Making AI context portable in the UK

Fabric1 like · 2 comments

TL;DR

  • GDPR gave users the right to their data, but most companies still hand users an archive in 30 days. The new Smart Data Scheme should require real-time programmatic, controller-to-controller sharing with user consent.

  • Open Banking proved that this model works. It delivered real value, a £4 billion ecosystem, and ~5,000 UK jobs. Digital markets can go further because the surface area is bigger and more dynamic.

  • EU’s Digital Markets Act APIs show a scheme is feasible in months, not years. Google, Meta, TikTok, and Booking are already meeting controller-to-controller portability in the UK, while LinkedIn and Amazon have not extended their DMA APIs here.

  • It is critical to have AI products (including search, browsers, and social) in scope. We propose using inclusive thresholds and allowing self-nomination so important services are not missed.

Fabric’s full responses to the DSIT’s Digital Markets Smart Data Scheme Consultation

What issues do customers face in accessing their data held by digital markets firms and sharing that data with third parties?

The UK has a strong history of protecting consumers’ data rights through regulations like the UK GDPR and Data Protection Act 2018. These regulations enforced the data subjects’ rights to obtain their data from data controllers. GDPR Article 20 provisions for data portability, including “the right to have the personal data transmitted directly from one controller to another, where technically feasible”.

While accessing digital data is possible post GDPR, a big part of the problem is that it is dumped on the user, not sent to a third party. Data delivered solely to the user in days and weeks as a “data dump” is hardly useful or usable. The real value of digital data is in its user driven movement and use. This is currently not possible for UK consumers.

The Payment Services Regulations 2017 (Open Banking) is the gold standard worldwide, implementing real-time, secure, and programmatic access to end user’s financial data with their informed consent. This led to substantial value creation in the UK. The Open Banking ecosystem is now valued at over £4 billion and has attracted substantial investment, creating ~5,000 jobs in the UK.

In the digital markets (excluding those covered by Open Banking), most companies do not observe the consumer’s right to real-time, secure, and programmatic data portability. This is now changing, starting in the European Union due to the Digital Markets Act 2024 which has made it possible for end users to share their data from ‘gatekeepers’ like Alphabet, Meta, Microsoft (LinkedIn), TikTok, Amazon, Apple, and Booking dot com.

The “controller to controller portability, where technically feasible” as provisioned in the UK GDPR is now technically feasible for all DMA gatekeepers in the UK but it is only being met by Alphabet, Meta, TikTok, Apple, and Booking dot com. Microsoft (LinkedIn) and Amazon have decided to not make their DMA APIs available in the UK, even though it is now technically feasible to support controller to controller portability.

While companies like Pinterest, Spotify, and Strava make some transfers of user data possible in the UK via APIs, there are substantial roadblocks in place that limit the use of these APIs for data portability and user empowerment (e.g. legal guarantees, service level agreements, uptime guarantees, standardisation, business model protection). These restrictions deter companies from making use of these tools and limit the ways in which their users can utilise their own data.

Creating an ecosystem where consumer data can be shared requires more than just patchy availability of data, it requires strong legal protections so businesses can build consumer products using the data with guarantees mitigating platform risk.

Where digital markets data is available, its format differs substantially between providers which makes it difficult to interpret, understand, and use. Considering the diverse nature of digital markets data, there is a need for specialised third parties in the ecosystem (like with Open Banking) which enable consumer companies to use digital data. For these parties to exist and have a business, they need strong legal protections (particularly around wide ranging business models e.g. legal protection on data use with a degree of business model agnosticity).

What use cases do you believe could be supported through a Smart Data scheme to address those issues, including types of products and services that ATPs might be able to offer, and what outcomes could this result in?

A targeted digital markets Smart Data scheme has the potential to have a substantially outsized impact as compared to Open Banking due to the unique market dynamics at play.

The next generation of consumer experiences are being built using AI. These experiences have the potential to be hyper-personalised to each individual consumer. However, if digital markets data continues to stay siloed, these incredible consumer experiences will lack the “rich user context” that they need to be truly lifechanging for consumers.

From our market research and customer discovery, we have identified the following high value categories (non exhaustive) with the potential to unlock billions in value for UK consumers and businesses if digital markets data followed a similar trajectory to Open Banking. Top consumer AI products like ChatGPT, Claude, Perplexity, and Character AI range from having 25% to 400% monthly usage compared with essential Internet apps like Google, YouTube, LinkedIn, and Amazon. And given how early we are in the adoption of AI products, this is only going to increase.

  • Personal AI Assistants: already being built by large companies like OpenAI and Google but also many other companies worldwide e.g. startups like Martin AI and Amurex AI. Given their large impact on consumer wellbeing by boosting productivity and reducing time spent on repetitive activities, better data driven products are crucial here.

