0% found this document useful (0 votes)
12 views44 pages

GDPR's Impact on Digital Marketing

The document discusses the history and theoretical scope of the GDPR and digital marketing. It analyzes the impact of GDPR on digital advertising and companies, including increased costs of compliance, disruption of business models, and reduced investment. The conclusion recommends that policymakers obtain a better understanding of compliance costs and their effects on businesses and the digital advertising industry.

Uploaded by

shantelwest48
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views44 pages

GDPR's Impact on Digital Marketing

The document discusses the history and theoretical scope of the GDPR and digital marketing. It analyzes the impact of GDPR on digital advertising and companies, including increased costs of compliance, disruption of business models, and reduced investment. The conclusion recommends that policymakers obtain a better understanding of compliance costs and their effects on businesses and the digital advertising industry.

Uploaded by

shantelwest48
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Contents

CHAPTER 1...................................................................................................................................................3
1.1 INTRODUCTION.........................................................................................................................3
1.2 Research Question and Scope...............................................................................................................4
1.3 Digital Marketing and History................................................................................................................5
1.4 Digital Marketing Pre GDPR era.............................................................................................................7
1.5 History of the GDPR...............................................................................................................................7
CHAPTER 2..................................................................................................................................................9
2.1 Theoretical Scope of the GDPR..............................................................................................................9
2.1.1 Material Scope....................................................................................................................................9
[Link] Personal Data................................................................................................................................10
[Link] Definition of Key Players (Controller, Processor and Data Subjects).............................................10
2.1.2 Territorial Scope...............................................................................................................................12
2.2 Theoretical Scope of Digital Marketing................................................................................................14
2.2.1 The New Business Model..................................................................................................................14
2.2.2 Targeted Marketing..........................................................................................................................15
2.2.3 Cookies.............................................................................................................................................17
2.2.4 The Importance of Targeting and Tracking Technologies in Digital Marketing and Advertising.......18
CHAPTER 3.................................................................................................................................................19
[Link] Of Companies Under GDPR................................................................................................19
3.2 Lawfulness, Fairness and Transparency...............................................................................................19
3.3 Purpose Limitation.........................................................................................................................20
3.4 Data Minimization...............................................................................................................................21
3.5 Accuracy..............................................................................................................................................21
3.6 Storage Limitation...............................................................................................................................21
3.7 Integrity and Confidentiality................................................................................................................22
3.8 Accountability......................................................................................................................................22
3.9 Privacy by Design and Privacy By Default...........................................................................................22
3.9.1 Privacy by Design..............................................................................................................................22
[Link] Data Protection Impact Assessment..............................................................................................23
[Link] Appointment of A Data Protection Officer....................................................................................23
3.9.2 Privacy by Default.............................................................................................................................24

Page 1 of 44
3.9.3 Breach Notification Requirement.....................................................................................................24
3.11 Consent Requirement........................................................................................................................25
3.12 The Rights of Data Subject.................................................................................................................26
CHAPTER 4.................................................................................................................................................28
THE IMPACT OF GDPR ON DIGITAL ADVERTISING AND COMPANIES.........................................................28
4.1 Cost of Compliance..............................................................................................................................28
4.1.2 Consequence of Non-Compliance.....................................................................................................32
4.2 Uneven Power Structure.....................................................................................................................32
4.2.1 The difficulty with Obtaining Consent..............................................................................................33
4.3 Reduced Investment............................................................................................................................34
4.4 Increased Risks to Business.................................................................................................................34
4.4.1 More Cyberattacks............................................................................................................................34
4.5 Disruption of Business Model..............................................................................................................35
CHAPTER 5.................................................................................................................................................38
5.1 Conclusion and Recommendations.....................................................................................................38
Recommendation......................................................................................................................................39
Bibliography............................................................................................................................................41

Page 2 of 44
CHAPTER 1

1.1 INTRODUCTION

Before the rise and popularity of the internet, businesses predominantly communicated with their
potential customers through one-way mass marketing initiatives. However, the internet made it
possible for businesses to communicate with prospective customers through a two-way structure,
enabling them to target their customers through the manipulation of personal data and the
tracking and monitoring of customers’ online behavior to tailor advertisement and marketing
more accurately and to budget more strategically.

This demand for customer data saw an increase in its value, so much so that Clive Humby have
come to describe data as being “the new oil” and like most things that are high in value, theft,
and misuse became commonplace and naturally customers and internet users become more
guarded about their personal data.

Before the popularity of the internet, people had more say in who they divulge their personal
data, but now people engage in many different online platforms, making it difficult for customers
to have a say in what happens to their data. These increased privacy concerns revealed that the
old rules regarding privacy were no longer sufficient, and this was the catalyst for European
supranational powers to spring into action. Out of this came the e-Privacy directive in 2009 and
the General Data Protection Regulation (GDPR) in 2016.

While these regulations benefit customers in ensuring security over their personal data, they
made it increasingly difficult for businesses to collect the information they need about potential
customers. To make matters worse the GDPR in particular is not only binding on EU member
states but also on any company processing the personal data of European residents regardless of
the company’s location, making the GDPR territorial scope very wide affecting more companies
than any other regulation.

Page 3 of 44
Moreover, policymakers are yet to obtain a comprehensive and precise understanding of the true
costs of complying with the regulation and to what extent these costs affect businesses and the
industry of internet advertising.

1.2 Research Question and Scope

The GDPR is a new regulation that has a global impact, in fact, its entry into force is one of the
biggest evolution of data privacy. It is usually lauded for the protection it offers to EU residents
but the fact that its entry into force can pose a real economic problem to companies and the
digital advertising industry is often ignored. This thesis will therefore be centered around the
negative impact of the GDPR on digital advertising and companies in general. To facilitate this
thesis, the researcher will examine the GDPR from a microeconomic view, examining how it
affects stakeholders particularly companies and digital advertising as it remains unclear what the
true cost of compliance is. The aim of this thesis, therefore, is to determine the overall impact of
the regulation on internet advertising, whether it is stifling it and ultimately stifling businesses or
whether it is merely a hurdle that most enterprises easily overcome. The thesis is, therefore, most
relevant to policymakers, corporate executives, entrepreneurs, and people in the marketing and
advertising field.

In an effort to successfully defend this thesis, there are a series of questions that the researcher
finds necessary to be answered, namely:
1) What is the history and purpose of the GDPR?
2) What is the scope of the GDPR?
3) What was the state of the digital advertising industry prior to the coming into effect of the
GDRR?
4) What is the impact of the GDPR on digital advertising and entities in general?

To address the research questions, the researcher will use the qualitative research method since
the research questions are mainly open-ended. A series of literature on GDPR and digital
advertising will be examined, and a comparison will be drawn between digital marketing pre and

Page 4 of 44
post the coming into effect of the GDPR and from this, an analysis will be conducted on the
effects of the GDPR on digital advertising and businesses.

This thesis is divided into four main chapters. The first chapter introduces the thesis and presents
a history of digital advertising and marketing pre-GDPR era, and the history of the GDPR itself.
The second chapter will provide a general overview of the theoretical framework of the GDPR
and internet advertising, the third chapter will examine the obligation of businesses under the
GDPR, the fourth chapter is entirely dedicated to the analysis of the impact of GDPR on the
internet advertising and companies, and the fifth and final chapter is dedicated will conclude the
findings and offer some useful recommendations regarding the amendment and tweaking of the
GDPR as well as how businesses and digital marketers can overcome or curtail some of the
negative impact of the GDPR including but not limited to the cost of compliance, while
maximizing on their abilities to reach potential customers.

1.3 Digital Marketing and History

The technological advancement that the world has witnessed over the past two decades plays a
significant role in how businesses are operating today. When the internet was introduced in the
1970s no one had imagined that it would be what it is now, especially since it was merely a
communication tool used by the government. It was not until 1989 that the interlinks were made
available to the public. Shortly thereafter companies slowly started to use the internet as some
form of an online brochure. From here businesses started to add their own websites and soon the
internet became the ‘little sister’ of traditional advertising channels such as newspapers,
billboards, and television1. The gravitation toward the internet as a new means of advertising was
heavily influenced by its interactive nature. Companies such as Electric Rain and Blast Radius
were some of the pioneers in internet advertising introducing new concepts such as banner
advertisements, online catalogs, directories, and virtual magazines2.

1
Todaro, M. (2007). Revealed, Internet Marketing Methods. Florida : Atlantic Publishing Group.
2
Todaro, M. (2007). Revealed, Internet Marketing Methods. Florida : Atlantic Publishing Group.

Page 5 of 44
Companies started to realize and see the impact of interactive advertising, and this initiated a
new method of adverting that placed the internet at the center of promotion and interaction,
however, the term digital advertising was not used until the 1990s and refers to the use of digital
channels to advertise products and services with the aim of reaching customers 3. Digital
advertising is also known as internet advertising and it involves the use of social media
marketing (SMM), search engine optimization (SEO), pay-per-click advertising (PPC), and
search engine marketing (SEM)4.

