{"id":"https://openalex.org/W4402953373","doi":"https://doi.org/10.1093/cybsec/tyae017","title":"GDPR and the indefinable effectiveness of privacy regulators: Can performance assessment be improved?","display_name":"GDPR and the indefinable effectiveness of privacy regulators: Can performance assessment be improved?","publication_year":2024,"publication_date":"2024-01-01","ids":{"openalex":"https://openalex.org/W4402953373","doi":"https://doi.org/10.1093/cybsec/tyae017"},"language":"en","primary_location":{"id":"doi:10.1093/cybsec/tyae017","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyae017","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/10/1/tyae017/61182301/tyae017.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://academic.oup.com/cybersecurity/article-pdf/10/1/tyae017/61182301/tyae017.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5051419218","display_name":"Gerard Buckley","orcid":"https://orcid.org/0000-0001-9261-0815"},"institutions":[{"id":"https://openalex.org/I4210098748","display_name":"Department of Science and Technology","ror":"https://ror.org/0101xrq71","country_code":"IN","type":"government","lineage":["https://openalex.org/I2799351866","https://openalex.org/I4210098748","https://openalex.org/I4210134808"]},{"id":"https://openalex.org/I45129253","display_name":"University College London","ror":"https://ror.org/02jx3x895","country_code":"GB","type":"education","lineage":["https://openalex.org/I124357947","https://openalex.org/I45129253"]}],"countries":["GB","IN"],"is_corresponding":true,"raw_author_name":"Gerard Buckley","raw_affiliation_strings":["Department of Computer Science, UCL , Gower Street, WC1E 6BT, London ,","Department of Computer Science, UCL , Gower Street, WC1E 6BT, London , United Kingdom"],"raw_orcid":"https://orcid.org/0000-0001-9261-0815","affiliations":[{"raw_affiliation_string":"Department of Computer Science, UCL , Gower Street, WC1E 6BT, London ,","institution_ids":["https://openalex.org/I4210098748","https://openalex.org/I45129253"]},{"raw_affiliation_string":"Department of Computer Science, UCL , Gower Street, WC1E 6BT, London , United Kingdom","institution_ids":["https://openalex.org/I45129253"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5076986372","display_name":"Tristan Caulfield","orcid":"https://orcid.org/0000-0002-7039-6472"},"institutions":[{"id":"https://openalex.org/I4210098748","display_name":"Department of Science and Technology","ror":"https://ror.org/0101xrq71","country_code":"IN","type":"government","lineage":["https://openalex.org/I2799351866","https://openalex.org/I4210098748","https://openalex.org/I4210134808"]},{"id":"https://openalex.org/I45129253","display_name":"University College London","ror":"https://ror.org/02jx3x895","country_code":"GB","type":"education","lineage":["https://openalex.org/I124357947","https://openalex.org/I45129253"]}],"countries":["GB","IN"],"is_corresponding":false,"raw_author_name":"Tristan Caulfield","raw_affiliation_strings":["Department of Computer Science, UCL , Gower Street, WC1E 6BT, London ,","Department of Computer Science, UCL , Gower Street, WC1E 6BT, London , United Kingdom"],"raw_orcid":"https://orcid.org/0000-0002-7039-6472","affiliations":[{"raw_affiliation_string":"Department of Computer Science, UCL , Gower Street, WC1E 6BT, London ,","institution_ids":["https://openalex.org/I4210098748","https://openalex.org/I45129253"]},{"raw_affiliation_string":"Department of Computer Science, UCL , Gower Street, WC1E 6BT, London , United Kingdom","institution_ids":["https://openalex.org/I45129253"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5036272832","display_name":"Ingolf Becker","orcid":"https://orcid.org/0000-0002-3963-4743"},"institutions":[{"id":"https://openalex.org/I4210098748","display_name":"Department of Science and Technology","ror":"https://ror.org/0101xrq71","country_code":"IN","type":"government","lineage":["https://openalex.org/I2799351866","https://openalex.org/I4210098748","https://openalex.org/I4210134808"]},{"id":"https://openalex.org/I45129253","display_name":"University College London","ror":"https://ror.org/02jx3x895","country_code":"GB","type":"education","lineage":["https://openalex.org/I124357947","https://openalex.org/I45129253"]}],"countries":["GB","IN"],"is_corresponding":false,"raw_author_name":"Ingolf