<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Data protection - China Business Knowledge</title>
	<atom:link href="https://cbk.bschool.cuhk.edu.hk/tag/data-protection/feed/" rel="self" type="application/rss+xml" />
	<link>https://cbk.bschool.cuhk.edu.hk</link>
	<description></description>
	<lastBuildDate>Mon, 17 Aug 2026 09:25:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.7</generator>
	<item>
		<title>If everyone uses AI, who stands out?</title>
		<link>https://cbk.bschool.cuhk.edu.hk/if-everyone-uses-ai-who-stands-out/</link>
		
		<dc:creator><![CDATA[Putro]]></dc:creator>
		<pubDate>Thu, 13 Aug 2026 01:37:02 +0000</pubDate>
				<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[Marketing]]></category>
		<category><![CDATA[advertising]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI models]]></category>
		<category><![CDATA[algorithm]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[ChatGPT]]></category>
		<category><![CDATA[China business knowledge]]></category>
		<category><![CDATA[CUHK Business School]]></category>
		<category><![CDATA[Data privacy]]></category>
		<category><![CDATA[Data protection]]></category>
		<category><![CDATA[digital marketing]]></category>
		<category><![CDATA[GenAI]]></category>
		<category><![CDATA[Generative AI]]></category>
		<category><![CDATA[Jesse Yao]]></category>
		<category><![CDATA[target setting]]></category>
		<category><![CDATA[Yao Jesse Yunfei（姚雲飛）]]></category>
		<guid isPermaLink="false">https://cbk.bschool.cuhk.edu.hk/?p=15194</guid>