  • AI x Lifestyle e.g. Travel and Concierge Products: already being built by companies like TeN Lifestyle Group and Airbnb. With AI and cross-platform user data, these products are now within reach for the everyday consumer. Enabling more products (especially those with full user context) will mean that the everyday individual can now participate in previously exclusive experiences.

  • AI-powered Shopping Apps: already being built by companies like OnBuy, Daydream, Alta, OpenAI, Gemini, Perplexity etc. Every part of the consumer shopping experience is being reimagined with AI. Innovations like dynamic pricing (to favour the user) and AI personal shopper experiences require user understanding beyond what most companies have. Enabling these will improve both the cost of living and the quality of consumer experiences.

  • Dating Apps: already include/building significant AI powered improvements in matching, profile completion etc. Some apps enable image imports from social media platforms.

  • Entertainment & Social Apps: already being built by companies like Replika, Character AI, Gigi etc.

In addition to unlocking billions in commercial and consumer value, creating a digital markets Smart Data ecosystem will empower individuals to support activities like data donations for academic research.

Similar to Open Banking, unsiloing digital markets data will also require infrastructure and API layer products offered by ATPs. Here are some key emergent roles:

  • Maintaining, aggregating and standardising integrations: digital markets data is spread across many gatekeepers and is significantly more diverse when compared with Open Banking data. From our experience in Open Banking and with DMA APIs, maintaining different APIs, aggregation and standardisation over diverse data sources requires substantial efforts which makes it impractical for individual consumer companies to solve. Companies like Truelayer, Plaid, and Tink have led to the creation of successful consumer businesses while empowering individuals.

  • Create and maintain APIs for data holders: Similar to efforts undertaken by Plaid and Tink, working with data holders to create and maintain APIs will likely emerge as a role given it’s not the core business of data holders to create and maintain consumer data APIs.

  • Enriching and making sense of the data for specific use cases: Given the diversity of the data sources and the wide ranging potential applications in verticals like fashion, dating, travel, etc. there are roles for specialised data processors who can create vertical specific understanding.

  • Secure, unified, user-controlled storage and access: Users need to be able to control, scope access to, use, and monetise their cross-platform data in a frictionless way. As the number of data sources and parties involved increase, this will enable the user to always stay in control of their data.

At Fabric, we understand the importance of these roles and the value of creating a Smart Data ecosystem. Fabric is a Smart Data Platform. Partnering with the largest online platforms, Fabric is the first ATP for the emerging ‘Open Digital’ ecosystem. What Truelayer, Plaid, and Tink can do with HSBC, Santander and Lloyds, Fabric can do with Google, Meta, TikTok, LinkedIn, Booking, Amazon, and hopefully many more data holders. In addition, Fabric also solves for the unique constraints of working with digital markets data (which is substantially more complex than financial data).

What types of data and data holders would need to be in scope of a scheme in order to support any business models and address data access issues and use cases you have identified above?

In order to support a digital markets Smart Data scheme, the following data holders and categories of data need to be in scope.

  • AI products: consumer behaviour is shifting massively with almost a billion consumers worldwide using AI products like ChatGPT and Gemini. Given the 3 year time horizon in which this shift has happened, it’s clear that for a digital markets Smart Data scheme to succeed, it must include user’s personal data from the usage of AI products e.g. prompts, full assistant conversations, generated media - images and videos, etc. Major data holders recognise that user’s AI data meets similar data ownership and portability criteria as other platform data (e.g. search) by including them in user data export tools. As of the time of this submission, Google Takeout and ChatGPT data export tool make user prompts, conversation history, user uploaded images, user generated images etc. available to users.

  • Search services: search is the gateway to the Internet. Search data from companies like Google (and newer contenders like Perplexity) demonstrates rich user intent and is already first in line to being unsiloed in multiple geographies via the Digital Markets Act, the UK’s own SMS investigations, as well as other legal actions in different geographies. It’s crucial to cover existing and emerging search platforms given the evolution of AI powered search.

  • Social media platforms: users spend a substantial part of their time online on platforms like Instagram, Facebook, TikTok, LinkedIn, Snapchat, and X. Social media platforms are increasingly using AI to make user experiences even more engaging which will increase time spent online even more. Therefore, including social media interactions (likes, comments, posts, stories, as well as other data collected - e.g. ads information, shopping information) is important. Critically, the data made available by such platforms must include detailed information about the content or ads that users have engaged with (particularly when its publicly available content), not merely the fact that they have engaged with an account at a particular time.

  • Browsers: Browsers like Chrome, Comet, and OpenAI’s browser are (or will be) vertically integrated with their search and AI products. Browser data, both traditional (e.g. Chrome, Safari, Bing, Mozilla) and AI (e.g. Comet, Operator, Dia) is important as it provides holistic context as opposed to search data which is the entry point into online activity. For e.g. new AI native browsers are performing actions on behalf of and in collaboration with users, collecting valuable user information in the process, similar in principle to user and AI assistant conversations. In addition, there is a strategic play undergoing for user data and attention which has reignited the browser wars. Therefore, including browser data where it is collected, stored, and used by the platform is important.

