Comparative Data Governance Systems .
Comparative Data Governance Systems
1. Introduction
Data governance refers to the legal, institutional, technical and organizational framework through which data is collected, processed, stored, shared, transferred, secured, retained and deleted, while assigning rights, duties and accountability to the persons and organizations handling that data.
It is broader than data protection.
- Data protection primarily focuses on protecting individuals from unlawful or unfair processing of personal data.
- Data governance additionally addresses data quality, ownership, stewardship, interoperability, cybersecurity, access, sharing, localization, cross-border transfers, public-sector use, artificial intelligence and institutional accountability.
A comparative study is particularly important because data routinely crosses national borders. The EU has developed a rights-oriented model centered on the GDPR and the fundamental right to data protection; India has adopted the Digital Personal Data Protection Act, 2023 and subsequently notified the DPDP Rules 2025 with phased commencement; the US uses a more fragmented sectoral model; Singapore follows a centralized statutory framework; and China adopts a stronger state-security and data-sovereignty-oriented model.
2. Meaning of Data Governance
A useful definition is:
Data governance is the system of rules, institutions, rights, responsibilities and technical controls governing the lifecycle and lawful use of data.
Its principal components are:
- Data collection
- Lawful processing
- Consent and authorization
- Purpose limitation
- Data minimization
- Data quality and accuracy
- Data security
- Data retention
- Individual rights
- Data sharing
- Cross-border transfers
- Government access
- Data localization
- Algorithmic use
- Accountability
- Remedies and enforcement
3. Data Governance vs Data Protection
| Data Protection | Data Governance |
|---|---|
| Protects personal data | Governs data generally |
| Primarily individual-rights focused | Individual + institutional + economic + public-interest focused |
| Privacy is central | Privacy is one component |
| Focuses on processing | Covers entire data lifecycle |
| Consent/legal basis important | Also includes standards, interoperability, security and access |
| Individual remedies important | Institutional governance equally important |
| GDPR is a major example | EU Data Governance framework is broader |
Therefore:
Data protection is a major component of data governance, but data governance is the broader concept.
4. Constitutional and Human-Rights Foundations
Modern data governance is increasingly constitutionalized.
The principal principles are:
1. Privacy
Individuals should retain meaningful control over information concerning them.
2. Dignity
Data processing should not reduce individuals to profiles or data points.
3. Autonomy
Individuals should have meaningful control over important uses of their data.
4. Equality
Data-driven systems should not produce discriminatory outcomes.
5. Freedom of expression
Data governance must not become a mechanism for unjustified censorship.
6. Due process
Individuals should be able to challenge consequential decisions based upon their data.
7. Security
Personal and institutional data must be protected against unauthorized access.
8. Accountability
Organizations should be able to demonstrate compliance.
5. Comparative Models of Data Governance
A. European Union — Rights-Based and Comprehensive Model
The EU is one of the most developed data-governance jurisdictions.
Its framework includes:
- General Data Protection Regulation (GDPR);
- Charter of Fundamental Rights;
- ePrivacy framework;
- Data Governance Act;
- Data Act;
- Law Enforcement Directive;
- AI Act;
- cybersecurity legislation.
The GDPR treats data protection as a fundamental right under Article 8 of the EU Charter and Article 16 TFEU. It provides extensive individual rights and independent supervisory authorities.
Core characteristics
- accountability;
- privacy by design;
- purpose limitation;
- data minimization;
- transparency;
- individual rights;
- independent regulators;
- cross-border regulatory cooperation;
- substantial penalties.
The EU therefore adopts a model that can be described as:
Fundamental rights + regulatory accountability + controlled data flows.
6. India — Rights-Based but Development-Oriented Model
India's principal comprehensive personal-data statute is the Digital Personal Data Protection Act, 2023 (DPDP Act).
The Act expressly seeks to regulate digital personal data while recognizing both:
- the individual's right to protect personal data; and
- the need to process data for lawful purposes.
The DPDP Rules 2025 provide implementation details and establish a phased commencement structure rather than making every provision operative simultaneously.
India's model is influenced by constitutional privacy jurisprudence, particularly Article 21, while also emphasizing India's digital economy and legitimate uses of data.
Principal institutions/concepts
- Data Principal;
- Data Fiduciary;
- Data Processor;
- Consent Manager;
- Significant Data Fiduciary;
- Data Protection Board;
- grievance mechanisms;
- security safeguards;
- breach notification.
