[Paper Review] GDPR: Is it worth it? Perceptions of workers who have experienced its implementation
This study investigates the dual perspective of UK workers who both implement and benefit from the GDPR, finding they perceive it as worthwhile despite compliance costs. Surveying 273 and 102 employees before, during, and after implementation, the research reveals that workers recognize their rights, observe tangible data protection improvements at work, and view GDPR as beneficial for privacy and corporate accountability, challenging the common narrative of regulation as bureaucratic burden.
The General Data Protection Regulation (GDPR) remains the gold standard in privacy and security regulation. We investigate how the cost and effort required to implement GDPR is viewed by workers who have also experienced the regulations' benefits as citizens: is it worth it? In a multi-stage study, we survey N = 273 & 102 individuals who remained working in the same companies before, during, and after the implementation of GDPR. The survey finds that participants recognise their rights when prompted but know little about their regulator. They have observed concrete changes to data practices in their workplaces and appreciate the trade-offs. They take comfort that their personal data is handled as carefully as their employers' client data. The very people who comply with and execute the GDPR consider it to be positive for their company, positive for privacy and not a pointless, bureaucratic regulation. This is rare as it contradicts the conventional negative narrative about regulation. Policymakers may wish to build upon this public support while it lasts and consider early feedback from a similar dual professional-consumer group as the GDPR evolves.
Motivation & Objective
- To examine the perceived value of GDPR from the dual perspective of employees who implement it and citizens who benefit from it.
- To assess whether the perceived costs of GDPR compliance are outweighed by observed benefits in workplace data practices.
- To investigate public awareness of the GDPR regulator and its role among informed professionals.
- To explore how employee perceptions of GDPR influence trust in corporate data handling and regulatory legitimacy.
Proposed method
- Conducted a multi-stage survey with 273 and 102 employees from the same UK organizations before, during, and after GDPR implementation.
- Collected data on awareness of GDPR rights, knowledge of the regulator (ICO), observed changes in workplace data practices, and perceptions of regulatory impact.
- Used regression analysis to identify mental models underlying perceptions of GDPR’s value, focusing on awareness, observed changes, and regulator knowledge.
- Compared self-reported perceptions of positive and negative changes in data handling with attitudes toward regulatory legitimacy and compliance.
Experimental results
Research questions
- RQ1Do employees who implement GDPR also perceive it as beneficial for privacy and corporate responsibility?
- RQ2To what extent are employees aware of the identity and powers of their data protection regulator?
- RQ3How do observed changes in workplace data practices influence employees’ perceptions of GDPR’s net value?
- RQ4What role does personal awareness of data rights play in shaping perceptions of GDPR’s overall worth?
Key findings
- Participants recognized their GDPR rights when prompted but had limited knowledge of the identity and powers of their data protection regulator.
- Workers observed concrete, positive changes in data handling practices at their workplaces, including improved data security and transparency.
- Despite acknowledging compliance costs, employees viewed GDPR as beneficial for their company, citing stronger data protection and reduced risk of breaches.
- The perception that GDPR is 'worth it' was strongest among those who observed more positive than negative changes and felt confident in their understanding of their rights.
- Employees were less likely to view GDPR as a burden if they were not highly knowledgeable about the regulator’s role, suggesting a 'goldilocks' effect of moderate awareness.
- The study challenges the dominant narrative of GDPR as a bureaucratic burden, showing that those who implement it see it as a net positive for privacy and organizational integrity.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.