  • Online shopping and travel aggregators: companies like Amazon, Booking, Zalando, Airbnb, Expedia, Skyscanner, Google Shopping aggregate vast amounts of user information from a shopping perspective (as evident from some of their DMA APIs). Many intentful digital markets actions (e.g. search, ad clicks) result in shopping transactions. Therefore, to capture full user understanding, shopping data is important.

  • Streaming services: similar to both social and search platforms, they command a substantial share of the user’s attention. Platforms like YouTube, Netflix, Prime, and Spotify have powerful personalisation algorithms that function off the user’s searches and watch history which is usable in multiple different contexts (e.g. Alphabet combining and using user data from across Search, YouTube, and Gemini).

Given the breadth and depth of digital markets coming up with broad categories and setting reasonable thresholds for self nomination is a sensible strategy as it will start capturing major digital markets players including strategically important AI companies. In addition, it’s worth examining the role of emerging data platforms and having proportionate thresholds for them.

  • Proposed categories: AI products, Search services, Social media platforms, Browsers, Online shopping and travel aggregators, Streaming services

  • Illustrative criteria: total UK users exceeds 2 million AND (global revenue exceeds 500 million OR funds raised exceed $1bn OR valuation exceeds $5bn)

What are your views on the feasibility to deliver a digital Smart Data scheme? Please consider any current or planned industry developments or changes that might affect delivery and highlight any key challenges.

There are overwhelmingly positive changes happening globally which make delivering a digital markets Smart Data scheme more feasible than it has been historically. Consumers are already primed due to the positive shifts associated with both Open Banking and GDPR in the UK.

These positive changes include the availability of new data portability APIs under the Digital Markets Act, which have made programmatic data portability with certain gatekeepers now possible in the European Union and to a lesser extent the UK.

Our experience (and publicly available Digital Markets Act workshop recordings) shows that gatekeepers such as Google and Meta understand and align on the need for consumer data portability. And that involved stakeholders view data portability as a reasonable investment. This is also reflected in their involvement in the Data Transfer Project (DTP) and subsequently, the Data Transfer Initiative (DTI).

The investments required (monetary and technical) in delivering a well-implemented Smart Data scheme are not substantial. This is evidenced by DMA gatekeepers delivering initial versions of their APIs in a reasonable time frame. In addition to the DMA gatekeepers, many companies already have the technical foundations to deliver on a Smart Data scheme. For e.g. companies like Pinterest, Spotify, and Strava make some transfers of user data possible in the UK via APIs, but there are substantial roadblocks in place that limit the use of these for data portability and user empowerment (e.g. legal guarantees, service level agreements, uptime guarantees, standardisation, business model protection). These restrictions deter companies from making use of these tools and limit the ways in which their users can utilise their own data. Many more companies (Twitter, LinkedIn, Snapchat, Reddit, Discord, Uber, Airbnb, Netflix, OpenAI etc.) provide download your information tools for users which can take anywhere from a few hours to a month for the data to be shared with the user. The ecosystem development is already in progress and the investments required with a well-implemented scheme are not substantial.

Given the emergence of AI enabled experiences and the consumer behaviour shifts towards using AI products (e.g. ChatGPT is one of the fastest growing consumer products in history), consumer data “context portability” will create opportunities to build new kinds of consumer experiences with perfect consumer information and consent.

Delivering the scheme will require careful coordination and phasing. One challenge is ensuring compliance and meaningful implementation across a wide range of digital businesses. Early DMA experience has shown that while APIs were built, several gatekeepers’ first attempts were not very user-friendly or fully compliant. The UK government can learn the lessons from that experience and provide clearer guidance to affected companies in advance.

Overall, the feasibility is high (technical and legal) but success will depend on implementation details (standards, enforcement, ecosystem development). Internationally, data portability is gaining traction (EU, Brazil etc.), so the UK can leverage existing solutions and learnings to reduce costs and risks while executing fast in a phased approach.

Do you have an initial or provisional view on the likely impacts (positive and negative) on:

Existing & Future Customers: A Smart Data scheme in digital markets would empower consumers with greater control and utility from their personal data. In practice, individuals could seamlessly share their activity data (social media, search history, AI prompts, purchases, etc.) with new apps and services of their choosing, enabling more personalized and convenient digital experiences. For example, users could let a personal AI assistant access their cross-platform data to receive truly tailored recommendations, or safely share their social media likes and music playlists with a third-party service to get a unified wellness or lifestyle report. Such portability reduces lock-in making it easier to switch providers or use multiple services, encouraging companies to compete on user experience rather than on hoarding data. UK consumers have already shown appetite for data-driven services when given the chance, over 10 million people now regularly use Open Banking services to improve their finances. We would expect a similar or greater scale of adoption in digital markets due to the breadth of use-cases (entertainment, shopping, productivity, etc.). There is increased risk of privacy breaches, however, Open Banking frameworks provide evidence that these are manageable and that the benefits significantly outweigh the costs.