7. Indian Constitutional Framework
The constitutional foundation comes principally from:
Article 14
Protects equality and non-arbitrariness.
Article 19
Protects freedoms potentially affected by data-driven censorship and surveillance.
Article 21
Provides the strongest foundation for privacy, dignity and autonomy.
Article 32 and Article 226
Provide constitutional remedies against unlawful State action.
The most important constitutional case is K.S. Puttaswamy v. Union of India.
8. United States — Sectoral and Market-Oriented Model
The United States does not have one comprehensive federal privacy statute equivalent to the GDPR.
Instead, governance comes from a combination of:
- constitutional law;
- federal statutes;
- state privacy legislation;
- sector-specific regulation;
- Federal Trade Commission enforcement;
- contractual principles;
- consumer-protection law.
Important federal statutes include legislation dealing with:
- health information;
- financial information;
- children's data;
- electronic communications;
- consumer reporting.
Several states have also adopted comprehensive privacy legislation.
Characteristics
The US model can therefore be described as:
Sectoral regulation + constitutional privacy + state experimentation + consumer protection.
9. Singapore — Centralized Regulatory Model
Singapore's Personal Data Protection Act (PDPA) establishes a comprehensive framework for personal-data protection in the private sector.
It emphasizes:
- consent;
- purpose limitation;
- reasonable security;
- access and correction;
- accountability;
- data-breach management;
- cross-border transfers.
Singapore attempts to balance:
privacy protection + innovation + economic use of data.
It therefore provides an interesting middle ground between the EU's stronger rights-based framework and the US's more fragmented model.
10. China — Sovereignty and Security-Oriented Model
China has developed a comprehensive data-governance architecture consisting principally of:
- Personal Information Protection Law (PIPL);
- Data Security Law;
- Cybersecurity Law.
China's framework places substantial emphasis on:
- national security;
- cybersecurity;
- data sovereignty;
- critical information infrastructure;
- cross-border transfers;
- governmental control;
- protection of personal information.
Consequently, China's model is significantly more state-security and sovereignty oriented than the EU model.
11. Comparative Table
| Feature | India | EU | USA | Singapore | China |
|---|---|---|---|---|---|
| Principal model | Rights + development | Fundamental rights | Sectoral/market | Centralized regulatory | Security/sovereignty |
| Comprehensive privacy statute | DPDP Act | GDPR | No single federal equivalent | PDPA | PIPL |
| Constitutional privacy | Strong | Strong | Fourth Amendment + other doctrines | Statutory emphasis | Statutory/state framework |
| Independent regulator | Data Protection Board framework | Strong DPAs | Fragmented | PDPC | State regulatory bodies |
| Consent | Important | One of several legal bases | Sector-dependent | Important | Important |
| Data localization | Government-regulated framework | Generally free flow within EU + controlled transfers | Sector/state specific | Controlled transfers | Stronger sovereignty orientation |
| Individual rights | Developing | Extensive | Fragmented | Extensive statutory rights | Extensive but state-security framework |
| Cross-border governance | Government restrictions/framework | Adequacy/SCCs/etc. | Sectoral | Transfer safeguards | Strong state control |
| Penalty approach | Statutory monetary penalties | High, including turnover-based fines | Statute-specific | Monetary penalties | Significant statutory penalties |
12. Important Case Laws
1. K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 — India
This nine-judge Constitution Bench recognized privacy as a fundamental right.
The Court connected privacy with:
- dignity;
- liberty;
- autonomy;
- personal choice;
- informational control.
The judgment established a proportionality-oriented framework for assessing restrictions on privacy. Subsequent Supreme Court decisions continue to treat informational privacy as part of Article 21.
Data-governance significance
Puttaswamy provides the constitutional foundation for asking:
- Why is data being collected?
- Is collection authorized by law?
- Is it necessary?
- Is it proportionate?
- Is the data being used for another purpose?
Principle
Data governance in India must operate consistently with constitutional privacy, dignity and autonomy.
13. Justice K.S. Puttaswamy (Retd.) v. Union of India (Aadhaar), (2019) 1 SCC 1 — India
The Aadhaar litigation considered the constitutional implications of large-scale biometric identification.
The Supreme Court examined:
- informational privacy;
- proportionality;
- surveillance concerns;
- data security;
- statutory authorization;
- State access to personal information.
The Court upheld some aspects while invalidating or restricting others.
