scieee AI-readable full text Open interactive document viewer

LEGAL REGULATION OF BIG DATA IN FOREIGN COUNTRIES' LEGISLATION

Tojiboyev Sarvar Zafarovich

Full text

International Law, Business and Political Science Journal ISSN-L 3235-9799 E-ISSN 3235-9799 IF(Impact Factor) 13.24 https://journallaw.totalh.net/ Volume: 11. Issue 12 November 2025 1 LEGAL REGULATION OF BIG DATA IN FOREIGN COUNTRIES' LEGISLATION Tojiboyev Sarvar Zafarovich Tashkent State University of Law Deputy Head of Civil Law department, PhD Email: [email protected] ABSTRACT This article examines the legal regulation of Big Data in foreign jurisdictions by comparing three dominant regulatory models: the restrictive European and British approach, the liberal United States approach, and the mixed Asian model. The study analyzes how the United Kingdom integrates Big Data governance into existing data protection law, emphasizing privacy and ethical self-regulation. The European Union’s advanced regulatory framework, centered on the GDPR and the Digital Services Act, is evaluated through scholarly critiques highlighting challenges in transparency, data subject rights, and technological development. The United States model, characterized by sectorial regulation and the commercial treatment of data, is assessed in terms of its flexibility and risks associated with information brokerage and discriminatory practices. The conclusion underscores the absence of a unified international Big Data regime and highlights the need for harmonized global standards amid growing cross-border data flows. The findings emphasize that differing national priorities—privacy, commercial freedom, or hybrid governance—shape Big Data regulation and influence the evolution of the global digital economy. Key words: Big Data regulation; GDPR; data protection law; ePrivacy Regulation; Digital Services Act; information law; United States privacy model; UK data governance; industrial data; personal data; digital economy; international data standards; data brokers. INTRODUCTION Many countries, recognizing the growing importance of global digitalization, have transitioned, in one way or another, to legally regulating the virtual world by International Law, Business and Political Science Journal ISSN-L 3235-9799 E-ISSN 3235-9799 IF(Impact Factor) 13.24 https://journallaw.totalh.net/ Volume: 11. Issue 12 November 2025 2 defining its basic institutions, their legal principles, and protection mechanisms. Undoubtedly, an active legal framework for Big Data is being developed worldwide, as it is the main link in the digital chain. However, since its emergence, it still lacks an appropriate legal regime. The need to go beyond national regulation and study foreign experiences in the legal regulation of this phenomenon is determined by its extraterritorial nature. The circulation of large volumes of digital data extends beyond the borders of a single country, which requires unified regulation at both international and national levels. Neglecting this leads to legal uncertainty for all market participants and slows down the development of the digital economy. Therefore, instead of introducing local norms within a single legal system, it is advisable to consider the experience of international lawmaking in this field, use uniform rules, and incorporate universal norms into national legislation. MAIN PART To analyze foreign practices, countries using three different legal approaches in the regulation of Big Data were selected: a restrictive regulation model within the framework of personal data legislation (European Union, Great Britain), a free regulation model (USA), and a mixed regulation model (Asian countries model). Great Britain model. The United Kingdom is considered the first country to pursue the legal regulation of Big Data and its integration into the national system. Preparations for formulating legal norms to regulate Big Data began in 2013, when the UK government declared Big Data as a key technology of crucial importance for the country. 1 The review of the legal regulation in this field should begin with the report "Big Data Technologies and National Security: Comparing International Perspectives on Strategy, Policy and Law" 2 (United Kingdom Report: Big Data Technology and National Security. Comparative International Perspectives on Strategy, Policy and Law). The report emphasizes that currently, British legislators aim to introduce amendments clarifying the legal regulation of Big Data specifically within data 1 Bart van der Sloot, Sascha van Schendel. International and comparative legal study on Big Data // The Netherlands Scientific Council for Government Policy. P.57. 2 Bennett Moses L;De Koker L;Mendelson D. Big Data Technology and National Security: Comparative International Perspectives on Strategy, Policy and Law -- United Kingdom Report. June 2018. International Law, Business and Political Science Journal ISSN-L 3235-9799 E-ISSN 3235-9799 IF(Impact Factor) 13.24 https://journallaw.totalh.net/ Volume: 11. Issue 12 November 2025 3 protection legislation. 