## sdnea2021005

## Source details

**Canonical URL:** [sdnea2021005](https://www.imf.org/-/media/files/publications/sdn/2021/english/sdnea2021005.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/sdn/2021/english/sdnea2021005.pdf.md)
- [Structured JSON version](/-/media/files/publications/sdn/2021/english/sdnea2021005.pdf.json)

---

### EXECUTIVE SUMMARY — Context and high-level findings
- Individual data is a key input and source of value across sectors, including Big Tech, pharmaceuticals, manufacturers, and financial services; data types include “likes,” purchase patterns, locations, social activities, biometrics, and financing choices.
- Use of individual data and digital innovation can power productivity; increase access to finance; and promote trade, including of digital services.
- Key policy challenges:
  - Balancing privacy trade-offs: privacy protections can mitigate undesired use of individual data but may impede efforts to generate economic and social gains; clear rules and effective individual control over data are needed.
  - Promoting inclusive digitalization: data can support inclusion but also enable price discrimination and algorithmic bias, disadvantaging some individuals.
  - Fostering competition: hoarding by large data collectors can reduce competition, dampen innovation, and raise financial stability risks.
- Domestic policy responses under consideration include interoperability mandates, data portability, creation of data fiduciaries, and public data utilities; these require unprecedented coordination among regulators across competition, financial stability, integrity, consumer protection, and privacy mandates.
- International cooperation is critical to contain fragmentation of the global digital economy; cross-border data flows underpin a rapidly growing proportion of international services trade.
- The note argues for development of international agreement on common minimum principles for the data economy to reduce avoidable divergences and support cross-border approaches to privacy definitions, interoperability, data portability, and data sharing for regulatory purposes.
- Scope includes implications for digital money, taxation, and competition; central bank digital currencies and cross-border private digital currencies will be heavily influenced by national data policies.

### THE ECONOMICS OF DATA — properties, production, and trade-offs
- Data as an input:
  - Data is an input in production of goods and services, particularly in the digital economy; deriving value requires costly processing and analysis combined with other factors (labor, algorithms).
  - Big data has supported AI as a general-purpose technology deployed across many fields.
- Nonrival nature and externalities:
  - Data is nonrival: it can be used multiple times and by multiple agents without being diminished; social returns increase when data is widely available, but private processors have incentives to hoard data.
  - Trade-offs from wider data access include increased social value versus compromised privacy and heightened cybersecurity risks.
- Information asymmetries and personalization:
  - Access to individual data reduces information asymmetries between buyers and sellers, enabling personalization (e.g., targeted ads, usage-based insurance) that can benefit customers and sellers if users have control over their data.

### DATA POLICY OBJECTIVES AND TRADE-OFFS
- Modernized data policy frameworks must address:
  - Opacity of data markets: consumers often lack awareness of how data is used, transferred, and processed; efficient and equitable data economies require clear rules and effective consent.
  - Hoarding by firms: large data sets concentrated in few firms can stifle competition and innovation.
  - Resilience of digital data infrastructure: ensuring integrity and protecting data from theft and misuse is critical to public trust and financial stability; policy should include adequate cybersecurity investment.
  - Public interest in disclosure: sharing certain types of data for regulatory and enforcement purposes must be balanced against privacy concerns.
- Domestic coordination:
  - Effective data policy requires coordination across ministries and regulators because policies impose trade-offs affecting growth, privacy, competition, and financial stability and integrity.
  - Mechanisms to foster greater coordination among domestic regulators merit further exploration; focusing on single objectives can have repercussions for others.

### VALUATION CHALLENGES, WHO CAPTURES VALUE, AND MARKET POWER
- Valuation challenges and nature of data:
  - Data is highly heterogeneous; no two pieces of data are perfect substitutes; value may change over time.
  - Individual data transactions usually take place through barter: individuals swap use of their data for “free” digital services.
  - Assessing returns is difficult: advertisers spend large sums on data but measuring returns can be hard; some studies find returns may be negative.
  - Governments are divided on placing value on data for digital taxation.
- Who accrues returns:
  - Value may come from each data point or from aggregation and analysis; substitutability with other factors of production matters.
  - Some data require advanced proprietary analytics and skilled labor; other uses require less analysis (targeted products).
- Market power and allocation of value:
  - If a data processor enjoys market power, granular client information can enable rent extraction (price discrimination) and stockpiled data sets can act as barriers to entry.
  - Tech sector shows rising market shares for firms with strong market power; evidence: Akcigit and others (2021) find rising markups driven by reallocation to existing high-markup firms.
  - In finance, banks traditionally hoard relationship data, making it hard for other lenders to price risk and compete.

### PRIVACY, ANONYMIZATION, AND THE PRIVACY PARADOX
- Economic consequences of privacy decisions:
  - Sharing data yields benefits (innovative services, customized products) but externalities arise when individuals lack awareness or control; firms’ collection and use of data can harm individuals who are not compensated.
  - Shift to digital payments and digital money increases privacy salience and policy importance.
- Agency and public goods tension:
  - Effective privacy is about giving individuals agency over their data rather than preventing all sharing; tension exists between individual restriction and public goods (e.g., contact tracing).
- Privacy paradox:
  - People express high concern for privacy in surveys yet often consent to data sharing for “free” services.
  - Evidence: only 0.2 percent of ad impressions opted out of targeted advertising under AdChoices; 12½ percent of users of a particular website opted out after GDPR implementation.
- Anonymization:
  - Anonymization can enable social benefits while preserving privacy in some applications (e.g., AI for driving, vaccine studies) but often reduces data value where person-level linkage is needed.
  - Limits: anonymization may be reversible by matching other characteristics to identities.