Data-governance significance
Aadhaar demonstrates that large-scale government databases require constitutional safeguards, particularly when biometric information is involved.
Principle
Mass digital identity systems must satisfy legality, legitimate purpose and proportionality.
14. PUCL v. Union of India, (1997) 1 SCC 301 — India
The Supreme Court addressed telephone interception and laid down procedural safeguards.
The case is important because communications data can reveal highly sensitive information concerning:
- relationships;
- political activity;
- professional activity;
- personal life.
Principle
Government surveillance involving communications must operate within legally defined safeguards.
Data-governance significance
It demonstrates that State access to data is itself a constitutional-governance question.
15. Digital Rights Ireland Ltd v. Minister for Communications, Joined Cases C-293/12 and C-594/12 — CJEU
The CJEU invalidated the EU Data Retention Directive because the generalized retention of communications data seriously interfered with fundamental rights.
The Court examined Articles 7 and 8 of the EU Charter concerning privacy and personal-data protection.
Significance
The case established an important proportionality principle:
Large-scale data retention cannot be justified merely by invoking public security; the legal regime must contain adequate limits and safeguards.
This is a foundational European data-governance decision.
16. Schrems II — Data Protection Commissioner v. Facebook Ireland Ltd, Case C-311/18, CJEU
The CJEU invalidated the EU-US Privacy Shield framework while upholding the general validity of Standard Contractual Clauses subject to adequate safeguards.
The Court focused on:
- Articles 7 and 8 of the EU Charter;
- effective legal protection;
- governmental surveillance;
- cross-border transfers;
- adequacy of third-country protection.
Principle
Cross-border data transfers cannot be governed solely by commercial contracts where the receiving jurisdiction's legal system fails to provide adequate protection against governmental access.
Data-governance significance
The case demonstrates that:
Data governance does not stop at national borders.
17. Google Spain SL v. Agencia Española de Protección de Datos, Case C-131/12 — CJEU
The CJEU recognized circumstances in which individuals may require search engines to remove links to information concerning them from search results.
The case became closely associated with the right to be forgotten.
Data-governance significance
It established the importance of:
- informational autonomy;
- relevance;
- accuracy;
- proportionality;
- balancing privacy and freedom of expression.
Principle
Data governance must address not only how information is collected but also how it remains publicly accessible and searchable.
18. Big Brother Watch and Others v. United Kingdom, App. Nos. 58170/13, 62322/14 and 24969/15 — ECtHR
The Grand Chamber considered UK bulk interception and communications-data regimes.
It found violations of Article 8 concerning the bulk interception regime and obtaining communications data from communications service providers, and also found Article 10 violations in relevant aspects.
Data-governance significance
The case demonstrates that modern surveillance systems require:
- legal safeguards;
- independent oversight;
- limits on access;
- protection for journalism and expression.
Principle
Bulk data collection is not beyond human-rights scrutiny merely because it is technologically sophisticated.
19. Carpenter v. United States, 585 U.S. 296 (2018) — USA
The US Supreme Court considered government access to historical cell-site location information.
The Court recognized that long-term location information creates significant privacy concerns and required a warrant in the circumstances before it.
Data-governance significance
Location data can reveal:
- movements;
- relationships;
- religious activities;
- medical visits;
- political activity;
- professional associations.
Principle
Technological changes can require constitutional doctrine to adapt when new forms of data create qualitatively different privacy risks.
20. Riley v. California, 573 U.S. 373 (2014) — USA
The Supreme Court held that police generally need a warrant to search digital information stored on a cell phone seized during an arrest.
The Court emphasized the extraordinary quantity and sensitivity of information contained in modern mobile devices.
Data-governance significance
The case demonstrates that:
Digital information cannot always be treated like ordinary physical objects.
The constitutional significance of data depends on its volume, sensitivity and capacity to reveal intimate details of life.
21. Comparative Case-Law Table
| Case | Jurisdiction | Main issue | Data-governance principle |
|---|---|---|---|
| K.S. Puttaswamy v Union of India | India | Privacy | Informational privacy and dignity |
| Puttaswamy (Aadhaar) | India | Biometric database | Proportionality and data safeguards |
| PUCL v Union of India | India | Telephone interception | Surveillance safeguards |
| Digital Rights Ireland | EU | Mass data retention | Necessity and proportionality |
| Schrems II | EU | International transfers | Adequate protection in destination State |
| Google Spain | EU | Search engines | Erasure/information control |
| Big Brother Watch v UK | Europe | Bulk surveillance | Privacy and expression safeguards |
| Carpenter v US | USA | Location data | Digital privacy under Fourth Amendment |
| Riley v California | USA | Mobile-device data | Enhanced protection for digital information |
22. Lawful Basis for Data Processing
One of the most important comparative differences concerns why an organization is legally permitted to process data.
