News: 1708500554

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Europe's data protection laws cut data storage by making information-wrangling pricier

(2024/02/21)


Europe's General Data Protection Regulation (GDPR) has led European firms to store and process less data, recent economic research suggests, because the privacy rules are making data more costly to manage.

In [1]a paper titled "Data, Privacy Laws and Firm Production: Evidence from the GDPR," distributed this week via the National Bureau of Economic Research (NBER), monetary boffins explore the cost of privacy. They start by analyzing corporate cloud computing, citing previous research that suggests the cost of GDPR compliance ranges from $1.7 million for SMBs to $70 million for large organizations.

GDPR was enacted in 2016 and affects more than 20 million firms in dozens of countries. And since then, other countries have followed suit with their own privacy rules – all of which have economic implications.

[2]

The consequence of Europe's privacy regime, according to the researchers, is that "EU firms decreased data storage by 26 percent and data processing by 15 percent relative to comparable US firms, becoming less 'data-intensive.'"

[3]

[4]

Four economists – Mert Demire (MIT Sloan School of Management), Diego J Jiménez Hernández (Federal Reserve Bank of Chicago), Dean Li (MIT), and Sida Peng (Microsoft) – contributed to the report.

[5]Staff say Dell's return to office mandate is a stealth layoff, especially for women

[6]Europe's datacenter dilemma is that hyperscalers are hogging them all

[7]Days after half a billion Asians went to the polls, Big Tech promises to counter 2024 election misinformation

[8]Europe loosens the straps tying Apple and Microsoft to tough antitrust rules

To comply with GDPR, EU firms have had to adopt measures that are the equivalent of a 20 percent increase on average in the cost of data. For businesses in data-intensive industries, the cost increases were larger: 24 percent in the software sector, compared to 18 percent for manufacturing and services.

GDPR and associated compliance measures have also increased the cost to produce information – though not to the same degree as data storage or computation costs.

"We find that the GDPR resulted in a 4 percent increase in the cost of producing information, a significantly smaller impact than the increase in the cost of data," the paper asserts. "This is primarily because data is significantly cheaper than computation and therefore accounts for only a small share of the information cost."

[9]

The authors stop short of determining whether the privacy provided by GDPR is worth the cost. The paper, they explain, doesn't address the benefits consumers may derive from GDPR protections.

Past research suggests that the privacy afforded consumers under GDPR is [10]mostly beneficial , but [11]can be detrimental when a monopoly is involved . ®

Get our [12]Tech Resources



[1] https://www.nber.org/papers/w32146

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZdXX2i7vvyePyvsHIMXyEgAAAcA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZdXX2i7vvyePyvsHIMXyEgAAAcA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZdXX2i7vvyePyvsHIMXyEgAAAcA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2024/02/20/dell_rto_mandate/

[6] https://www.theregister.com/2024/02/20/europe_datacenter_space/

[7] https://www.theregister.com/2024/02/19/big_tech_election_misinformation_accord/

[8] https://www.theregister.com/2024/02/14/apple_microsoft_dma_exemptions/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZdXX2i7vvyePyvsHIMXyEgAAAcA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://som.yale.edu/blog/the-benefits-of-privacy

[11] https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3643979

[12] https://whitepapers.theregister.com/



Cloud Multipass proposal

Anonymous Coward

There is a huge redundancy in handling personal information. Every service provider asks for an ID, proof of address, bank details etc. For many people all those details are already stored in their email accounts or smartphone-related storage. What happens is the data is unnecessarily replicated to badly managed business storages of all kind. This also keeps alive lots of redundant IT support businesses.

Large cloud providers together with governments should form a consortium to unify such PII storage types, so the PII can be kept in one or few user-chosen *special provider* storages. Typically those would be Google, Apple, Amazon, Microsoft, but could be other providers certified for well managed security and to stimulate competition. Existing solutions such as Google Drive, S3 etc can be the basis for the service.

Non-provider businesses will not store PII, only basic identifiers, like business-related account number, email and phone number. Each business has to register to access PII super-storage with access logged and users notified on each access. Businesses will pay reasonable fees for each access, which will be a monetary motivator to limit excessive usage, but also will pay for service maintenance. Any business can upload necessary additional data to the storage, but cannot access it later without user authorization. Users will be able to authorize over the smartphone. Documents can have hashes and time stamp to avoid content manipulation.

Identify theft can be eliminated by immediate comparison of personal IDs across consortium providers. For example, instantly alerting if someone uses your passport photo to open an account in your name. Well, intelligence services might dislike the idea for impossibility to issue fake IDs.

Re: Cloud Multipass proposal

Dan 55

That's a very brave proposal, AC. First it concentrates everyone's PII into the Big Tech oligopoly and gives them all the data they need for their advertising business that nobody else has. Second none of the corporations you propose are based in the EU and so they are beholden only by Safe Harbour, Privacy Shield, Privacy Figleaf or whatever it's called this year.