By the beginning of the 2000s big corporations started to incorporate digital marketing in their
promotional plan and portions of their marketing budgets were allocated to facilitate internet
marketing and advertising. As time elapsed and the technology evolved, the options started to
increase, and more formal techniques of internet marketing started to emerge such as Search
Engine Optimization (SEO). SEO is an activity that combines Web programming and statistical
calculation with the objective of defining the rules that make a website user-friendly for the
search engine and easy to rank 5. SEO became popular in the early 2000s when Google
introduced a new formula that combined keyword analysis, link popularity, contextual content,
and parametrical regulations6. The workings of SEO do not require personal data from the users
and as such SEO is not one of those internet advertising or marketing methods that are affected
by the GDPR. Other types of digital marketing methods such as email marketing and targeted
advertising on the other hand often involve and require the use of personal data from and as such,
these methods of digital marketing are most relevant to this thesis.

Online advertising describes the use of the internet for promoting goods, products, and services
through the internet. This form of advertising encapsulates banner adverting, video advertising
and social media network advertising, and search engine advertising. This type of advertisement
unlike print advertisement is very wide, far-reaching and interactive. Because of its far-reaching
nature, online advertising is often customized to reach its intended audience or customers who
are likely to be interested in the product or service that is being offered. In order for advertisers
3
Todaro, M. (2007). Revealed, Internet Marketing Methods. Florida: Atlantic Publishing Group.
4
Todaro, M. (2007). Revealed, Internet Marketing Methods. Florida: Atlantic Publishing Group.
5
Todaro, M. (2007). Revealed, Internet Marketing Methods. Florida: Atlantic Publishing Group.
6
Todaro, M. (2007). Revealed, Internet Marketing Methods. Florida: Atlantic Publishing Group.

Page 6 of 44
and marketers to properly customize these advertisements, they need to collect data from a pool
of people to then decipher who their target audience would be. It is this collection of data that is
affected by the GDPR.

1.4 Digital Marketing Pre GDPR era

Online advertisement is a branch of digital marketing that has witnessed tremendous growth
prior to the GDPR. In 2017, for the first-time advertiser spent more on digital advertising than on
television advertising accounting for 37.6% of total advertising expenditures. At the center of
this means of digital advertising is data. Data allowed these companies to gather insights into
their customers behavior and background which resulted in effective marketing. Nowadays
companies can track customers’ digital footprint using data to get a more accurate picture of a
customer’s preferences and habits; this is done through what is referred to as analytics. While the
use of analytics is not a new concept, digital media has provided new ways of collecting more
data from a wide range of internet users and this data is then used to create targeted advertising
in real-time.

Prior to the GDPR, such data was collected on a large scale often without the active consent of
users. Collecting valuable data by barely having to consult with users for their consent made it
easier for companies to gather a wide array of data that they need to create more targeted
advertisement. Essentially prior to the GDPR, there were few barriers for companies and
advertisers to gather personal data.

1.5 History of the GDPR

Companies had a smoother time collecting personal data from internet users prior to the GDPR
because most transactions on the internet require the user to give up some form of personal data.
The result of this is that a large amount of data is collected by service providers and spying
entities on daily basis. Once the user has disclosed their data on the internet, they had no say in
how it is used or for what. The GDPR was introduced to give individuals more control over their
personal data.

Page 7 of 44
The GDPR is a new European regulation that is intended to strengthen and unify data protection
for all individuals within the EU. The regulation came into effect on May 25, 2018, and replaced
the previous controlling European Data Protection Directive 95/46/EC. The significance of the
GDPR lies on the basis that it expands beyond the European Union and applies not just to
entities in the EU but also to entities outside of the EU that offers goods and services to EU
residents. 7

The principles behind the EU GDPR are not necessarily new and date back to World II, when the
leaders of post-war Europe, realized that the best way to guarantee ongoing peace and prosperity
is to encourage more international cooperation and reconstruction. The Organization for
Economic Co-operation (OECD) was borne out of this idea. Thirty-five years after OECD
introduced a set of international guidelines called the “Guidelines Governing the Protection of
Privacy and Transborder Data Flows of Personal Data,” which established a set of principles
that are now being reflected in the GDPR.

For several years the OECD became the global standard for data protection, however, the
guidelines were merely guidelines and were, therefore, non-binding in nature. The EU’s 1995
Data Protection Directive 95/46/EC(DPD) was introduced to improve upon the OECD
guidelines. The directive was binding on all Member States and all Member States were required
to adopt this privacy law into their local law. The DPD was in place for twenty years, but some
Member States went a step further than the requirement under the DPD, by legislating to protect
personally identifiable information (PII), making it difficult for EU residents to know how their
rights were protected across the EU. It also made it difficult for organizations to determine which
set of laws they should comply with, particularly when trading across the multiple Member
States. To remedy this problem, the European Commission came together in 2012 and proposed
a new regulation called The General Data Protection Regulation (GDPR). 8 The aim of this
regulation is to harmonize uneven data protection rules across the EU and promote free flows of

7
Kramer, J., & Hoar, S. (2017, October 26). Lewisbrisbois. Retrieved from [Link]:
[Link]
protection-law
8
Ernst-Oliver Wilhelm. (2016, February). A brief history of the General Data Protection Regulation. Retrieved from
[Link] [Link]

Page 8 of 44
personal data within the Single Market while strengthening the rights of individuals concerning
the usage of their personal data.9

CHAPTER 2

2.1 Theoretical Scope of the GDPR

In order to garner a better understanding of the interplay and ultimately the true impact of the
GDPR on digital advertising, it is only logical to discuss the theoretical scope of the regulation.

The GDPR is often described as the gold standard for privacy and the strictest piece of privacy
legislation in the world. It is very wide in its application, it applies across all Member States of
the EU, and any organization anywhere in the world that provides services in the EU that involve
processing personal data will have to comply with it. The GDPR applies both a material scope
and a territorial scope. At the center of the GDPR is the use of personal data and the geographic
regions that are governed by the Regulation.

2.1.1 Material Scope

Article 2 of the GDPR gives an overview of its material scope, highlighting that the regulation
only applies to all automated personal data processing and in some cases also manual processing
of personal data which forms part of a filing system or processing or that is intended to form part
of a filing system10.

It is important to note that the regulation does not apply to all processing of personal data and
Article 2 (2) provides some exceptions to the rule under Article 2 (1), however, such exceptions
are not relevant to the thesis and will not be discussed.

9
European Commission, (2012).
10
Art. 2 (1) GDPR

Page 9 of 44
[Link] Personal Data

At the center of the GDPR is the protection of personal data which means that the GDPR is only
concerned with those data that belongs to a person. Personal data is defined under Article 4, as
any information which is related to an identified or identifiable natural person 11. The use of the
words” any information” can be interpreted as a deliberate act on the part of the legislators to
bring as much information as possible that can be linked to the individual, under the scope of the
GDPR. Once can deduce that the widest interpretation should be applied when it comes to
deciding whether a set of information can be classified as personal information for the purposes
of the GDPR. In the case of Patrick Breyer v Germany12, for instance, the Claimant Patrick
Breyer brought an action against the German government for prohibitory injunction because the
German government owned and operated a publicly accessible website that stored the IP
addresses of visitors to their websites. One of the issues the court was faced with deciding was
whether dynamic IP addresses of website visitors constitute personal data for website operators.
The ECJ decided that it did. This means that other ‘online identifiers’ and tracking technologies
showing a user’s online browsing behavior such as cookies also falls within the definition of
personal data. The regulations under the GDPR will have some implications for businesses and
advertisers who rely on these technologies for retaining customers.

The true implication of the GDPR on digital advertising and business will be judged and
assessed based on the requirements it imposes on two key players; controllers and processors on
the handling of personal data.

[Link] Definition of Key Players (Controller, Processor and Data Subjects)


A discussion regarding the implication of the GDPR cannot be had without defining the key
players under the GDPR. The GDPR imposes obligations on what it refers to as controller and
processor for the protection of data subjects. A business that handles a user’s personal data will
either be a data controller or a data processor, with each role bearing specific responsibilities and
obligations.

11
GDPR Article 4
12
Patrick Breyer v Germany (Case 582/14)

Page 10 of 44
The bulk of the obligation under the GDPR rests with the data controller. Under Article 4 of the
GDPR, a controller is anyone, whether natural or legal person or a public body of agency which
either by themselves or together with another, determines the purposes and means of processing
personal data.13 In other words the controller decides what the data is for and what will happen to
it. From this definition, it is clear that a data controller can be person, a company, a legal entity
such as an incorporated partnership, or public authority but it is important to note that the GDPR
is not applicable to individuals processing personal data for household purposes.14

A processor on the other hand, according to Article 4 of the GDPR, is a natural or legal person,
public authority, agency, or other body which processes personal data on behalf of the
controller.15 Data processing is a anything that is done to or with personal data. An example of
data processing is collecting data, analyzing it and then using it for market research. All these
16
processes mentioned are considered to be a part of processing under the GDPR. It is important
to note that the processor and the controller must be separate persons as the controller can make
request from the processor.

The most valuable key player in the equation is the data subject; the GDPR exists to protect and
guard the personal data belonging to the data subject. Data subjects are the owners of personal
data, which means that they are identified or identifiable natural person (s) from whom or about
whom information is collected.

