2024 European Summer Meeting, Rotterdam: August, 2024
Regulatory Compliance with Limited Enforceability: Evidence from Privacy Policies
Bernhard Ganglmair, Julia K. Krämer, Jacopo Gambato
We study how asymmetric enforceability of regulatory rules affects firms’ compliance using a simple inspection model and a large sample of German privacy policies. We exploit the introduction of the General Data Protection Regulation, compelling firms to disclose, in accessible language, details of their data use. The specifics of disclosure are objective, whereas readability is subjective and difficult to enforce. We show that firms increased disclosure, but the policy readability did not improve. In line with theory, firms anticipating regulatory scrutiny and those facing higher-budget data protection authorities demonstrated a stronger response in readability compliance without sizeable effects on disclosure.