EU
The GDPR contains several lawful bases, including:
- consent;
- contract;
- legal obligation;
- vital interests;
- public task;
- legitimate interests.
The EU therefore does not make consent the universal basis for all processing.
India
The DPDP framework is structured differently, with consent and specified legitimate uses forming the central processing architecture. The Act expressly distinguishes lawful processing from the individual's right to data protection.
USA
The lawful basis is highly dependent upon the applicable sector and statute.
Singapore
Consent remains important, but statutory exceptions and deemed-consent mechanisms are also significant.
23. Individual Rights
Modern data governance commonly provides rights concerning:
Right of access
Individuals can ask what information is held about them.
Right of correction
Incorrect information can be challenged.
Right of deletion/erasure
In specified circumstances, data may have to be removed.
Right to object
Individuals can object to certain forms of processing.
Right to portability
Data can be obtained in a usable format and transferred in appropriate circumstances.
Right concerning automated decisions
Some legal systems provide protections where significant decisions are made through automated processing.
The EU provides the broadest and most developed bundle of these rights.
24. Data Governance and Consent
Consent is frequently misunderstood.
Valid consent should generally be:
- informed;
- specific;
- voluntary;
- understandable;
- capable of withdrawal.
A major governance problem arises where consent becomes:
"Take it or leave it."
If a consumer cannot realistically refuse processing while accessing an essential service, the quality of consent becomes questionable.
Therefore, good governance requires examining power imbalance, not simply whether a box was checked.
25. Data Minimization
Data minimization means:
Collect only data that is reasonably necessary for the stated purpose.
For example, a restaurant delivery service may require:
- name;
- address;
- contact information;
- payment information.
It generally does not need:
- unrelated medical history;
- political views;
- complete contact lists.
Data minimization reduces:
- privacy risks;
- cybersecurity risks;
- misuse;
- unauthorized secondary use.
26. Purpose Limitation
Information collected for one purpose should not automatically be reused for another incompatible purpose.
For example:
Original purpose: employee payroll.
New use: AI-based personality profiling.
The second use may require an independent legal justification.
Purpose limitation is therefore essential to prevent function creep.
27. Data Accuracy
Incorrect data can cause serious consequences.
Examples:
- incorrect credit score;
- inaccurate criminal record;
- mistaken employment profile;
- wrong medical information;
- erroneous AI risk score.
Therefore, data governance must provide mechanisms for:
- verification;
- correction;
- contesting automated classifications.
This is especially important when AI systems use historical datasets.
28. Data Security
Data governance must include appropriate technical and organizational safeguards.
These include:
- encryption;
- access controls;
- authentication;
- logging;
- pseudonymization;
- cybersecurity monitoring;
- incident response;
- backup systems;
- employee training.
Security is not merely an IT function.
It is increasingly a legal duty.
29. Cross-Border Data Transfers
Global businesses routinely transfer data between:
- India;
- Europe;
- USA;
- Singapore;
- China;
- other jurisdictions.
This creates a conflict between:
Free flow of data
Necessary for global commerce.
and
Data sovereignty
Governments may want sensitive information retained within their jurisdiction or subject to domestic safeguards.
Schrems II demonstrates how cross-border transfers can become constitutional/fundamental-rights issues.
India's DPDP framework also provides a mechanism under which the Central Government may restrict transfers to notified countries or territories.
30. Data Localization
Data localization means requiring certain data to be:
- stored domestically;
- processed domestically;
- transferred internationally only under specified conditions.
Arguments supporting localization
- national security;
- law-enforcement access;
- sovereignty;
- economic development;
- protection against foreign surveillance.
Arguments against excessive localization
- increased costs;
- reduced innovation;
- fragmented digital markets;
- duplication of infrastructure;
- restrictions on international commerce.
The ideal system therefore attempts to balance:
data sovereignty + legitimate international data flows.
31. Government Access to Data
One of the most difficult issues is government access.