### DATA AND THE FINANCIAL SECTOR — inclusion, efficiency, resilience
- Core role of personal data:
  - Personal data is a core input for financial services; lenders rely on data to reduce borrower information gaps.
  - Need for data has intensified with digitalization and increased regulatory data collection for identification and suspicious transaction detection.
- Data and credit allocation:
  - Incomplete borrower information causes adverse selection and credit rationing (Stiglitz and Weiss 1981).
  - Nontraditional data can boost inclusion: online-collected information (social habits, utility payments, traces of activity) can evaluate creditworthiness for those without prior financial access.
  - Evidence: Frost and others (2019) and Berg and others (2020) show nontraditional online data can predict creditworthiness more accurately than a traditional credit score.
  - Figure 3 (Berg and others (2020)) shows explained credit scores improving when combining credit bureau and digital footprint data; vertical axis values range from 65 to 74 with labels "Credit Bureau", "Digital footprint", "Combined".
- Data sharing, competition, and open banking:
  - Data sharing approaches give individuals greater agency and can boost competition and efficiency.
  - Open banking and credit bureaus reduce information asymmetries, lessening adverse selection and moral hazard and increasing credit provision.
- Data resilience and financial stability:
  - Financial system depends on robust, resilient digital data infrastructure; confidentiality, integrity, and availability are crucial.
  - Incidence of data breaches has sharply risen with very large exposures of individual data records.
  - Figure 4 selected incidents (user impact numbers as presented): Heartland Payment System: 134 million; LinkdIn: 165 million; Adobe Date: 153 million; MySpace: 360 million; Ebay: 145 million; Yahoo: 3 billion; Marriott: 500 million; Adult Friend Finder: 412 million; Equifax: 147.9 million; Dubsmash: 162 million; Canva: 137 million; My Fitness Pal: 150 million; Zynga: 218 million; Sina Weibo: 538 million.
  - The chart covers years 2007 2009 2011 2013 2015 2017 2019 2021 and plots number of data breaches with y-axis labels 0, 500, 1,000, 1,500, 2,000, 2,500.
  - Private incentives may underdeliver systemic resilience because firms do not internalize broader impacts on public trust.
- Cloud services, concentration, and systemic risks:
  - Third-party cloud providers offer efficient management and cyber defenses, but agglomeration of data in a handful of cloud providers poses single-point-of-failure risks.
  - FSB notes cloud use may reduce firm-level operational risk but “also pose new risks and challenges for the financial system as a whole.”
  - Data-intensive services can increase concentration and “too-big-to-fail” risks; efficiency gains may be unevenly shared, favoring incumbents.
  - Research on China during COVID-19 finds digital banks’ portfolio quality held up well; IMF research finds banks that adopted data technologies before the global financial crisis were more efficient and experienced fewer mortgage defaults and problem loans.
- Regulatory data needs and suptech:
  - Volume of data for legal requirements demands high-quality IT systems for market participants and regulatory authorities (suptech) to detect outliers and suspicious transactions.

### RISKS FROM GRANULAR DATA AND AI-DRIVEN DECISIONS
- Exclusion and higher costs:
  - Data-driven profiling can lead to exclusion or higher costs for vulnerable individuals (example: health insurer inferring preexisting conditions to charge higher premiums or deny coverage).
  - Regulations should specify types of data that may be used in decision-making (e.g., restrict denial of health insurance based on preexisting conditions).
- AI bias and black-box concerns:
  - AI trained on biased historical data can worsen exclusion (example: Fuster and others (2020) in US housing market).
  - AI models may be accurate but lack structural interpretation and be perceived as discriminatory “black boxes.”
  - Cross-sector example: facial recognition error rates for darker-skinned people were dozens of percentage points higher than for lighter-skinned people (Buolamwini and Gebru 2018).

### THE DATA POLICY TOOLKIT — mechanisms, trade-offs, and institutional design
- National approaches differ: EU rights-based (GDPR 2016); US activity-based “notice and choice” with sectoral protections; some large emerging markets emphasize public interest access and data localization.
- Public law versus private law: private law enforces contractual agreements (consent-focused); public law sets regulatory standards and inalienable fundamental rights.
- Key mechanisms to promote competition, privacy, and public good:
  - Interoperability: interoperable platforms ease sharing under mutually accepted rules; supports multi-homing, reduces network hold, can be pro-competitive, and may lower “too-big-to-fail” risks.
  - Data portability: gives individuals control over flows between platforms and can promote competition by lowering switching costs.
  - Data fiduciaries: agents responsible for managing subjects’ data and seeking consent; proposed for effective consent management (discussed in India).
  - Public data utilities: independent central repositories (analogous to public credit bureaus) enabling level-playing-field access; use cases include pandemic contact tracing and biomedical research but must address surveillance and cybersecurity concerns.
- Need for regulatory coordination and institutional arrangements:
  - Coordinated approach should involve central banks, ministries of finance and economics, financial regulators, consumer protection agencies, privacy regulators, and competition agencies.
  - Example: central banks issuing digital monies must coordinate on privacy issues with domestic privacy and consumer protection regulators.

### INTERNATIONAL COOPERATION — rationale, principles, and possible architectures
- Rationale:
  - Data’s mobility and economies of scale imply large gains from cross-border data flows; fragmentation could undermine innovation, financial stability, integrity, and efficiency, and disadvantage smaller countries.
  - Common minimum principles across countries can balance growth and competition with privacy concerns and avoid a digital divide.
- BOX 1 — Key elements of common minimum international principles:
  - Principles for data protection:
    - International agreement on common minimum standards for acceptable protection when individual data is shared across borders would reduce uncertainty for businesses.
    - Approach could draw on OECD Principles on Privacy (1980 and amended 2013), with further consideration of consent and definitions of data and individuals.
  - Principles on interoperability and data portability:
    - Need common principles on cross-border interoperability and portability (use cases: cross-border payments, open banking).
    - Challenge: coordinate principles for interoperability of cross-border central bank digital currencies, including digital identification methods, standards for digital wallets, and data flows.
  - Principles on data sharing for regulatory purposes:
    - A rigorous framework should govern protection and disclosure to public bodies where necessary for public policy objectives (e.g., criminal law enforcement, tax liability).
    - Exemptions to confidentiality and secrecy are commonplace in national frameworks and align with international standards (Financial Action Task Force, OECD tax initiatives).
    - Principles on disclosure should aim for common ground to allow global data sharing for enforcement or regulatory purposes.
- Recent recognition and initiatives:
  - In April 2021, G20 finance ministers and central bank governors asked the IMF, in close cooperation with other international organizations, to prepare a proposal for a new G20 Data Gaps Initiative, in which Access to Private Data Sources is a priority area.
- Existing and proposed frameworks:
  - Some arrangements exist via multilateral trade treaties (WTO) and bilateral agreements; many rely on opt-in participation.
  - Global frameworks exist for official data exchange (e.g., automatic exchange of bulk taxpayer information; anonymized statistical exchanges via IMF, WTO, BIS; INTERPOL Information System; Egmont Secure Web).
  - “Soft law” proposals include OECD guidelines and APEC Roadmap; WTO e-commerce initiative seeks voluntary rules to allow cross-border data flows while ensuring privacy.
- Risks of fragmentation and ways forward:
  - Without global approaches, ad hoc sectoral, regional, or bilateral approaches will continue, risking fragmentation.
  - A gradual piece-by-piece approach can proceed alongside development of common global principles; bilateral agreements may offer conflict-resolution modalities.
  - A new treaty regime is ambitious, but scope exists to expand cooperative regimes and volunteer standards (e.g., ISO), subject to national legislative agreement.
- Balance and recommended actions:
  - Balance trade-offs across objectives via national coordination across sectoral regulators.
  - Action at national and international levels is needed to mitigate risk of fragmentation into localized national data pools that would diminish productivity, trade, and inclusion benefits.
  - Absent new international agreements, ad hoc solutions will persist and tensions between privacy, security, competition, and stability will continue.

