Data And Regulation
From the Digital Omnibus to India's Privacy Law: Global Data Governance Shifts Gears in Tandem, Rewriting the Compliance Cost Structure of the Platform Economy
In November 2025, the EU Digital Omnibus proposal, the second phase of the UK’s DUAA taking effect, India’s first digital privacy law coming into force, the UK Cyber Security Bill entering Parliament, and China’s revised Cybersecurity Law set to take effect in 2026—global data governance is shifting gears simultaneously across five main tracks, and the compliance costs of the platform economy, the boundaries of data assets, and the rules for cross-border flows are being redefined.
Introduction
In November 2025, global data and cybersecurity governance advanced simultaneously along five main tracks. On November 19, the European Commission released the "Digital Omnibus" regulatory proposal, which plans to amend the GDPR, the ePrivacy Directive, the Data Act, the Data Governance Act, the NIS2 Directive, and the AI Act in parallel, with the goal of simplifying existing laws, unlocking room for innovation, and maintaining a high standard of protection. In the UK, the second phase of the Data (Use and Access) Act 2025 (DUAA) has gradually come into force, with digital verification services taking effect first, while many core data protection amendments are expected to take effect in early January 2026. On November 13, India officially published the Digital Personal Data Protection Rules, 2025, launching the phased implementation of its first comprehensive digital privacy law. During the same period, the UK's Cyber Security and Resilience (Network and Information Systems) Bill was submitted to Parliament; China's revised Cybersecurity Law will take effect on January 1, 2026, and the Measures for the Administration of Cybersecurity Incident Reporting came into effect on November 1.
This is not scattered compliance news. For any company that relies on cross-border data flows, AI training corpora, and platform user scale, this is a wholesale shift in the underlying rulebook.
Event Background: Five Regulatory Tracks in One Month
EU: Digital Omnibus Tries to "Subtract" from the GDPR and the AI Act
On November 19, the European Commission released the Digital Omnibus package, covering data, AI, and cybersecurity legislation. The proposal introduces substantive amendments to the GDPR, the ePrivacy Directive, the Data Act, the Data Governance Act, the NIS2 Directive, and the AI Act. The core logic is to simplify compliance processes, reduce corporate burdens, and accelerate innovation while not lowering protection standards.
It must be emphasized that all details will take effect only after trilogue negotiations among the EU institutions. This means that over the next 12 to 24 months, EU data and AI rules will be in a state of "changing while being negotiated," and companies' compliance roadmaps must leave room for adjustment.
UK: DUAA Phase 2 Lands, Digital Identity First
DUAA is being advanced in four phases. On November 17, Sections 89 and 90 came into force, concerning joint processing of personal data for law enforcement purposes and between intelligence agencies. On November 19, the Data (Use and Access) Act 2025 (Commencement No. 4) Regulations 2025 were made, bringing Part 2 of DUAA (digital verification services) into force from December 1, except Sections 45 to 48 (sharing of information by public authorities with registered digital verification service providers).The key lies in the timing: regulators expect DUAA’s main data protection amendments to come into force in a cluster in early January 2026. This means that while the EU advances its amendments, the UK will independently complete its own institutional upgrade path.
India: First Digital Privacy Law Implemented, with an 18-Month Transition Period
On November 13, India officially notified the Digital Personal Data Protection Rules, 2025, to operationalize the Digital Personal Data Protection Act, 2023. This is India’s first statute comprehensively regulating the processing of digital personal data; it adopts a principles-based approach and is implemented in phases:
- The Data Protection Board (DPB) and its operating procedures take effect immediately;
- Consent Managers obligations start after 12 months. These regulated intermediaries are responsible for helping individuals give, manage, review, and withdraw consent, and must register with the DPB, operate independently, and have security safeguards in place;
- Core compliance requirements (consent notices, security safeguards, data retention, children’s data, and processing restrictions) take effect after 18 months, i.e., on May 13, 2027.
Other key points include: mandatory minimum security standards, encryption, and access controls; data breaches adopt a two-stage reporting mechanism, requiring simultaneous notification of affected individuals and the DPB, as well as a detailed follow-up within 72 hours of becoming aware; large platforms must delete user data after three years of inactivity, while all Data Fiduciaries must retain at least some data for one year; processing children’s data requires parental consent, with limited exemptions in the healthcare and education sectors; the government may designate “Significant Data Fiduciaries” (SDFs), impose annual impact assessment and audit obligations, and restrict certain cross-border data transfers. The maximum fine for serious violations is 250 million Indian rupees (about US$30 million).
The scope of application is noteworthy: it covers not only data processed within India, but also processing carried out outside India that relates to providing goods or services to individuals in India.
UK Cybersecurity Bill: NIS Regime Upgrade
On November 12, the UK Department for Science, Innovation and Technology introduced the Cyber Security and Resilience (Network and Information Systems) Bill to Parliament. The backdrop is a significant rise in cybersecurity threats—over 600,000 UK businesses were affected by cyberattacks in the previous financial year, and several major incidents dealt a blow to the national economy.