3 This reflects the general trend in the development of this field, particularly within the framework of data privacy legislation, which prioritizes the principle of privacy protection. In the absence of special norms or regulatory legal acts directly governing activities in the field of Big Data, the United Kingdom currently employs an indirect approach to legally regulating this area through existing legislation, which in various ways covers the use of certain categories of data. The first category includes personal data, which is regulated by the General Data Protection Regulation (hereinafter - GDPR) 4 , as well as the Data Protection Act 2018, which supplements the main provisions of the GDPR and regulates areas outside the jurisdiction of this document (for example, national security). 5 Both documents impose stricter regulations on the process of collecting and processing personal data, establish high standards of protection, and set serious sanctions for violating the rules, such as the prohibition of selling or offering for sale illegally collected personal data without the subject's consent. In addition to the two above-mentioned regulatory documents, there are a number of other documents regulating the processing of specific data in healthcare, media (Telecommunications Act 1984 and Broadcasting Act 1996), security (Police Act 1997), and other areas. Furthermore, when reviewing the legal experience of Great Britain, it is impossible to overlook the highly significant document of the European Commission from 2017 titled "Building a European Data Economy," which contains two important conclusions. 6 Firstly, the issue of the legal regime for machine-generated industrial data was raised for the first time. Thus, it was proposed to introduce a new entity - the "industrial data creator," who is the owner of the data-generating equipment or possesses the equipment based on another right. 7 As a result, it was proposed to establish the "right of the new data creator," which defines the possibility for such an entity to use 3 Bennett Moses L; De Koker L; Mendelson D. Big Data Technology and National Security: Comparative International Perspectives on Strategy, Policy and Law -- United Kingdom Report. P.58 4 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). 5 Data Protection Act 2018. URL: http://www.legislation.gov.uk/ukpga/2018/12/contents/enacted 6 Bart van der Sloot, Sascha van Schendel. International and comparative legal study on Big Data. P.60. 7 Communication on Building a European Data Economy // European Comission. 2017. P 13. URL:https://ec.europa.eu/digitalsingle-market/en/news/communication-building-european-data-economy International Law, Business and Political Science Journal ISSN-L 3235-9799 E-ISSN 3235-9799 IF(Impact Factor) 13.24 https://journallaw.totalh.net/ Volume: 11. Issue 12 November 2025 4 unstructured (noSQL) data and grants others the right to use the data. 8 Secondly, the proposal to provide access to third parties' personal data based on the principles of fairness, justice, and proportionality, without the consent of the intellectual property owner, but for a certain fee, similar to the use of intellectual property objects, was revolutionary in its approach. 9 In our opinion, this implies that participants in civil legal relations should act in good faith, reasonably, and fairly. As is known, these principles are also enshrined in national civil legislation. Subsequently, a special regulatory legal document was developed - the EU Regulation "On the Protection of Privacy in the Field of Electronic Communications" (hereinafter - the ePrivacy Regulation) 10 , which was supposed to enter into force simultaneously with the GDPR. However, the date of entry into force of the document was postponed to 2019. This Regulation is a specific continuation of the aforementioned European Commission document, which reinforces the free circulation of non-personal data. In particular, it regulates the rules for the use of web communication metadata (for example, WhatsApp), which must be deleted or anonymized when the user refuses to consent to their collection and processing. It also includes rules for processing web communication content to provide a specific service with the user's consent. According to it, such processing should be carried out only for the provision of a particular service, without exceeding the scope of the original purpose. Furthermore, the document under consideration prohibits operators from storing data after achieving the communicative goal, specifically after a particular user has received the message, unless there is direct consent from the person for such storage. A special procedure is established for a large set of cookies 11 , which does not require the user's consent for their collection and processing if they do not contain confidential information, are used for user statistics, are aimed at improving the operation of the internet resource, and so on. 12 An important aspect of the ePrivacy Regulation was the prohibition on denying access to a service if the user refused to consent to the collection and processing of their personal data, even if the service charges a fee for data processing. 