### ANNEX I — What is data? definitions, trends, and policy implications
- Economic relevance and technological trends:
  - Data on individuals has proliferated with digitalization.
  - Two trends: reduced costs of collecting/storing data; advances in analytics (AI, machine learning) enabling more value extraction across sectors (drug discovery, financial services, targeted advertising).
- Definition and scope:
  - Focus on individual data mapped to people’s attributes and behavior (distinct from aggregated sectoral or geographic data).
  - Types: physical attributes and behavior; economic characteristics; social connections; tastes; sensitive personal data.
  - Identification: individuals can often be identified or geolocated.
- Opportunities and measurement challenges:
  - Channels where individual data improves economic measurement: answer new questions, bridge time lags, serve as innovative sources for official statistics.
  - Challenges: data quality, access difficulties, need for new skills and technologies—especially for less developed countries.
  - International statistical cooperation is key (FSB-IMF G20 Data Gaps Initiative).
- Box A1 — Data and the Pandemic:
  - Pandemic increased use of big individual data for contact tracing and mobility tracking; privacy protections sometimes conflicted with cross-border medical data sharing, impeding research collaboration.
- Box A2 — Open Banking:
  - Open banking promotes competition and innovation via data sharing subject to consumer consent.
  - Jurisdictions include: Australia, Brazil, European Union, India, Mexico, Singapore, United Kingdom.
  - Variants: public mandates, public encouragement, private-sector-led initiatives.
  - Implementation tools: open APIs, digital ID integration; India example emphasizes digital ID and interoperability.
  - Concern: scale of digital ID provision under central governments and potential misuse suggests need for modernized privacy framework.
- Box A3 — National approaches to data privacy frameworks:
  - Privacy definitions vary (constitutional right vs common law); many frameworks allow state exceptions for public interest.
  - Extraterritorial reach is present in some frameworks (e.g., GDPR).
  - Consent, portability, localization, security requirements, and penalties vary across jurisdictions.
  - GDPR imposes monetary penalties ranging from 2 to 4 percent of global turnover depending on severity.
- Box A4 — Data as property:
  - Debate over treating data as property; not widely adopted though some regimes have property-like aspects.
  - Complications: constitutional questions about assigning away privacy rights; risk of inequities where poorer individuals sell privacy; unresolved rights over deceased individuals’ data.
  - Fragmentation risk: differing views on property rights may push processors to jurisdictions with fewer protections (“privacy for sale”).

*Source: Excerpt from sdnea2021005 (TOWARD A GLOBAL APPROACH TO DATA IN THE DIGITAL AGE), International Monetary Fund.*

### EXECUTIVE SUMMARY __________________________________________________________________________ 3

### EXECUTIVE SUMMARY

### CONTEXT
- Individual data is a key input and source of value across sectors, including Big Tech, pharmaceuticals, manufacturers, and financial services. Data types include “likes,” purchase patterns, locations, social activities, biometrics, and financing choices.
- Use of individual data and digital innovation can power productivity; increase access to finance; and promote trade, including of digital services.
- Key challenges for policymakers:
  - Balancing privacy trade-offs: Policies to protect privacy can mitigate undesired use of individual data but can impede private and public efforts to generate economic and social gains from access to data and its use in support of regulatory enforcement and the fight against criminal activity. Clear rules are needed, including giving people effective control over their data.
  - Promoting inclusive digitalization: Data can support efficiency and inclusion, including in financial services, but can also enable price discrimination and feed algorithmic biases, disadvantaging and excluding some individuals.
  - Fostering competition in the digital economy: Data can support productivity and public goods (for example, biomedical research), but hoarding by large data collectors can reduce competition, dampen innovation, and raise financial stability risks.
- Domestic policy responses under consideration include interoperability mandates, data portability, creation of data fiduciaries, and public data utilities. These require unprecedented coordination among regulators with mandates across competition, financial stability, integrity, consumer protection, and privacy.
- International cooperation is critical to contain fragmentation of the global digital economy. Cross-border data flows underpin a rapidly growing proportion of international services trade. Fragmentation could particularly harm smaller countries with smaller data pools and those dependent on multinational foreign digital firms.
- The note argues for development of international agreement on common minimum principles for the data economy to reduce avoidable divergences and support cross-border approaches to privacy definitions, interoperability, data portability, and data sharing for regulatory purposes.
- The paper’s scope includes implications for digital money, taxation, and competition in the digital economy, noting that central bank digital currencies and cross-border private digital currencies will be heavily influenced by national data policies.