2.1.2 Territorial Scope

As stated previously, the GDPR is also applicable to persons and entities outside of the EU who
are involved in the processing of personal data that takes place outside of the EU, once the data
is data belonging to EU residents. Due to its international reach, one is not exempted from the
13
GDPR Article 4
14
Stephens, A. (2018, February). Data controller or data processor? Understanding your responsibilities and risks.
Retrieved from [Link]: [Link]
controller-data-processor-understanding-responsibilities-risks/
15
GDPR Article 4
16
Stephens, A. (2018, February). Data controller or data processor? Understanding your responsibilities and risks.
Retrieved from [Link]: [Link]
controller-data-processor-understanding-responsibilities-risks/

Page 11 of 44
obligations under the EU on the basis that they are outside of the EU and this is referred to the
territorial scope of the GDPR. Article 3 of the GDPR speaks to its territorial scope by stating
that: “This Regulation applies to the processing of personal data in the context of the activities
of an establishment of a controller or a processor in the Union, regardless of whether the
processing takes place in the Union or not.17”

The entities that will fall within the territorial scope of the GDPR are therefore entities that meet
one of the two requirements; (1) offering goods or services, to residents within the EU and (2)
monitoring EU residents’ behavior that takes place within the EU.

Unfortunately, Article 3, is not very specific when it comes to defining what it means by
“offering goods and services”. It therefore, begs the question as to whether any businesses with a
website would fall within the purview of the GDPR irrespective of location since websites are
globally accessible. In an attempt to answer this question, it is necessary to examine the recitals.
According to Thomas [Link], while recitals are not as binding as the operative provisions,
in cases where EU laws are ambiguous, one can look to recitals to assist in interpreting the
ambiguous provision. In this case, some clarification as to what is meant by “goods and services”
is offered under Recital 23, which essentially states that a website accessible to a global audience
is not an indication of an intention of “offering goods and services” to EU residents. 18 An entity
will not be subject to the rules of the GDPR merely on the basis of simply having a website that
is accessible globally.

Recital 24 of the GDPR also offers more incite as to what will constitute an intention to offer
goods and services to residents within the EU. It states that entities show their intention of
offering goods and services to EU residents if they provide the option to interact with their
website in the native language of an EU Member State or in Euros; and or advertise testimonials
from customers who are based in the EU with the goal of appealing to other users in the same
locality.19

The European Court of Justice (ECJ) also offers some interpretation on what is meant by the
word “intention”, in relation to offering goods and services to EU residents. It states that obvious
17
Article 3(1)
18
Recital 23, GDPR (2018)
19
Recital 24, GDPR (2018)

Page 12 of 44
evidence such as the payment of money to a search engine to facilitate access by EU residents
or where targeted Member States are designated by name or the mention of telephone
numbers with international codes or the use of domain names such as .de or .eu and mention of
an “international clientele composed of customers domiciled in various Member States, would
constitute intention to offer goods and services to EU residents.”20

Another possible way that entities may fall under the territorial scope of the GDPR is when a
business monitors the behaviors of EU residents within the EU. Again, no definition of what
constitutes monitoring is offered under the Article, and so once again for clarification, the Recital
is consulted. According to Recital 24 of the regulation, in order to determine whether the
processing activities can be considered as monitoring, it has to be determined whether natural
persons are being tracked on the internet, such tracking includes the subsequent use of personal
data processing techniques which consist of profiling natural persons, particularly in order to
make decisions concerning them or for analyzing or predicting their personal preferences,
behaviors and attitudes.21

As will be discussed later on in this thesis, a significant part of attracting customers today is
through monitoring the behavior of customers or what is sometimes referred to as behavioral
advertising or targeted advertising. Therefore Article 3, when interpreted, will capture companies
operating within the EU and outside of the EU once they partake in monitoring EU residence
activities online.

2.2 Theoretical Scope of Digital Marketing

2.2.1 The New Business Model

The progression of technology, particularly digital technology has created a new era where data
is king. The internet, mobile devices, social media, and cloud computing have truly intensified
the growth of data. It is safe to agree with scholars when they say that data gathering, and data
commercialization has transformed contemporary economies so much so that today’s economy

20
Kish, K. (2018, January 23). What does territorial scope mean under the GDPR? Retrieved from [Link]/:
[Link]
21
Recital 24 , GDPR (2018)

Page 13 of 44
can be classified as a data-driven economy.22 This view can be substantiated by a study by
Deighton Associates, commissioned by IAB, that revealed that the internet economy has grown
seven times faster than the U.S. economy over the past four years. The report also reveals that
the internet economy accounts for 12% of the U.S. GDP.23

Companies are quickly adapting to this new change as the technology improves and data
becomes more abundant, companies are adopting new business models that rely heavily on data,
which are referred to as data-driven business models (DDBMs).24

Data-driven business models depend heavily on big data which is commonly defined as “high-
volume, high-velocity and high-variety information assets that demand cost-effective, innovative
forms of information processing for enhanced insight and decision making”.25 Another author
gives a simpler definition describing big data as comprising the volume of information, the
velocity or speed at which it is created and collected, and the variety or scope of the data points
being covered.26

This new shift in business models according to is beneficial to both companies and customers by
providing a competitive advantage for companies by allowing them to provide more targeted
advertising and marketing and more efficient and improved quality of service for the customer. 27

22
Böhmecke-Schwafert, M., & Niebel, C. (2018). The General Data Protection’s (Gdpr) Impact On Data-Driven
Business Models:. ITU Journal: ICT Discoveries, Special Issue No. 2,, 1, 2.
23
Walters, L. (2021, October 18). Study Finds Internet Economy Grew Seven Times Faster Than Total U.S. Economy,
Created Over 7 Million Jobs in the Last Four Years. Retrieved from [Link]: [Link]
finds-internet-economy-grew-seven-times-faster/
24
Hartmann, M. P.; Zaki, M.; Feldmann, N.; Neely, A. (2016). Capturing value from big data – a taxonomy of data-
driven business models used by start-up firms. International Journal of Operations & Production Manage-ment. 36.
1382 - 1406.
25
Sicular, S. (2013, April 2). Gartner’s Big Data Definition Consists of Three Parts, Not to Be Confused with Three
“V”s. Retrieved from [Link]: [Link]
consists-of-three-parts-not-to-be-confused-with-three-vs/

26
Segal, T. (2022, March 28). Investopedia. Retrieved from [Link]
[Link]
27
Böhmecke-Schwafert, M., & Niebel, C. (2018). The General Data Protection’s (Gdpr) Impact On Data-Driven
Business Models:. ITU Journal: ICT Discoveries, Special Issue No. 2,, 1, 2

Page 14 of 44
2.2.2 Targeted Marketing

Research has shown that 90% of consumers gravitate toward targeted advertising. Targeting
advertising focuses on the customers’ age, gender and what they like, and what they are likely to
purchase.28

Most scholars agree that targeting advertising is a major source of revenue for companies
especially digital companies compared to general and blind advertising. Retailer John
Wannamaker is said to have lamented that “I know that half my marketing is wasted, I just don’t
know which half.”29 This longstanding issue is what makes targeting marketing so attractive for
companies.

This type of online marketing has been a game-changer for companies, and this is best illustrated
by an author who compares targeting marketing to a billboard on a highway. He stated that the
only thing the advertisers know about the viewer of the billboard is that they are drivers or riders.
The advertiser doesn’t have specific details about the viewer that suggest that the viewer is
interested in what is being sold30. Targeted advertising, on the other hand, relies on the user to
allow the advertiser to present his advertisement to him or her thereby creating the perfect
audience for their advertisement. Many scholars agree that marketing in today’s world works
best when it is personalized.

Targeting advertising or behavioral advertising in the digital sphere takes many forms, one of the
most prominent forms being “real-time bidding” (RTB) which is also known as “programmatic
advertising”. The rationale behind this name is that advertisers and publishers use algorithms to

buy and sell advertising.31 Using any form of targeted marketing allows companies to not only
tailor their advertisement to the demography interested in their product and avoid spending on

28
Froehlich, N. (2022, February 24). [Link]. Retrieved from [Link]:
[Link]
sh=7f58b4a7355e
29
Blattberg, R. C., Kim, B.-D., & Neslin, S. A. (2008). Why Database Marketing? New York: Springer Science +
Business Media, LLC.
30
Smith, M. (2015). Targeted. New York;: Haper Collins Publisher.
31
Kosorin, D. (2016). Introduction to Programmatic Advertising. Dominik Kosorin

Page 15 of 44
marketing and advertising unnecessary to demography that has no interest in the product or
service.

The abundance of data has made this method of advertising more popular, and this evidence is
seen in the 2021 IAB report that shows that 88% of advertisements are sold as programmatic
32
advertising. Of course, this raises privacy concerns since in most cases it involves the
exchange of data between firms. This type of transfer is achieved by way of auctioning
advertisements33.

The auctioning of advertisements is usually done through what is commonly referred to as Real-
Time Bidding (RTB), which is “the technological infrastructure used to sell opportunities to
display an ad in real-time (for example, less than 100 milliseconds) and in a fully automated
manner.34

How this works is that the company will advertise a service for “free”, which naturally will
attract a large group of people interested in the “free service”, these people will “sign up” using
personal information and data. This is what helps companies to collect more data about their
customers.

It is significant to point out that user tracking plays an important role in targeted advertising.
User tracking is the collection of data about users over time 35. Targeted marketing works by
collecting and analyzing the user’s online activities and using the result from his analysis to
determine the type of advertisement the purchaser is shown 36. For instance, a user who searches
for baby clothes will be shown the most recent summer collection of baby clothes.