Data Holders (Digital Platforms): gatekeepers can better opine on the costs of implementing Smart Data schemes but considering that many large platforms now support data portability tools (programmatic as mandated by the DMA) and non-programmatic (APIs and Download your information), the implementation costs for the largest companies are expected to be very manageable. These companies already handle enormous volumes of user data. Notably, several tech companies have publicly embraced data portability as a right and proactively participated in initiatives like the Data Transfer Project and subsequently the Data Transfer Initiative. We recognise that building APIs to support a Smart Data scheme will come with some costs and we are receptive and open to supporting scheme design choices that do not disproportionately increase costs to data holders. Now we need a Smart Data Scheme to go further and faster, encouraging more large digital companies with the capacity and expertise to step up and take responsibility for empowering modern consumers.

Small and Micro-Businesses: For small companies, especially startups and small/micro businesses, a Smart Data scheme would be a great enabler. For instance, a small UK e-commerce retailer could, with a customer’s permission, access that customer’s “digital wallet” of past product likes or Pinterest pins to personalize recommendations. We expect the scheme to also create entirely new B2B opportunities: an ecosystem of intermediary service providers (data aggregators, analytics providers, etc.) who will help small businesses make sense of imported data. A new market of data-enabled service providers would grow, serving as vendors to SMEs (much like fintech APIs serve smaller banks or merchants today). Fabric is a Smart Data platform and we view the upcoming Smart Data scheme as an opportunity larger in scale than Open Banking. It would make the UK the most exciting market for us and other innovative data startups. A well designed Smart Data scheme should ensure proportionate measures so that small and micro businesses aren’t unnecessarily encumbered particularly if they don’t hold substantial amounts of user data.

Do you have an initial or provisional view on the likely impacts (positive and negative) on:

Innovation: We expect rapid innovation especially in areas like AI-powered applications (e.g. personalised digital assistants) once developers can safely incorporate rich user data (with consent) into their products. The UK’s Open Banking experience shows how data-sharing led to the development of hundreds of new financial apps (budgeting tools, alternative lenders, payment initiators, etc.) that were not possible before. The pace of innovation will likely accelerate in digital markets, because these markets move even faster and touch every aspect of life (social, shopping, entertainment, productivity). The availability of cross-platform data means consumer services can be smarter, for example, a travel app that automatically plans a trip based on your Amazon purchase history and Instagram photos, or an AI health coach that uses your grocery orders, fitness app data, and YouTube viewing habits to give personalised advice. Many such ideas have been blocked by lack of data access. Fabric’s goal as a Digital Markets Smart Data platform is to enable thousands of new, context-rich applications for consumers.

Competition: We expect competition in digital markets to increase substantially as a result of the scheme. When users can move their data or share it with alternative providers, the barriers to switching services decrease. This undermines the “data network effects” that often lock users into a few dominant ecosystems. However, we do not recommend making this the primary goal of a digital markets Smart Data Scheme, as this will result in a scheme that is too narrowly scoped, lacking in ambition, and too dependent on other factors for being successful.

Business investment and economic growth: The UK’s tech market exceeds £1 trillion and is one of the largest in the world. By lowering the barrier for access to rich consumer data, the UK would create an attractive environment for a new category of data-driven startups serving new consumer use cases. Similar to how fintech boomed post Open Banking, we expect to see increased venture capital interest in companies building services on top of Smart Data. Our personal experience raising millions in weeks from top Silicon Valley investors post DMA demonstrates the value of a regulatory “why now” moment. A comprehensive Smart Data scheme will accelerate Fabric in becoming the global Smart Data platform of choice and attract substantially more investment. Our goal is to help incubate thousands of new consumer applications built on top of rich consumer context, unlocking tens of billions in value. The government itself has estimated that open data initiatives (like Open Banking and Smart Data) could significantly boost the economy. The Department for Business and Trade projected that such schemes have the potential to increase UK GDP by £28 billion over coming years. The Open Banking ecosystem alone is now valued at over £4 billion and has attracted substantial investment, creating ~5,000 jobs in the UK. A Smart Data scheme in digital markets, which touches an even larger portion of the economy, could have a correspondingly larger impact on investment and employment in the tech sector.

What challenges and risks should we consider when developing a digital markets smart data scheme and how can we mitigate these? This might include (but is not limited to): competition; customer exclusion; data quality or data misuse; ethical, operational or technical readiness.