### THE ECONOMICS OF DATA
- Data functions as an input in the production of goods and services, particularly in the digital economy; deriving value requires costly processing and analysis combined with other factors (labor, algorithms).
- Big data has supported AI in solving increasingly complex problems; AI is being deployed as a general-purpose technology across many fields.
- Data is nonrival: it can be used multiple times and by multiple agents without being diminished. Social returns increase when data is widely available, but private processors have incentives to hoard data.
- Trade-offs from wider data access include increased social value versus compromised privacy and heightened cybersecurity risks.
- Access to individual data reduces information asymmetries between buyers and sellers, enabling personalization (e.g., targeted ads, usage-based insurance) that can make both customers and sellers better off if users have control over their data.

### DATA POLICY OBJECTIVES AND TRADE-OFFS
- Modernized data policy frameworks must address:
  - Opacity of data markets: consumers often lack awareness of how data is used, transferred, and processed; achieving an efficient and equitable data economy requires clear rules and effective consent.
  - Hoarding of data by firms: large data sets concentrated in few firms can stifle competition and innovation.
  - Resilience of digital data infrastructure: ensuring data integrity and protecting data from theft and misuse is critical to public trust and financial stability; policy should include adequate cybersecurity investment.
  - Public interest in disclosure: there is a public policy case for sharing certain types of data for regulatory and enforcement purposes that must be balanced against privacy concerns.

### DOMESTIC COORDINATION
- Effective data policy requires coordination across ministries and regulators because policies impose trade-offs affecting growth, privacy, competition, and financial stability and integrity.
- Mechanisms to foster greater coordination among domestic regulators merit further exploration; focusing on single objectives can have repercussions for others.

### THE CASE FOR GLOBAL POLICY COOPERATION
- Data’s mobility and economies of scale imply large gains from cross-border data flows; distrust or perceived unequal benefits can lead countries to erect digital barriers that impede international data flows.
- Fragmentation of the global digital economy could undermine innovation, financial stability, integrity, and efficiency, and disadvantage smaller countries.
- The note argues for international agreement on common minimum principles to mitigate avoidable divergences arising from different national priorities (privacy, competition, stability).

### BOX 1 — KEY ELEMENTS OF COMMON MINIMUM INTERNATIONAL PRINCIPLES
- Principles for data protection:
  - An international agreement on common minimum standards for acceptable protection of individual data when shared across borders would reduce uncertainty for businesses.
  - Such an approach could draw on the OECD Principles on Privacy (1980 and amended 2013), with further consideration of the role of consent and the definition of data and individuals.
- Principles on interoperability and data portability:
  - Need to discuss common principles on cross-border interoperability and portability given global businesses’ reach.
  - Use cases include cross-border payments and cross-border data sharing across open banking initiatives (Committee on Payments and Market Infrastructures 2020).
  - A concrete challenge is coordinating principles for interoperability of digital currencies issued by central banks when used across borders, including methods for digital identification, standards for digital wallets, and data flows.
- Principles on data sharing for regulatory purposes:
  - A rigorous data framework should govern both protection of data and its disclosure to public bodies where necessary for public policy objectives.
  - Exemptions to confidentiality and secrecy provisions are already commonplace in many national frameworks (for instance, tax law and anti–money laundering and combating the financing of terrorism) and align with international standards and best practices (such as Financial Action Task Force standards and Organisation for Economic Co-operation and Development tax initiatives).
  - Balancing privacy concerns against disclosure for public policy objectives is needed as data regimes evolve; principles on data disclosure to public authorities should aim for common ground across national frameworks to allow global data sharing for enforcement or regulatory purposes.

*sdnea2021005 - EXECUTIVE SUMMARY*

### 13.        Assessing the value of individual data is difficult. Unlike a commodity, data is highly

### 13.        Assessing the value of individual data is difficult. Unlike a commodity, data is highly 

### Valuation challenges and nature of data
- Data is highly heterogeneous; no two pieces of data are perfect substitutes and they need not hold the same value, and their value may change over time.
- Individual data transactions usually take place through barter: individuals swap use of their data for “free” digital services.
- Assessing data’s value is challenging even for parties with direct incentives:
  - Advertisers spend large sums on data about online users on the premise that displaying a well-targeted ad will influence behavior; some studies flag difficulty measuring returns to such efforts (Lewis and Rao 2015) and point out returns may be negative (Marotta, Abhishek, and Acquisti 2019).
  - Information from stock listings, mergers, and acquisitions offers a sense of commercial value but may not capture social value because the data economy is opaque and privacy is not fully respected.
- A lack of information combined with individual costs of privacy breaches not fully internalized by data processors may lead to data priced differently from its true economic value.
- Governments remain divided over how to place value on data from a digital taxation perspective (Aslam and Shah 2021).

### Who accrues returns to data
- Key question: how much value comes from each individual data point versus from aggregation and subsequent analysis; answer varies by data type and context.
- Important factor: degree of substitutability between data and other factors of production.
  - Some data require very advanced and proprietary analytical tools and highly skilled labor to convert into useful information (e.g., big data sets used to train machine learning algorithms).
  - In other cases, information can be extracted with less analysis, e.g., individual data used to provide a targeted product.
- Value of such data may differ greatly depending on characteristics of data subjects, such as their income, age, and consumption preferences.

### Market power, competition, and allocation of value
- Allocation of value in the data economy depends on competition and market power of individuals and data processors.
- If a data processor enjoys market power:
  - Granular client information can enable extraction of considerable rents via price discrimination strategies (documented for major online retailers (Hannak and others 2014)).
  - Stockpiled data sets can act as barriers to entry that deter competition.
- Tech sector displays rising market shares for firms with strong market power, consistent with a winner-takes-most market structure.
  - Akcigit and others (2021) document in a study spanning 82 countries that the main driver of rising markups in the tech industry is the rising market share of existing high-markup firms (the “reallocation effect”).
- In finance, banks traditionally hoard relationship data, making it hard for other lenders to price risk and compete with incumbents (Carrière-Swallow and Haksar 2021a).