32
2021, I. A. (2022, April 12). Retrieved from [Link] [Link]
advertising-revenue-report-full-year-2021/
33
Skiera, B., Miller, K., Jin, Y., Kraft, L., & Laub, R. (2022). The Impact of the GDPR on The Online
Advertising Market advertising Market . Frankfurt, Germany,: Amazon ebook.
34
Skiera, B., Miller, K., Jin, Y., Kraft, L., & Laub, R. (2022). The Impact of the GDPR on The Online
Advertising Market Advertising Market . Frankfurt, Germany,: Amazon ebook.
35
Skiera, B., Miller, K., Jin, Y., Kraft, L., & Laub, R. (2022). The Impact of the GDPR on The Online Advertising Market
Advertising Market . Frankfurt, Germany,: Amazon ebook
36
Skiera, B., Miller, K., Jin, Y., Kraft, L., & Laub, R. (2022). The Impact of the GDPR on The Online
Advertising Market Advertising Market . Frankfurt, Germany,: Amazon ebook

Page 16 of 44
2.2.3 Cookies
One-way companies accomplish tracking users online is by collecting cookies. Cookies is one of
the most popular tracking technologies. A cookie is a small piece of data that is sent to a user’s
browser and stored on his computer from a publisher’s or advertiser’s website 37. An access
request is sent to a publisher’s site server whenever a user visits a website for the first time. The
publisher’s server then generates an Id number and then the browser stores the cookies locally on
the user device and loads the page. In the future when the user visits that same website, the user
will be identified by the ID of the cookies stored in the browser. Cookies are a critical part of
38
most websites, particularly session cookies There are different types of cookies, some more
invasive than others, but cookies generally help the website to recognize a particular user each
time that user visits a website. What this means is that if a user for instance selects English as her
preferred language on a website and clicks off and then revisits it later, the language setting will
remain in English.

Cookies can be classified into three main types: namely, first-party cookies, second-
party cookies, and third-party cookies. First-party cookies are those that are installed on the
website that the user is visiting, whereas second-party cookies are those set by another website
that belongs to the same owner of the website that the user is visiting, and third-party cookies, on
the other hand, is also referred to as tracking cookies. These cookies collect data based on the
users’ online behavior, by collecting various types of data that are then passed on or sold to
advertisers by the website that created the cookie. Third-party cookies track the user’s interests
based on search trends and send the information so that marketers can provide the user
with custom advertisements. These are the advertisements that appear on websites users visit
and display content relevant to your interests.39

37
Skiera, B., Miller, K., Jin, Y., Kraft, L., & Laub, R. (2022). The Impact of the GDPR on The Online
Advertising Market Advertising Market . Frankfurt, Germany,: Amazon ebook
38
McGrady, P. D. (2019). McGrady on Social Media. LexisNexis.
39
Dutko, J. (2018, April August). [Link] Retrieved from [Link]
[Link]
%20are%20three%20types%20of,any%20data%20that%20companies%20request.

Page 17 of 44
2.2.4 The Importance of Targeting and Tracking Technologies in Digital Marketing and
Advertising

The use of targeting and tracking technologies have been a game-changer for sales and
marketing and digital advertising and their significance cannot be emphasized enough.
Targeting users serve as a tremendous benefit to the advertisers as it prevents the advertiser from
spending money unnecessarily on users who are unlikely to purchase the product that is being
advertised. Advertisers and marketers will be more willing to pay for an advertisement with a
measurable outcome. The chances of converting users or the audience of the advertisement is
also higher when using targeted advertising. The success of targeted advertisement can also
easily be measured through what is referred to as the “click-through rate”. The click-through rate
is the number of clicks divided by the number of impressions of the advertisement.40

Being able to measure the success rate of an advertisement helps advertisers to compare the
success rates of different advertisements and (Froehlich, 2022), cited the perfect example, by
assuming that if an advertiser decides to run two separate advertisements, through targeted
advertising and tracking technologies she would be able to determine which advertisement was
more effective by simply comparing the number of clicks each advertisement received. The
advertiser would also be able to, from tracking technologies such as third-party cookies even see
the demography of persons who are interested and not interested in the advertisement.

CHAPTER 3
[Link] Of Companies Under GDPR

The manner in which the processing of data should be handled is established under Article 5 of
the GDPR and failure to comply with these requirements is punishable by fines of up to EUR
20,000,0000.00 or 4% of the total annual turnover of the entity handling the processing, making

40
Skiera, B., Miller, K., Jin, Y., Kraft, L., & Laub, R. (2022). The Impact of the GDPR on The Online Advertising Market
Advertising Market . Frankfurt, Germany,: Amazon ebook

Page 18 of 44
it essential for entitles dealing with the processing of personal data to understand and comply
with the requirements of this Article.41

3.2 Lawfulness, Fairness and Transparency

Firstly, under Article 5 (1) (a), all personal data must be processed “lawfully, fairly and in a
transparent manner in relation to the data subject”. 42 This means that the collection of personal
data must either be legally permitted or was consented to the data subject. Article 6 further
elaborates on what constitutes lawful processing. It essentially states that lawful processing
occurs where the data subject has given his or her consent or the processing is conducted as a
part performance of a contract, or it was within the interest of the public to process the data or it
was conducted to provide first aid.43

The data subject should also know that her personal data is being collected, used consulted, or
otherwise processed.44 Recital 39 further goes on to state the criteria to be fulfilled in order to
meet the transparency requirement which is summarized as follows:

a. the identity of the controller must be known by the user


b. the purpose of the processing must be known by the user
c. the data subject must be informed in respect of their right to obtain confirmation
and communication of processing activities.
d. informing data subjects as to their right to obtain conformant

41
Voigt, P., & Bussche, A. v. (2017). The EU General Data Protection Regulation (GDPR)
A Practical Guide. Berlin Germany: Springer International Publishing AG.
42
Article 5 (1) (a) GDPR
43
Article 6 GDPR
44
Rec. 39. GDPR

Page 19 of 44
Personal data should also only be collected for specific and legitimate reasons for a specific
time45, it should be kept up to date, and the controllers and processors should apply data
46
minimization techniques to limit the extent of the processing activities. The said Article 5 of
the GDPR places a burden on the controller or processor to take measures to prevent destruction,
loss, or damage to the personal data of data subjects47 and to demonstrate compliance with the
authorities.48 Article 6 and recital 45 and 50 offers further explanation on the meaning of
lawfulness of the process

3.3 Purpose Limitation

This obligation is defined under Article 5 (1)(b) of the GDPR and is merely an extension of the
previously discussed obligations of lawfulness, fairness, and transparency. The purpose
limitation is the second principle that is closely related to the principle of lawfulness, fairness
and transparency. The principle of purpose limitation suggests that where personal data is
collected, it should only be collected for a specified, explicit, and legitimate purpose and it
should not be used and processed in any manner that is incompatible with that purpose.49

3.4 Data Minimization

Data minimization is the third principle established under Article 5 (1)(c ) of the GDPR. It
provides that only adequate relevant adequate, relevant and limited’ personal data that is
‘necessary’ for processing50. Unfortunately, there is no explanation as to what constitutes
“adequate, relevant and limited, yet there is an obligation on entities processing personal data to
do an assessment to determine what is ‘necessary’ for the purposes for processing. The aim of

45
GDPR Article 5(1) (b)
46
GDPR Article 5(1) (c)
47
GDPR Article 5(1) (f)
48
GDPR Article 5(2)
49
Voigt, P., & Bussche, A. v. (2017). The EU General Data Protection Regulation (GDPR)
A Practical Guide. Berlin Germany: Springer International Publishing AG.
50
Article 5 (1) (C) GDPR (2018)

Page 20 of 44
this obligation is to prohibit the controller and or processor from having more personal data than
is needed to achieve the purpose of processing.

3.5 Accuracy

The GDPR also impose an obligation on controllers and processors under Article 5 of the GDPR,

demanding that the data be ‘accurate’, ‘kept up to date’ and ‘erased or rectified’ in the event that

it is inaccurate. Once again, no definition is given for what the GDPR meant by inaccurate and so

the literal meaning of accurate is typically applied in its interpretation of the word. In this context,
data is inaccurate when it is incorrect or misleading.

3.6 Storage Limitation

A limitation on the storage of personal data is another obligation that the GDPR places on
controllers and processors. This rule suggests that processors and controllers should have clear
rules regarding when they acquire the personal data, how long they will store it for and when it
will be erased.

3.7 Integrity and Confidentiality

The integrity and confidentiality obligation are also referred to as the security obligation.
Essentially it requires data processors and controllers to ensure that they implement the
appropriate security measures to avoid data from being compromised. This obligation goes hand
in hand with cyber security.51

51
Article 5 (1) GDPR

Page 21 of 44
3.8 Accountability
The requirement that processors and controllers should take accountability means that they should
be responsible for the processing activities and the method in which they chose to comply with
data protection principles. 52

3.9 Privacy by Design and Privacy By Default

Another requirement that the GDPR imposes on controllers and processors of personal data is the
complex concepts of “privacy by design” and “privacy by default.

3.9.1 Privacy by Design

Privacy by design is a concept that companies should emphasize privacy concerns from the
outset of data processing practices as opposed to applying these features retroactively.53 In other
words, steps should be taken by companies and entities dealing with personal data, to prevent
and mitigate potential risks before they occur. They should ensure they improve poor privacy
practices and security early before any harm is done.