8 Communication on Building a European Data Economy // European Comission. 2017. P. 13 9 Communication on Building a European Data Economy // European Comission. 2017. P. 13 10 Regulation of the European Parliament and of the Council concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (Regulation on Privacy and Electronic Communications). URL: https://eur-lex.europa.eu/legal content/EN/TXT/?uri=CELEX%3A52017PC0010 11 Bittersweet cookies. Some security and privacy considerations // European Network and Information Security Agency. 2011. 12 Regulation on Privacy and Electronic Communications. Art. 8-10. International Law, Business and Political Science Journal ISSN-L 3235-9799 E-ISSN 3235-9799 IF(Impact Factor) 13.24 https://journallaw.totalh.net/ Volume: 11. Issue 12 November 2025 5 Thus, in Great Britain, there is a general need to update outdated laws to reflect current realities and take into account the characteristics of new types of data. The legislators of Great Britain openly acknowledge that the legal regulation of Big Data is at an early stage of development. In this regard, self-regulation of this area is emerging, which involves creating special recommendations for the ethical use of Big Data at the level of individual organizations. 13 European Union model (EU model). In the context of the modern digital economy, Big Data technologies are becoming increasingly important. The legal regulation of processes for processing and utilizing data collected through these technologies is one of the urgent tasks facing the global community. In this regard, the experience of the European Union (EU) deserves special attention, as it is recognized as one of the most advanced systems for regulating big digital data. Based on the EU model, one can observe the existence of a specific mechanism aimed at regulating Big Data processes. The European Union's General Data Protection Regulation (General Data Protection Regulation (GDPR) ) 14 , adopted in 2016 and effective from 2018, is the primary document for the legal regulation of big data. This document established new standards for personal data protection and strengthened citizens' rights in the digital world. According to Professor Elena Romano, the adoption of GDPR has revolutionized the field of personal data protection. This document has influenced data protection standards not only in Europe but also on a global scale. 15 The Digital Services Act (DSA), adopted in 2022, established new standards for handling big digital data. In particular, this document clarified the obligations of online platforms and digital service providers. 16 Lawyer Hans Müller expressed the following critical opinion on this matter: Although the DSA is a progressive document in many respects, it cannot fully encompass all aspects of big digital data. Specifically, the issues of regulating data created by artificial intelligence systems remain unresolved. 17 13 Bart van der Sloot, Sascha van Schendel. International and comparative legal study on Big Data. P. 61. 14 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. 15 Romano, E. (2023). "The Impact of GDPR on Global Data Protection Standards". European Law Review, 45(3), 78-95. 16 Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 17 Müller, H. (2023). "Critical Analysis of the Digital Services Act". Digital Law Journal, 12(2), 145-162. International Law, Business and Political Science Journal ISSN-L 3235-9799 E-ISSN 3235-9799 IF(Impact Factor) 13.24 https://journallaw.totalh.net/ Volume: 11. Issue 12 November 2025 6 A number of data principles apply within the framework of the AI model. From the perspective of Big Data processing, it indicates that the participants in the relationship must act within the bounds of the law and transparently. According to the GDPR, data processing must be carried out in a lawful, fair, and transparent manner. In Professor Sarah Martinez's view, the principle of transparency allows data subjects to have a complete understanding of how their data is being used. However, fully implementing this principle in practice remains a complex challenge. 18 Data should only be collected and processed for clearly defined, open, and legitimate purposes. This principle creates certain challenges in the context of big digital data technologies. According to the critical perspective of legal expert Philippe Dubois, the principle of purpose limitation contradicts the fundamental concept of big data analytics, as big data technologies often rely on discovering unexpected correlations and utilizing data for new purposes. 19 GDPR grants data subjects the right to access their personal data (Data access rights) . Professor Angela White points out that while the right to access data appears theoretically sound, it presents several practical challenges. Specifically, she emphasizes that extracting and presenting individual data from big data systems can be technically complex. 