Government may require data for:
- national security;
- criminal investigation;
- taxation;
- welfare administration;
- public health.
But unrestricted access can threaten:
- privacy;
- freedom of expression;
- political participation;
- journalism;
- professional confidentiality.
Cases such as Digital Rights Ireland, Big Brother Watch, Carpenter, PUCL and Puttaswamy demonstrate the need for legality, necessity and proportionality.
32. Data Governance and Artificial Intelligence
AI makes data governance more complicated because AI systems depend upon:
Data → Training → Model → Inference → Decision
Potential problems include:
- biased datasets;
- unlawful collection;
- copyrighted data;
- sensitive personal information;
- inaccurate outputs;
- profiling;
- automated decision-making;
- re-identification.
Thus:
Effective AI governance is impossible without effective data governance.
33. Data Governance and Big Data
Big-data systems create three major problems.
Volume
Massive quantities of data are collected.
Variety
Data may include:
- text;
- photographs;
- location;
- biometric information;
- transactions;
- health information.
Velocity
Data is collected and processed continuously.
The legal challenge is that traditional consent models may not fully address continuously evolving uses.
34. Data Governance and Children
Children require enhanced protection because of:
- limited bargaining power;
- developmental vulnerability;
- targeted advertising;
- behavioral profiling;
- educational technologies;
- social-media tracking.
Different jurisdictions adopt different age thresholds and consent structures.
The EU GDPR generally uses a lower default age for children's consent to information-society services, subject to Member State variation, while India's DPDP framework adopts a stronger under-18 child-protection approach.
35. Data Governance and Corporate Accountability
Organizations should implement:
Data inventory
Know what information they hold.
Data mapping
Know where it moves.
Data classification
Identify sensitive/high-risk data.
Governance roles
Clearly assign responsibility.
Privacy impact assessments
Identify risks before processing.
Security controls
Prevent unauthorized access.
Retention policies
Avoid keeping data indefinitely.
Incident response
Respond quickly to breaches.
Auditing
Verify compliance.
36. Independent Regulators
The effectiveness of data governance depends heavily upon enforcement institutions.
EU
Independent national Data Protection Authorities cooperate through the European Data Protection Board.
India
The DPDP Act establishes the Data Protection Board of India as the principal statutory enforcement body.
Singapore
The Personal Data Protection Commission performs regulatory functions.
USA
There is no single comprehensive federal privacy regulator equivalent to the EU system; enforcement is distributed among federal agencies and state authorities.
This is one of the most significant comparative differences.
37. Remedies for Data Violations
A sophisticated data-governance system should provide:
1. Correction
Wrong data can be rectified.
2. Deletion
Unlawfully retained data can be removed where applicable.
3. Injunction
Courts may prevent unlawful processing.
4. Compensation
Individuals may receive compensation where legally available.
5. Regulatory penalties
Authorities may impose fines.
6. Administrative appeals
Individuals may challenge regulatory or organizational decisions.
7. Constitutional remedies
In jurisdictions such as India, constitutional courts may intervene against unlawful State processing.
38. Major Challenges in Comparative Data Governance
1. Fragmentation
Different countries apply different standards.
2. Extraterritoriality
One company's processing may simultaneously trigger several jurisdictions.
3. Government surveillance
National-security laws may conflict with privacy requirements.
4. Artificial intelligence
AI makes it difficult to predict future uses of data.
5. Consent fatigue
Individuals may accept lengthy privacy notices without understanding them.
6. Data monopolies
Large technology companies may accumulate enormous informational power.
7. Cybersecurity
Even lawful data processing can become harmful after a security breach.
8. Data inequality
Poorer communities may receive fewer benefits while bearing greater surveillance risks.
39. Comparative Evaluation
European Union
Best characterized as:
Rights + regulation + independent oversight.
Its strongest feature is comprehensive individual protection and institutional accountability. The GDPR is explicitly connected to the fundamental right to data protection.
India
Best characterized as:
Constitutional privacy + statutory governance + digital-development objectives.
Its major strength is the constitutional foundation supplied by Puttaswamy, combined with a dedicated statutory framework.
United States
Best characterized as:
Sectoral regulation + constitutional litigation + state experimentation.
Its strength is flexibility and innovation, but protection can vary substantially depending on the type of data and applicable jurisdiction.
Singapore
Best characterized as:
Centralized statutory governance + innovation orientation.
China
Best characterized as:
Data protection + cybersecurity + national sovereignty.
