Does the GDPR Enhance Consumers' Control over Personal Data? An Analysis From a Behavioural Perspective

Iris van Ooijen (Corresponding Author), Helena Vrabec

Research output: Contribution to journalArticleAcademicpeer-review

2 Citations (Scopus)
75 Downloads (Pure)

Abstract

Because of increased technological complexities and multiple data-exploiting business practices, it is hard for consumers to gain control over their own personal data. Therefore, individual control over personal data has become an important subject in European privacy law. Compared to its predecessor, the General Data Protection Regulation (GDPR) addresses the need for more individual control over personal data more explicitly. With the introduction of several new principles that seem to empower individuals in gaining more control over their data, its changes relative to its predecessors are substantial. It appears however that, to increase individual control, data protection law relies on certain assumptions about human decision making. In this work, we challenge these assumptions and describe the actual mechanisms of human decision making in a personal data context. Further, we analyse the extent to which new provisions in the GDPR effectively enhance individual control through a behavioural lens. To guide our analysis, we identify three stages of data processing in the data economy: (1) the information receiving stage (2) the approval and primary use stage, and (3) the secondary use (reuse) stage. For each stage, we identify the pitfalls of human decision-making that typically emerge and form a threat to individual control. Further, we discuss how the GDPR addresses these threats by means of several legal provisions. Finally, keeping in mind the pitfalls in human decision-making, we assess how effective the new legal provisions are in enhancing individual control. We end by concluding that these legal instruments seem to have made a step towards more individual control, but some threats to individual control remain entrenched in the GDPR.
Original languageEnglish
Number of pages18
JournalJournal of consumer policy
Early online date11 Dec 2018
DOIs
Publication statusPublished - 11 Dec 2018

Fingerprint

Data protection
Personal data
Decision making
Threat
Business practices
Privacy
Reuse
Technological complexity

Keywords

  • UT-Hybrid-D
  • online privacy
  • individual control
  • behavioral economics
  • data collection
  • GDPR

Cite this

@article{ce30990bef20434f8be7b1c9097de0de,
title = "Does the GDPR Enhance Consumers' Control over Personal Data?: An Analysis From a Behavioural Perspective",
abstract = "Because of increased technological complexities and multiple data-exploiting business practices, it is hard for consumers to gain control over their own personal data. Therefore, individual control over personal data has become an important subject in European privacy law. Compared to its predecessor, the General Data Protection Regulation (GDPR) addresses the need for more individual control over personal data more explicitly. With the introduction of several new principles that seem to empower individuals in gaining more control over their data, its changes relative to its predecessors are substantial. It appears however that, to increase individual control, data protection law relies on certain assumptions about human decision making. In this work, we challenge these assumptions and describe the actual mechanisms of human decision making in a personal data context. Further, we analyse the extent to which new provisions in the GDPR effectively enhance individual control through a behavioural lens. To guide our analysis, we identify three stages of data processing in the data economy: (1) the information receiving stage (2) the approval and primary use stage, and (3) the secondary use (reuse) stage. For each stage, we identify the pitfalls of human decision-making that typically emerge and form a threat to individual control. Further, we discuss how the GDPR addresses these threats by means of several legal provisions. Finally, keeping in mind the pitfalls in human decision-making, we assess how effective the new legal provisions are in enhancing individual control. We end by concluding that these legal instruments seem to have made a step towards more individual control, but some threats to individual control remain entrenched in the GDPR.",
keywords = "UT-Hybrid-D, online privacy, individual control, behavioral economics, data collection, GDPR",
author = "{van Ooijen}, Iris and Helena Vrabec",
note = "Springer deal",
year = "2018",
month = "12",
day = "11",
doi = "10.1007/s10603-018-9399-7",
language = "English",
journal = "Journal of consumer policy",
issn = "0168-7034",
publisher = "Kluwer Academic Publishers",

}

Does the GDPR Enhance Consumers' Control over Personal Data? An Analysis From a Behavioural Perspective. / van Ooijen, Iris (Corresponding Author); Vrabec, Helena.

In: Journal of consumer policy, 11.12.2018.

Research output: Contribution to journalArticleAcademicpeer-review

TY - JOUR

T1 - Does the GDPR Enhance Consumers' Control over Personal Data?

T2 - An Analysis From a Behavioural Perspective

AU - van Ooijen, Iris

AU - Vrabec, Helena

N1 - Springer deal

PY - 2018/12/11

Y1 - 2018/12/11

N2 - Because of increased technological complexities and multiple data-exploiting business practices, it is hard for consumers to gain control over their own personal data. Therefore, individual control over personal data has become an important subject in European privacy law. Compared to its predecessor, the General Data Protection Regulation (GDPR) addresses the need for more individual control over personal data more explicitly. With the introduction of several new principles that seem to empower individuals in gaining more control over their data, its changes relative to its predecessors are substantial. It appears however that, to increase individual control, data protection law relies on certain assumptions about human decision making. In this work, we challenge these assumptions and describe the actual mechanisms of human decision making in a personal data context. Further, we analyse the extent to which new provisions in the GDPR effectively enhance individual control through a behavioural lens. To guide our analysis, we identify three stages of data processing in the data economy: (1) the information receiving stage (2) the approval and primary use stage, and (3) the secondary use (reuse) stage. For each stage, we identify the pitfalls of human decision-making that typically emerge and form a threat to individual control. Further, we discuss how the GDPR addresses these threats by means of several legal provisions. Finally, keeping in mind the pitfalls in human decision-making, we assess how effective the new legal provisions are in enhancing individual control. We end by concluding that these legal instruments seem to have made a step towards more individual control, but some threats to individual control remain entrenched in the GDPR.

AB - Because of increased technological complexities and multiple data-exploiting business practices, it is hard for consumers to gain control over their own personal data. Therefore, individual control over personal data has become an important subject in European privacy law. Compared to its predecessor, the General Data Protection Regulation (GDPR) addresses the need for more individual control over personal data more explicitly. With the introduction of several new principles that seem to empower individuals in gaining more control over their data, its changes relative to its predecessors are substantial. It appears however that, to increase individual control, data protection law relies on certain assumptions about human decision making. In this work, we challenge these assumptions and describe the actual mechanisms of human decision making in a personal data context. Further, we analyse the extent to which new provisions in the GDPR effectively enhance individual control through a behavioural lens. To guide our analysis, we identify three stages of data processing in the data economy: (1) the information receiving stage (2) the approval and primary use stage, and (3) the secondary use (reuse) stage. For each stage, we identify the pitfalls of human decision-making that typically emerge and form a threat to individual control. Further, we discuss how the GDPR addresses these threats by means of several legal provisions. Finally, keeping in mind the pitfalls in human decision-making, we assess how effective the new legal provisions are in enhancing individual control. We end by concluding that these legal instruments seem to have made a step towards more individual control, but some threats to individual control remain entrenched in the GDPR.

KW - UT-Hybrid-D

KW - online privacy

KW - individual control

KW - behavioral economics

KW - data collection

KW - GDPR

U2 - 10.1007/s10603-018-9399-7

DO - 10.1007/s10603-018-9399-7

M3 - Article

JO - Journal of consumer policy

JF - Journal of consumer policy

SN - 0168-7034

ER -