Data Misuse and Privacy/Security Concerns: Opening up data sharing channels could lead to misuse of personal data or security breaches. However, this is a manageable risk by enforcing compliance with standards like CASA (similar to Google’s approach when granting DMA API access) and encouraging companies to be compliant with international standards like SOC and ISO. However, these need to be used proportionally considering the limited resources available to smaller companies so they are not used as a tool to restrict access. For e.g. Fabric is SOC 2 Type 1 compliant voluntarily and a recipient of personal data from multiple gatekeepers, however, Amazon demands SOC 2 Type 2 compliance to deny access (in addition to not making its API available in the UK, and responding to emails with over a month’s delay). In practice, thousands of companies share user’s personal data between each other frequently without asking for the user’s consent or being transparent about the nature of data sharing. The justifications for these transfers are buried in privacy policies and often justified by legitimate interests. The introduction of effective portability tools will introduce a level of sophistication in data sharing where specialised intermediaries can faciliate user consented data sharing, over time replacing the need for companies to resort to non-transparent data use.

Business Model Agnosticity: Creating a successful data ecosystem will give rise to wide ranging businesses focusing on consumer use cases, intermediation, enrichment, etc. Therefore, it’s important to ensure protection of diverse business models by default. Considering the diverse nature of digital markets data, there is a need for specialised third parties in the ecosystem (like with Open Banking) which enable consumer companies to use digital data. For such parties (including Fabric) to exist, build successful businesses, and attract venture capital investment, we need strong legal protections (particularly around wide ranging business models e.g. legal protection on data use with a degree of business model agnosticity).

What are the potential implementation costs to industry of introducing a digital markets Smart Data scheme? What aspects of a scheme might be most expensive to implement?

Data holders will need to build or upgrade technical infrastructure to provide APIs or data interfaces that meet the scheme’s requirements. However, many moderate and large data holders offer Download Your Information tools (and sometimes basic APIs) already. While the scale of costs will range substantially depending on the data holder and should be discussed directly with them, for companies that already have some form of data export tools, this cost is moderate (largely adapting existing systems). It’s worth noting that the largest players are either already under scope from similar regulations (e.g. Digital Markets Act) or provide Download tools as part of other compliance (e.g. GDPR) or as a trust building exercise.

How can we build and maintain customer trust in a digital markets Smart Data scheme? For example, what responsibilities need to be considered for data owners and ATPs?

Responsibilities of Data Holders: Data holders need to provide secure, transparent, and clear authorisation mechanisms. When a user is asked for data access by a third party, the data holder’s interface (e.g., an authentication screen on a social media platform) should mainly focus on authentication and authorisation rather than including consent mechanisms and to some extent scope selection, which should take place on the third party application’s side. There should be no misleading warnings or “dark patterns” that confuse users including unnecessarily hampering the authorisation experience. Providing deep links to avoid unnecessarily complex user journeys is required. Some early DMA implementations are overly complex (for instance, Booking dot com requiring users to copy and paste URLs manually into a different experience, Google displaying multiple warning screens in the experience). Ensuring the accuracy and completeness of data is another responsibility which is not being observed by many platforms under the DMA, given the differences in the data collected by each platform and the enforcement nuances. Finally, providing SLAs and uptime guarantees would be desirable.

Responsibilities of Accredited Third Parties (ATPs): The third-party service providers receiving user data carry the primary responsibility for using it ethically and securely. Desirable ATP conduct is covered substantially by data protection law including GDPR. To maintain consumer trust, ATPs should observe standards on data handling and proactively obtain security verifications like those provided by CASA, SOC, and ISO. This includes implementing state-of-the-art security on their systems (encryption of data, strong access controls so that only necessary personnel or processes can access raw personal data, regular security testing, etc.). As already covered by data protection regulations, ATPs should provide users with accessible privacy policies, terms of service, data revocation requests, and observe data minimisation principles.

What common principles are needed to support the development of a digital markets smart data scheme and why?

User-Centric Control: The scheme must be designed around the consumer’s interests and agency. Users should always be in the driver’s seat, meaning data is only shared at their explicit request (opt-in consent) and they can manage or revoke access easily at any time. This principle ensures that Smart Data doesn’t become a backdoor for involuntary data flow; it’s the customer’s right being exercised. A user-centric approach also implies intuitive design: tools should be easy to find and use for ordinary users (as Microsoft noted while it was involved in the Data Transfer Project, portability tools should be “easy to find, intuitive to use, and readily available”). The process should empower users, not overly worry them.

Privacy and Security by Design: Protecting personal data is non-negotiable. All systems and processes in the scheme should implement privacy and security from the ground up. This includes data minimisation (only sharing the data necessary for a given service, and nothing more) and robust security measures (encryption, secure authentication, access controls etc.). Any company wishing to maintain a loyal and growing customer base, a strong reputation, external investment, and consistent revenue growth will be strongly incentivised to make significant ongoing investments in this aspect of the business.

