•  
  •  
 

Digital Markets and Hidden Noncompliance

Start Page

433

Abstract

Regulatory oversight in digital markets faces a significant challenge. With millions of websites, apps, and service providers, monitoring compliance at scale is daunting. Existing empirical research often relies on firms’ self-reported compliance. We argue that such an approach, while convenient, may systematically understate actual noncompliance. Using European privacy law as a case study—and focusing on the fallout from the European Court of Justice’s 2020 invalidation of the EU-US Privacy Shield—we examine how over 2,500 apps from the Spanish Google Play store responded to this legal shift. We find divergence between firms’ stated privacy policies and their cross-border data transfers. Drawing on tools from information technology security research to observe data flows, we show that traditional empirical legal methods may miss over 70 percent of privacy violations. These findings raise important questions for privacy scholarship and regulatory design, particularly in settings marked by limited observability and high information asymmetry.

Share

COinS