### Privacy and the digital economy — economic consequences
- Decisions on privacy have important economic consequences; sharing data over digital networks and making it public to a global audience has increased privacy salience (Acquisti, Taylor, and Wagman 2016).
- Significant benefits can accrue to individuals from use of their data, including innovative services and more customized products.
- When individuals are unaware or lack input over data use, an externality results: firms’ decisions to collect, process, or share personal data can harm individuals who may not be compensated.
  - These externalities are often negative: data may be used to charge higher prices, leading to too much data on individuals being collected and processed (Acemoglu and others, forthcoming).
- Emerging example: shift away from cash toward digital payments and digital money—including central bank digital currencies—whose inherent traceability raises privacy decisions (Garratt and van Oordt 2021).

### Agency, data markets, and public goods
- Effective privacy is about giving individuals agency over their data; privacy is control over access to data rather than preventing sharing (Acquisti, Taylor, and Wagman 2016).
- When companies govern data access, results may include less competition, more data hoarding, and less privacy for consumers (Jones and Tonetti 2020).
- For the data market to work efficiently, data subjects must control access to their data to close the externality; tension can arise between an individual’s desire to restrict data sharing and public goods (e.g., refusal to participate in contact tracing during a pandemic).

### Valuing privacy and the privacy paradox
- Placing a value on privacy is inherently difficult; literature identifies an apparent privacy paradox (Nissenbaum 2009): people place a much lower value on privacy in private actions than when asked in surveys to give it a subjective value.
- Survey evidence: large percentages state they are very concerned about companies sharing private information yet almost all willingly give consent in exchange for basic “free” online services.
  - Evidence cited: Johnson, Shriver, and Du (2020) find only 0.2 percent of ad impressions opted out of targeted advertising under AdChoices; Aridor, Che, and Salz (2020) find only 12½ percent of users of a particular website opted out after GDPR implementation despite less precise ads.
  - Mobile weather apps example: users grant access to detailed location data to avoid typing a city name (Carrière-Swallow and Haksar 2021b).

### Anonymization: benefits and limits
- Anonymization can enable some social benefits of data access while preserving privacy.
  - In several applications, analytics can provide valuable insights without data being individually identifiable (e.g., training an AI system for automated driving, studying vaccine effects using anonymized global data).
  - These applications rely on huge amounts of individual data but do not require linking data to an identified person.
- In many other applications, the value of data is substantially reduced through anonymization because it no longer reveals information about a specific person.
- Limits: anonymization may be reversible by matching other characteristics to identities (Su and others 2017).

### Data and the financial sector — core role of personal data
- Access to personal data is a core input for financial services; lenders face uncertainty about borrower creditworthiness and rely on data to reduce information gaps.
- Need for data has intensified as the global financial system has become heavily digitalized and interconnected; regulatory data collection has grown to meet identification, suspicious transaction detection, and source-of-funds requirements.

### Data and efficiency in financial services
- Incomplete information about borrowers prevents efficient credit allocation because of adverse selection (Stiglitz and Weiss 1981); lenders may ration credit when creditworthiness is unknown.
- Adverse selection is particularly relevant in developing economies for informal sector workers or those without prior financial access.
- Access to nontraditional data can boost inclusion by alleviating adverse selection:
  - Online-collected information (social habits, payment of utility bills, traces of economic and social activity) may evaluate creditworthiness for borrowers without prior interactions.
  - Evidence: Frost and others (2019) and Berg and others (2020) show nontraditional online data can predict creditworthiness more accurately than a traditional credit score.
  - Figure 3 (from Berg and others (2020)) shows explained credit scores (area under curve) improving when combining credit bureau and digital footprint data; labels: "Credit Bureau", "Digital footprint", "Combined" with values on vertical axis ranging from 65 to 74.

### Data sharing, competition, and open banking
- New data-sharing approaches give individuals greater agency and can boost competition and efficiency.
- Long history of data sharing in financial services: credit bureaus (reciprocal information sharing) and public credit registers where private bureaus do not emerge.
- Data sharing lessens adverse selection and moral hazard, increasing credit provision by reducing information asymmetries (Jappelli and Pagano 2002; Djankov, McLiesh, and Schleifer 2007).
- Desire for greater competition and efficiency underlies open banking initiatives.

### Data resilience and financial stability
- Data resilience is needed to ensure financial stability: financial system depends on robust, resilient digital data infrastructure for key functions; ICT systems must process data reliably and protect sensitive individual data.
- Incidence of data breaches has sharply risen over time with very large exposures of individual data records (Figure 4).
  - Figure 4 lists selected incidents with user impact numbers (as presented): Heartland Payment System: 134 million; LinkdIn: 165 million; Adobe Date: 153 million; MySpace: 360 million; Ebay: 145 million; Yahoo: 3 billion; Marriott: 500 million; Adult Friend Finder: 412 million; Equifax: 147.9 million; Dubsmash: 162 million; Canva: 137 million; My Fitness Pal: 150 million; Zynga: 218 million; Sina Weibo: 538 million.
  - The chart covers years 2007 2009 2011 2013 2015 2017 2019 2021 and plots number of data breaches (number of cases) with y-axis labels 0, 500, 1,000, 1,500, 2,000, 2,500.
- Private incentives to protect data may not deliver systemic data resilience: confidentiality, integrity, and availability are crucial properties; firms may underinvest in cybersecurity because they do not internalize broader impacts on public trust (Kopp, Kaffenberger, and Wilson 2017; Kashyap and Wetherilt 2019).

### Cloud services, concentration, and systemic risks
- Growing use of cloud services introduces trade-offs:
  - Third-party cloud providers offer efficient data management, analytic tools, and cyber defenses.
  - Massive agglomeration of data in a handful of cloud providers poses potential systemic financial stability risks from single points of failure.
  - Financial Stability Board (FSB) notes cloud use may reduce operational risk at the firm level but could “also pose new risks and challenges for the financial system as a whole.” 
- Data-intensive financial services could increase concentration and impact financial stability:
  - Large intermediaries may generate more data and gain advantage over smaller competitors, leading to greater concentration.
  - Concentration of data in a few global platforms could lead to “too-big-to-fail” risks.
  - Efficiency gains from data proliferation may be unevenly shared, benefiting larger incumbents more than smaller firms (Begenau, Farboodi, and Veldkamp 2018).
  - Data-based lending tends to favor more concentration in production (Farboodi and Veldkamp 2020).
  - Concerns arise because big-data-driven credit models may not span a full financial cycle, raising questions about performance if conditions deteriorate (Claessens and others 2018).
  - Counterevidence: research on China during COVID-19 indicates digital banks’ portfolio quality held up well (Sun and others, 2021); IMF research (Pierri and Timmer 2020) finds banks that adopted data technologies more intensively before the global financial crisis were more efficient in screening borrowers and experienced fewer mortgage defaults and problem loans during that crisis.

