SearcharxivSearch

arXiv subjects

Julia Schmitt

Publications and source records attributed to Julia Schmitt.

2 recordsLinked to original sources

The Impact of the General Data Protection Regulation (GDPR) on Online Usage Behavior

Privacy regulations aim to safeguard consumers, but can have unintended consequences on how users interact with websites. This article estimates the causal effect of the EU's General Data Protection Regulation (GDPR) on online usage behavior and decomposes it into usage frequency (unique visitors) and usage intensity (visits per unique visitor). Using a generalized synthetic control estimator across trillions of visits to 6,387 websites in 24 industries and 13 countries-11 months before and 19 months after enforcement-it compares observations subject to the GDPR (EU users or EU websites) with unaffected observations (non-EU users on non-EU websites). Weekly visits decline by 4.88% within 3 months and by 10.02%% after 18 months, with the decline increasingly driven by usage frequency: by 18 months, unique visitors decline by 6.61%, whereas visits per unique visitor decline by only 0.59%. The average conceals offsetting effects consistent with a reallocation of online activity: about one quarter of websites gain significantly, and among websites losing users, the remaining users engage more intensively, whereas intensity falls where user numbers grow. Losses concentrate among hedonic and smaller websites and continue to deepen during the first wave of data-protection enforcement actions rather than being concentrated around the GDPR compliance deadline. Taken together, these patterns are more consistent with restricted data-driven user acquisition and privacy salience, than with consent friction and degraded retention as persistent explanations. Long-horizon, decompositional evaluation thus reveals GDPR's differential effect on usage frequency/intensity and heterogeneous effects not distinguished by the aggregate traffic effects reported in prior work.

econ.GN

The Impact of Privacy Laws on Online User Behavior

Policymakers worldwide draft privacy laws that require trading-off between safeguarding consumer privacy and preventing economic loss to companies that use consumer data. However, little empirical knowledge exists as to how privacy laws affect companies' performance. Accordingly, this paper empirically quantifies the effects of the enforcement of the EU's General Data Protection Regulation (GDPR) on online user behavior over time, analyzing data from 6,286 websites spanning 24 industries during the 10 months before and 18 months after the GDPR's enforcement in 2018. A panel differences estimator, with a synthetic control group approach, isolates the short- and long-term effects of the GDPR on user behavior. The results show that, on average, the GDPR's effects on user quantity and usage intensity are negative; e.g., the numbers of total visits to a website decrease by 4.9% and 10% due to GDPR in respectively the short- and long-term. These effects could translate into average revenue losses of $7 million for e-commerce websites and almost $2.5 million for ad-based websites 18 months after GDPR. The GDPR's effects vary across websites, with some industries even benefiting from it; moreover, more-popular websites suffer less, suggesting that the GDPR increased market concentration.

econ.GN