Privacy Rights and Data Security: GDPR and Personal Data Markets

被引:26
|
作者
Ke, T. Tony [1 ]
Sudhir, K. [2 ]
机构
[1] Chinese Univ Hong Kong, Shatin, Hong Kong, Peoples R China
[2] Yale Sch Management, New Haven, CT 06511 USA
关键词
GDPR; privacy; data security; personalization; price discrimination; digital marketing; CONSUMER PRIVACY; CUSTOMER; COMPETITION; ECONOMICS; BEHAVIOR;
D O I
10.1287/mnsc.2022.4614
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
General Data Protection Regulation (GDPR)-the European Union's data protection regulation-has two key principles. It recognizes that individuals own and control their personal (but not contractual) data in perpetuity, leading to three critical privacy rights, namely, the rights to (i) explicit consent (data opt-in), (ii) to be forgotten (data erasure), and (iii) portability (data transfer). It also includes data security mandates against privacy breaches through unauthorized access. We study GDPR's equilibrium impact by including these features in a dynamic two-period model of forward-looking firms and consumers. Firms collect consumer data for personalization and price discrimination. Consumers trade off gains from personalization relative to potential losses from privacy breaches and price discrimination in their purchase, data opt-in, erasure, and transfer decisions. Though data security mandates impose fines on firms for privacy breaches, firms can benefit from higher opt-in given lower breach risk. Surprisingly, data security mandates can hurt consumers. The effect of privacy rights is nuanced. Since the right to opt in separates goods exchange from the provision of personal data, it prevents market failure under high breach risk. But it also reduces consumer opt-in and personal data availability. Erasure and portability rights reduce consumers' hold-up concerns by disciplining firms to provide ongoing value by limiting price discrimination and not slacking off on data security; but they also reduce the incentive to offer lower initial prices that encourages opt-in. Overall, privacy rights always benefit consumers in competitive markets, but they can surprisingly hurt consumers under monopoly, as monopolists have less incentives to subsidize consumer opt-in. They raise (reduce) firm profit and social welfare when breach risk is high (low). Finally, privacy rights increase firm profit most at moderate levels of data transferability.
引用
收藏
页码:4389 / 4412
页数:24
相关论文
共 50 条
  • [1] The challenges of personal data markets and privacy
    Sarah Spiekermann
    Alessandro Acquisti
    Rainer Böhme
    Kai-Lung Hui
    [J]. Electronic Markets, 2015, 25 : 161 - 167
  • [2] The Interface of Privacy and Data Security in Automated City Shuttles: The GDPR Analysis
    Benyahya, Meriem
    Kechagia, Sotiria
    Collen, Anastasija
    Nijdam, Niels Alexander
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (09):
  • [3] The security of personal data under the GDPR: a harmonized duty or a shared responsibility?
    Wolters, P. T. J.
    [J]. INTERNATIONAL DATA PRIVACY LAW, 2017, 7 (03) : 165 - 178
  • [4] GDPR Personal Privacy Security Mechanism for Smart Home System
    Jhuang, Yun-Yun
    Yan, Yu-Hui
    Horng, Gwo-Jiun
    [J]. ELECTRONICS, 2023, 12 (04)
  • [5] Personal data anonymization for security and privacy in collaborative environments
    El Kalam, AA
    Deswarte, Y
    Trouessin, G
    Cordonnier, E
    [J]. 2005 INTERNATIONAL SYMPOSIUM ON COLLABORATIVE TECHNOLOGIES AND SYSTEMS, PROCEEDINGS, 2005, : 56 - 61
  • [6] Decentralized data processing: personal data stores and the GDPR
    Janssen, Heleen
    Cobbe, Jennifer
    Norval, Chris
    Singh, Jatinder
    [J]. INTERNATIONAL DATA PRIVACY LAW, 2020, 10 (04) : 356 - 384
  • [7] Personal Big Data, GDPR and Anonymization
    Domingo-Ferrer, Josep
    [J]. FLEXIBLE QUERY ANSWERING SYSTEMS, 2019, 11529 : 7 - 10
  • [8] Data privacy, data protection and the importance of integration for gdpr compliance
    Brunswick, Dave
    [J]. ISACA Journal, 2019, 1 : 14 - 17
  • [9] Promise not fulfilled: FinTech, data privacy, and the GDPR
    Dorfleitner, Gregor
    Hornuf, Lars
    Kreppmeier, Julia
    [J]. ELECTRONIC MARKETS, 2023, 33 (01)
  • [10] Promise not fulfilled: FinTech, data privacy, and the GDPR
    Gregor Dorfleitner
    Lars Hornuf
    Julia Kreppmeier
    [J]. Electronic Markets, 2023, 33