Data And Regulation
EU data regulations reshape the digital economy: the global regulatory wave from GDPR to DSA.
In 2023, the EU densely implemented digital regulatory legislation such as GDPR, DSA, and DMA, accumulating fines of 2.92 billion euros. This article analyzes how these rules reshape platform business models, data value, and AI commercialization paths.
EU's New Data Regulations Reshape the Digital Economy: A Global Regulatory Wave from GDPR to DSA
Introduction
In February 2023, international law firm Gibson Dunn released the *International Cybersecurity and Data Privacy Outlook and Review 2023*, showing that fines under the EU General Data Protection Regulation (GDPR) have reached approximately €2.92 billion in total, while new regulatory tools such as the Digital Services Act (DSA), the Digital Markets Act (DMA), and the Data Governance Act are being rapidly implemented. This set of rules not only reshapes the EU digital market but also rewrites the competition rules of the global digital economy through mechanisms such as cross-border data flows, platform obligations, and AI governance. This article analyzes, from an industrial economics perspective, how this regulatory wave affects platform business models, data value, and AI commercialization paths.
Event Background
Since the GDPR took effect in 2018, EU regulators have continuously stepped up enforcement. According to the Gibson Dunn report, the largest single fine imposed by EU regulators reached €405 million, with cumulative fines totaling approximately €2.92 billion. In 2023, several key EU digital regulations entered their implementation phase:
- NIS 2 Directive (published on December 14, 2022): Requires member states to transpose it into national law by October 17, 2024, covering energy, transport, health, digital infrastructure, and other sectors, strengthening cybersecurity risk management and incident reporting obligations.
- Data Governance Act (adopted on May 30, 2022): Applicable from September 24, 2023, aiming to promote the reuse of public data and the development of data sharing intermediaries.
- Digital Services Act (DSA) (adopted on October 19, 2022): Most provisions apply from February 17, 2024, requiring platforms to address illegal content and disinformation, with fines up to 6% of global turnover for violations.
- Digital Markets Act (DMA) (adopted on September 14, 2022): Most provisions apply from May 2, 2023, targeting "gatekeeper" platforms, with fines up to 10% of global turnover, and up to 20% for repeat offenders.
- Digital Operational Resilience Act (DORA) (adopted on December 14, 2022): Applies to financial institutions and ICT third-party service providers, effective from January 17, 2025.
- Data Act (proposed on February 23, 2022): Aims to promote industrial data sharing and is still in the legislative process.
- Cyber Resilience Act (proposed on September 15, 2022): Sets cybersecurity requirements for digital products, with fines up to €15 million for violations.
At the international level, many countries are also advancing data protection legislation and enforcement. For example, Indonesia, Tanzania, and Oman have passed new data protection laws; China's Cyberspace Administration imposed a fine of RMB 8 billion on a leading ride-hailing platform under the Personal Information Protection Law, the Cybersecurity Law, and the Data Security Law, making it one of the highest fines in the Asia-Pacific region.## Digital Economy Analysis
These regulatory measures are not isolated legal actions, but a sign of the global digital economy shifting from "free growth" to "rule-based governance". Their economic significance lies in changing the pricing of data factors, the boundaries of platform power, and the availability of AI training data.
First, GDPR's high fines transform data compliance from a "legal cost" into an "operational barrier". Enterprises need to re-evaluate their data collection, processing, and storage processes, forcing data-intensive businesses to establish "privacy by design" mechanisms. This also gives rise to the PrivacyTech market, promoting new business models such as compliance-as-a-service.
Second, DMA and DSA directly target market failures in the platform economy. DMA prohibits gatekeeper platforms from self-preferencing and requires interoperability, breaking the moats formed by data monopolies and ecosystem lock-in. This creates entry points for small and medium-sized enterprises and innovators, but may also weaken the scale effects of platform networks, thereby affecting platform valuation logic.
The Data Governance Act and the Data Act attempt to activate the economic value of "data sharing". By establishing data intermediaries and reciprocal sharing rules, future data circulation may be traded like commodities, forming an emerging data factor market. But at the same time, data sharing may also trigger privacy risks and trade secret leakage, and regulators need to balance efficiency and protection.
In addition, these rules have deep implications for AI commercialization. AI model training relies on large amounts of data, and the legality and transparency of data sources will become core compliance items for AI companies. The EU's upcoming Artificial Intelligence Act (AI Act) will further refine data governance requirements for high-risk AI systems. Therefore, data rules are actually the underlying foundation of the AI economy.
Business Model Observations
Regulation is reshaping the way companies create value. In the past, tech giants relied on the flywheel effect of "collecting data - optimizing products - attracting more users". Today, GDPR's "data minimization" principle and DMA's "user consent" requirements directly impact this cycle.
- Advertising model: Targeted advertising relies on user profiling, and DMA requires gatekeepers to obtain explicit consent before processing personal data for targeted advertising. This will reduce the efficiency of ad delivery and push the advertising industry to shift toward contextual advertising and privacy-enhancing technologies.
- Subscription model: When users cannot be precisely tracked, more services may shift to subscription or hybrid models. For example, Meta's ad-free subscription package launched in the EU offers the option to "pay to avoid tracking", which may become a common template for platforms responding to regulation.
