Editorial by Aymeric Pontvianne
On the 23 and 24 March, the Brussels Privacy Hub and HEC Paris organised an academic workshop “Towards a competitive digital EU : regulatory effectiveness in practice”, whose first day I had the opportunity to conclude by developing the regulator’s perspective of CNIL. Eight years after the entry into force of GDPR, the current debate around the data omnibus seem to blur the lines, opposing deregulation revendications and the belief that EU values should be put first. Thank you Sophie and David for giving me the opportunity to comment on the far reaching and valuable research we discussed, mainly from an economic point of view, but with a pluridisciplinary focus.
CNIL already had the occasion to comment on the economic impact of GDPR, which is more profound and complex than sometimes sketched.
The omnibus, at least in its intentions, aims to simplify the rules, in other words, “reduce the regulatory burden” applicable to EU firms, mainly to SMEs. Simplification, however, is not an easy objective to reach in practice, and from the point of view of a cost-benefit analysis, regulatory stability has an interest as well when it comes to the substance of the data protection rules. This is all the more true as the Draghi report itself didn’t put into question the level of protection provided by the GDPR, but its lack of harmonisation across Member States, a topic often disregarded by the simplification agenda.
The question of the economic impact of GDPR is a hot topic, but not conclusive so far. CNIL organised an academic event dedicated to the subject in May last year, whose summary has been made available on our website: https://www.cnil.fr/en/event-gdpr-what-economic-impact-summary-discussions . The main takeaway is that a more comprehensive view of the economic impact is needed. The literature documents well the costs for firms, less often the positive effects for individuals in terms of welfare and hardly ever the economic benefits of compliance for firms. Yet, only conclusions on the net welfare effects, which are still ahead of us, could be a good scientific basis for a regulatory change.
On innovation more specifically, the effects of privacy regulation are ambivalent and studies do not support the negative narrative proposed by the industry.
There is a political economy of policy making when it comes to GDPR and data protection but there is also a political economy of narratives proposed by the industry and civil society alike. Against this background, one can only warn against the “magnifying glass effect” affecting economic research based on the collection of feelings and opinions of business executives. They tend to overestimate the costs but underestimate the weight of market-wide factors like confidence or reduction of risks for final users, quite an important issue in the data area, where no market prices exist that can be internalised by firms in their production functions. Such polls are not relevant for a scientific approach and should be replaced by more objective empirical evidence.
In reality, economic research shows that the effects of privacy regulation on innovation are twofold. On one hand, yes, the regulation has a cost and will prevent unlawful or toxic innovations, like the prohibited practices under the AI act for example, to develop. One the other, compliance, cybersecurity and incentives to individuals to exercise more control over their data lead to the development of specific innovations, be they called “privacy enhancing technologies” or “compliance innovations”. The fact that the PETs are most often developed in the US than in the EU, relates to broader factors affecting innovation in Europe (size of capital markets, access to computing power, risk appetite of actors, etc) other than regulations themselves.
In this regard, it’s likely that privacy regulation, like any other regulation, is more burdensome for innovators and can increase the time to market, but this effect is probably of second order, and is to be weighted against its positive societal effects (reduction of harms, increase of trust) that the digital economy crucially needs to develop.
The “value for money” of regulation : optimising regulatory effectiveness requires the mobilisation of a wide range of tools, with the collaboration of the ecosystems.
Examining the economic impact of GDPR, after its entry into force, means also assessing the efficiency of the regulation to reach its policy goals, which is often called “regulatory effectiveness”. The literature has underlined enforcement gaps, and some, like noyb, have even denounced “a culture of non-compliance”. The primary task on the authority when it comes to its enforcement strategy is to develop a risk-based, dynamic approach to bridge the gaps over time.
Data protection authorities want to develop a facts-based approach, where data rights are not only imposed if necessary but also harnessed by individual and integrated by markets as a competitive factor. In this regard, cooperation between data protection authorities and competition authorities, who has gained track in the last years, plays an important role to reduce legal uncertainty and increase regulatory previsibility. The advisory role of regulatory authorities is also often underestimated : CNIL has developed a sandbox, for example, supporting several start-ups by year since 2021, and has instructed 1450 requests for advice in 2025 (as opposed to 83 sanctions).
But the authorities are only part of this effort to optimise regulatory effectiveness : ecosystems can help, too, by adhering to certifications, structuring codes of conduct or developing accounting and financial metrics to measure how data and privacy risks are mitigated across the economies. The discussion around such tools creates more value, eventually, than a battle of narratives.
Aymeric Pontvianne has been the head of the CNIL’s economic team since 2023. An economist by training and a graduate of the École Nationale d’Administration, he previously held various positions within the Directorate General of the Treasury.
