Abstract

AbstractUsing the enforcement of the General Data Protection Regulation (GDPR) as our empirical setting, we examine how stricter data privacy and data protection requirements affect shareholder wealth, firms’ investment decisions, and data breaches. Consistent with consumer privacy negatively affecting firms, we find that U.S. firms exposed to the GDPR lose 0.7%–1.1% in market value relative to unexposed firms in the week in which the regulation became enforceable. We find that the decrease in market value is partially attributable to a decrease in sales growth. GDPR‐exposed firms increase their investment above that of control firms and become less likely to report a data breach post‐regulation. The decrease in data breach likelihood is statistically and economically significant, resulting in up to 34 million records not being leaked, which costs between $205 million and $561 million to firms in breach mitigation expenses per year. The results of this study should be of interest to academics and regulators worldwide by examining the costs and benefits of regulating data.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call