Becker","raw_affiliation_strings":["Department of Security & Crime Science, UCL , Gower Street, WC1E 6BT, London ,","Department of Security & Crime Science, UCL , Gower Street, WC1E 6BT, London , United Kingdom"],"raw_orcid":"https://orcid.org/0000-0002-3963-4743","affiliations":[{"raw_affiliation_string":"Department of Security & Crime Science, UCL , Gower Street, WC1E 6BT, London ,","institution_ids":["https://openalex.org/I4210098748","https://openalex.org/I45129253"]},{"raw_affiliation_string":"Department of Security & Crime Science, UCL , Gower Street, WC1E 6BT, London , United Kingdom","institution_ids":["https://openalex.org/I45129253"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5051419218"],"corresponding_institution_ids":["https://openalex.org/I4210098748","https://openalex.org/I45129253"],"apc_list":{"value":1864,"currency":"USD","value_usd":1864},"apc_paid":{"value":1864,"currency":"USD","value_usd":1864},"fwci":7.3853,"has_fulltext":true,"cited_by_count":7,"citation_normalized_percentile":{"value":0.96905636,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":98},"biblio":{"volume":"10","issue":"1","first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11045","display_name":"Privacy, Security, and Data Protection","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T11045","display_name":"Privacy, Security, and Data Protection","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T12921","display_name":"European Criminal Justice and Data Protection","score":0.9790999889373779,"subfield":{"id":"https://openalex.org/subfields/3320","display_name":"Political Science and International Relations"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T14432","display_name":"Freedom of Expression and Defamation","score":0.972100019454956,"subfield":{"id":"https://openalex.org/subfields/3308","display_name":"Law"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/general-data-protection-regulation","display_name":"General Data Protection Regulation","score":0.7676132917404175},{"id":"https://openalex.org/keywords/accountability","display_name":"Accountability","score":0.6672033071517944},{"id":"https://openalex.org/keywords/transparency","display_name":"Transparency (behavior)","score":0.6397527456283569},{"id":"https://openalex.org/keywords/sanctions","display_name":"Sanctions","score":0.5505219101905823},{"id":"https://openalex.org/keywords/enforcement","display_name":"Enforcement","score":0.5367855429649353},{"id":"https://openalex.org/keywords/legitimacy","display_name":"Legitimacy","score":0.5223965644836426},{"id":"https://openalex.org/keywords/public-relations","display_name":"Public relations","score":0.4806072413921356},{"id":"https://openalex.org/keywords/political-science","display_name":"Political science","score":0.474237859249115},{"id":"https://openalex.org/keywords/data-protection-act-1998","display_name":"Data Protection Act 1998","score":0.45835816860198975},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.4358224868774414},{"id":"https://openalex.org/keywords/autonomy","display_name":"Autonomy","score":0.4106510281562805},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.3792201280593872},{"id":"https://openalex.org/keywords/law","display_name":"Law","score":0.22791442275047302},{"id":"https://openalex.org/keywords/politics","display_name":"Politics","score":0.2275896966457367}],"concepts":[{"id":"https://openalex.org/C3090818","wikidata":"https://www.wikidata.org/wiki/Q1172506","display_name":"General Data Protection Regulation","level":3,"score":0.7676132917404175},{"id":"https://openalex.org/C2776007630","wikidata":"https://www.wikidata.org/wiki/Q2798912","display_name":"Accountability","level":2,"score":0.6672033071517944},{"id":"https://openalex.org/C2780233690","wikidata":"https://www.wikidata.org/wiki/Q535347","display_name":"Transparency (behavior)","level":2,"score":0.6397527456283569},{"id":"https://openalex.org/C2778069335","wikidata":"https://www.wikidata.org/wiki/Q32098","display_name":"Sanctions","level":2,"score":0.5505219101905823},{"id":"https://openalex.org/C2779777834","wikidata":"https://www.wikidata.org/wiki/Q4202277","display_name":"Enforcement","level":2,"score":0.5367855429649353},{"id":"https://openalex.org/C46295352","wikidata":"https://www.wikidata.org/wiki/Q207982","display_name":"Legitimacy","level":3,"score":0.5223965644836426},{"id":"https://openalex.org/C39549134","wikidata":"https://www.wikidata.org/wiki/Q133080","display_name":"Public