Regulatory Compliance with Limited Enforceability: Evidence from Privacy Policies
Jacopo Gambato (University of Mannheim and ZEW Mannheim); Bernhard Ganglmair (University of Mannheim and ZEW Mannheim); Julia Krämer (Erasmus University Rotterdam)
Abstract
This paper examines the effect of the enforceability of regulatory rules on firms' compliance, specifically focusing on the implications of ambiguous and subjective requirements. Analyzing a sample of privacy policies from German firms between 2014 and 2021, we find that when regulatory practices are vague or based on unverifiable information, enforcement becomes challenging, resulting in limited compliance. Using text-as-data techniques to measure disclosure and readability, we find that firms responded to the GDPR's transparency requirements by significantly increasing information disclosure. However, the readability of their privacy policies did not improve and, in some cases, worsened. Larger firms and those in concentrated industries demonstrated higher compliance levels with the readability requirements, possibly due to heightened regulatory scrutiny. We emphasize the significance of regulatory capacity, as better-resourced regulators (state-level data protection authorities) with better enforcement capabilities foster improved compliance with ambiguous rules. This study sheds light on the intricate dynamics between enforceability, compliance, and the influence of ambiguity within regulatory frameworks