Big Data & Issues & Opportunities: Data Ownership

In this twelfth article in our series on "Big Data & Issues & Opportunities" (see our previous article here), we take a closer look at the data ownership issues surrounding the (big) data value chain and examine how such issues are addressed at EU and Member State level. Where relevant, illustrations from the transport sector will be provided.

The European Commission has voiced on multiple occasions the most important legal issues in a data environment. In its data-driven economy Communication of July 2014 already, but also in the context of its 2016 free flow of data initiative, it highlighted that "barriers to the free flow of data are caused by the legal uncertainty surrounding the emerging issues on 'data ownership' or control, (re)usability and access to/transfer of data and liability arising from the use of data".[1]

Indeed, if they cannot rely on any of the other exclusive rights discussed in this article series (see for instance our article on Intellectual Property Rights), stakeholders in the (big) data analytics lifecycle increasingly try to claim "ownership" in (parts of) the datasets used in the analytics.

The "ownership" concept

There is often some kind of misunderstanding between legal practitioners and non-legal professionals on the meaning of the term "ownership".

Following the Oxford Dictionary of Law, the word "ownership" has the following meaning: "it is the exclusive right to use, possess, and dispose of property, subject only to the rights of persons having a superior interest and to any restrictions on the owner's rights imposed by agreement with or by act of third parties, or by operation of law."[2] It is therefore something that implies certain rights over a property such as being able to enjoy, use, sell, rent, give away, or even destroy an item of property. Ownership may be corporeal (i.e. title to a tangible/material (im)movable object) or incorporeal (i.e. title to an intangible object, such as intellectual property, or a right to recover debt).

However, for businesses, the meaning of "ownership" may be different, especially in a data environment. It is often used to assign responsibility and accountability for specific databases, whereby reference to the "data owner" is made.[3] In such particular context, 'ownership' does not have a legal connotation but refers to other concepts such as assurance of data quality and security. There is thus no transfer of or licence over a property as such.

In this article, the term "ownership" will be used in its legal meaning. This nevertheless includes certain difficulties due to the particularities of data. Indeed, data is not like any other tangible or intangible "thing". It has certain characteristics often put forth when discussing the data economy, such as the fact that data is limitless and non-rivalrous, that fit uneasily with the legal concept of "ownership".

Actors in the data value chain who could claim ownership in data

The issue of data ownership is even more complicated by the data value cycle which can be rather complex and involves numerous stakeholders. This increases the difficulties in determining who could or would be entitled to claim ownership in data. Many of such stakeholders may attempt claiming ownership in data because, for instance, they create or generate data, or because they use, compile, select, structure, re-format, enrich, analyse purchase of, take a licence on, or add value to the data. Accordingly, in many instances, different stakeholders will have different powers depending on their specific role. Hence, no single data stakeholder will have exclusive rights.[4]

The following Figure created by the Organisation for Economic Co-operation and Development (OECD) aims to depict the data value cycle.[5]

Looking at the data value cycle, one can distinguish various actors and determine their roles in the data economy, in particular in the "datafication" process, the analysis of data, and the decision-making phase. It should however be kept in mind that certain organisations may play multiple roles. Also, the data value cycle does not reflect the cross-border flow of data and the legal intricacies related thereto.

There is a multitude of actors on the market actively reaping the benefits of the data economy. The relationships between such actors are an essential element of the data value cycle. Some of the most important actors are depicted in the layered Figure below, whereby the underlying layers supply the upper layers with goods and services[6]:

Illustration in the transport sector: The developments in relation to connected and autonomous vehicles have also raised questions with respect to data ownership.[7] The on-board computing systems present in connected and autonomous vehicles will allow for the transfer of substantial amounts of information, including about the driver and its location. At the current stage, it is still unclear who will "own" this information among the many different actors involved; i.e. the driver who the personal data relates to, the owner of the vehicle (if different from the driver), the manufacturer of the vehicle, insurance companies, navigation service providers, the government, or any other third party. Any data ownership claim may have a far-reaching impact on the further implementation of the technology concerned. In any event, the personal data protection rules will need to be respected.


Legislation on data ownership

Our researches have not enabled us to identify any EU legislation that would specifically regulate the question of ownership in data. This being said, such absence of ownership-related legislation does not exclude the fact that there are numerous legislations that have an impact on data or that may confer some kind of protection to certain types of data or on datasets (i.e. copyright, database rights and trade secrets).

The same issues apply when looking at the situation at Member State level. There clearly is no specific data-related legislation that explicitly recognises ownership in data in the various Member States. Having said that, some countries have legislation in place allowing to control the flow of data. One example would be France, where the civil code sets out mechanisms (based on both civil and criminal law measures) enabling the holder of data to prevent or restrain the misuse of data.