[Link] Data Protection Impact Assessment

The natural question that flows from such requirement is how do entities manage to constantly
detect poor privacy practices in their operations? The answer to this question is Data Protection
Impact Assessments (DPIAs). DPIAs are said to be the heart of privacy by design. 54 The
regulation places the burden on organizations to complete DPIAs whenever it introduces or
creates a new system, service product or process that involves the use of personal data. The
entities are also required to incorporate technologies, processes, and policies to mitigate the risks
that are discovered in the DPIA.55 They are also required to write privacy notices, data protection
policies as well as provide the customers (data subjects) with the contact detail for their Data

52
Article 5 (2) GDPR
53
Irwin, L. (2021, November 23). [Link]/blog. Retrieved from [Link]
[Link]

54
[Link]
55
[Link]

Page 22 of 44
Protection Officer (DPO). Needless to say, the GDPR also requires some private and most of the
public entities to appoint a DPO.

[Link] Appointment of A Data Protection Officer

Article 37 of the GDPR calls for the appointment of a DPO in certain organizations and entities.
The appointment of a DPO is mandatory in the following circumstances:

(1) The processor is a public authority, or body, except for courts acting in their judicial
capacity

(2) the controller and processor performs processing which requires regular and systematic
monitoring of data subjects on a broad extent;

(3) the controller and processor processes on a large scale of special categories of data under
Article 9 and personal data relating to criminal convictions and offences referred to in
Article 10.56

The role of the DPO is to monitor the companies’ data processing operations.

3.9.2 Privacy by Default

Privacy by default on the other hand, mandates that entities only perform processing activities if
they are necessary to achieve a specific and documented goal 57. Privacy by default is a concept
closely related to the concept of data minimization which was discussed earlier. The purpose of
privacy by default concept is to prohibit data processors and controllers from acquiring more
personal data than they need. Such concept of course is somewhat incompatible with targeted
advertising since most entities in their interaction with their customers or would-be customers try
to get as much information as possible, which is not always necessary to achieve a particular
goal.

56
Article 37 GDPR
57
[Link]

Page 23 of 44
3.9.3 Breach Notification Requirement

Under Article 33 of the GDPR, there’s a further obligation on entities processing personal data
to report a breach of personal data to what it refers to as a supervisory authority within 72 hours
of becoming aware of the breach58. The only exception to such obligation is if the breach has not
caused any damage to the data subjects. The repercussions of failing to comply is the possibility
of having to pay hefty fines if the Data Protection Authority finds that the entity did not take
sufficient steps towards the protection of data. These fines of course have the potential of
bankrupting a company which is one of the harsh realities of the GDPR.

Moreover, the breach requirement obligation forces entities to share that there has been an attack
on their privacy data within their business which of course exposes the business to public
judgement and possibly the loss of customers’ confidence

The Regulation implies that the companies have to include the categories of data and records
compromised and an approximation of the number of data subjects who would have been
affected by the breach..59 While it can be argued that data breach notification is not a new
concept unique to the GDPR since the USA and Australia privacy laws have similar obligations,
the difference between those privacy notification and that of the GDPR is the exorbitant fines for
non-compliance and the small 72 hour window of reporting a breach, which is insufficient for a
company to assess and estimate the consequences of the breach on data subjects.

3.11 Consent Requirement

One of the biggest hurdles to data processing under the GDPR is obtaining the consent of the
data subject. Article 9 of the GDPR mandates that data controllers who are processing special
categories of personal data first obtain the explicit consent of the data subject. 60 and Article 4
provides a definition of what constitutes consent in the context of the GDPR.

According to Article 4, consent must be free, specific, informed and unambiguous indication of a
data subject’s wishes by means of statement or clear affirmative action that she agrees to the
58
Article 33 GDPR
59
O’Brien, R. (2016, June 8). Privacy and security: The new European data protection regulation and it’s data breach
notification requirements. Business Information Review , pp. 81-84.

60
Article 9 GDPR

Page 24 of 44
processing of personal data that is related to her.61 The threshold based on the definition is quite
high. In order to prove valid consent, data processors and controllers would have to show the
following:

1. The consent was freely given: meaning that when the data subject
gives her consent there should have been no pressure or threat.
Instead, what should exist between controller and the data subject
is a balance which ceased to exist if the controller offers the data
subject a service that is contingent upon the data subject giving her
consent

2. The consent must be specific: Meaning that the information


relating to consent must be written in a way that the average
person can is aware of what they are consenting to. The data
subject has to show some deliberate consent such as by ticking a
website box or choosing am app setting. Consent in the context of
the GDPR is not valid if it’s by silence or omission of an
information.

3. The data subject should be informed: This requirement calls for the
data subject to be aware of who the data controller is and what the
reason behind the processing of her personal data by the data
controller.

4. The consent must be unambiguous- The ambiguous aspect of the


consent means that the consent must be clearly expressed either
through a statement or through some definitive action. Inactivity,
silence, or pe-ticked box does not constitute consent.

61
Article 5 GDPR

Page 25 of 44
From the definition and explanation, it is clear that the consent requirement is not one that is easy
for companies and advertisers to obtain. Unlike under previous privacy laws, the consent under
the GDPR has to be active co This makes it incredibly difficult as today’s digital advertising
relies heavily on personal data.

3.12 The Rights of Data Subject

In addition to the obligations that the GDPR imposes on processors and controller, it offers data
subjects some several rights which must be observed and honored by controllers and processors.
The GDPR dedicated an entire chapter to the protection of the data subjects. The preceding
Articles, Articles 13 and 14 highlights the obligations of transparency by those who are entrusted
with the data subjects’ data so that it is clear the nature of the data being stored and processed
and by whom.62

The rights granted to data subjects under the GDPR includes the right to access, the right of
rectification and erasure, the right to restriction of processing, the right to data portability, the
right to object63.

3.12.1The Right to Access, Rectification and Erasure


The right to Access provides the data subject with the privilege of being able to access their own
personal data upon request to the data controller or processor. The processors and controllers
should provide the data subjects upon request by the data subject for access, the following: the
purpose of processing, categories of personal data, recipients of the data and a copy of the
collected personal data.

In cases where the data subject becomes aware that his or her personal data in the possession of a
controller and or processor is inaccurate, the data subject has the right to request a rectification of
his or her personal data. Should the incorrect data be transferred to a third party the processor or
controller is obligated to inform the third party of the incorrect data, unless it would be
impractical to do so.

62
Schwabe, C. (n.d.). Data subjects' rights in the General Data Protection Regulation. Retrieved from [Link]-
[Link]: [Link]
63

Page 26 of 44
The data subject is also free to object to the processing of his or her personal data. If the data
subject does objects, the processor and controller have to cease processing unless they are able to
prove that they have legitimate grounds that override the interests, rights and freedoms of the
data subject.

The Right to Be Forgotten or The Right to Erasure

The right to be forgotten is one of the most common and talked about rights that the data subject
has. It imposes an obligation on processors and controllers to erase personal data within a month
if the data subject withdraws consent or objects to processing, if the data is unlawfully being
processed and if the personal data is no longer necessary for the initial purpose for which it was
acquired.

Once one of these events has occurred, the controller and processor must erase the personal data
and request any third party that the data was shared with to delete it as well.

The Right to Data Portability

Data subjects also enjoy the right to data portability, meaning that the data subject may obtain
from processors and controllers their personal data in a structured way and machine-readable
format, and reuse that said data across different services and platforms as the data subject is free
to then transmit their data to another controller of their choice.

CHAPTER 4

THE IMPACT OF GDPR ON DIGITAL ADVERTISING AND COMPANIES

The main goal of the GDPR has always been to protect the privacy of EU residents and there is
no doubt that the GDPR is helping to achieve this. The strict nature of the GDPR however has
imposed a heavy burden on companies and advertisers whose business models are built on access
to personal data. This burden of course has a negative effect on companies and advertisers. This
chapter will therefore explore the negative impacts of the GDPR on companies and digital

Page 27 of 44
advertising. It will examine four main impacts; the cost of compliance, the uneven power
structure that the restriction of the GDPR causes, the effects on company investment, how it
exposes businesses to increased risks and how it is disrupting the current business model.

4.1 Cost of Compliance

Having examined the various obligations that, the GDPR imposes on processors and controllers,
it is only logical to examine the costs of implementing these practices within businesses.
Historically compliance has always been a big part of companies’ budget and the introduction of
the GDPR has resulted in a greater increase of this costs.

Compliance with the GDPR from any point of view is costly whether it is adopting policies to
become GDPR compliant or failing to do so which can result in fines of up to $25 million or 4%
of the annual revenue, whichever is more. 64 The fear of high compliance costs was echoed back
in 2013 by the United Kingdom Ministry of Justice approximately five years prior to the coming
into effect of the GDPR. He feared that the compliance cost for the new privacy law that the EU
was proposing at the time would cost businesses between £80 million and £320 million per year.
The Ministry’s fear was not unfounded, and this chapter will prove just that.65

Some scholars such as Smith, O. (2018, May 2). are so outraged by the compliance cost
associated with the GDPR, so much so that one described it as a “the multi-year, multibillion-
dollar, herculean racket”66. Considering the cost to appoint Data Protection Officer, the cost to
carry out DPIA report as well as the cost to notify breaches and adopting new software for data
management, it is tempting to agree with Smith. Evidence of the high costs of GDPR compliance
can be observed everywhere. There is a 2019 survey that revealed that 70% of companies
reported to have an increase in GDPR compliance staff.67

64
Art. 83(5) GDPR
65
London Economics. (2013). Implications of the European Commission’s proposal for a general data protection
regulation for business. London: London Economics.
66
Smith, O. (2018, May 2). Retrieved from [Link]:
[Link]
business-shakedown/?sh=5e78667f34a2
67
Prasad, A., & R.Pérez, D. (2020, September 14). The Effects of GDPR on the Digital Economy:. Retrieved from
[Link]

Page 28 of 44
In addition to this, the DPIA for instance is estimated to cost Small and Medium-sized
Enterprises (SMEs) an estimated €14,000 and an estimated to €149,000.00 for Multinational
Corporation. (MNCs1) according to the European Commission. 68 Likewise, the requirement to
report a data breach within 72 hours of becoming aware of it is also costly for companies. This
provision calls for technology that comes at a cost because of the time in which they have to
notify the supervisory advisory of the breach. 69 It is for this reasons why digital middlemen who
depended on data collection had to exit the EU with their businesses because the cost to fulfil the
obligations under the GDPR was too high.