### Regulatory data needs and suptech
- Financial sector increasingly gathers data to satisfy regulatory requirements: due diligence, customer identification, transaction and customer monitoring rely heavily on data.
- Volume of data to meet legal requirements requires high-quality IT systems for market participants (e.g., AI to detect outliers and suspicious transactions) and for regulatory authorities (suptech—technology to support financial supervision).

*International Monetary Fund, Staff Discussion Note excerpt*

### 29.        The use of granular individual data could lead to the exclusion of people who exhibit traits

### 29.        The use of granular individual data could lead to the exclusion of people who exhibit traits associated with risky financial behavior.

### Risks from granular individual data and AI-driven decisions
- Data-driven profiling can lead to exclusion or higher costs for vulnerable individuals:
  - A health insurer harvesting customer data to infer preexisting medical conditions or risk propensities may charge higher premiums or deny coverage (Arrow 1963), undermining the risk-sharing function of insurance.
  - Recommendation implied in text: regulations should specify the types of data that may be used to make decisions—for example, restricting in some cases the denial of health insurance coverage based on a preexisting condition.
- Inappropriate use of individual data to train AI models can worsen biases in access to financial services:
  - AI algorithms trained on data of “expert individuals” may inherit bias from training data, e.g., patterns of lending that reduce access based on location or race.
  - Empirical demonstration: Fuster and others (2020) study of the US housing market.
  - Concern: AI algorithms often produce accurate predictions but lack structural interpretation and may be perceived as discriminatory “black boxes” that cannot be explained to customers or regulators.
- Cross-sector prevalence of bias:
  - Example outside finance: Buolamwini and Gebru (2018) find facial recognition error rates for darker-skinned people were dozens of percentage points higher than for lighter-skinned people, tied to training data composition.

### The data policy toolkit: frameworks, legal underpinnings, and trade-offs
- Purpose of data policy frameworks:
  - Set rules for how data is stored, who may have access, how it can be used, and for what purposes (Box A3).
  - Well-designed policies underpin public trust and participation in the digital economy (World Bank 2021).
- National approaches differ widely (three broad trends):
  - EU rights-based approach exemplified by the General Data Protection Regulation of 2016.
  - US activity-based “notice and choice” approach with sector-specific protections (health care, finance).
  - Some large emerging markets (China example) protect privacy for individuals but emphasize public interest access to individual data and introduce data localization.
  - Result: no clear global data governance approach and attendant risks of fragmentation.
- Public law versus private law:
  - Private law enforces contractual agreements on data usage (consent-focused); public law sets regulatory standards and inalienable fundamental rights (for example, privacy under the GDPR).
  - Debate exists on the role of consent once an individual or entity “owns” data and on whether a property right over data is possible (see Box A4).
- Balancing privacy and public interest:
  - Private/confidential data can have social value (e.g., identification, financial stability and integrity).
  - Public law often weaves this balance into disclosure requirements as prerequisites for service access (financial services) or to fulfill legal obligations (tax filing, suspicious transaction reports), and may require disclosure upon demand by regulators or law enforcement.

### Need for regulatory coordination and institutional arrangements
- Sectoral data policies create trade-offs that require coordination:
  - Tighter privacy protection can limit access to data and stifle innovation.
  - Open banking can boost competition but may create some financial stability risks.
  - Coordinated approach should involve central banks, ministries of finance and economics, financial regulators, consumer protection agencies, privacy regulators, and competition agencies.
  - Example: central banks issuing digital monies must coordinate on privacy issues with domestic privacy and consumer protection regulators (Bank of England 2021).

### Modernizing data policy: mechanisms to promote competition, privacy, and public good
- Interoperability:
  - Interoperable platforms ease sharing and transmission of data under a mutually accepted set of rules.
  - Interoperability supports multi-homing, reduces network hold, can be pro-competitive, and may lower “too-big-to-fail” risks.
  - Requires accessibility, assignment, and management of rights and responsibilities.
- Data portability:
  - Portability gives individuals control over what flows between platforms and can promote competition by lowering switching costs (open banking example).
  - Potential to manage competition broadly in network environments.
- Data fiduciaries:
  - Agents responsible for managing subjects’ data and seeking consent for processing; proposed as a solution to effective consent management (discussed in India).
  - Could achieve privacy objectives while operationalizing consensual data sharing.
- Public data utilities:
  - Aggregation of individual data in an independent central repository (analogous to a public credit bureau) could enable level-playing-field access for solution development.
  - Use cases include pandemic contact tracing and biomedical research (PEPP-PT example).
  - Must address surveillance-state and cybersecurity concerns; decentralized solutions like interoperability and portability may dominate in practice.

### The case for global policy cooperation
- Cross-border data flows are rising and underpin economic activity and international trade (Figure 5):
  - Data movement is crucial for trade in services and cross-border payments; disparate standards raise costs.
- Cross-border data protection challenges:
  - Personal data can flow through jurisdictions with noncomparable privacy protection.
  - With incomplete markets, national data subjects may not be fully compensated for global corporations’ use of their data.
  - Authorities may legitimately seek control over individual data for regulatory or security purposes, creating tensions between privacy and other objectives.
  - Example legal tension: Schrems I and Schrems II litigation following disclosure that data of non-US Facebook users could be accessed by US intelligence agencies, resulting in the breakdown of the EU-US Privacy Shield agreement (footnote discussion).
- Trade-offs for developing economies:
  - Cross-border data flows drive dynamic exports (data processing and data-related business services).
  - Statistic: These services contributed to more than $50 billion worth of developing economy exports to the European Union in 2015—of which one-fifth came from Africa (Mattoo and Meltzer 2018).
  - Tightened data regulation in advanced economies forces developing economies to adopt higher-compliance standards or risk losing market access, raising compliance costs.
- Costs of data localization:
  - Data localization policies (limits on transfer of national subjects’ data outside national boundaries) may reflect cybersecurity concerns or protectionism and can undermine digital trade benefits (Menon 2018).
  - Because data is nonrival, cross-border usage yields large gains; reduction in trade of large data sets can undermine growth and innovation and may generate a digital divide that excludes some countries from digitalization benefits.