The bill updates and expands the Network and Information Systems Regulations 2018, introducing new obligations to identify and manage cyber risks, mandatory incident reporting obligations to regulators and affected customers, and strengthening regulators’ investigative and enforcement powers. The maximum fine is raised to £17 million or 4% of global turnover. Its scope covers organizations providing relevant services in the UK, regardless of where they are established: operators of essential services such as energy, transport, health, and water; data center providers; digital service providers such as cloud computing, online marketplaces, and search engines; managed service providers; and critical suppliers in the aforementioned sectors.It is worth noting that the EU has completed its own NIS upgrade, forming NIS 2. Since then, the UK and the EU have evolved separately in the field of cybersecurity.
China: Dual-Track Tightening in Legislative Amendment and Incident Reporting
In November, China presented two parallel threads. First, the amended Cybersecurity Law will take effect on January 1, 2026, significantly increasing penalties for violations; the maximum fine for violations related to critical information infrastructure will rise to RMB 10 million (approximately GBP 1.074 million), and compliance and enforcement risks will rise accordingly. Second, the Measures for the Management of National Cybersecurity Incident Reporting came into effect on November 1, 2025.
Enforcement and Litigation: Two Rulings That Carry Signaling Significance
The European Court of Justice (ECJ) ruled that in direct marketing scenarios, the ePrivacy Directive takes precedence over the GDPR. This directly affects marketing technology chains that rely on email, SMS, and programmatic outreach. On the other hand, the UK Financial Conduct Authority (FCA) has brought a criminal prosecution against an employee who sold customer personal data, indicating that regulation is extending from "fining institutions" to "pursuing individuals."
Digital Economy Analysis: What Does the Regulatory Gear Shift Mean?
First, compliance is shifting from a cost item to an architectural variable. As the EU discusses simplification, the UK advances digital verification services, and India establishes a consent manager regime, the regulatory focus has shifted from "whether collection is lawful" to "how data is governed across its full lifecycle." This directly determines the design boundaries of enterprise data architecture.
Second, data retention and deletion rules are beginning to carry financial implications. India requires large platforms to erase data of users inactive for three years, while also requiring data fiduciaries to retain at least some data for one year. This combination of a "ceiling + floor" effectively brings storage costs, the availability of training corpora, and user re-engagement capability into the regulatory framework at the same time. For systems that use historical behavioral data to drive recommendations and advertising, this is a structural constraint.
Third, cross-border data flows are entering a phase of differentiated pricing. India imposes cross-border transfer restrictions on significant data fiduciaries, the EU is amending the Data Act and the Data Governance Act, the UK is establishing an independent regime, and China continues to strengthen cybersecurity and incident reporting. The "comply once, reuse globally" model of multinational companies is failing, and instead they need to build switchable data processing pipelines by jurisdiction.
Fourth, penalties and individual liability are converging. The UK bill raises the maximum fine to 4% of global turnover, aligning with the GDPR's scale; China raises the maximum fine; the FCA pursues individual accountability. Compliance risk extends from corporate financial statements to personal risk for management and key positions.
Business Model Observation: Compliance Is Becoming a Product
In this round of regulatory restructuring, the most noteworthy business signal is: regulatory obligations themselves are generating new product forms.Part 2 of the UK DUAA institutionalizes “digital verification services,” meaning identity verification has shifted from an internal enterprise capability to a service market with regulated market access. For cloud service providers, identity technology companies, and payment institutions, this is an embeddable compliance infrastructure layer.
India’s “consent manager” regime is more direct: regulators explicitly require the establishment of regulated independent intermediaries responsible for giving, managing, reviewing, and withdrawing consent. This inserts a new market role between individuals and data controllers that must be registered and independently operated. It may evolve into a consent-layer infrastructure covering hundreds of millions of users—its value lies not in technology, but in the qualification and trusted status granted by regulation.
At the same time, the EU’s simplification orientation may reduce the administrative burden on some companies, but it will strengthen substantive requirements for high-risk scenarios. This means “compliance suites” will shift from audit reports to continuously operating engineering capabilities: data mapping, retention policy enforcement, incident response deadline management, and cross-border transfer controls. For SaaS and cloud vendors, this is a window of opportunity to upgrade from tool suppliers to compliance operations partners.
At the AI commercialization level, the AI Act has been included in the scope of Digital Omnibus amendments, indicating that the EU is trying to recalibrate between “promoting innovation” and “risk classification.” For companies that rely on the EU market to train and deploy models, regulatory uncertainty itself is a product roadmap risk—model iteration cycles are usually shorter than legislative cycles.
Market Competition Analysis: Who Benefits, Who Is Under Pressure
There are roughly three types of beneficiaries.
First, compliance infrastructure providers: identity verification, consent management, data mapping, incident reporting, and cybersecurity services. When regulatory requirements shift from “principles” to “verifiable processes,” procurement demand for these capabilities is inelastic.
