IDEAS home Printed from https://ideas.repec.org/a/inm/ormnsc/v69y2023i8p4389-4412.html
   My bibliography  Save this article

Privacy Rights and Data Security: GDPR and Personal Data Markets

Author

Listed:
  • T. Tony Ke

    (Chinese University of Hong Kong, Shatin, N.T., Hong Kong)

  • K. Sudhir

    (Yale School of Management, New Haven, Connecticut 06511)

Abstract

General Data Protection Regulation (GDPR)—the European Union’s data protection regulation—has two key principles. It recognizes that individuals own and control their personal (but not contractual) data in perpetuity, leading to three critical privacy rights , namely, the rights to (i) explicit consent (data opt-in), (ii) to be forgotten (data erasure), and (iii) portability (data transfer). It also includes data security mandates against privacy breaches through unauthorized access. We study GDPR’s equilibrium impact by including these features in a dynamic two-period model of forward-looking firms and consumers. Firms collect consumer data for personalization and price discrimination. Consumers trade off gains from personalization relative to potential losses from privacy breaches and price discrimination in their purchase, data opt-in, erasure, and transfer decisions. Though data security mandates impose fines on firms for privacy breaches, firms can benefit from higher opt-in given lower breach risk. Surprisingly, data security mandates can hurt consumers. The effect of privacy rights is nuanced. Since the right to opt in separates goods exchange from the provision of personal data, it prevents market failure under high breach risk. But it also reduces consumer opt-in and personal data availability. Erasure and portability rights reduce consumers’ hold-up concerns by disciplining firms to provide ongoing value by limiting price discrimination and not slacking off on data security; but they also reduce the incentive to offer lower initial prices that encourages opt-in. Overall, privacy rights always benefit consumers in competitive markets, but they can surprisingly hurt consumers under monopoly, as monopolists have less incentives to subsidize consumer opt-in. They raise (reduce) firm profit and social welfare when breach risk is high (low). Finally, privacy rights increase firm profit most at moderate levels of data transferability.

Suggested Citation

  • T. Tony Ke & K. Sudhir, 2023. "Privacy Rights and Data Security: GDPR and Personal Data Markets," Management Science, INFORMS, vol. 69(8), pages 4389-4412, August.
  • Handle: RePEc:inm:ormnsc:v:69:y:2023:i:8:p:4389-4412
    DOI: 10.1287/mnsc.2022.4614
    as

    Download full text from publisher

    File URL: http://dx.doi.org/10.1287/mnsc.2022.4614
    Download Restriction: no

    File URL: https://libkey.io/10.1287/mnsc.2022.4614?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    References listed on IDEAS

    as
    1. Rodrigo Montes & Wilfried Sand-Zantman & Tommaso Valletti, 2019. "The Value of Personal Information in Online Markets with Endogenous Privacy," Management Science, INFORMS, vol. 65(3), pages 1342-1362, March.
    2. Yongmin Chen, 1997. "Paying Customers to Switch," Journal of Economics & Management Strategy, Wiley Blackwell, vol. 6(4), pages 877-897, December.
    3. Lingxiao Huang & K. Sudhir & Nisheeth K. Vishnoi, 2020. "Coresets for Regressions with Panel Data," Papers 2011.00981, arXiv.org, revised Nov 2020.
    4. Avi Goldfarb & Catherine E. Tucker, 2011. "Privacy Regulation and Online Advertising," Management Science, INFORMS, vol. 57(1), pages 57-71, January.
    5. Posner, Richard A, 1981. "The Economics of Privacy," American Economic Review, American Economic Association, vol. 71(2), pages 405-409, May.
      • Posner, Richard A., 1980. "The Economics of Privacy," Working Papers 16, The University of Chicago Booth School of Business, George J. Stigler Center for the Study of the Economy and the State.
    6. Drew Fudenberg & Jean Tirole, 2000. "Customer Poaching and Brand Switching," RAND Journal of Economics, The RAND Corporation, vol. 31(4), pages 634-657, Winter.
    7. Guy Aridor & Yeon-Koo Che & Tobias Salz, 2020. "The Effect of Privacy Regulation on the Data Industry: Empirical Evidence from GDPR," NBER Working Papers 26900, National Bureau of Economic Research, Inc.
    8. Alessandro Acquisti & Hal R. Varian, 2005. "Conditioning Prices on Purchase History," Marketing Science, INFORMS, vol. 24(3), pages 367-381, May.
    9. S. Nageeb Ali & Greg Lewis & Shoshana Vasserman, 2019. "Voluntary Disclosure and Personalized Pricing," Papers 1912.04774, arXiv.org, revised Aug 2020.
    10. Miguel Godinho de Matos & Idris Adjerid, 2022. "Consumer Consent and Firm Targeting After GDPR: The Case of a Large Telecom Provider," Management Science, INFORMS, vol. 68(5), pages 3330-3378, May.
    11. Alessandro Acquisti & Curtis Taylor & Liad Wagman, 2016. "The Economics of Privacy," Journal of Economic Literature, American Economic Association, vol. 54(2), pages 442-492, June.
    12. Curtis R. Taylor, 2004. "Consumer Privacy and the Market for Customer Information," RAND Journal of Economics, The RAND Corporation, vol. 35(4), pages 631-650, Winter.
    13. Taylor, Curtis R, 2003. "Supplier Surfing: Competition and Consumer Behavior in Subscription Markets," RAND Journal of Economics, The RAND Corporation, vol. 34(2), pages 223-246, Summer.
    14. Oliver D. Hart & Jean Tirole, 1988. "Contract Renegotiation and Coasian Dynamics," The Review of Economic Studies, Review of Economic Studies Ltd, vol. 55(4), pages 509-540.
    15. Jiwoong Shin & K. Sudhir, 2010. "A Customer Management Dilemma: When Is It Profitable to Reward One's Own Customers?," Marketing Science, INFORMS, vol. 29(4), pages 671-689, 07-08.
    16. J. Miguel Villas-Boas, 2004. "Price Cycles in Markets with Customer Recognition," RAND Journal of Economics, The RAND Corporation, vol. 35(3), pages 486-501, Autumn.
    17. Lingxiao Huang & K. Sudhir & Nisheeth K. Vishnoi, 2021. "Coresets for Time Series Clustering," Papers 2110.15263, arXiv.org.
    18. James Campbell & Avi Goldfarb & Catherine Tucker, 2015. "Privacy Regulation and Market Structure," Journal of Economics & Management Strategy, Wiley Blackwell, vol. 24(1), pages 47-73, March.
    19. J. Miguel Villas-Boas, 1999. "Dynamic Competition with Customer Recognition," RAND Journal of Economics, The RAND Corporation, vol. 30(4), pages 604-631, Winter.
    20. Vincent Conitzer & Curtis R. Taylor & Liad Wagman, 2012. "Hide and Seek: Costly Consumer Privacy in a Market with Repeat Purchases," Marketing Science, INFORMS, vol. 31(2), pages 277-292, March.
    Full references (including those not matched with items on IDEAS)

