Privacy Rights and Data Security: GDPR and Personal Data Markets

被引:26
|
作者
Ke, T. Tony [1 ]
Sudhir, K. [2 ]
机构
[1] Chinese Univ Hong Kong, Shatin, Hong Kong, Peoples R China
[2] Yale Sch Management, New Haven, CT 06511 USA
关键词
GDPR; privacy; data security; personalization; price discrimination; digital marketing; CONSUMER PRIVACY; CUSTOMER; COMPETITION; ECONOMICS; BEHAVIOR;
D O I
10.1287/mnsc.2022.4614
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
General Data Protection Regulation (GDPR)-the European Union's data protection regulation-has two key principles. It recognizes that individuals own and control their personal (but not contractual) data in perpetuity, leading to three critical privacy rights, namely, the rights to (i) explicit consent (data opt-in), (ii) to be forgotten (data erasure), and (iii) portability (data transfer). It also includes data security mandates against privacy breaches through unauthorized access. We study GDPR's equilibrium impact by including these features in a dynamic two-period model of forward-looking firms and consumers. Firms collect consumer data for personalization and price discrimination. Consumers trade off gains from personalization relative to potential losses from privacy breaches and price discrimination in their purchase, data opt-in, erasure, and transfer decisions. Though data security mandates impose fines on firms for privacy breaches, firms can benefit from higher opt-in given lower breach risk. Surprisingly, data security mandates can hurt consumers. The effect of privacy rights is nuanced. Since the right to opt in separates goods exchange from the provision of personal data, it prevents market failure under high breach risk. But it also reduces consumer opt-in and personal data availability. Erasure and portability rights reduce consumers' hold-up concerns by disciplining firms to provide ongoing value by limiting price discrimination and not slacking off on data security; but they also reduce the incentive to offer lower initial prices that encourages opt-in. Overall, privacy rights always benefit consumers in competitive markets, but they can surprisingly hurt consumers under monopoly, as monopolists have less incentives to subsidize consumer opt-in. They raise (reduce) firm profit and social welfare when breach risk is high (low). Finally, privacy rights increase firm profit most at moderate levels of data transferability.
引用
收藏
页码:4389 / 4412
页数:24
相关论文
共 50 条
  • [31] Property, privacy, and personal data
    Schwartz, PM
    [J]. HARVARD LAW REVIEW, 2004, 117 (07) : 2055 - 2128
  • [32] PERSONAL DATA - RIGHT TO PRIVACY
    不详
    [J]. DATA PROCESSING, 1978, 20 (08): : 14 - &
  • [33] Investigating the Compliance of the GDPR: Processing Personal Data On A Blockchain
    Poelman, Michelle
    Iqbal, Sarfraz
    [J]. 2021 IEEE 5TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP), 2021, : 38 - 44
  • [34] GDPR and Health Personal Data; Tricks and Traps of Compliance
    Orel, Andrej
    Bernik, Igor
    [J]. DECISION SUPPORT SYSTEMS AND EDUCATION: HELP AND SUPPORT IN HEALTHCARE, 2018, 255 : 155 - 159
  • [35] Data Security and Privacy for Outsourced Data in the Cloud
    Sahin, Cetin
    El Abbadi, Amr
    [J]. 2018 IEEE 34TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE), 2018, : 1731 - 1734
  • [36] Not the doctor's business: Privacy, personal responsibility and data rights in medical settings
    Fournier, Veronique
    Bretonniere, Sandrine
    Spranzi, Marta
    [J]. BIOETHICS, 2020, 34 (07) : 719 - 726
  • [37] Personal Data Rights in the Era of Big Data
    Xiao, Cheng
    [J]. SOCIAL SCIENCES IN CHINA, 2019, 40 (03) : 174 - 188
  • [38] Achieving Data Truthfulness and Privacy Preservation in Data Markets
    Niu, Chaoyue
    Zheng, Zhenzhe
    Wu, Fan
    Gao, Xiaofeng
    Chen, Guihai
    [J]. IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2019, 31 (01) : 105 - 119
  • [39] Big Data Security and Privacy
    Bertino, Elisa
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2016, : 3 - 3
  • [40] PRIVACY AND SECURITY IN DATA SYSTEMS
    DAVIS, RM
    [J]. COMPUTERS AND PEOPLE, 1974, 23 (03): : 20 - 27