Case law addressing the issues of "ownership" of data

Thus far, there has been no real EU or national jurisprudence satisfactorily dealing with the issues surrounding data ownership. Nevertheless, some decisions at EU and national level may give an indication on how these issues may be dealt with in the future:

  • EU: According to some authors, the Court of Justice of the European Union opened the door for a discussion on ownership in intangible assets in its UsedSoft judgment issued on 3 July 2012.[8] In this ruling, the Court held that the commercial distribution of software via a download on the Internet is not only based on a licence, but on a sale of goods.[9] Therefore, the owner of copyright in software cannot prevent a perpetual "licensee" from selling his software (understood as downloaded file). The decision implies that there is a specific ownership attributed to intangible goods like software downloaded via the Internet. Applicability of this model to other digital goods remains to be considered in future court decisions.
  • Germany: In a case concerning the destruction of data, the Higher Regional Court of Karlsruhe considered that deletion of data stored on a data carrier may violate the ownership in the data carrier under the German Civil Law Code, extending the protection of the ownership in the data carrier to data stored on it.[10] Later decisions of German courts opposed the possibility to hold ownership over data as such, since data lacks the necessary material character[11] and since it is not considered a ‘thing’ under the German Civil Law Code.[12] The Court of Appeal of Nuremberg[13] has built on the general principle adopted in Germany, according to which things that are neither rights nor goods may nevertheless be sold within a sale contract (Section 453 of the German Civil Act). To decide whether former employees were allowed to delete the data stored on their company-owned laptops, the Nuremberg Court made reference to the theory of the so-called "Skripturakt". According to this theory, the person who generates the data gets the right to the data, even if the data afterwards are used for the business or for the sake of the employer. In consequence, under criminal law and in this particular case, the employees were allowed to delete the data.[14]
  • United Kingdom: So far, the UK courts held that data is not property and therefore cannot be stolen[15], that data are not eligible to be the subject of a common law lien[16], and that there is no proprietary right in the content of an email.[17]
  • France: The French Supreme Court ("Cour de cassation") rendered a ruling[18] in 2015 that could open a way to recognising the ownership of "data". The Court found that (remotely) downloading computer data without taking away their support may amount to the offence of theft, acknowledging therefore indirectly that such independent data may be owned.

Commission Communications having an impact on the Data Ownership Debate

"Towards a Thriving Data-Driven Economy" (2014)

The 2014 Commission Communication entitled "Towards a thriving data-driven economy" expected the big data market to grow worldwide to USD 16.9 billion in 2015 at an annual rate of 40%. The Commission nonetheless also indicated that the EU had been slow in embracing this revolution and that the complexity of the legal environment and the insufficient access to large datasets created entry barriers to SMEs and stifled innovation. 

The 2014 Communication addressed the various challenges by sketching the features of the European data-driven economy of the future and drawing some conclusions to support and speed up the transition towards it. It notably concluded that to be able to seize the opportunities related to a data-driven economy and to compete globally in such economy, the EU must "make sure that the relevant legal framework and the policies, such as on interoperability, data protection, security and IPR are data-friendly, leading to more regulatory certainty for business and creating consumer trust in data technologies".[19]

In a section dedicated to the regulatory issues, the Communication further highlighted the issues related to personal data protection and consumer protection, data mining, and security. It also raised the concerns pertaining to the ownership and liability of data provision and data location requirements in various sectors that limit the flow of data.

"A Digital Single Market Strategy for Europe" (2015)

In its 2015 Staff Working Document related to the Digital Single Market, the Commission reiterated the legal issues by putting forth problem drivers related to the data economy: "currently, collecting, processing, accessing and protecting data is a major challenge. This includes issues such as ownership of data, treatment of personal and industrial data, availability, access and re-use, contractual terms and conditions, data security, quality of data (e.g. timely updates), authentication of users, cybercrime, acceptance of electronic documents, liability for incorrect information, standardisation of languages and formats."[20]

"Building a European Data Economy" (2017)

The EU Commission carefully examined the most topical issues related to data in its Communication on "Building a European Data Economy" and the associated Staff Working Document.[21]

With respect to the particular issue of data access, we note in particular the EU Commission's conclusion according to which "comprehensive policy frameworks do not currently exist at national or Union level in relation to raw machine-generated data which does not qualify as personal data, or to the conditions of their economic exploitation and tradability. The issue is largely left to contractual solutions."[22] In the same vein, the EU Commission also concludes that "where the negotiation power of the different market participants is unequal, market-based solutions alone might not be sufficient to ensure fair and innovation-friendly results, facilitate easy access for new market entrants and avoid lock-in situations."[23]