Interoperability and Common Standards: To maximise the scheme’s effectiveness, compatibility across different data sources is crucial. This principle means developing common standards (data formats, API protocols, authentication methods) either directly or via intermediaries. Industry efforts e.g. Data Transfer Project was founded on this idea, aiming to encourage broad participation through standard tools. Common standards also reduce costs in the long run, as companies and developers can reuse code and knowledge across multiple connections.

Are there any tensions, overlaps, gaps or other features of the regulatory landscape in digital markets that the Government should take into consideration?

Avoiding International Fragmentation given EU’s Digital Markets Act: Many of the largest digital markets companies (Google, Meta, Amazon, Apple, LinkedIn, TikTok, Booking etc.) are already under portability obligations in the EU via the DMA. The UK is no longer under the EU regime, which means there is a regulatory gap. Some companies have not extended their DMA compliance to UK users. For example, LinkedIn and Amazon implemented data portability APIs for the EU only, explicitly excluding UK residents. To minimise compliance burdens and expedite implementation, the UK scheme should consider closely aligning technical requirements with the DMA, so that companies can reuse the solutions they built for Europe. Regarding coverage, the UK should go broader than the DMA in scope (since DMA only covers nominated ‘gatekeepers’ above huge thresholds). The UK scheme should be wider in data and platform scope.

Scope Criteria and Perception of Targeting (Domestic vs Foreign firms): If scope is too narrowly defined (e.g. only the largest global tech firms), the scheme could be politically perceived as just targeting foreign (mostly US) companies. While it’s true many key digital platforms are US incorporated, a UK Smart Data scheme should not be set up in a way that could be perceived as an anti-US tech measure. This argues for scope that includes a diverse set of companies. For instance, notable European or UK-based digital firms that meet reasonable thresholds e.g. Spotify, Booking.com, Zalando and other large UK online services. The DMA’s quantitative thresholds (€7.5 billion turnover, 45 million users) are very high and ended up designating large US companies plus one or two others. The UK should set reasonable thresholds and qualitative criteria that capture services important to consumers even if the company isn’t mega cap. We have outlined a possible self nomination approach that would cover companies that might be widely used but not massive in revenue, or vice versa, ensuring no important data source is missed. The DMA’s concept of an ‘emerging gatekeeper’ which might need to meet proportionate obligations is a qualitative criteria that the UK scheme can also adopt, given the pace of new consumer AI platform adoption.

Data Sharing Fees and Monetisation Rules: A current topic of debate is whether data holders should be allowed to charge for access to data. Under most existing data portability regimes (GDPR, DMA, Open Banking), the data holder must provide data free of charge to the consumer or their authorised third party (aside from some nominal fees for excessive or repeat requests). This is meant to reduce friction and acknowledge that the data belongs to the user while also creating the conditions for innovative startups to flourish and develop new markets with reduced financial pressures. However, there have been moves by industry, notably in the US, to introduce fees for data access. For instance, JP Morgan announced plans to charge fintech aggregators for API access to customer financial data, which fintechs criticised as “a tollbooth on data” that would harm competition. This further led to Visa pulling out of US Open Banking in favour of high potential markets like Europe and Latin America. In the UK scheme context, allowing platforms to charge ATPs for data (or charge users) would likely stifle the emerging ecosystem. Startups might not afford the fees, costs would be passed to consumers, and the incentive for incumbents would be to set high prices to discourage switching. By comparison, the DMA explicitly forbids gatekeepers from charging users or third parties for portability services. The UK could adopt the same stance for parity. After the ecosystem matures (~10 years in the case of Open Banking), the Government should review if cost recovery is required for sustainability, but initially, free access will encourage maximal participation and innovation. Ideally, in time, data portability tools will become so widespread and available by all major platforms that charging becomes a moot point, particularly as by this point such functionality will be expected or demanded by users.

What data sharing initiatives already exist in digital markets that the Government should be aware of when evaluating a Smart Data scheme in digital markets?

There are several relevant data-sharing initiatives and precedents that the Government should be aware of, as they provide useful building blocks for a Smart Data scheme in digital markets:

Data Transfer Project (DTP): The Data Transfer Project is an open-source collaboration launched in 2018 by major tech companies including Google, Meta, Apple, and others. Its goal is to develop common frameworks and tools to enable direct, service-to-service data portability for consumers. DTP provides open-source code and defined standards for transferring data types like photos, mail, contacts, and more between platforms. For example, it has powered features like Facebook photo transfers to Google Photos.

Open Banking (UK and international): Open Banking in the UK (under the Payment Services Regulations 2017 and CMA Order) is often cited as the gold standard of Smart Data in action. It created a secure API ecosystem for banking data (payments accounts) that now serves over 10 million users and has led to hundreds of new fintech services. Additionally, globally, Open Finance is extending these principles to investments, insurance, etc., and Open Data initiatives are picking up in other countries (Latin America, Asia). In short, Open Banking provides a template and proof that Smart Data can work at scale, as long as security and user needs are prioritised.