relations","level":1,"score":0.4806072413921356},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.474237859249115},{"id":"https://openalex.org/C69360830","wikidata":"https://www.wikidata.org/wiki/Q1172237","display_name":"Data Protection Act 1998","level":2,"score":0.45835816860198975},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.4358224868774414},{"id":"https://openalex.org/C65414064","wikidata":"https://www.wikidata.org/wiki/Q484105","display_name":"Autonomy","level":2,"score":0.4106510281562805},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.3792201280593872},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.22791442275047302},{"id":"https://openalex.org/C94625758","wikidata":"https://www.wikidata.org/wiki/Q7163","display_name":"Politics","level":2,"score":0.2275896966457367},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1093/cybsec/tyae017","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyae017","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/10/1/tyae017/61182301/tyae017.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"},{"id":"pmh:oai:eprints.ucl.ac.uk.OAI2:10195151","is_oa":true,"landing_page_url":"https://discovery.ucl.ac.uk/id/eprint/10195151/","pdf_url":"https://discovery.ucl.ac.uk/10195151/1/buckley_GDPR_2024.pdf","source":{"id":"https://openalex.org/S4306400024","display_name":"UCL Discovery (University College London)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I45129253","host_organization_name":"University College London","host_organization_lineage":["https://openalex.org/I45129253"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"   Journal of Cybersecurity       (2024)     (In press).  ","raw_type":"Article"}],"best_oa_location":{"id":"doi:10.1093/cybsec/tyae017","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyae017","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/10/1/tyae017/61182301/tyae017.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/8","display_name":"Decent work and economic growth","score":0.6100000143051147}],"awards":[{"id":"https://openalex.org/G205667250","display_name":"EPSRC Centre for Doctoral Training in Cybersecurity","funder_award_id":"EP/S022503/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"},{"id":"https://openalex.org/G479549078","display_name":"Protecting public-facing professionals and their dependents online (3PO)","funder_award_id":"EP/W032368/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"}],"funders":[{"id":"https://openalex.org/F4320334627","display_name":"Engineering and Physical Sciences Research Council","ror":"https://ror.org/0439y7842"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4402953373.pdf","grobid_xml":"https://content.openalex.org/works/W4402953373.grobid-xml"},"referenced_works_count":58,"referenced_works":["https://openalex.org/W52732106","https://openalex.org/W81685006","https://openalex.org/W619877947","https://openalex.org/W1484402763","https://openalex.org/W1510299685","https://openalex.org/W1531100425","https://openalex.org/W1640628807","https://openalex.org/W1971219113","https://openalex.org/W1979290264","https://openalex.org/W1991926806","https://openalex.org/W2006164615","https://openalex.org/W2021710644","https://openalex.org/W2029593486","https://openalex.org/W2034645929","https://openalex.org/W2120315333","https://openalex.org/W2126070475","https://openalex.org/W2147803348","https://openalex.org/W2149988075","https://openalex.org/W2150332298","https://openalex.org/W2154094938","https://openalex.org/W2154828947","https://openalex.org/W2161355345","https://openalex.org/W2171380100","https://openalex.org/W2182973359","https://openalex.org/W2314911175","https://openalex.org/W2324580958","https://openalex.org/W2518944817","https://openalex.org/W2535172017","https://openalex.org/W2953485448","https://openalex.org/W2954332150","https://openalex.org/W3018836199","https://openalex.org/W3023419211","https://openalex.org/W3048560297","https://openalex.org/W3084163594","https://openalex.org/W3121242664","https://openalex.org/W3121768899","https://openalex.org/W3122320101","https://openalex.org/W3122648900","https://openalex.org/W3123012