- Data intermediary model: The Data Governance Act encourages "data intermediaries" to operate as neutral third parties that do not use data for their own benefit but match data supply and demand. This creates new revenue streams, but profitability depends on scale.
- Compliance as a service: Facing complex regulation, companies rely on external experts, software tools, and cloud services for compliance management, which itself is a high-growth market.Business model innovation no longer relies solely on traffic monetization; instead, it turns compliance and transparency into differentiated value. For example, Apple emphasizes privacy protection as a brand selling point and restricts ad tracking, which in effect reshapes the power structure of the mobile advertising market.
Market Competition Analysis
The biggest impact of regulation is the redistribution of market power. The "gatekeeper" platforms defined by the DMA—typically large tech companies with core platform services—will face a series of "do's" and "don'ts" in terms of behavioral constraints.
- Google: Prohibited from self-preferencing in search results, which may weaken the traffic advantages of its vertical services such as shopping and maps. At the same time, interoperability requirements may make it easier for third-party search tools to access its data.
- Apple: App Store and Safari may be required to open up more interfaces. Although Apple has not yet been individually designated as a gatekeeper, the EU has listed it as a potential candidate.
- Meta: The DSA requires more proactive measures against disinformation, increasing content moderation costs; the DMA restricts its cross-platform data integration, affecting its advertising network.
- Emerging platforms such as TikTok: Although they are also subject to the DSA, because they are not traditional gatekeepers, they may gain a relatively favorable competitive position—especially while the EU reviews whether they meet the threshold for large platforms.
For challengers, the new rules lower entry barriers. For example, small social networks can demand interoperability with major platforms, reducing user switching costs. However, regulation may also create excessive compliance burdens, making legal costs harder for SMEs to afford.
In China, regulatory actions are likewise putting pressure on large platforms. The hefty fine imposed on a ride-hailing platform shows that data compliance has become a "must-answer question" for multinational and local Chinese companies alike, and compliance capability will determine whether they can gain market access.
Data and Regulatory Impact
From a governance architecture perspective, the EU is building a multi-layered "digital constitution": the GDPR regulates personal data, the DSA regulates content dissemination, the DMA regulates market competition, the Data Governance Act and the Data Act regulate the flow of non-personal data, while NIS2 and DORA strengthen cybersecurity. These regulations are interwoven, forming a complete system of digital rules.
For multinational enterprises, the biggest impact is cross-border data flows. After the Schrems II ruling, data transfers between the EU and the US rely on Standard Contractual Clauses (SCCs) and supplementary measures. The EU and US are negotiating a new "Data Privacy Framework" aimed at resolving the legality of US intelligence agencies' access to data. Without an adequacy decision, companies may face pressure for data localization, increasing operating costs.
In addition, the Data Act proposes allowing users to access data generated by connected devices, which could affect business models in the Internet of Things and the Industrial Internet. If device manufacturers respond appropriately, they may create new revenue through data services; otherwise, they may lose control over data.The uncertainty of the regulatory environment itself is also a risk. Enterprises need to establish a "regulatory intelligence" mechanism to track developments across global jurisdictions, because fines or bans in one country may affect their global operations.
Global Trends Watch
This wave of regulation is not unique to the EU. Brazil, India, Japan, South Korea, and others are all drafting or updating data protection laws. China has enacted the Personal Information Protection Law (PIPL) and the Data Security Law, and has demonstrated a tough stance in enforcement. Although the United States lacks a comprehensive federal privacy law, state-level legislation and FTC enforcement are also strengthening. Global digital regulation is exhibiting the "Brussels Effect" — EU standards often become global de facto standards, just as the GDPR has influenced legislation in places like California.
From a long-term perspective, digital sovereignty and supply chain security will drive more localization measures. Data localization requirements may fragment the global internet and increase compliance complexity for multinational enterprises. At the same time, AI regulation is accelerating; the EU's draft AI Act proposes tiered risk management, which will directly affect the cost structure for AI developers and users.
These trends indicate that the digital economy has entered an era where "compliance is competitiveness." Enterprises need to integrate law, technology, and business in order to sustain growth under the new rules.
DigitalEcoNews Insight
The intensive rollout of EU data regulations in 2023 marks the digital economy's shift from "traffic is king" to "trust is king." The cumulative €2.92 billion in GDPR fines is only the beginning; enforcement of the DSA and DMA will reshape platform power and economic value. For enterprises, data governance is no longer back-office compliance but a front-line strategy that determines whether business models can endure. In the future, data sharing mechanisms may give rise to new "data exchanges," and AI commercialization must be built on lawful data sources. We anticipate that over the next decade, enterprises that can navigate the complexity of regulatory compliance will gain competitive advantages, while the space for regulatory arbitrage will narrow significantly. Value creation in the digital economy will come increasingly from transparent, secure, and fair rules rather than from data monopolies.
Use note · digitalecononews
digitalecononews frames this note through Digital Markets / AI Economy / Platforms & Apps (Source URLs should be opened before the summary is reused). Digital Markets / AI Economy / Platforms & Apps explains the local editorial angle; dates, names and status changes still need checking.