The DPO appointment is not an inexpensive endeavor either. As stated previously, Article 37 of
the GDPR calls for the appointment of a DPO where companies process personal data on a large
scale and or companies engaged in regular and systematic monitoring. The DPO must have
expert knowledge about data protection which means that companies either have to hire
additional staff, train an existing employee or retain the service of a DPO who is not a part of the
company. In any event this is an extra cost that did not exists before the GDPR.

A study conducted in 2016 by The International Association of Privacy Professionals (IAPP) by


using Euro stat data, found that there would be a need for approximately 28,000 DPOs after the
adoption of the GDPR.70

Other observations such as a report conducted by Price water House Coopers revealed that when
it comes to the cost of GDPR compliance 88% of companies spent more than USD 1 million and
40% spend more than USD 10million71

Adding to the burden of high compliance cost is the fact that the GDPR appears to
disproportionately affect small and medium sized enterprises (SMEs) as they are the ones who
68
European Commission, 2012.
69
CIRIANI, S. (2015, March 31). The Economic Impact of the European. Retrieved from ttps://[Link]:
[Link]
70
Heimes, R., & Pfeifle, S. (2016, April 19). [Link]. Retrieved from [Link]: [Link]
least-28000-dpos-needed-to-meet-gdpr-requirements/
71
Luke, I. (2022, April 26). How much does GDPR compliance cost in 2022? Retrieved from [Link]:
[Link]

Page 29 of 44
lack the resources to implement technologies and adopt new practices to be compliant with the
new regulation. This view is supported by observations that smaller businesses were particularly
affected by the costs of compliance associated with the GDPR 72 Due to their limited resources
when compared to large enterprises, SME’s naturally have simple informal rules and procedures
and overall simple control systems which are incompatible with the GDPR as the demands fill
control over every process that includes personal data. 73 If these small and medium sized
enterprises fail to be compliant with the regulation, the chances of being reported to the
supervisory authority is very high since anyone can lodge a complaint, in fact, approximately
60,000 complaints were filed during the first 8 months of coming into effect of the GDPR and
these complaints resulted in fines of around USD 57 million.74

The result of the high compliance costs and high fine is that smaller businesses are disappearing
which then creates a greater advantage for bigger companies by reducing the competition.

While it is difficult to quantify the true cost of compliance, around 1,129 newspaper websites
outside of the EU has cut access to EU residents because they see the obligations under the
GDPR as too costly to bear.75Cecil Whig for instance, a local paper in Cecil County Maryland
United States of America is no longer available online in the EU because of compliance costs
associated with the GDPR; the same is true for the Chicago Tribune.76 Uber Entertainment is
another interesting example. They make online games, but they announced that they would shut
down their Super Monday Night Combat game because of the cost to comply with the GDPR.
According to the company, the costs to rewrite the game or to migrate the data into a different
platform would be too costly.77

72
Espinoza, J. (2020, June 23). Retrieved from [Link]: [Link]
706a 483d-b24a-18cfbca142bf
73
Supyuenyong V, Islam N, Kulkarni U (2009) Influence of SME characteristics on knowledge management
processes: the case study of enterprise resource planning. J Enterp Inf Manag 22(1/2):63–8
74
Olenick D (2019) 60,000 EU data breaches fled under GDPR. Retrieved 10 Feb 2019, from https://
[Link]/home/security-news/privacy-compliance/60000-eu-data-breaches-fled-under -gdpr/
75
Worstall, T. (2019, June 5). [Link] Retrieved from
[Link] [Link]
76
Worstall, T. (2019, June 5). [Link] Retrieved from
[Link] [Link]
77
Kottasová, I. (2018, May 11). These companies are getting killed by GDPR. Retrieved from
[Link]: [Link]

Page 30 of 44
Others such as British pub chain Wetherspoons have decided to dump huge amounts of data
rather than to deal with the costs of complying with the GDPR. The consequence of this is a lost
of revenue for these companies.

(Worstall, 2019) , also estimated that at GDPR compliance will cost 7.8 billion US dollars just for
the 500 largest global firms. He also went on to state that Microsoft had to hire 1,600 engineers
for compliance only.78 (Smith O. , 2018) also reported that Fortune 500 and FTSE 350 businesses
are spending billion of dollars in an attempt to be compliant with the May 25 deadline for the
GDPR regulation. He further went on to state that British firms have spent a combined 1.1 billion
USD on the preparation of the GDPR while in America companies spend 7.8 billion USD in an
effort to avoid the threat of fines for non-compliance.

Where there is an increase in the costs of compliance, this will inevitably affect the costs of
production which means that customers would have to pay a higher price for goods and services.
Implementing the obligations under the GDPR can easily increase IT spending by 20% in some
sectors.79

4.1.2 Consequence of Non-Compliance

As it relates to non-compliance, businesses are caught between a rock and a hard place; while
compliance costs are high the fines associated with non-compliance and the domino effect of
noncompliance is even more costly. If there is a data breach for instance that a company fails to
report within the 72-hour window provided by the GDPR and an audit later takes place, the
result will be published for everyone to see including potential customers or potential data
subjects. The consequence of this is customers will lose trust in the busines which can affect
revenue.

[Link]
78
Worstall, T. (2019, June 5). [Link] Retrieved from
[Link] [Link]
79
Prasad, A., & R.Pérez, D. (2020, September 14). The Effects of GDPR on the Digital Economy:. Retrieved from
[Link]

Page 31 of 44
The costs of noncompliance are also very high. Under Article 83(5) GDPR, the fine for non-
compliance may be up 20 million euros, or in the case of an undertaking, up to 4 % of their total
global turnover of the preceding fiscal year, whichever is higher 80. And for of less severe
violations under Art. 83(4) GDPR, fines can range up to 10 million euros, or, up to 2% of its
entire global turnover of the preceding fiscal year, whichever is higher. 81 These fines are
sufficient to bankrupt a business and while it is important to note that authorities will take in
account a business “good faith” effort to comply with the GDPR, this is not to say that the
authorities may not make an example out of a business for non-compliance.

4.2 Uneven Power Structure

Some scholars have criticized the GDPR for being favorable to large companies as they are the
ones with the resources to afford to be compliant. They believed that bigger companies like
Google and Facebook’s advantages may increase market concentration since they are in a better
position to be GDPR compliant in their collection and processing data. 82 The CEO of the
advertising firm Kargo agreed by lamenting that Facebook and Google are “…throwing
engineers and lawyers at the problem and reassuring brands at a time of uncertainty”. 83 It is
important to note that the said company Kargo decided to withdraw its advertising from the EU
due to the GDPR. Due to the lack of resources to be GDPR compliant, the companies that decide
to remain in the European market are forcing advertisers to rely on larger advertising networks
such as google, this new phenomenon is referred to as the “Google Effect”. The Google effect is
essentially where advertisers can only rely on Google to purchase measuring system to assist
them in getting the information they need about their customers. The GDPR essentially spells big
profit for Google as it fuels the growth and the empowerment of technology empires and creates
an uneven power structure where the success of advertisers businesses are tied to Google-
controlled systems .

80
Article 83(5) GDPR
81
Article 83(4) GDPR
82
Aviv, M. S. (2020). The Competitive Effects of The GDPR. Forthcoming, Journal of Competition Law and
Economics (2020), 2-28.
83
IANS. (2018, August 23). Europe's New Data Law Upends Global Online Advertising. Retrieved from
[Link]: [Link]
[Link]

Page 32 of 44
The dominance that large companies enjoy under the GDPR puts a cap on the amount of data
smaller companies chose to process and may even discourage them from entering the EU market
altogether. The situation is particularly bad for digital advertisers and companies who offer
services that depends on tracking user behavior online as their access to data is now limited. The
ultimate effect of this is a lost in revenue for these companies.

4.2.1 The difficulty with Obtaining Consent

The consent requirement under the GDPR further widens the uneven power structure. As was
discussed previously, the data subject’s consent is an important element of data processing and
data collection under the GDPR. However, the likely outcome in situations where firms request
consent from their users is that users are likely to refuse to consent to data collection and
processing from smaller and less popular businesses when compared to larger and more popular
businesses. Companies such as Google and Facebook, due to their global reach and loyal
customers are bound to have little to no problem in acquiring consent from data subjects, unlike
smaller sized companies. This is another win for big companies such as Google and Facebook.
When examining the outcome of consent via the opt-in policy, unsurprisingly, the requirement
for consent imposes additional costs on specialized smaller businesses which discourages some
of them from remaining or entering the EU market. The natural unintended consequence of this
is that the more generalist businesses take over the entire market, thereby increasing their
advantages. 84

4.3 Reduced Investment

Investment in data driven market is also said to have been affected by the adoption of the GDPR.
Mergers and acquisition deal fell through due to concerns over the parties compliance with
GDPR at a rate of 58% according to the Merrill Corporation. There is also another study that
found that after implementing the GDPR, the number of deals involving EU ventures with data-
related business activities decreased by almost 31%.85
84
Campbell, J., Goldfarb, A., & Tucker, C. (2015). Privacy Regulation and Market Structure. Journal of Economics &
Management Strategy, 47-48.