40. Comparative Case-Law Matrix for Examination
| No. | Case | Jurisdiction | Key doctrine |
|---|---|---|---|
| 1 | K.S. Puttaswamy v Union of India | India | Fundamental right to privacy |
| 2 | Puttaswamy (Aadhaar) | India | Biometric data/proportionality |
| 3 | PUCL v Union of India | India | Communications surveillance |
| 4 | Digital Rights Ireland v Ireland | EU | Mass data retention |
| 5 | Schrems II | EU | Cross-border transfers |
| 6 | Google Spain v AEPD | EU | Right to be forgotten |
| 7 | Big Brother Watch v UK | ECtHR | Bulk surveillance |
| 8 | Carpenter v United States | USA | Location-data privacy |
| 9 | Riley v California | USA | Digital-device privacy |
41. Key Differences: India vs EU vs USA
| Issue | India | EU | USA |
|---|---|---|---|
| Constitutional privacy | Article 21 | Charter Articles 7 & 8 | Primarily Fourth Amendment + statutory protection |
| Comprehensive statute | DPDP Act 2023 | GDPR | No single federal equivalent |
| Regulatory approach | Developing | Comprehensive | Fragmented |
| Consent | Central | One lawful basis among several | Sector-dependent |
| Data portability | More limited than GDPR | Strong | Generally sector/state dependent |
| Right to erasure | More limited | Strong GDPR right | No universal federal equivalent |
| Regulator | Data Protection Board | Independent DPAs | Multiple agencies |
| Cross-border transfers | Government-regulated | Highly developed safeguards | Sectoral |
| Constitutional litigation | Strong | Strong fundamental-rights review | Strong |
| Data localization | Government restrictions possible | Generally controlled transfer rather than broad localization | Generally sectoral |
42. Future of Comparative Data Governance
Future data governance is likely to focus on:
1. AI-generated data
Who controls data generated by AI systems?
2. Synthetic data
Can synthetic datasets reproduce protected characteristics?
3. Biometric governance
Facial recognition, voice recognition and behavioral identification.
4. Neurodata
Brain-computer interfaces create entirely new privacy concerns.
5. Data trusts
Collective institutions may manage data on behalf of communities.
6. Data commons
Certain datasets may be treated as shared resources.
7. Digital identity
Governments increasingly use digital identity infrastructures.
8. Cross-border interoperability
Different privacy regimes will need mechanisms for recognizing one another.
9. Algorithmic accountability
Data governance will increasingly overlap with AI governance.
43. Core Principles of an Ideal Data Governance System
An effective comparative model should incorporate:
- Legality
- Purpose limitation
- Data minimization
- Accuracy
- Transparency
- Security
- Accountability
- Privacy by design
- Human oversight
- Proportionality
- Independent supervision
- Effective remedies
- Responsible cross-border transfers
- Protection of vulnerable groups
- Democratic accountability
44. Conclusion
Comparative Data Governance Systems demonstrate that modern data governance is no longer merely an issue of corporate privacy compliance. It has become a question of constitutional rights, economic power, national sovereignty, cybersecurity, democratic accountability and technological governance.
The EU has developed the most comprehensive rights-based model, combining the GDPR with broader data-governance legislation and independent regulatory institutions. The GDPR expressly treats personal-data protection as a fundamental right and strengthens individual rights, transparency and accountability.
India is developing a distinctive constitutional-statist model in which the privacy guarantee under Puttaswamy operates alongside the DPDP Act's statutory framework. The DPDP Act expressly seeks to balance individual data protection with lawful data processing, while the 2025 Rules provide the implementation framework through phased commencement.
The United States relies more heavily on constitutional litigation, sectoral statutes and state experimentation, with Riley and Carpenter demonstrating how constitutional privacy principles have adapted to technologically generated data.
European jurisprudence in Digital Rights Ireland, Schrems II, Google Spain and Big Brother Watch demonstrates that data governance must regulate not only private-sector collection but also mass retention, international transfers, searchability and State surveillance.
The central comparative principle is:
Data governance is legitimate only when the economic and governmental value of data is balanced against privacy, dignity, autonomy, equality, security and effective remedies.
In the digital era, the real question is no longer simply "Who owns the data?" It is:
Who may collect it, who may use it, for what purpose, for how long, where may it travel, who may access it, and what remedy does the individual have when the system gets it wrong?

comments