*Source: Excerpt from sdnea2021005 (TOWARD A GLOBAL APPROACH TO DATA IN THE DIGITAL AGE), International Monetary Fund.*

### 41.        There is a strong case for international cooperation on data governance. While we should

### There is a strong case for international cooperation on data governance

### Rationale for international cooperation
- International dialogue and cooperation can help ensure the digital economy does not become subject to undue fragmentation.
- Aspiring to the best principles of privacy and individual rights, while satisfying social objectives, need not trigger fragmented policy approaches that lead to localized data markets and undermine cross-border data sharing benefits.
- There is a need for common minimum principles across countries that balance growth and competition with national and individual privacy concerns, and such principles should be developed in a setting where all countries can have a say to avoid the emergence of a digital divide (World Bank 2021).

### Key elements of common minimum international principles (especially for financial services)
- Principles for data protection:
  - An international agreement on common minimum standards for acceptable protection of individual data when shared across borders would reduce uncertainty for businesses seeking to comply.
  - Such an approach could draw on the OECD Principles on Privacy (1980 and amended 2013), with further thought on issues such as the role of consent and the definition of data and individuals.
- Principles on interoperability and data portability:
  - Need to discuss common principles on how interoperability and portability should work across borders (Furman and others 2019).
  - Specific use cases include cross-border payments and cross-border data sharing across open banking initiatives (Committee on Payments and Market Infrastructures 2020).
  - A concrete challenge: coordinate on principles for enabling the interoperability of digital currencies issued by central banks when these can be used across borders, including a method for digitally identifying individuals and standards for digital wallets and data flows.
- Principles on data sharing for regulatory purposes:
  - A rigorous data framework should govern protection of data and its disclosure to public bodies, including regulatory authorities, where necessary for public policy objectives (for example, to facilitate criminal law enforcement activities and determine tax liability).
  - Exemptions to confidentiality and secrecy provisions are already commonplace in many national frameworks (for instance, tax law and anti–money laundering and combating the financing of terrorism) and in line with many international standards and best practices (such as Financial Action Task Force standards and Organisation for Economic Co-operation and Development (OECD) tax initiatives).
  - Principles on data disclosure to public authorities should, to the extent possible, aim to achieve common ground across national frameworks to allow for global data sharing for enforcement or regulatory purposes.

### Recent international recognition and initiatives
- In April 2021, the G20 finance ministers and central bank governors asked the IMF, in close cooperation with other international organizations, to prepare a proposal for a new G20 Data Gaps Initiative, in which Access to Private Data Sources is featured as one of the four main priority areas.
- Policymakers and statisticians continue to face barriers to data access from private entities domestically and across borders because of confidentiality and legal provisions.

### Existing and proposed frameworks
- Some limited formal arrangements for exchange of data for commercial and financial services are governed by multilateral trade treaties (particularly via the World Trade Organization (WTO)) and bilateral trade agreements; while binding, most rely on participants to opt in, and some major countries have not participated.
- Bilateral agreements and statements of intent can be effectively hard law (example cited: the EU-US Privacy Shield agreement, though it was invalidated following the Schrems litigation).
- Certain global frameworks exist for large-scale exchange of data between countries for official purposes (for example, automatic exchange of information for “bulk” taxpayer information; anonymized statistical data exchanges via IMF, WTO, Bank for International Settlements; and other regimes such as INTERPOL Information System, Egmont Secure Web).
- A “soft law” approach of international standards and practices has been proposed for data privacy (for example, OECD guidelines and the APEC Internet and Digital Economy Roadmap).
- The WTO’s e-commerce initiative (a voluntary multilateral approach) seeks a common system of rules to allow cross-border data flows while ensuring privacy protection.

### Risks of fragmentation and possible ways forward
- Without a global approach to data policy frameworks, continuation of ad hoc, sectoral, regional, or bilateral approaches is likely, raising concerns of fragmentation.
- A gradual and piece-by-piece approach could proceed alongside development of common global principles; bilateral agreements may offer modalities for resolving conflicts between regulatory heterogeneity and international data flows.
- A new treaty regime on global data regulation is highly ambitious, but there is scope to expand upon existing cooperative regimes and build upon existing standards (for example, voluntary standards set by the International Organization for Standardization (ISO)).
- Using ISO standards to streamline data usage hinges on agreement by national legislators since ISO is not itself a regulatory authority.

### Need to balance objectives and recommended actions
- Balancing trade-offs across objectives requires a coordinated approach at the national level, involving cooperation among different sectoral regulators.
- Action is needed at the national and international levels to mitigate the risk of fragmentation into localized national data pools, which would diminish benefits that data sharing offers for productivity gains, trade, and financial inclusion.
- Absent new international agreements, ad hoc solutions will need to be found; in the interim, tensions between data privacy, security, competition, and stability will continue to play out in the increasingly integrated global digital economy.

*Source: IMF Staff Discussion Note excerpt (sdnea2021005).*

### Annex I. What Is Data?

### Annex I. What Is Data?

### Economic relevance and technological trends
- Data on individuals has long been used in commerce, finance, and public policy, but it has proliferated with digitalization.24
- Two recent technological trends driving the explosion in economic relevance of data:
  - Technological progress has drastically reduced the costs of collecting and storing data. Widespread digitalization leads to more data being produced as a by-product of economic and social activities.
  - Advances in analytic techniques (including artificial intelligence and machine learning) enable more sophisticated processing to extract greater value from available data, pushing the use of massive databases across sectors and deploying prediction algorithms in areas such as drug discovery, financial services delivery, targeted advertising, and operational efficiency.

