Do US State Breach Notification Laws Decrease Firm Data Breaches?

55 Pages Posted: 10 Aug 2021 Last revised: 26 Jun 2023

See all articles by Brad N. Greenwood

Brad N. Greenwood

George Mason University - Department of Information Systems and Operations Management

Paul M. Vaaler

University of Minnesota, Twin Cities - Law School and Carlson School of Management

Date Written: March 6, 2023

Abstract

From 2003-2018, 50 states and the District of Columbia enacted breach notification laws (BNLs) mandating that firms suffering data breaches provide timely notification to affected persons and others about breach incidents and mitigation responses. BNLs were supposed to decrease data breaches and develop a market for data privacy where firms could strike their preferred balance between data security quality and cost. We find no systemic evidence for either supposition. Results from two-way difference-in-difference analyses indicate no decrease in data breach incident counts or magnitudes after BNLs are enacted. Results also indicate no longer-term decrease in data misuse after breaches. These non-effects appear to be precisely estimated nulls that persist for different firms, time-periods, data-breach types, and BNL types. Apparently inconsistent notification standards and inadequate information dissemination to the public may explain BNL ineffectiveness. An alternative federal regime may address these shortcomings and let a national BNL achieve goals state BNLs have apparently failed to meet.

Keywords: Breach Notification, Consumer Privacy, Difference in Difference

Suggested Citation

Greenwood, Brad and Vaaler, Paul M., Do US State Breach Notification Laws Decrease Firm Data Breaches? (March 6, 2023). Minnesota Legal Studies Research Paper, Available at SSRN: https://ssrn.com/abstract=3885993 or http://dx.doi.org/10.2139/ssrn.3885993

Brad Greenwood (Contact Author)

George Mason University - Department of Information Systems and Operations Management ( email )

4400 University Drive
Fairfax, VA 22030
United States

Paul M. Vaaler

University of Minnesota, Twin Cities - Law School and Carlson School of Management ( email )

229 19th Avenue South
Minneapolis, MN 55455
United States
612-625-4951 (Phone)
612-626-1316 (Fax)

HOME PAGE: http://carlsonschool.umn.edu/faculty/paul-vaaler

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
134
Abstract Views
1,191
Rank
408,068
PlumX Metrics