Finally, the Communication suggests several non-exhaustive and not mutually exclusive possibilities[24], to be discussed with stakeholders, to move forward on the issue of access to machine-generated data. Some suggested measures are non-legislative and consist of (i) the creation of guidance on incentivising businesses to share data; (ii) fostering the development of technical solutions for reliable identification and exchange of data; and (iii) the creation of model contract terms. Other suggested measures are of a legislative nature and amount to (i) the creation of default contract rules; (ii) providing access to commercially-held data to public sector bodies for public interest and scientific purposes; (iii) granting a right to use and authorise the use of non-personal data to the "data producer"; and (iv) the creation of a legal framework governing access to data against remuneration.

"Towards a Common European Data Space" (2018)

In its Communication entitled "Towards a common European data space", the Commission proposes a package of measures as a key step towards a common data space in the EU.[25]

Such initiative was supported and driven by a stakeholder dialogue and replies to the Public Consultation on "Building the European Data Economy".[26] As regards business-to-business data sharing, such stakeholder dialogue showed that stakeholders are not in favour of a new 'data ownership' type of right, on grounds that "the crucial question in business-to-business sharing is not so much about ownership, but about how access is organised".[27]

Legal doctrine related to data ownership

In line with the increasing coverage of data ownership by the Commission in its Communications, the problem of data ownership has been reported by numerous authors.

Some authors are generally in favour of the creation of an ownership right[28], whereas others make the distinction between an exclusive and non-exclusive right to property in data. Thus, the Max Planck Institute for Innovation and Competition has stated, jointly with other authors, that it could see neither a justification nor a necessity to create exclusive rights in data.[29] Other academics do not necessarily dismiss the idea of an exclusive right in data, but claim its advent to be premature.[30] The authors of this article already expressed their preference for the creation of a non-exclusive ownership right paired with data sharing obligations in the context of the EU-funded H2020 project TOREADOR.[31]

Looking at the situation under Member States' laws, we observe a similar level of divergence.

The current lack of clarity as to the status of data under UK law was addressed for instance by Christopher Rees[32], who believes that data could be classified as property (based on a simple definition of property as the right to use something and exclude others from its use).

Most of the German academics argue that German law does not know a right in data as such[33], even if in some instances they recognised the need for creating such right. There are however voices opposing this line of thought, in view of the jurisprudence of the German Courts. In particular, Prof. Dr. T. Hoeren examined the issues of data ownership under the current German legal framework and jurisprudence[34], concluding that "in general, the property in data is attributed to the originator, creator, or producer of these data. However, in the case of data made for hire (to use the US copyright term), the data belong to the employer". Other scholars seem to suggest that one may rely on the current wording of Section 950 of the German Civil Code to claim some kind of property right in data. Such Section stipulates that "A person who, by processing or transformation of one or more substances, creates a new movable thing acquires the ownership of the new thing, except where the value of the processing or the transformation is substantially less than the value of the substance. Processing also includes writing, drawing, painting, printing, engraving or a similar processing of the surface." Despite the legal uncertainty surrounding such theory, and notably its particular application to intangible assets such as data, certain undertakings have already relied on it in their general terms and conditions. Having said that, the majority of German academics seems to agree that no right in data exists.

Commentators seem to be divided as to the ownership of data under French law. While some commentators indicate that data are not appropriable as such[35], others believe that in view of the abovementioned ruling of the French Supreme Court the ownership over data cannot be called into question.[36] Having said that, most discussions on the recognition of ownership seem to focus on individuals' ownership over their personal data.[37]

Illustration in the transport sector: In the course of 2017, the German Federal Ministry of Transport and Digital Infrastructure (Bundesministerium für Verkehr und digitale Infrastruktur – "BMVI") conducted a study, the results of which advocate the creation of an ownership right for (mobility) data.[38] In said study, the BMVI highlights the opportunities of (big) data use in the transport sector. It however regrets the heterogeneity and fragmentation of data-related regulations, and therefore advocates the creation of a – potentially exclusive – property-like right in (mobility) data in order to encourage the development of new business models. The BMVI suggests assigning data to the one who has made a substantial investment in the creation thereof, as it feels this would be in line with the economic reality and would provide legal certainty. In order to implement the ownership right in practice, the BMVI considers two different options. The first option entails the immediate creation of an entirely new "data law". The second option consists of different measures that would eventually lead to the development of a data law.


Conclusion

In a big data context, different third-party entities may try to claim ownership in (parts of) a dataset, which may hinder the production of, access to, linking and re-use of big data, including in the transport sector. This article has however amply demonstrated that the current legal framework relating to data ownership is not satisfactory.

