
- Access to data is an important competitive parameter (Crémer, de Montjoye, and Schweitzer 2019); incumbents appear to earn large rents, reflected in high profits and equity valuations, with many digital markets showing high concentration (Furman 2019).
- Policy tools to increase access:
  - Data portability: grants users the right to access and transfer personal data held by collectors/processors to promote competition and lower switching/multihoming costs.
    - Implementing portability imposes costs on processors; single-format exports from dominant incumbents can favor competitors; multiple incumbent formats reduce portability’s effectiveness.
    - Crémer, de Montjoye, and Schweitzer (2019) propose imposing portability on specific dominant firms where lock-in is pronounced.
  - Interoperability: require common standards across platforms; often implemented sector-specifically (example: open banking frameworks in Australia, the United Kingdom, and European Union where portability and interoperability are mandated together).
- Multisided platforms:
  - Platforms can offer services free to users while monetizing data via advertisers; normative question concerns distribution of rents and adequacy of user compensation (Arrieta-Ibarra and others 2018).
  - Furman (2019) recommends mandating portability and interoperability and proposes a pro-competition data markets unit to compel data sharing in particular cases.
  - Limitations of portability:
    - Strong economies of scale and network externalities can sustain concentration and reduce the value of portability if alternative platforms lack scale.
    - Antitrust theory for single-sided firms may be limited for multisided platforms; more work is needed on regulating market structure given data access and control (Evans and Schmalensee 2013).
- Alternative governance models:
  - Public data trusts or data utilities could provide sensitive, valuable data under social-optimum privacy and cybersecurity standards while exploiting returns to scale to promote competition.
  - Options include state-managed access or private entities under strict oversight; recent cyber-attacks on public data sets highlight risks and no single model is a panacea.

### Financial instability
- Data proliferation in finance affects systemic stability via multiple channels; not all imply higher systemic risk if managed well, but current approaches may allow buildup of stability risks requiring prudential responses.
- Cybersecurity and breaches:
  - Large-scale data breaches at banks and data intermediaries underscore need for adequate investment in client-data security; Kashyap and Wetherilt (2019) argue private incentives may be insufficient due to externalities.
  - Challenges include monitoring, surveillance, and redesigning supervisory and enforcement tools.
- Third-party cloud service providers:
  - Rapid increase in use of third-party cloud providers as critical repositories raises systemic concerns (Financial Stability Board 2017, 2019).
  - Cloud usage may reduce operational risk at firm level but could create system-wide risks if complexities and interconnectedness grow; market concentration in cloud services can create single points of failure.
  - Open question whether cloud risks differ materially from existing data-center risks.
  - Policy development challenges: domestic and international coordination, deepening scarce supervisory skills at the intersection of economics, finance, and computer science.
- Data-driven credit analytics:
  - Power growth in financial-service provision and inclusion (Sahay, von Allmen, and Lahreche, forthcoming); benefits include alleviating credit constraints for high-return projects in emerging market and developing economies.
  - Concerns:
    - Models and data often do not span a full financial cycle → resilience under deteriorating conditions is uncertain (Claessens and others 2018).
    - Consumer protection risks in online and person-to-person lending platforms.

### International fragmentation
- Divergent national data-policy approaches risk fragmenting international data and goods trade, undermining cross-border gains.
- Data is nonrival and transferable at virtually zero cost; cross-country scale can generate sustained growth, but national restrictions may impede this.
- Current global governance is decentralized around protocols and standards; there is no singular global data governance framework, though trade agreements sometimes address data flows.
- National approaches vary by country and sector; some laws require in-country storage of citizen data.
- GDPR example:
  - GDPR’s extraterritorial reach caused firms worldwide to realize applicability when serving EU residents; GDPR generated sizable policy spillovers and influences other jurisdictions’ policy considerations.
- Externalities and coordination:
  - Instability or loss of trust in one jurisdiction can impose costs on interconnected jurisdictions; domestic regulation focused solely on local concerns may not internalize global externalities.
  - Strong case for international dialogue and cooperation to avoid fragmentation and preserve benefits of cross-border data sharing.
  - Need for coordination to develop international frameworks setting minimum standards balancing growth, competition, national and individual privacy concerns.
  - Possible framework elements include modalities for efficient cross-border data management using trust-generating entities (private-public partnerships or certain financial centers) that store and validate data subject to standards providing assurance to national authorities.