225","https://openalex.org/W3123722854","https://openalex.org/W3123845435","https://openalex.org/W3124283101","https://openalex.org/W3144530836","https://openalex.org/W4231019253","https://openalex.org/W4231157298","https://openalex.org/W4246736128","https://openalex.org/W4248056879","https://openalex.org/W4300765601","https://openalex.org/W4306955473","https://openalex.org/W4388316013","https://openalex.org/W4397028651","https://openalex.org/W6635497245","https://openalex.org/W6682832347","https://openalex.org/W6686100111","https://openalex.org/W6693783523","https://openalex.org/W6764573258","https://openalex.org/W6866607200","https://openalex.org/W6986904598"],"related_works":["https://openalex.org/W2917102635","https://openalex.org/W3023256691","https://openalex.org/W2789497412","https://openalex.org/W2883729192","https://openalex.org/W2910484607","https://openalex.org/W2794700933","https://openalex.org/W2901967497","https://openalex.org/W3171079982","https://openalex.org/W3048759155","https://openalex.org/W3000605968"],"abstract_inverted_index":{"Abstract":[0],"Data":[1,7],"protection":[2,59],"regulations":[3],"like":[4],"the":[5,55,119,127,138,152,171,178,183,222,234],"General":[6],"Protection":[8],"Regulation":[9],"(GDPR)":[10],"are":[11,54],"increasingly":[12],"important":[13,219],"in":[14,46,134,230,233],"securing":[15],"individuals\u2019":[16],"privacy":[17],"as":[18],"society":[19],"goes":[20],"digital.":[21],"The":[22,89],"success":[23],"of":[24,57,109,137,154,167,182,191,204,225,237],"any":[25],"regulation,":[26],"however":[27],"good,":[28],"ultimately":[29],"depends":[30],"on":[31],"how":[32,62],"well":[33],"it":[34,105],"is":[35,141],"executed.":[36],"Existing":[37],"literature":[38],"fails":[39],"to":[40,71,124,131,158,206],"answer":[41],"what":[42,51],"good":[43],"execution":[44],"means":[45],"this":[47],"context.":[48],"We":[49,67,77,103,169,214],"research":[50],"practitioners":[52],"think":[53],"objectives":[56,122],"data":[58],"regulators":[60,125],"and":[61,84,99,126,144,149,174,195,201,212,228,232],"they":[63],"evaluate":[64],"their":[65],"effectiveness.":[66],"explore":[68],"novel":[69],"ways":[70],"assess":[72],"regulator":[73,226],"performance":[74,193],"more":[75],"systematically.":[76],"surveyed":[78],"70":[79],"chief":[80],"information":[81],"security":[82],"officers":[83],"conducted":[85],"23":[86],"structured":[87],"interviews.":[88],"interviewees":[90],"included":[91],"informed":[92],"business":[93],"executives,":[94],"lawyers,":[95],"digital":[96],"rights":[97],"activists,":[98],"four":[100],"national":[101],"regulators.":[102],"supplement":[104],"with":[106],"an":[107],"analysis":[108],"diverse":[110],"enforcement":[111],"databases.":[112],"Our":[113],"findings":[114,217],"indicate":[115],"a":[116,189],"mismatch":[117],"between":[118],"broad":[120],"presumed":[121],"attributed":[123],"narrow":[128],"criteria":[129],"used":[130],"judge":[132],"them":[133,160],"practice.":[135],"Perception":[136],"regulator\u2019s":[139],"effectiveness":[140],"subjective,":[142],"sanctions-focused,":[143],"influenced":[145],"by":[146],"one\u2019s":[147],"role":[148],"responsibilities.":[150],"Moreover,":[151],"independence":[153],"regulators,":[155],"intentionally":[156],"designed":[157],"insulate":[159],"from":[161],"daily":[162],"politics,":[163],"raises":[164],"serious":[165],"questions":[166],"accountability.":[168],"examine":[170],"historical,":[172],"cultural,":[173],"organizational":[175],"motivations":[176],"behind":[177],"current":[179],"byzantine":[180],"complexity":[181],"GDPR":[184],"regime.":[185],"Lastly,":[186],"we":[187],"contribute":[188],"series":[190],"key":[192],"indicators":[194],"make":[196],"structural":[197],"suggestions":[198],"around":[199],"centralized":[200],"standardized":[202],"reporting":[203],"cases":[205],"deliver":[207],"improved":[208],"learning,":[209],"legitimacy,":[210],"transparency,":[211],"comparability.":[213],"believe":[215],"our":[216],"have":[218],"implications":[220],"for":[221],"future":[223],"development":[224],"assessment":[227],"accountability":[229],"Europe":[231],"growing":[235],"number":[236],"GDPR-like":[238],"regimes":[239],"outside":[240],"Europe.":[241]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":3}],"updated_date":"2026-05-07T13:39:58.223016","created_date":"2025-10-10T00:00:00"}