No specific ownership right subsists in data and the existing data-related rights do not respond sufficiently or adequately to the needs of the actors in the data value cycle. Up until today, the only imaginable solution is capturing the possible relationships between the various actors in contractual arrangements.

Nevertheless, filling the data ownership gap with contractual arrangements is far from ideal. It would be practically burdensome – and probably even impossible – to regulate with full legal certainty by means of contracts the ownership issues in large-scale data undertakings where there is a multitude of data sources, storages, analyses and thus a myriad of actors who would want to claim ownership in the data concerned. On top of all that, comes the issue where contracts are in principle nonbinding, and therefore unenforceable, vis-à-vis third parties. This issue is further examined in our next article in this series, which will address data sharing agreements in the context of big data, with illustrations drawn from the transport sector.


This series of articles has been made possible by the LeMO Project (www.lemo-h2020.eu), of which Bird & Bird LLP is a partner. The LeMO project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement no. 770038.

This article on data ownership has also been made possible by the TORADOR Project (www.toreador-project.eu), of which Bird & Bird LLP was a partner. The TOREADOR Project received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement no. 688797.

The information given in this document concerning technical, legal or professional subject matter is for guidance only and does not constitute legal or professional advice.

The content of this article reflects only the authors’ views. The European Commission and Innovation and Networks Executive Agency (INEA) are not responsible for any use that may be made of the information it contains.


[1] COM (2014) 442 final; European Commission, 'European Free Flow of Data Initiative within the Digital Single Market' (Inception impact assessment, European Commission 2016) <http://ec.europa.eu/smart-regulation/roadmaps/docs/2016_cnect_001_free_flow_data_en.pdf> accessed 21 February 2019

[2] Jonathan Law and Elizabeth A. Martin, A Dictionary of Law (7th edition, Oxford University Press 2014) <http://www.oxfordreference.com/view/10.1093/acref/9780199551248.001.0001/acref-9780199551248-e-2745?rskey=2MFh2r&result=2900> accessed 21 February 2019

[3] OECD, Data-driven Innovation: Big Data for Growth and Well-being (OECD Publishing 2015) 195

[4] Ibid

[5] Ibid 33

[6] Ibid 72

[7] Caitlin A. Surakitbanharn and others, 'Preliminary Ethical, Legal and Social Implications of Connected and Autonomous Transportation Vehicles (CATV)' <https://www.purdue.edu/discoverypark/ppri/docs/Literature%20Review_CATV.pdf> accessed 18 October 2018

[8] Judgment of 3 July 2012, UsedSoft, C-128/11, ECLI:EU:C:2012:407

[9] Thomas Hoeren, 'Big Data and the Ownership in Data: Recent Developments in Europe' (2014) 36(12) EIPR 751

[10] OLG Karlsruhe, Urt. v. 07.11.1995 – 3 U 15/95 – Haftung für Zerstörung von Computerdaten

[11] LG Konstanz, Urt. v. 10.05.1996 – 1 S 292/95 = NJW 1996,2662

[12] OLG Dresden, Beschl. v. 05.09.2012 – 4 W 961/12 = ZD 2013,232

[13] OLG Nürnberg 1. Strafsenat decision of 23.01.2013, 1 Ws 445/12

[14] One should bear in mind that the discussed case had a strong criminal law connotation; the employees who deleted the data without prior authorisation were accused of theft, with their employer asking for a conviction under Section 303(a) of the German Criminal Act (prohibiting unlawfully erasing, corrupting or altering computer data under penalty of imprisonment). It is unclear whether the same rule would be applied by German courts in a civil law matter; OLG Nürnberg 1. Strafsenat decision of 23.01.2013, 1 Ws 445/12, par. 14

[15] Oxford v Moss [1979] 68 Cr App Rep 183

[16] Your Response v Datateam Business Media [2014] EWCA Civ 281

[17] Fairstar Heavy Industries v Adkin, [2013] EWCA Civ 886

[18] May 20, 2015 (No14-81336)

[19] COM (2014) 442 final

[20] Commission, 'A Digital Single Market Strategy for Europe – Analysis and Evidence Accompanying the document Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions A Digital Single Market Strategy for Europe' (Staff Working Document) SWD (2015) 100 final

[21] COM (2017) 9 final, 4

[22] Ibid 10. See also the summary of the findings in relation to the EU law regime applicable to processing data in SWD (2017) 2 final, 22.