### Definition and scope of individual data
- Focus: individual data, mapped to people’s attributes and behavior; information is at the level of an individual (distinct from aggregated sectoral or geographic data).
- Types of information captured:
  - Physical attributes and behavior (for example, gender and age).
  - Economic characteristics (including income, property, and transactions).
  - Social connections (friends, professional networks).
  - Tastes (web browsing habits, purchase history).
  - Sensitive personal data (health characteristics and security information).
- Identification: The individual whose data is recorded can in many cases be identified or geolocated.
- Policy implication: The breadth and detail of direct and incidental information gathering, coupled with unclear agency by individuals over control of their data, is central to privacy challenges and to opportunities in commerce and finance.

### Opportunities and challenges for economic measurement
- Three main channels through which digital capture of individual data can improve economic measurement (as discussed in Hammer, Kostroch, and Quirós-Romero (2017)):
  - Answer new questions and produce new indicators.
  - Bridge time lags in the availability of official statistics and support timelier forecasting of existing indicators.
  - Serve as an innovative data source in the production of official statistics.
- Challenges to incorporation of individual data into reliable policy-relevant indicators:
  - Data quality issues.
  - Difficulties with access.
  - Need for new skills and technologies, which may be less accessible to less developed countries.
- International statistical cooperation is key to overcoming big data challenges, including in the context of the ongoing FSB-IMF G20 Data Gaps Initiative (DGI).25
- Note: The initiative has recommended “data sharing” both within and across countries; progress has been limited due to sensitivity of individual and firm-level data.

### Box A1 — Data and the Pandemic
- During the pandemic there was a surge in use of big individual data sets to analyze virus spread and policy effects.
- Real-time big data from platforms was used for contact tracing and mobility tracking; policy analysis using cell phone data and platform information increased (World Bank 2021).
- Privacy protections sometimes conflicted with necessary cross-border medical data sharing; differing standards impeded collaboration on medical research (Peloquin and others 2020), making solutions more pressing during the pandemic.

### Box A2 — Open Banking
- Purpose: Open banking initiatives promote competition and innovation through data sharing in the financial sector.
- Jurisdictions implementing open banking initiatives include: Australia, Brazil, the European Union, India, Mexico, Singapore, and the United Kingdom.
- Characterization: Open banking is a data access policy for the financial sector allowing data sharing subject to consumer consent (Carrière-Swallow and Haksar 2021a).
- Expected effects: Change how data flows in the financial system—who has it, who doesn’t, and who decides—facilitating entry, competition, and innovation.
- Variants of frameworks:
  - Public mandates for reciprocal data sharing among regulated entities at consumer initiation.
  - Public encouragement by regulators.
  - Private-sector-led initiatives with public neutrality.
- Implementation tools: Open application programming interfaces (APIs) to transfer data securely in standardized formats.
- Innovations vs. credit bureaus:
  - Direct exchange of customer data between financial institutions (not only processed credit scores but granular data for proprietary analysis and customized products).
  - Users have more control; open banking envisions user-initiated data transfers with user control over what is shared.
- Integration needs: Success may depend on integration with digital ID systems and interoperability standards for payments.
  - Example: India’s open banking infrastructure emphasizes digital ID and interoperability (Carrière-Swallow, Haksar, and Patnam 2021).
  - Digital ID can lower identity verification costs and facilitate anti–money laundering and know-your-customer compliance.
- Concern: Scale of digital ID provision under central governments and potential misuse that infringes individual privacy rights suggests the need for a modernized privacy framework to implement stack-based approaches.

### Box A3 — National Approaches to Data Privacy Frameworks
- Definitions of privacy:
  - Some frameworks define privacy constitutionally as a fundamental right and freedom.
  - Others frame the right as a common law concept protecting data in commercial and financial transactions.
  - A key difference concerns the role of the state; many frameworks allow exceptions for clear public interest (for example, regulatory requirements or law enforcement).
- Spillovers: Many frameworks have extraterritorial reach (e.g., GDPR covers processors outside the EU processing personal data for goods/services offered in the EU or for monitoring behavior of individuals in the EU).
- Consent: Lawful consent to process individual data varies; in most frameworks consent for defined legal purposes must be freely given and explicit, with exceptions for legitimate interests.
- Portability: Right allowing data subjects to obtain and reuse their personal data; many frameworks require provision in a structured, commonly used, machine-readable format and allow transfer to different controllers, with differences on whether the subject can mandate transfer to third parties and on the perimeter of portable information.
- Localization: Data localization laws require storage or processing within the country to assert data sovereignty and protect sensitive data; some require or encourage storing citizens’ data domestically or restrict cross-border transfers; others establish extraterritorial jurisdiction and may use localization to retaliate against discriminatory technology trade measures.
- Security requirements: Mandate secure processing against unauthorized processing and accidental loss; some frameworks do not impose security requirements but include rights of action for breaches resulting from violations of reasonable security practices.
- Penalties: Vary across jurisdictions. The GDPR imposes monetary penalties ranging from 2 to 4 percent of global turnover, depending on severity of the violation, and are relatively high compared with other jurisdictions.

### Box A4 — Data as Property
- Debate: Treating data as property (real property or akin to intellectual property) is heavily debated; premise is that data has value and individuals related to the data should have property rights (for example, rights to exclude others or charge for use).
- Adoption: The overall concept has not been widely adopted, though some regimes have property-like aspects.
- Complications:
  - Constitutional questions in some jurisdictions about whether individuals can assign away their right to data privacy.
  - Data-as-property regimes could lead to inequities (people with less wealth more willing to sell data, reducing their privacy).
  - Ignoring property aspects can produce unexpected consequences (for example, unresolved rights over data of the deceased).
- Fragmentation: Countries have different views on property rights for data, especially when weighed against privacy or national security, potentially leading processors to shift activities to jurisdictions with fewer protections and raising equity concerns (for example, “privacy for sale”).
- Options: Discussion continues on whether aspects of property law—particularly intellectual property law—may inform data regulation, such as defining rights to revenue streams arising from use of individual data.

*Source: Annex I. What Is Data?*

---


_Source: https://www.imf.org/-/media/files/publications/sdn/2021/english/sdnea2021005.pdf_
