GDPR: Is it worth it? Perceptions of workers who have experienced its implementation

Gerard Buckley,Tristan Caulfield,Ingolf Becker
2024-05-17
Abstract:The General Data Protection Regulation (GDPR) remains the gold standard in privacy and security regulation. We investigate how the cost and effort required to implement GDPR is viewed by workers who have also experienced the regulations' benefits as citizens: is it worth it? In a multi-stage study, we survey N = 273 & 102 individuals who remained working in the same companies before, during, and after the implementation of GDPR. The survey finds that participants recognise their rights when prompted but know little about their regulator. They have observed concrete changes to data practices in their workplaces and appreciate the trade-offs. They take comfort that their personal data is handled as carefully as their employers' client data. The very people who comply with and execute the GDPR consider it to be positive for their company, positive for privacy and not a pointless, bureaucratic regulation. This is rare as it contradicts the conventional negative narrative about regulation. Policymakers may wish to build upon this public support while it lasts and consider early feedback from a similar dual professional-consumer group as the GDPR evolves.
Computers and Society
What problem does this paper attempt to address?
This paper attempts to explore whether the costs and efforts involved in the implementation of the General Data Protection Regulation (GDPR) are worth it. Specifically, the researchers surveyed employees who worked at the same company and had work experience both before and after the implementation of GDPR to understand their perspectives as employees executing GDPR and as consumers benefiting from it. The main research question is: "GDPR: Is it worth it?" ### Research Background - **GDPR**: GDPR is the gold standard for data protection and privacy regulation in Europe, aimed at protecting personal data and ensuring that organizations handling this data act responsibly. - **Research Subjects**: The research subjects are employees who worked at the same company and had experience both before and after the implementation of GDPR. They are both executors and beneficiaries of GDPR. ### Research Objectives - **Costs and Benefits**: To assess employees' views on the costs and efforts required during the implementation of GDPR and whether they believe these costs and efforts are worth it. - **Consumer Perspective**: To understand employees' awareness and feelings about GDPR as consumers, particularly whether they believe their privacy is better protected. - **Corporate Perspective**: To explore the responses and changes within companies during the implementation of GDPR and employees' views on the changes resulting from GDPR. ### Research Methods - **Survey Design**: Through a multi-stage survey, researchers first conducted interest tests and potential sample size tests, followed by a final detailed survey. - **Sample Selection**: Participants were recruited through the Prolific platform, requiring them to have worked at the same company for at least 5 years and be familiar with GDPR. - **Data Collection**: Data was collected using the Qualtrics platform. The final survey included 102 participants, with a representative and high-quality sample. ### Key Findings - **Consumer Awareness**: Most respondents confirmed they were aware of GDPR, but the level of understanding of specific rights varied. - **Privacy Perception**: Respondents generally believed their privacy was better protected after the implementation of GDPR. - **Corporate Response**: Companies generally responded to GDPR by making necessary legal, technical, and organizational changes. - **Employee Cognition**: Despite the corporate response, some employees were not fully aware of the actual benefits of these changes. ### Conclusion - **Overall Evaluation**: Overall, respondents believed that GDPR is worth it. Despite some challenges and costs, it plays a positive role in protecting personal privacy and promoting data protection. - **Policy Recommendations**: The research results support policymakers in continuing to promote and optimize GDPR while considering early feedback to further enhance public support and compliance effectiveness. Through this research, the authors hope to provide valuable references for policymakers and regulatory agencies to better understand and address the challenges and opportunities in the practical application of GDPR.