20 Data subjects have the right to request the deletion of their personal information. Exercising this right raises complex issues in the context of big data. According to legal expert Klaus Weber, the Right to be Forgotten holds significant importance in the modern digital world. However, fully ensuring this right in big data systems can be technically challenging and sometimes impossible. 21 In accordance with GDPR rules, data processors are obligated to ensure data security. Professor Richard Thompson expresses a critical opinion on this matter. Specifically, he emphasizes that the security measures defined in the GDPR rules are general in nature and may not be sufficient in the context of rapid technological development. 22 The European Union's model of legal regulation of big data plays an important 18 Martinez, S. (2023). "Transparency in Big Data Processing: Theory and Practice". International Journal of Data Protection, 8(4), 234-251. 19 Dubois, P. (2022). "Purpose Limitation in the Age of Big Data". European Data Protection Law Review, 7(2), 167-184. 20 White, A. (2023). "Access Rights in Big Data Systems: Practical Challenges". Technology Law Review, 15(1), 89-106. 21 Weber, K. (2023). "The Right to be Forgotten in the Context of Big Data". Digital Rights Law Review, 9(3), 212-229. 22 Thompson, R. (2022). "Security Measures under GDPR: A Critical Assessment". Cybersecurity Law Journal, 11(4), 178195. International Law, Business and Political Science Journal ISSN-L 3235-9799 E-ISSN 3235-9799 IF(Impact Factor) 13.24 https://journallaw.totalh.net/ Volume: 11. Issue 12 November 2025 7 role in the modern digital world. GDPR and other legal acts are aimed at protecting personal data and creating a balanced system for using big data technologies. However, as evident from the opinions of the aforementioned legal scholars, this system still requires improvement. In the future, given the development of new technologies and the expansion of the global digital economy, further improvement of legal regulation mechanisms will be necessary. In this process, the EU model has global significance and can serve as an example for other countries. US model A distinctive feature of US information law is that, with the exception of restrictions established by sector-specific laws in this country, there are practically no rules governing the use of any information, which is explained by the free collection and processing of any information. In this regard, it is deemed appropriate to examine the American legal regulation of various categories of data that collectively constitute Big Data, using an analogy of legal analysis based on the United Kingdom's experience. Thus, beginning with the category of industrial data, the United States is currently refraining from adopting specific acts to regulate the field under study. Nevertheless, within the scope of the issue being examined, the "Computer Fraud and Abuse Act" 23 merits attention. It establishes a general prohibition on unauthorized access to data stored on any computer device, as well as the misuse of such access. In this context, a computer device is defined as a data storage medium or a communication device that is directly connected to or operates in conjunction with such a device. The aforementioned Act has undergone numerous amendments expanding the list of illegal actions falling under its regulation. However, the latest attempt to amend it in 2015 was unsuccessful, where, among other considerations, it was indicated that excessive regulation of the area in question should be avoided, as it could lead to restrictions on the free flow of information and a decline in the level of technological development. 24 The next important category of data is personal data. Unlike other countries, the United States does not have a single federal data privacy law. Additionally, there is no unified definition of personal data or generally accepted rules, such as obtaining the 23 The Code of Laws of the United States of America (18 U.S.C. § 1030). URL: https://www.law.cornell.edu/uscode/text/18/1030 24 Dana Liebelson. Democrats, Tech Experts Slam Obama's Anti-Hacking Proposal // Huffington Post. 2015. URL: https://www.huffpost.com/entry/obama-hackers_n_6511700 International Law, Business and Political Science Journal ISSN-L 3235-9799 E-ISSN 3235-9799 IF(Impact Factor) 13.24 https://journallaw.totalh.net/ Volume: 11. Issue 12 November 2025 8 user's prior consent for collecting and processing personal data (except in cases of collecting and processing "sensitive" data). However, there is the Privacy Act of 1974, which regulates the activities of collecting and analyzing public data stored in federal bodies within the framework of public administration, excluding the private sector. 25 Primarily, the classification of certain data as personal information is determined by the scope of regulation and establishes specific restrictions in sectoral legislation (finance, media, healthcare, etc.). 26 For example, if we refer to the Children's Online Privacy Protection Act of 2013, it provides an extensive list of personal data relating to children, including IP addresses, geolocation data, and other network identifiers. 