2024 European Summer Meeting, Rotterdam: August, 2024

Regulatory Compliance with Limited Enforceability: Evidence from Privacy Policies

Bernhard Ganglmair, Julia K. Krämer, Jacopo Gambato

We study how asymmetric enforceability of regulatory rules affects firms’ compliance using a simple inspection model and a large sample of German privacy policies. We exploit the introduction of the General Data Protection Regulation, compelling firms to disclose, in accessible language, details of their data use. The specifics of disclosure are objective, whereas readability is subjective and difficult to enforce. We show that firms increased disclosure, but the policy readability did not improve. In line with theory, firms anticipating regulatory scrutiny and those facing higher-budget data protection authorities demonstrated a stronger response in readability compliance without sizeable effects on disclosure.



Preview

Page 1
Page 2
Page 3
Page 4
Page 5
Page 6
Page 7
Page 8
Page 9
Page 10
Page 11
Page 12
Page 13
Page 14
Page 15
Page 16
Page 17
Page 18
Page 19
Page 20
Page 21
Page 22
Page 23
Page 24
Page 25
Page 26
Page 27
Page 28
Page 29
Page 30
Page 31
Page 32
Page 33
Page 34
Page 35
Page 36
Page 37
Page 38
Page 39
Page 40
Page 41
Page 42
Page 43
Page 44
Page 45
Page 46
Page 47
Page 48
Page 49
Page 50
Page 51
Page 52
Page 53
Page 54