85
Jian, J., Zhe, i. G., & Liad, W. (2019, May 31). The Short-Run Effects of GDPR on Technology Venture Investment .
Retrieved from [Link]

Page 33 of 44
4.4 Increased Risks to Business

4.4.1 More Cyberattacks

One of the mor surprising effects of the GDPR is the fact that it may increase the risks to
businesses. Enhancing the protection of personal data has increased the demand and value that
has been attached to personal data. Hackers understand the consequences a company would face
should its data become compromised and so hacking for ransom has increased with the
introduction of the GDPR. It is clear that the hackers are emboldened to do this because of the
risks businesses face if it should ever become public that their data has been compromised. As
stated supra, the businesses have an obligation to report such breach within 72 hours and failure
to do so can result in hectic fines. So, the hackers use this as leverage to bargain with companies
after hacking their data. When a company’s data is compromised it affects customer’s confidence
in the business and can even affect the share price of a company, as was the case between 1995
and 2000 where 38 United States witnessed a drop in stock prices due to personal data
breaches.86

Since the GDPR has come into effect in 2018, a report from 2019 has revealed that financially
motivated cyber-attacks have outnumbered cyber espionage by a 40% difference.87

In addition to this, an article published in July 2018, a mere two months after the GDPR,
revealed that since the start of 2018, there were 181.5million ransomware attacks which
represents a 229% increase compared to the previous year. Figure 1 below represents a
comparison of ransomware attacks between 2017 and 2018. The yellow bars represents 2018 and
the blue bars represents 2017.

86

87
Verizon . (2019). 2019 Data Breach report . Retrieved from [Link]

Page 34 of 44
Figure 1:

Note: From: Ransomware back in big way, 181.5 million attacks since January. (2018, July 11). Retrieved
from [Link]: [Link]
sonicwall-cyber-threat-report

4.5 Disruption of Business Model

Data-driven business models (DDBMs) are the center of the digital economy but due to the
demands of the GDPR, many businesses are forced to change their current business models from
using behavioral data to finding an alternative. Behavioral advertising is one of the more
effective and preferred advertising strategies. Before the GDPR, most businesses used behavioral
or targeted adverting to reach it potential customers, However, Marketers and advertisers who
previously relied on behavioral data collection, are forced to rethink the way they operate as
several business practices such as the way businesses used to obtain consent from data subject
have been revised and a higher standard has been implemented under the GDPR. Unlike before,
consent from data subject must be active and not passive, as was the case Pre-GDPR. Advertisers
and marketers are now at the mercy of the internet user. If the user decides to withhold consent,
his or her profile cannot be tracked or targeted for advertising purposes. The advertiser will not
know what the user is doing, what the user is interested in and as a result cannot learn the nature
of the user to send targeted advertisement his or her way.

Page 35 of 44
Where businesses and advertisers are unable to target users, the result is possible wastage of
resources on blind marketing. Inevitably, when advertisers advertise blindly, it decreases the
effectiveness or impact of the advertisement. Once again, the impact is greater on smaller
businesses than large businesses as customers if untargeted will search for known brands. 88 It is
therefore not economically practical for small businesses to try to compete against larger and
more established businesses for advertisement placements if they are unable to track users.

Businesses that rely on behavioral data collection for their advertising online will have to make a
change to what is referred to as contextual advertising, a tamer, and more privacy friendly
version of targeted advertising. Contextual advertising is essentially placing advertisement not
based on the profile of the user but rather what the user is viewing online in real time. To put into
perspective, contextual targeting, traditionally depends on webpage content itself to segment
users whereas behavioral advertising is content-neutral. 89 An example of contextual advertising
is where a user is reading an article about fashion and then there is an advertisement prompting
the user to purchase clothes from a particular retailer. Contextual advertising similar to what
companies use to do before the internet age where an advertisement for motor car for instance,
would be place in a car magazine.

So, while behavioral advertising is based on the action of the user prior to him or her going on a
particular website, contextual advertising works based on the environment the user is browsing.

Behavioral advertising is considered a very profitable enterprise, in fact online advertising was
built on targeting and behavioral advertising, with companies being forced to change their
business model and adopt a different method of advertising, it is important to compare the
effectiveness of the two and whether such change in business model has any negative impact on
companies or advertisers.

Behavioral advertising is the most frequently used method of digital advertising as it allows
advertisers and publishers to efficiently target customers. The GDPR, by limiting behavioral
advertisement through the requirement for consent by users, may limit the effectiveness of digital
advertisement. Scholars agree on a large scale that behavioral advertisement has significantly
88
McGee, M. (2013, December 11). Brand Bias: 70% Of Consumers Look For Known Retailers When Doing Product
Searches. Retrieved from [Link]: [Link]
for-known-retailers-when-doing-product-searches-179570
89
Acquisti, A., Taylor, C., & Wagman, L. (2016). The Economics of Privacy. Journal of Economic Literature .

Page 36 of 44
increase advertisement efficiency from what advertisement used to be when it was non-
personal90 If the advertisement is ineffective then the businesses will lose revenue. A report
conducted by reveals that shows that after third party cookies were disabled, thereby preventing
behavioral tracking, the publishers a majority of them experienced revenue losses of over 50% or
more, with some losing over 75% of their revenue and a small minority saw a loss of less than
10%.91

Figure 2:

Note: Figure 2 depicts the revenue loss of top 500 publisher after switching from behavioral advertising
to contextual advertising92.

The result of minimizing behavioral advertising and forcing businesses to use contextual
advertising is a potential loss in revenue for companies. Finally, it is important to note though
that the disruption in businesses caused by the GDPR that forces some to change their business
model is bound to disproportionately affect smaller businesses, as well as small advertisers and
publishers.

90
Bleier, A., Avi, G., & Tucker, C. (2020). “Consumer Privacy and. International Journal of Research in Marketing,
466–468, Hoban, P. R. (2015). Effects of Internet display advertising in the purchase funnel : model-based insights
from a randomized field experiment. Journal of Marketing Research 52(3), 375–393.
91
Ravichandran, D., & Korula, N. (2019, August 27). Effect of disabling third-party cookies on publisher
revenue. Retrieved from [Link]: [Link]
party_cookies_publisher_revenue.pdf
92
Ravichandran, D., & Korula, N. (2019, August 27). Effect of disabling third-party cookies on publisher revenue.
Retrieved from [Link]: [Link]
party_cookies_publisher_revenue.pdf

Page 37 of 44
CHAPTER 5
5.1 Conclusion and Recommendations

One cannot deny the significance of the GDPR and its intention to protect personal data. In fact,
the world has never seen such high standard of data privacy law and due to its extra territorial
scope, its relevance and importance cannot be ignored. However, while the GDPR is
revolutionary in every way, it had created some number of concerns for advertisers and
businesses who rely on personal data, as it has the potential of seriously affecting their future and
viability.

The purpose of the GDPR can be safely summarized as a protection for personal data and a set of
rules to keep data controllers and processors in check and while this is great, the lengths which
the GDPR goes to achieve these two goals is excessive so much so that the negative impacts are
apparent.

While the GDPR’s negative impact can be categorized into different heading, all impacts appear
to threaten the very fuel that a business runs on- revenue. The cost to comply with the GDPR is
quite high and the consequence of non-compliance is also quite high so much so that the GDPR
has forced some companies out of Europe and intimidate others to shy away from the market
altogether. The result of this is the expansion and profit increase for large businesses such as
Google. The GDPR essentially created a world where most businesses who are reliant on tracing
customer behavior for their business has to go through them,

It is imperative to appreciate that the fuel that keeps any business going is revenue and the
biggest impact the GDPR appears to have on digital advertising and companies is the loss of
revenue, either through being unable to participate in the European market, having to spend
thousands, if not millions of dollars on compliance or missing out on business opportunities
because of failure of non-compliance. Once the revenue of any business is under threat, the
business itself too is at risks. So, with these being the results and some of the impact of the
GDPR on business, it is safe to say that the GDPR does have a negative impact on digital
advertising and businesses in general. This makes the GDPR appear one-sided instead of striking
a balance between the protection of personal data and without the threat of destroying businesses
particularly small and medium sized businesses.

Page 38 of 44
A more balance approach as to how the GDPR can balance these two things is discussed in the
recommendation below.

Recommendation

Having examined the nature of the GDPR and its impact on digital advertising and having seen
the degree of its negative impact, it is important to offer some recommendation. The most
obvious recommendation is an amendment to the GDPR.