### The General Data Protection Regulation (GDPR)
- Implemented by the European Union in May 2018.
- Key features:
  - Defines and protects rights of EU residents over their personal data; noncompliance exposes data processors to large fines regardless of country of origin.
  - Principle of data minimization: handle only as much personal data as required for a lawful purpose; data should not be repurposed without further user consent.
  - Expanded individual rights: “right to be forgotten,” “right to erasure,” “right to rectification,” and “right to portability” to retrieve or transfer personal data in an electronic format at no charge.
  - Requires data collectors to anonymize user data they store (for instance, through encryption or tokenization) so that information cannot be readily matched to an identity.
- Economic consequences and trade-offs:
  - GDPR may engender a better-ordered market balancing opportunities and risks by clarifying externalities from privacy and excludability.
  - Concerns:
    - Emphasis on privacy protection may act as a tax on digital technologies; compliance costs for start-ups may be high, potentially reducing competition and adversely affecting consumers.
    - Early evidence suggests GDPR has affected e-commerce firms’ ability to attract users and generate revenue (Goldberg, Johnson, and Shriver 2019) and to raise funding (Jia, Jin, and Wagman 2018).
  - Further study needed on broader economic implications and trade-offs of strengthening consumer privacy protections.

*Source: Box 1. Data Sharing in Banking: From Credit Bureaus to Open Banking*

### Box 2. The European Union’s General Data Protection Regulation

### Box 2. The European Union’s General Data Protection Regulation

### Context
- Many multinational companies store data on their customers on global networks that span national borders.
- Some governments have introduced data localization laws that either require or encourage companies to store individual data on their citizens within national borders, or even restrict the transfer of individual data across borders.
- In some cases, restrictions are limited to data from specific sectors that are deemed particularly sensitive to personal or national security (such as health or finance), but in others the requirements are broader.
- Data localization laws raise several conceptual issues.

### Protectionism
- Data autarky may stifle competition and growth in the digital economy.
- By raising the cost of collecting, transferring, and storing data across borders, data localization (including local storage requirements and restrictions on cross-border data flows) may act as a trade barrier to protect local firms from competition with foreign incumbents, with the unintended consequence of reducing innovation and integration.
- Localization is expensive for data-intensive companies to implement, as it requires the installation of data infrastructure in each country whose users it serves.
- Although initial costs are likely to be borne by large incumbent firms, implications could be more wide-spread.
- For instance, if imposed by smaller jurisdictions, the cost of compliance may prove high and lead providers to curtail services.

### Sovereignty
- Localization requirements give national governments the ability to exert sovereignty over their citizens’ personal data.
- In the face of concerns over covert surveillance by foreign intelligence agencies, some jurisdictions have invoked an interest in protecting their citizens’ right to privacy through more stringent data law and regulation.
- Data localization has been a part of these discussions, as it, in principle, allows domestic governments more control over the personal data stored on corporate servers.
- Whether localization laws end up leading to greater privacy protection ultimately depends on the relative protections offered by the domestic and foreign jurisdictions.

### Cyber risk
- Data localization laws may mitigate or amplify cyber and national security risks by decentralizing the storage of data across countries.
- Although this expands the number of potential targets for cyber-attacks––increasing the cost of protecting the whole network––it also implies that any single data breach may have a smaller chance of causing globally systemic damage.
- When the information relates to core infrastructures such as financial services, health provision, or energy distribution, that are all relevant for national security, local data storage may also make it easier for national governments to physically protect these infrastructures.
- Whether risks can be mitigated by local oversight will depend crucially on scale and capacity.

*Source: Box 2. The European Union’s General Data Protection Regulation, teidea - Box 2. The European Union’s General Data Protection Regulation*

---


_Source: https://www.imf.org/-/media/files/publications/dp/2019/english/teidea.pdf_