27 Nevertheless, with the emergence of digital phenomena such as Big Data and the increasing instances of confidential personal information leaks, American citizens are increasingly feeling the need to protect their personal data. This is driving the regional development of relevant legislation. It is noteworthy that according to California's Consumer Privacy Protection Act of 2018, the concept of personal data includes not only traditional personal identifiers, but also cookies and social network activity data, as well as results obtained from processing such data. 28 Naturally, this significantly expands the boundaries of the term "personal data." In the USA, information is considered a commodity, allowing for the possibility of selling individuals' personal data. However, due to insufficient regulation in this area, the issue of abuse by information brokers - organizations that collect personal data for resale to other parties - has become acute in the USA. Unfortunately, this matter has not yet been regulated at the federal level, though some states have attempted to legally address it. For instance, in 2018, the state of Vermont enacted the Information Brokers Act, which solidified their legal status and established specific rules for their operations. These rules include registering with the state's authorized body, submitting periodic reports on their activities, implementing an effective security system, prohibiting the use of information contrary to the purpose of collection, and other measures. 29 Depersonalized data, as well as publicly available information, which is almost 25 Overview of the Privacy Act 1974 // US Department of Justice. URL:https://www.justice.gov/opcl/privacy-act-1974 26 Such regulatory documents may include, for example, the Health Insurance Portability and Accountability Act of 1996, the Family Educational Rights and Privacy Act of 1974, the Children's Online Privacy Protection Act of 1998, and others. 27 The Children's Online Privacy Protection Rule of 2013. §312.2. URL:http://uscode.house.gov/view.xhtml?req=granuleid%3AUSC-prelim-title15-section6501&edition=prelim 28 California Consumer Privacy Act. Art. 1798.140(o). URL: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180AB375 29 Information broker Act 2018. International Law, Business and Political Science Journal ISSN-L 3235-9799 E-ISSN 3235-9799 IF(Impact Factor) 13.24 https://journallaw.totalh.net/ Volume: 11. Issue 12 November 2025 9 entirely free from regulation by information legislation (except for restrictions on special categories of information), can be freely collected and analyzed without any notification of such activity taking place. Nevertheless, some authors point out that there is a practice in the USA where technology startups are required to pay a fee to access Big Data. Furthermore, in the USA, special attention is being paid to limiting discriminatory practices in the implementation and use of Big Data across various sectors. For example, the 2016 Federal Trade Commission report strongly highlighted the issue of how Big Data usage might restrict access to certain services for specific population groups (such as in the use of scoring systems in the lending sector). In this context, the report's authors emphasized the urgent need to establish a legal framework for this new phenomenon to prevent violations of citizens' rights and potential risks. CONCLUSION Summarizing the above, it can be concluded that the regulation of Big Data in the USA generally has a very liberal nature, providing all interested parties with free access to it, which undoubtedly has a positive impact on the development of the field in question. 30 Additionally, it can be noted that there is a trend towards substituting access to Internet of Things (IoT) devices for the subject's personal data. Firstly, there is no specific law in foreign legislation regulating activities related to Big Data. Treating Big Data as a special commodity with commercial value (as in the USA) appears to be successful. Secondly, there is a difference in the legal regulation model of Big Data between countries. For example, while the United Kingdom structures the management of this field around privacy legislation and prioritizes the need to undergo a process of "legalizing" the collection and processing of such data, in the United States, due to the lack of unified data privacy regulations, there is an opportunity to freely collect and analyze any data, prioritizing the commercial potential of information. In literature, the different approaches of countries to the same phenomena are explained by the fact that the USA views data as a special commodity, while the UK points to the continuous connection between an individual and their personal data. Thirdly, the analysis of foreign doctrine did not reveal an urgent need in countries 30 Gribanov A. Protection of rights to marketing tools of e-commerce (big data, social media pages, YouTube channels, Telegram channels and bots) // Zakon.ru. 2017.