Affiliation:
1. Norwich Business School University of East Anglia Norwich UK
2. School of Management University of Texas at Dallas Richardson Texas USA
Abstract
AbstractUsing the enforcement of the General Data Protection Regulation (GDPR) as our empirical setting, we examine how stricter data privacy and data protection requirements affect shareholder wealth, firms’ investment decisions, and data breaches. Consistent with consumer privacy negatively affecting firms, we find that U.S. firms exposed to the GDPR lose 0.7%–1.1% in market value relative to unexposed firms in the week in which the regulation became enforceable. We find that the decrease in market value is partially attributable to a decrease in sales growth. GDPR‐exposed firms increase their investment above that of control firms and become less likely to report a data breach post‐regulation. The decrease in data breach likelihood is statistically and economically significant, resulting in up to 34 million records not being leaked, which costs between $205 million and $561 million to firms in breach mitigation expenses per year. The results of this study should be of interest to academics and regulators worldwide by examining the costs and benefits of regulating data.
Reference65 articles.
1. The Costs of Wrongful-Discharge Laws
2. Binfarè M.(2019).The real effects of operational risk: Evidence from data breaches.https://doi.org/10.2139/ssrn.3411553