[23] Ibid

[24] Such possibilities are detailed in the Commission Staff Working Document SWD (2017) 2 final, 30 ff

[25] COM (2018) 232 final

[26] European Commission, 'Public Consultation on Building the European Data Economy' (European Commission) <https://ec.europa.eu/digital-single-market/en/news/public-consultation-building-european-data-economy> accessed 18 October 2018

[27] COM (2018) 232 final 9

[28] Herbert Zech, 'Information as Property' (2015) 6 JIPITEC 192 <https://www.jipitec.eu/issues/jipitec-6-3-2015/4315> accessed 18 October 2018

[29] Josef Drexl and others, 'Data Ownership and Access to Data - Position Statement of the Max Planck Institute for Innovation and Competition of 16 August 2016 on the Current European Debate' (Max Planck Institute for Innovation and Competition Research Paper No. 16-10, 2016) <http://dx.doi.org/10.2139/ssrn.2833165>; Josef Drexl, 'Designing Competitive Markets for Industrial Data in Europe – Between Propertisation and Access' (2017) 8 JIPITEC 257 <https://www.jipitec.eu/issues/jipitec-8-4-2017/4636> accessed 18 October 2018; Bernt Hugenholtz, 'Against Data Property' in Hanns Ullrich, Peter Drahos and Gustavo Ghidini (eds), Kritika: Essays on Intellectual Property (Volume 3, Edward Elgar Publishing Limited 2018); Wolfgang Kerber, 'A New (Intellectual) Property Right for Non-Personal Data? An Economic Analysis' (Joint Discussion Paper Series in Economics No. 37-2016) <https://www.uni-marburg.de/fb02/makro/forschung/magkspapers/paper_2016/37-2016_kerber.pdf> accessed 18 October 2018

[30] Andreas Wiebe, 'Protection of Industrial Data – A New Property Right for the Digital Economy?'(2017) 12(1) Journal of Intellectual Property Law & Practice 62

[31] Benoit Van Asbroeck, Julien Debussche and Jasmien César, 'White Paper – Data Ownership in the Context of the European Data Economy: Proposal for a New Right' (Bird & Bird 2017) <https://www.twobirds.com/en/news/articles/2017/global/data-ownership-in-the-context-of-the-european-data-economy> accessed 21 February 2019; Benoit Van Asbroeck, Julien Debussche, Jasmien César, 'Supplementary Paper – Data Ownership: a new EU right in data' (Bird & Bird 2017) <https://www.twobirds.com/en/news/articles/2017/global/data-ownership-a-new-eu-right-in-data> accessed 21 February 2019.

[32] Christopher Rees, 'Who Owns our Data?' (2014) 30(1) Computer Law & Security Review 75

[33] See e.g.: Michael Dorner, 'Big Data und “Dateneigentum”' (2014) 9 CR 617, Malte Grützmacher; 'Dateneigentum – ein Flickenteppich' (2016) 8 CR 485

[34] Thomas Hoeren, 'Big Data and the Ownership in Data: Recent Developments in Europe' (2014) 36(12) EIPR 751

[35] Alexandra Mendoza-Caminade, 'La protection pénale des biens incorporels de l’entreprise: vers l’achèvement de la dématérialisation du délit' (2015) 7 Recueil Dalloz 415; Céline Castets-Renard, 'Les opportunités et risques pour les utilisateurs dans l’ouverture des données de santé: big data et open data' (2014) 108 Revue Lamy Droit de l’immatériel 38

[36] Pierre Berlioz, 'Consécration du vol de données informatiques. Peut-on encore douter de la propriété de l’information?' (2015) 4 Revue des contrats 951

[37] The particular issue of personal data ownership will be discussed in a separate article in this article series; Alain Bensoussan, 'Propriété des données et protection des fichiers' (2010) 296 Gazette du Palais 2; Isabelle Beyneix, 'Le traitement des données personnelles par les entreprises: big data et vie privée, état des lieux' (2015) 46-47 Semaine juridique 2113.

[38] Bundesministerium für Verkehr und digitale Infrastruktur, 'Eigentumsordnung für Mobilitätsdaten? – Eine Studie aus technischer, ökonomischer und rechtlichter Perspektive' (BMVI) <https://www.bmvi.de/SharedDocs/DE/Artikel/DG/studie-mobilitaetsdaten-fachkonsultation.html> accessed 18 October 2018

Latest insights

More Insights

Balancing the candid disclosure of information to regulators, with the desire to maintain privilege: Recent developments regarding voluntary disclosure agreements

Apr 19 2024

Read More

Instant Payments Regulation

Apr 19 2024

Read More

Navigating the legal landscape of plastics – balancing utility with environmental responsibility

Apr 19 2024

Read More

Related capabilities