Second, large cloud and platform companies with scaled compliance capabilities. The UK cybersecurity bill brings data centers, cloud computing, online marketplaces, search engines, and hosting service providers into regulatory scope; in the short term it is a burden, but in the long term it constitutes an entry barrier—small and medium competitors must bear the same obligations but lack the ability to amortize them.
Third, multinational companies that are first to complete architectural transformation. While competitors are still mapping data flows, companies that already have the ability to switch data strategies by jurisdiction can launch services faster in new markets.
The parties under pressure are equally clear.
Advertising and recommendation systems that rely on accumulated historical data face direct constraints from retention caps; companies that rely on cross-border transfers for centralized data processing need to rebuild regional architectures; overseas service providers that have not established compliance systems in India may fall within scope as long as they provide goods or services to individuals in India.From the perspective of platform competition, the EU revision and the UK's independent route run in parallel, in effect forming two mutually referencing but not fully compatible compliance systems; combined with India's and China's respective paths, the global digital economy is shifting from a "unified rules dividend" to "competition in multi-rule arbitrage and adaptation capability." The more modular one's architecture, the lower one's marginal compliance cost.
Data and Regulatory Impact: Three Structural Changes
Change 1: Consent shifts from an interaction design issue to an institutional infrastructure issue. India assigns this function to registration-based Consent Managers, and its impact may extend beyond India itself—if this model is borrowed by other emerging markets, regionalized standards may emerge at the global consent layer.
Change 2: Incident response deadlines become hard constraints. India requires detailed follow-up within 72 hours, the UK bill requires mandatory reporting to regulators and affected customers, and China implements measures for cybersecurity incident reporting. Together, the three point to one conclusion: security incident management must be an ongoing operational capability, not an emergency response plan document.
Change 3: Legal applicability priority is reconfirmed. The European Court of Justice ruled that in direct marketing scenarios the ePrivacy Directive takes precedence over the GDPR, reminding companies that compliance judgments cannot focus only on the main overarching laws; specialized rules for specific scenarios may have priority effect. Such precedents will reshape the compliance design of marketing technology stacks.
Global Trend Observation: Digital Sovereignty Enters the "Institutional Competition" Stage
Putting the five threads together, one can reach a long-cycle judgment: global digital governance has moved from the "rule convergence" stage into the "institutional competition" stage.
Through the Digital Omnibus, the EU attempts to find a new balance between protection and innovation while maintaining its position as a rule-maker; after Brexit, the UK independently builds its data and cybersecurity regime, covering digital verification services and an upgraded NIS; India uses its first digital privacy law to establish a domestic governance framework and, through Consent Managers and the Significant Data Fiduciary system, establishes regulatory levers; China uses the dual track of legislative amendments and incident reporting to strengthen the binding force of cybersecurity.
These are not short-term events, but underlying parameters of the digital economy for the next five to ten years. They determine not only whether companies can comply, but also where data is stored, where AI models are trained, and in what form platform services are delivered cross-border.
The practical implication for companies is that data governance budgets need to be reclassified from "legal spend" to "infrastructure investment."
DigitalEcoNews Insight
The most important economic significance of this batch of regulatory actions in November 2025 is not how many new obligations were added, but that the "operating system" of global data governance is being rewritten—and rewritten simultaneously by multiple jurisdictions.First, the asset attributes of data are being redefined. India requires large platforms to erase data on users inactive for three years while requiring data fiduciaries to retain it for at least one year. This combination of "deletable + must be retained" writes the time value of data into mandatory rules for the first time. For platforms that build recommendation and advertising models on long-term user behavior data, the stock of data they can accumulate will no longer be a curve of unlimited growth, but a finite resource whose slope is set by regulators. This will change the core variable of platform competition: from "who owns more historical data" to "who can use data more efficiently within the compliance window."
Second, compliance capability is becoming a product, not merely a cost. The UK's independent digital verification services market and India's registered consent managers are both market roles directly created by regulation. The commercial value of such roles comes from trust credentials, not technological leadership, and once they achieve scale, they may grow into a new infrastructure layer in the digital economy. For investment institutions, this is a track protected by institutional demand.
Third, the parallel existence of multiple jurisdictions means architecture determines competitiveness. The EU is simplifying, the UK is building independently, India is implementing in phases, and China is tightening, and the compatibility costs of these four systems are rising. The key capability for companies in the future is not "understanding a particular law," but "making data-processing architecture switchable by jurisdiction." The degree of modularity will translate directly into a marginal compliance-cost advantage.
Overall judgment: this round of rule restructuring will not end in 2026, but will continue to the end of this decade. In the short term, it raises compliance thresholds and lowers the marginal returns of data-driven businesses; in the medium term, by eliminating participants that lack architectural flexibility and compliance engineering capabilities, it redistributes market share in the platform economy. What truly deserves attention is not which company is fined today, but which company has already turned compliance capability into a product and an entry barrier.
Use note · digitalecononews
digitalecononews frames this note through Digital Markets / AI Economy / Platforms & Apps (Source URLs should be opened before the summary is reused). Digital Markets / AI Economy / Platforms & Apps explains the local editorial angle; dates, names and status changes still need checking.