EU Digital Markets Act (DMA) Portability Provisions: As discussed, the DMA (effective 2024) requires designated gatekeepers to provide continuous and real-time portability of user data (Article 6(9) of the DMA) for a range of core platform services. This has resulted in new APIs or tools from Google, Meta, Amazon, Apple, Microsoft (LinkedIn), ByteDance (TikTok), and Booking. The Government should note what data is covered: for example, Google’s DMA APIs cover search queries, clicks, page visits, YouTube history, Chrome MyActivity, Maps history etc.; Facebook covers a user’s social graph, interactions, content etc. The DMA defines a baseline of user and platform generated data categories that should set a floor for the UK scheme. Being aware of DMA’s specifics will allow the UK to create a scheme that covers companies already compliant in EU and creates a framework that improves upon it by learning from the DMA’s recent enforcement actions.

Data Portability Tools by Individual Companies (beyond DMA): Some digital markets companies have built minimal user data export tools. Meta, Google, Twitter, LinkedIn, TikTok, Snapchat, Spotify, Reddit, Discord, Uber, Airbnb, Netflix, OpenAI etc. allow users to download an archive of their data which takes anywhere from a few hours to a month. While companies like Pinterest, Spotify, and Strava make some programmatic transfers of user data possible in the UK via APIs, there are substantial roadblocks in place that limit the use of these APIs for data portability and user empowerment (e.g. legal guarantees, service level agreements, uptime guarantees, standardisation, business model protection). These restrictions deter companies from making use of these tools and limit the ways in which their users can utilise their own data.

Brazil’s Data Monetisation Pilot (dWallet): Brazil is launching a pilot known as dWallet, which will allow citizens to not only control but monetise their personal data via a data savings account. This is backed by a draft law proposing that individuals have property rights in their data and can receive compensation when businesses use it. While this goes beyond simple portability (it’s an attempt to restructure the digital economy’s value exchange), it’s an important initiative to watch. The pilot will start with payroll loan data and see how people can earn interest or income from sharing that data. For the UK, this raises interesting questions for the future: should a Smart Data scheme eventually enable consumers not just to share data for free services, but potentially be rewarded for sharing data? There is growing global conversation about “data dividends”. However, there are concerns too, Brazil’s example has critics warning that vulnerable or less-educated individuals might be exploited (selling access without understanding consequences). The UK might take a more nuanced approach, focusing first on access and innovation rather than monetisation.

What lessons should we bear in mind from Open Banking that would be helpful to consider when developing a digital markets Smart Data scheme?

Demonstrate Clear Consumer Value to Drive Adoption: Open Banking was successful because it unlocked very tangible consumer benefits (e.g. easier loan affordability checks, automated budgeting, better savings rates through aggregation of accounts). Even so, consumer adoption was initially slow until compelling use cases emerged and awareness grew. For Smart Data in digital markets, it’s crucial to identify and possibly even catalyse killer use cases early on i.e. services that truly make life easier or better for consumers using their cross-platform data. The examples from earlier (personal AI assistants, AI shopping experiences, AI travel apps etc.) would help consumers see the value in sharing their data immediately. Open Banking taught us to focus on consumer outcomes (money saved, time saved, improved decisions) in communication and design. Open Banking’s adoption curve turned upward as trust grew and people heard success stories; similarly, proactive outreach (perhaps including government-run pilots or challenges to develop useful apps) can help jumpstart usage.

Minimise Friction in User Experience (especially as dealing with multiple accounts): One pain point observed in Open Banking is that connecting multiple bank accounts to an app can be tedious as each account requires a separate authentication journey. In digital markets, an average user has many more accounts (dozens of apps/platforms). A user approving +10 data connections separately to use each new service is entirely unreasonable. Relatedly, given the number of possible data connections, having clear and streamlined consent experiences is critical (e.g. comparing Pinterest or TikTok’s streamlined consent experiences with Booking’s consent experience showcases how critical user experience is). Open Banking also provided for persistent consent (with current reauthentication periods at 90 days in the UK and 180 days in Europe) which from our personal experiences both as a user and builder of fintech applications is far too short and when combined with the number of digital markets data sources would seriously undermine the consumer experience under a Smart Data scheme. By comparison, most DMA platforms provide for a one year authentication with Meta providing for a 3 year authentication.

Standardisation vs. Diversity of Data: One challenge that is much greater for digital markets than for banking is the heterogeneity of data types. In banking, the data was fairly uniform (transactions, balances, payee info, etc.) making standardisation achievable. Digital platforms differ substantially so will need a more modular or flexible approach. We should expect to iterate and improve data standards for digital Smart Data as we learn from real world usage. Standardisation won’t be possible from the beginning but implementing early and refining over time will be.