After extensive research, it is clear that the GDPR could benefit from some amendments to strike
a greater balance between businesses (data controllers and processors) and data subjects. The
GDPR in its current form appears place a premium on the protection of personal data over the
survival of businesses. The fines, as many scholars and businesspersons have acknowledged are
inordinately high. They are so high that the drove entire companies out of the EU, willing to
sacrifice whatever revenues they realizing in the EU to avoid the heavy fines

While it is also appreciated that one rationale behind the high fines may be to encourage
compliance, it’s excessive nature is overshooting its intention by essentially driving businesses
into retreat. It is recommended therefore that Article 83 (4) and Article 84 (5) be amended to
reduce fines to 1 million Euros or 0.25% and 0.5% of the of the annual turnover of a the
company. This is a more reasonable and balanced fine to attach to non-compliance. It is also
suggested that the GDPR abandon the option to charge 10 million and 20 million Euros as there
are companies that will simply not be able to afford that, and fines like that would result in
bankruptcy. Since the aim of the GDPR is not to punish businesses to the point where they are
forced to close, this recommendation in the view of the researcher is a reasonable one.

In addition to this, it is highly recommended that the regulators for the GDPR provides some
form of addendum to the GDPR to offer some clarity to some of the vague and opaque articles
under the GDPR such as the data subject’s right to accuracy. It is impractical for the fines for
non-compliance under the GDPR to be so high when the means of compliance is not clear.

Some scholars have argued that the GDPR while providing the optimum protection for data
subjects can also have a positive impact on businesses by encouraging innovation. It is believed
that with the barriers and limitations that the GDPR impose on businesses when it comes to

Page 39 of 44
accessing and processing personal data, businesses particularly advertising businesses will come
up with creative ways of advertising. So far only Google is the leader where this is concerned.
However other businesses can invest in the development of software that will allow them to
utilize measuring system to assist them in getting the information they need about their
customers, this will provide an edge in advertising.

The missed opportunities businesses faced when it comes to acquiring customers consent to their
personal data can also be alleviated by seeking other means of targeting customers. One such
means is by using the services of social media influencers. Since a massive 58% of the world’s
population is active on social media and there are influencers for almost every market and every
audience one can think of, advertisers and more businesses can look into using more social
media as an advertising medium if they find that contextual advertising is not yielding the results
they wish.
Finally, from this research, it is clear that the GDPR although revolutionary, is very tough on
businesses and advertisers so much so that it has the potential to stifle targeted adverting and hurt
a large number of businesses.

Bibliography
Barone, A. (2022, June 23). What Is Digital Marketing? Investopedia. Retrieved July 1, 2022, from
[Link]
Blattberg, R. C., Kim, B., & Neslin, S. A. (2010). Database Marketing: Analyzing and Managing Customers
(International Series in Quantitative Marketing Book 18) (2008th ed.). Springer.
Bleier, A., Goldfarb, A., & Tucker, C. E. (2020). Consumer Privacy and the Future of Data-Based
Innovation and Marketing. SSRN Electronic Journal. [Link]
Böhmecke-Schwafert, M., & Niebel, C. (2018). The General Data Protection’s (Gdpr) Impact On Data-
Driven Business Models: The Case Of The Right To Data Portability And Facebook. The General
Data Protection’s (Gdpr) Impact On Data-Driven Business Models: The Case Of The Right To Data
Portability And Facebook, 2, 1–4.

Page 40 of 44
Campbell, J., Goldfarb, A., & Tucker, C. (2015). Privacy Regulation and Market Structure. Journal of
Economics & Management Strategy, 24(1). [Link]
Ciriani, S. (2015a). The Economic Impact of the European Reform of Data Protection.
COMMUNICATIONS & STRATEGIES, 97, 42–43.
Dutko, J. (2021, June 22). How Types of Computer Cookies Affect Your Online Privacy. CRU Solutions |
Cleveland Managed IT Services & IT Support. [Link]
computer-cookies-affect-your-online-privacy/
European Commission 2021
Espinoza, J. (2020, June 23). EU admits it has been hard to implement GDPR. Financial Times.
[Link]
Froehlich, N. (2022, February 25). The Truth In User Privacy And Targeted Ads. Forbes.
[Link]
targeted-ads/?sh=7f58b4a7355e
Gal, M. S., & Aviv, O. (2020). The Competitive Effects of the GDPR. Journal of Competition Law &
Economics, 16(3), 349–391. [Link]
Heimes, R. S. P. (2020, May 6). Study: At least 28,000 DPOs needed to meet GDPR requirements.
International Association of Privacy Professionals. Retrieved July 12, 2022, from
[Link]
Hoban, P. R., & Bucklin, R. E. (2015). Effects of Internet Display Advertising in the Purchase Funnel:
Model-Based Insights from a Randomized Field Experiment. Journal of Marketing Research,
52(3), 375–393. [Link]
IAB. (2022a, May 27). Internet Advertising Revenue Report: Full Year 2021. Retrieved July 7, 2022, from
[Link]
IAB. (2022b, May 27). Internet Advertising Revenue Report: Full Year 2021. Retrieved July 18, 2022, from
[Link]
Irwin, L. (2022a, April 26). How much does GDPR compliance cost in 2022? IT Governance Blog En.
Retrieved July 21, 2022, from [Link]
compliance-cost-in-2020
Irwin, L. (2022b, April 27). The GDPR: Why you need to adopt privacy by design. IT Governance Blog En.
Retrieved July 10, 2022, from [Link]
to-adopt-the-principles-of-privacy-by-design

Page 41 of 44
Jia, J., Jin, G. Z., & Wagman, L. (2018). The Short-Run Effects of GDPR on Technology Venture
Investment. SSRN Electronic Journal. [Link]
Kish, K. (2020, May 6). What does territorial scope mean under the GDPR? International Association of
Privacy Professionals. Retrieved July 10, 2020, from [Link]
territorial-scope-mean-under-the-gdpr/
Kosorin, D. (2022). Introduction to Programmatic Advertising [E-book]. Dominik Kosorin.
Kottasová, I. (2018, May 11). These companies are getting killed by GDPR. CNNMoney. Retrieved July 20,
2022, from [Link]
[Link]
Law, G. D. (2022, February 15). What does “accountability” mean under EU Data Protection law?
Medium. Retrieved July 12, 2022, from [Link]
accountability-mean-under-eu-data-protection-law-af630e40648b
London Economics. (2013, May). Implications of the European Commission’s proposal for a general data
protection regulation for business. [Link]
[Link]
McGee, M. (2022, March 3). Brand Bias: 70% Of Consumers Look For Known Retailers When Doing
Product Searches. Search Engine Land. Retrieved July 12, 2022, from
[Link]
doing-product-searches-179570
McGrady, P. D. (2021). McGrady on Social Media Aspects of Employment Law 2021 Edition (2021st ed.).
Lexisnexis.
News18. (2018, August 23). Europe’s New Data Law Upends Global Online Advertising. Retrieved July 13,
2022, from [Link]
[Link]

O’Brien, R. (2016, June 8). Privacy and security: The new European data protection regulation and it’s
data breach notification requirements. Business Information Review , pp. 81-84.

Olenick, D. (2019, February 5). Retrieved from [Link]


[Link]

Prasad, A., & R.Pérez, D. (2020, September 14). The Effects of GDPR on the Digital Economy:. Retrieved
from [Link]

Page 42 of 44
Ransomware back in big way, 181.5 million attacks since January. (2018, July 11). Retrieved from
[Link]: [Link]
cyber-threat-report/

Ravichandran, D., & Korula, N. (2019, August 27). Effect of disabling third-party cookies on publisher
revenue. Retrieved from [Link]:
[Link]

Schwabe, C. (n.d.). Data subjects' rights in the General Data Protection Regulation. Retrieved from
[Link]: [Link]
data-subject-gdpr

Segal, T. (2022, March 28). Investopedia . Retrieved from [Link]


[Link]

Sicular, S. (2013, April 2). Gartner’s Big Data Definition Consists of Three Parts, Not to Be Confused with
Three “V”s. Retrieved from [Link]:
[Link]
not-to-be-confused-with-three-vs/

Skiera, B., Miller, K., Jin, Y., Kraft, L., & Laub, R. (2022). The Impact of the GDPR on The Online Advertising
MarketAdvertsing Market . Frankfurt, Germany,: Amazon ebook.

Smith, M. (2015). Targeted . New York;: Haper Collins Publisher .

Smith, O. (2018, May 2). Retrieved from [Link]:


[Link]
from-this-9bn-business-shakedown/?sh=5e78667f34a2

Stephens, A. (2018, February). Data controller or data processor? Understanding your responsibilities
and risks. Retrieved from [Link]:
[Link]
understanding-responsibilities-risks/

Team, I. P. (n.d.). EU General Data Protection Regulation (GDPR) An Implementation and Compliance
Guide (Third Edition ). Retrieved from EU General Data Protection Regulation (GDPR) An
Implementation and Compliance Guide (Third Edition ) IT Privacy Team.
[Link]

The Impact of the GDPR on Digital Marketing . (n.d.). In K. M. Bernd Skiera, The Impact of the GDPR on
Digital Marketing .

Todaro, M. (2007). Revealed, Internet Marketing Methods. Florida : Atlantic Publishing Group.

Verizon . (2019). 2019 Data Breach report . Retrieved from [Link]

Voigt, P., & Bussche, A. v. (2017). The EU General Daa Protection Regulation (GDPR) A Practical Guide.
Berlin Germany: Springer International Publishing AG.

Walters, L. (2021, October 18). Study Finds Internet Economy Grew Seven Times Faster Than Total U.S.
Economy, Created Over 7 Million Jobs in the Last Four Years. Retrieved from [Link]:

Page 43 of 44
[Link]

Worstall, T. (2019, June 5). [Link] Retrieved from


[Link] [Link]
worth-the-cost

Page 44 of 44

You might also like