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Flavio Pino, 2022. "The microeconomics of data – a survey," Economia e Politica Industriale: Journal of Industrial and Business Economics, Springer;Associazione Amici di Economia e Politica Industriale, vol. 49(3), pages 635-665, September.
    2. Vincent Conitzer & Curtis R. Taylor & Liad Wagman, 2012. "Hide and Seek: Costly Consumer Privacy in a Market with Repeat Purchases," Marketing Science, INFORMS, vol. 31(2), pages 277-292, March.
    3. Didier Laussel & Ngo Van Long & Joana Resende, 2023. "Profit Effects of Consumers’ Identity Management: A Dynamic Model," Management Science, INFORMS, vol. 69(6), pages 3602-3615, June.
    4. Rodrigo Montes & Wilfried Sand-Zantman & Tommaso Valletti, 2019. "The Value of Personal Information in Online Markets with Endogenous Privacy," Management Science, INFORMS, vol. 65(3), pages 1342-1362, March.
    5. Loertscher, Simon & Marx, Leslie M., 2020. "Digital monopolies: Privacy protection or price regulation?," International Journal of Industrial Organization, Elsevier, vol. 71(C).
    6. Lagerlöf, Johan N.M., 2023. "Surfing incognito: Welfare effects of anonymous shopping," International Journal of Industrial Organization, Elsevier, vol. 87(C).
    7. Chen, Yongmin & Hua, Xinyu & Maskus, Keith E., 2021. "International protection of consumer data," Journal of International Economics, Elsevier, vol. 132(C).
    8. Zhijun Chen & Chongwoo Choe & Noriaki Matsushima, 2020. "Competitive Personalized Pricing," Management Science, INFORMS, vol. 66(9), pages 4003-4023, September.
    9. Florian Morath & Johannes Münster, 2018. "Online Shopping and Platform Design with Ex Ante Registration Requirements," Management Science, INFORMS, vol. 64(1), pages 360-380, January.
    10. Bernard Caillaud & Romain De Nijs, 2014. "Strategic Loyalty Reward in Dynamic Price Discrimination," Marketing Science, INFORMS, vol. 33(5), pages 725-742, September.
    11. Morlok, Tina & Matt, Christian & Hess, Thomas, 2017. "Privatheitsforschung in den Wirtschaftswissenschaften: Entwicklung, Stand und Perspektiven," Working Papers 1/2017, University of Munich, Munich School of Management, Institute for Information Systems and New Media.
    12. Masuyama, Ryo, 2023. "Endogenous privacy and heterogeneous price sensitivity," MPRA Paper 117316, University Library of Munich, Germany.
    13. Li, Jianpei & Zhang, Wanzhu, 2022. "Behavior-based price discrimination and signaling of product quality," MPRA Paper 111572, University Library of Munich, Germany.
    14. Curtis Taylor & Liad Wagman, 2008. "Who Benefits From Online Privacy?," Working Papers 08-26, NET Institute.
    15. Mark Armstrong, 2005. "Recent Developments in the Economics of Price Discrimination," Industrial Organization 0511004, University Library of Munich, Germany.
    16. Johan N. M. Lagerlöf, 2018. "Surfing Incognito: Welfare Effects of Anonymous Shopping," Discussion Papers 18-13, University of Copenhagen. Department of Economics.
    17. Florian Hoffmann & Roman Inderst & Marco Ottaviani, 2020. "Persuasion Through Selective Disclosure: Implications for Marketing, Campaigning, and Privacy Regulation," Management Science, INFORMS, vol. 66(11), pages 4958-4979, November.
    18. Qiaowei Shen & J. Miguel Villas-Boas, 2018. "Behavior-Based Advertising," Management Science, INFORMS, vol. 64(5), pages 2047-2064, May.
    19. Shota Ichihashi, 2020. "Online Privacy and Information Disclosure by Consumers," American Economic Review, American Economic Association, vol. 110(2), pages 569-595, February.
    20. Arieh Gavious & Ella Segev, 2017. "Price Discrimination Based on Buyers’ Purchase History," Dynamic Games and Applications, Springer, vol. 7(2), pages 229-265, June.

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:inm:ormnsc:v:69:y:2023:i:8:p:4389-4412. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Chris Asher (email available below). General contact details of provider: https://edirc.repec.org/data/inforea.html .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.