Importance of Ecosystem Stimulation and Engagement: Open Banking didn’t automatically result in great products, the ecosystem had to be nurtured. The OBIE and others organized hackathons, provided sandboxes, did outreach to fintech developers, and ensured there were proper testing tools. For digital Smart Data, engaging developers and entrepreneurs early will help ensure the scheme results in useful services. The lesson is to provide tools and support.

What lessons should the Government bear in mind from the EU DMA and other Smart Data schemes in other jurisdictions including the establishment of Open Banking schemes around the world?

Enforcement and Compliance: One clear lesson from the EU DMA is that simply requiring something in law is not enough; active enforcement is needed to ensure meaningful compliance. As noted, each of the big gatekeepers did roll out data portability tools to meet the DMA obligations, but early assessments found most tools lacking in usability or completeness. For example, some required very frequent re-authentication or were limited to narrow types of data. Regular feedback from industry participants and the European Commission has led to steady improvements which still have a long way to go. The UK should be prepared to closely supervise delivery of high-quality implementations, not just minimal checkbox compliance. It is reasonable to build in a review phase: e.g. 3-6 months post launch to evaluate the effectiveness of data flows and propose fixes. Another DMA lesson is to set clear implementation guidelines upfront if possible: the ambiguity in the DMA allowed gatekeepers to start with half measures. The UK can learn from that by providing more detailed guidance or standards (potentially using what the EU has learned from the DMA and what the UK and EU have learned from Open Banking to define what effective portability means, e.g. continuous access, reasonable authentication durations, simple ATP driven reauthentication etc.). On the positive side, the DMA shows that large platforms can technically implement portability in a relatively short timeframe (months, not years). The DMA’s success in creating API access provides a precedent the UK can point to.

Preventing Dark Patterns in User Experience: Relatedly, the EU experience (and others) show that companies might introduce substantial frictions to dissuade data sharing which is particularly problematic for a digital markets Smart Data scheme as the number of data holders a user interacts with is much larger. It’s a form of “dark pattern” if a user wants to share data but the platform makes it confusing or scary e.g. through multiple warning pop-ups. The UK should consider a framework to prevent this, for instance requiring that any in-app authorisation flow be neutral in tone, equally easy to approve as to cancel to ensure that patterns like Booking’s URL copy paste should not be possible. Getting multiple data sharing notifications per platform is another example of a UX dark pattern: e.g. in the case of Google, 2 emails per scope when initiating the transfer. If we request 5 scopes like Search, Shopping, YouTube, Maps, Google Play, users receive 10 emails informing them about the data download. In the case of Meta, users get a daily notification informing them about the transfer.

Trust Registry and Verification: Integrating with multiple data providers under the DMA with each provider having arbitrary approval criteria creates a non-transparent process which will create significant challenges to a successful digital markets Smart Data scheme. For e.g. Fabric is approved individually by multiple gatekeepers, is SOC 2 and CASA certified, and is listed in the DTI Trust Registry, but Amazon insists on a completely separate process and criteria to other gatekeepers taking weeks to respond to each email. Booking arbitrarily declined Fabric’s application but upon explaining that Fabric is approved by multiple gatekeepers, decided to grant our application without requesting any changes. Even more importantly, we believe there is a need for strong verification by a Government body in order to prevent bad actors (e.g. hostile states) from accessing end user data under false pretences. Similar to the UK Open Banking Directory, there is a need for an industry body to run a joint trust framework so intermediaries seeking to serve businesses by providing a unified API through a single connection can reliably faciliate data portability while guaranteeing the safety of user data. This does not mean that companies/intermediaries bypass the individual gatekeeper registration and integration but rather that there is a transparent process through a joint framework that increases consumer and business trust in the ecosystem. The DTI’s Trust Registry is an industry backed initiative and an excellent step in that direction. Given there are cross-jurisdiction dynamics in play, the DTI could help faciliate alignment between the UK and European verification processes.

Avoiding Gaps in Scope and Thresholds: The DMA covered only the largest gatekeepers and thus left out many services that, while smaller, are still significant to consumers. For example Spotify is not a DMA gatekeeper, yet it holds valuable personal data (music tastes, listening history) and could be very useful in a Smart Data context (for instance, a dating app that matches people partly based on music compatibility). If the UK scheme only mirrored DMA’s scope, it would miss such opportunities. So, a lesson is to set inclusive criteria. The DMA’s fixed criteria were swift for identification but limited. The UK should adopt a hybrid approach: reasonable, quantitative thresholds plus the ability to designate additional companies (or allow voluntary participation). It should ensure that the scheme covers categories like AI services, smaller but growing platforms given the scale of AI adoption, and ensures sufficient non-US companies.