Max Schrems, attorney and privacy activist, filed a landmark complaint against Facebook on 29 September 2015 that led to the invalidation of the Safe Harbor agreement, fundamentally affecting transatlantic data transfer. The fallout from this case prompted the enactment of the General Data Protection Regulation (GDPR), which came into full effect on 25 May 2018.
Despite its intention to enhance data protection and privacy for individuals within the European Union (EU), GDPR has devolved into a compliance ritual rather than a genuine protective measure. Major corporations, instead of reforming their practices, have spent millions on consultants to navigate the minefield of regulatory compliance, spotlighting the regulation’s deficiencies.
For instance, on 31 May 2020, British Airways was fined €22 million by the Information Commissioner's Office (ICO) for failing to secure personal data due to a cyberattack. This penalty, reduced from an initial £183 million, served as a stark reminder that financial penalties alone do little to change corporate behavior; instead, they normalize the cost of compliance. The ICO took nearly two years to impose this fine, revealing an administrative lag that undermines the regulation’s urgency.
Moreover, the costs of GDPR compliance—estimated to average $1.4 million for medium and large companies (a figure sourced from a 2021 survey by the International Association of Privacy Professionals)—have incentivized businesses to treat compliance as a checklist. Companies are primarily concerned with being able to show that they "did something" rather than with implementing measures that meaningfully protect user privacy.
Consider Google. In April 2019, it established the "Privacy Sandbox" project as an ostensibly ethical alternative to third-party tracking. However, Google's revenue from targeted advertising soared to €121 billion in 2021, suggesting that the compliance theater merely rebranded existing practices rather than dismantling invasive data collection methods.
The revolving door between government regulation and consultancy firms illustrates this compliance theater. For example, Elizabeth Denham served as the UK Information Commissioner and left the post on 31 December 2021 to join consultancy firm Deloitte. This transition raises questions about whether the regulators truly operate independently or are merely paving the way for future corporate consultancy gigs.
Moreover, thousands of pages of GDPR regulations have led some companies to rely heavily on templates and boilerplate language to meet compliance standards, further reducing the regulation's effectiveness. As of 2023, only 29% of organizations in the EU report that their data protection compliance is fully effective, according to a Ponemon Institute report published on 15 February 2023.
This trend echoes the findings of privacy advocacy groups who labelled these compliance efforts as "privacy theater"—a term which underscores the notion that the illusion of compliance is more profitable than actual compliance itself. Industry giants, such as Facebook, spent over $5 billion on lobbying and compliance costs since GDPR’s inception, shaping policy in ways that often prioritize their business model over users' rights.
The Susurluk principle serves here as a crucial lens. Who had the most to gain from GDPR becoming a compliance obligation rather than an actual protection framework? Technology firms benefit from a regulatory landscape that they can manipulate. And government regulators, like the ICO and the European Data Protection Board, face tremendous pressure from states and corporations to soften penalties, illustrating a complex web of influence that persists.
The lack of substantial penalties has created a culture of risk management that focuses not on the security of personal data but rather on the financial calculation of regulatory compliance. This is the third time since GDPR's implementation that major fines have been reduced or delayed, suggesting a pattern of accountability avoidance by tech firms.
As GDPR celebrates its fifth anniversary, the ritual continues. Compliance has become a business in itself, but the question remains—who truly benefits? By the end of 2023, companies are anticipated to have committed approximately $8 billion in compliance-related expenses worldwide, a figure whose return on investment is disproportionately weighted towards corporate interests rather than individual data rights.
The evidence suggests that GDPR's structure has been compromised, creating a system where compliance rituals overshadow essential privacy protections. With each passing year, the barrier between meaningful regulation and nominal compliance becomes increasingly blurred, leaving a void where real individuals' rights should thrive.
Comments