If someone wanted to try and render GDPR worthless and make everyone in the EU more dependent on US cloud, that would probably be the way they would go about it, so this proposal should be stored in the round filing cabinet.

> it concentrates everyone's PII into the Big Tech oligopoly

Anonymous Coward

The data has already got concentrated by Big Tech. In the proposed system they will be obliged to access the data on same basis as everyone else, log, request permission, alert the user. The proposed services can be separate from Big Tech main business by law, with data localized per country. As for dependence on US cloud - when will EU cloud get sufficiently competitive, like Airbus? Besides any EU cloud provider can join the consortium. The consortium itself is about common standards, not to reinvent the wheel.

Re: Cloud Multipass proposal

Doctor Syntax

user-chosen *special provider* storages. Typically those would be Google, Apple, Amazon, Microsoft

I wouldn't trust any of them to be the digital me that this implies, no more than would I trust anyone else who offered themselves to play the same role.

Privacy?

Mike 137

" Past research suggests that the privacy afforded consumers under GDPR is mostly beneficial, but can be detrimental when a monopoly is involved. "

Judging by the abstract, the paper ('Privacy Rights and Data Security: GDPR and Personal Data Markets') considers privacy breaches as equating to data leaks. This is the most common (and excessively narrow) interpretation of privacy to be applied to the Regulation. But the Regulation clearly expresses that privacy means data subject control over the processing of their data, so its definition is much wider -- including, for example, the right to object to specific processing on the basis of ethical grounds. So in principle if I object ethically to some social media platform I have a right under the Regulation to complain against any business that passes my personal data to it without giving me a prior opt-out, or to object to a business profiling my activities without my consent. Unfortunately, businesses have in general ignored this, and regulators have tended to refuse to act when alerted to such breaches of broader data subject rights . Consequently the Regulation has effectively been neutered as a real protection almost from day one because nobody has taken seriously the fact that the GDPR is human rights law relating to data, not data law.

Re: Privacy?

Anonymous Coward

Good point.

In my experience implementing GDPR does have a cost for any company which wasn't taking privacy very seriously but once it's there it costs virtually nothing. Of course any company starting in recent years should have been designed with GDPR in mind from day one which means it should effectively be free. In fact if GDPR means storing less and then less processing on the data you haven't got then it might actually be cheaper in the long run...

Seatbelts and airbags also cost money but I wouldn't want to be without them now that I've got them.

Anonymous Coward

"Europe's General Data Protection Regulation (GDPR) has led European firms to store and process less data".

This is a good thing, companies should not be endlessly hoarding personal data. Same with the "pay or OK" dilemma. It's not a dilemma, the GDPR is working as intended to protect data subjects.

If a business cannot exist without the unlawful and unethical exploitation of data subjects then in the public interest is should close.

Shareholders should not be the number one consideration in evey matter regarding business. If they lose out for investing in an unlawful unethical business then they should lose their money.

AMBxx

The cost savings appear to assume that there was no benefit to holding the information. Doesn't sound likely.

The missing cost is having to monitor all of this to ensure compliance.

Doctor Syntax

Don't forget the cost of not complying. The more data is held the more there is to lose in the case of a leak.

We should be well past the stage where the cost to the leaker is a year or five years or whatever of "monitoring" by some business which is itself a data hoarder. If the leaked data enables bank fraud the leaker should pay the losses. If every data subject has to spend hours or days rearranging their affairs they should be paid a fairly generous sum for their time doing that. If someone loses their house or their livelihood as a result of the leak that should also be made good. At present these costs are likely to fall on the data subject. They should fall on the leaker, together with any legal costs the data subject incurs in claiming them. In principle companies should be looking at the prospect of being wiped out by a leak. In practice they'd probably insure but the insurers would undoubtedly take a close look at the risks they were insuring and charge accordingly.

TL;DR PII should be regarded as potentially toxic waste. The more you hold the more you have to spend onf containment.

Law of unintended consequences

Andy 73

So you make "doing business" 20% more expensive in an attempt to reduce competition from the big American companies... how's that working out?

Or alternatively, this is about privacy and encouraging users to have control and receive value for their data... again, how's that working out?

This has basically shifted revenue over to an entire class of compliance officers and consultants that spend most of their time trying to reduce functionality.

1.7 million for an SMB? Just wait until they add in compliance for AI regulations.

Re: Law of unintended consequences

Doctor Syntax

So you're saying the data subjects should bear the cost of the businesses careless losses of hoarded data?

oh okay. my mistake.

Yafcot:atj(*),

mark

* Yet another fool coming over this: according to joey
-- mark@mail.novare.net