					<description><![CDATA[<p>When all businesses use the same playbook, they just step on each other’s toes and miss out on potential customers Featured faculty: Jesse Yao Written by Putro Harnowo For the first time, Meta will eclipse Google as the largest advertising platform on earth. The social media company is poised to claim more than US$243 billion in [&#8230;]</p>
<p>The post <a href="https://cbk.bschool.cuhk.edu.hk/if-everyone-uses-ai-who-stands-out/">If everyone uses AI, who stands out?</a> first appeared on <a href="https://cbk.bschool.cuhk.edu.hk">China Business Knowledge</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3 class="article__heading__content">When all businesses use the same playbook, they just step on each other’s toes and miss out on potential customers</h3>
<p class="article_author">Featured faculty: <a href="https://www.bschool.cuhk.edu.hk/staff/yao-jesse/" target="_blank" rel="noopener">Jesse Yao</a><br />
Written by <a href="mailto:cbk@baf.cuhk.edu.hk" target="_blank" rel="noopener">Putro Harnowo</a></p>
<p class="article__paragraph">For the first time, Meta will eclipse Google as the largest advertising platform on earth. The social media company is poised to claim more than <a href="https://www.wsj.com/business/media/meta-expected-to-unseat-google-as-worlds-largest-digital-ad-player-83d3f522">US$243 billion</a> in revenue this year, edging out Google’s US$240 billion. Artificial intelligence (AI) has optimised Meta’s algorithms to better match ads to its 3.56 billion daily users while engaging them with <a href="https://www.wsj.com/tech/meta-reels-revenue-ade4179e">short videos</a> across Instagram and Facebook.</p>
<p>Both giants have <a href="https://www.barrons.com/articles/alphabet-google-stock-sale-ai-funding-meta-041c029b">invested heavily</a> in AI, yet neither can sit on its laurels since other big techs have also ramped up their AI-driven algorithms to refine their social media ad targeting. Advertisers pay digital platforms to ensure their message reaches the right users and receive a payoff if those users make a purchase. Without being targeted with an ad, a potential consumer would not be aware of the product and may never buy it.</p>
<figure class="right" data-aos="fade-right">
<div class="img-container"><img fetchpriority="high" decoding="async" class="alignnone" src="/wp-content/uploads/iStock-21952300790.jpg" alt="algorithms" width="900" height="600" /></div><figcaption>When algorithms find individuals with a high purchase probability, the targets are probably already eyed by many advertisers.</figcaption></figure>
<p>Ad targeting creates value for businesses and consumers when advertisers accurately reach their target audience. AI technologies like machine learning and large language models come in handy to help platforms collect information about users’ behaviours and demographics, such as age and location, and crunch the data to predict their likelihood of purchase.</p>
<p>At this point, it may be scary to see how social media uses AI-fueled algorithms to match their user profiles with the diverse needs of advertisers. However, <a href="https://www.bschool.cuhk.edu.hk/staff/yao-jesse/">Jesse Yao</a>, an Associate Professor at the Department of Marketing at the Chinese University of Hong Kong (CUHK) Business School, argues that perfect targeting is impossible.</p>
<p>“When competition is strong, companies have a high chance of targeting the same pool of individuals, especially if their algorithms use similar mechanisms,” he says. “Companies will definitely develop more sophisticated algorithms to improve their targeting ability, but data privacy regulations will continue to limit their ability to perfect their targeting.”</p>
<p>Data privacy laws restrict businesses from collecting personal data that could identify an individual, so businesses must implement measures to decouple users from their real identities. Consequently, algorithms cannot achieve 100 per cent accurate targeting or certainty that someone is interested, and even if they did, the targets would no longer be high-quality.</p>
<h2>How do businesses deal with flawed targeting</h2>
<p>Since perfect targeting is arduous, advertisers often ponder whether to focus on “precision” to carefully target only a small number of very interested groups or on “recall” to cast a wider net to reach almost everyone who might be interested. The drawback is that prioritising high precision may miss out on other individuals who are also interested but were not identified, while prioritising high recall may waste resources.</p>
<p>A paper titled <a href="https://doi.org/10.1287/mksc.2024.0930"><em>Algorithmic targeting and the precision-recall tradeoff</em></a>, tries to navigate this dilemma. In the study, Professor Yao collaborates with Ganesh Iyer at the University of California, Berkeley and Zachary Zhong Zemin at the University of Toronto to use game theory, a mathematical study of strategic decision-making in which the outcome for each party depends on the choices of all involved.</p>
<blockquote><p><span class="quote quote--left">“</span>When competition is strong, companies have a high chance of targeting the same pool of individuals, especially if their algorithms use similar mechanisms.<span class="quote">”</span></p>
<p><cite>Professor Jesse Yao</cite></p></blockquote>
<p>The study highlights that the algorithms used by many platforms may be highly similar. While the algorithms used by the platforms are proprietary, their underlying machine learning techniques are similar, especially when they use public data and the same data analytics tools or AI models. People also typically search for products on multiple channels, signalling their interest in different platforms.</p>
<p>When algorithms identify individuals with a high probability of purchase, there is a big chance that other competitors are also eyeing the same targets. Even across distinct apps like TikTok, Facebook, and Amazon, there would still be significant overlap, and advertisers end up targeting similar groups with their competitors. This is often why, when you Google a brand, you might see an ad for the product you searched for on social media, and then see more ads from other brands.</p>
<p>“Companies can benefit a lot from being the only one that targets interested people, but will benefit less from competing for the same targets,” says Professor Yao. “To soften competition, they strategically target fewer people who are moderately interested, or lower both recall and precision. This way, the targets still have a reasonable chance of making a purchase when seeing ads, but without as much costly head-to-head competition.”</p>
<h2>What if businesses tailor their algorithms differently?</h2>
<figure class="left" data-aos="fade-right">
<div class="img-container"><img decoding="async" class="alignnone" src="/wp-content/uploads/iStock-498551705.jpg" alt="algorithms" width="900" height="600" /></div><figcaption>Advertisers should seek unique segments they can own, rather than competing for the most obvious targets.</figcaption></figure>
<p>Undoubtedly, targeting fewer people with moderate interest is not ideal, as it could also result in a pool of duds. Hence, advertisers are motivated to develop unique algorithms and analytics tools to differentiate their predictions. “The more unique, proprietary data a company uses, the less likely they are to target the same people as their competitors,” Professor Yao adds.</p>
<p>Advertisers nowadays can either work with digital platforms or build their own custom algorithms, but this approach is costly. It may also indirectly help their competitors by making the markets less crowded with ads, without the competitors even needing to spend a penny, so this strategy must be executed carefully.</p>
<p>Some may consider combining public and proprietary data to improve predictions and reduce costs. However, data privacy regulations in many jurisdictions require companies to choose either public or proprietary data for a given consumer, but not both at once.</p>
<p>Combining data sources also creates new personal data profiles, which require new consent or a re-evaluation under most data privacy regulations. Some digital platforms even explicitly forbid data scraping or combining user profiles for commercial targeting, especially if the data becomes personally identifiable.</p>
<h2>Modern targeting in ever-competitive markets</h2>
<p>Given that there is no easy way to avoid targeting overlap, Professor Yao suggests that advertisers strategically adjust their precision and recall while keeping tabs on the rivals’ digital campaigns. “Companies should not only think about the potential customers but also consider the strategic response from their competitors.”</p>
<p>When ad costs are low, they may consider targeting a larger pool of people to reach as wide an audience as possible or to achieve high recall. When ad costs are high, they should be more selective and target only those genuinely interested. To minimise overlap, advertisers should continue seeking unique segments they can own, rather than competing for the most obvious targets all the time.</p>
<div class="article__related">
<div class="article__related__label">RELATED ARTICLE</div>
<p><a href="https://cbk.bschool.cuhk.edu.hk/tech-rivalry-erodes-your-privacy/" target="_blank" rel="noopener">Tech rivalry erodes your privacy</a></p>
</div>
<p>For Meta, perhaps its unique segments are its short videos and cross-platform ecosystem, but for advertisers, its vast user base may increase overlap with their competitors. While the study does not specifically analyse Meta’s success, its framework provides a useful lens on how developing proprietary data analytics and strategic differentiation can gain a competitive edge.</p>
<p>There are plenty of fish in the sea, but if all the boats have trawlers, a wise fisher is those who know where to cast their line.</p><p>The post <a href="https://cbk.bschool.cuhk.edu.hk/if-everyone-uses-ai-who-stands-out/">If everyone uses AI, who stands out?</a> first appeared on <a href="https://cbk.bschool.cuhk.edu.hk">China Business Knowledge</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When data security drives AI preference</title>
		<link>https://cbk.bschool.cuhk.edu.hk/when-data-security-drives-ai-preference/</link>
		
		<dc:creator><![CDATA[Putro]]></dc:creator>
		<pubDate>Thu, 06 Aug 2026 01:47:52 +0000</pubDate>
				<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI models]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[ChatGPT]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[China business knowledge]]></category>
		<category><![CDATA[Chinese AI]]></category>
		<category><![CDATA[CUHK Business School]]></category>
		<category><![CDATA[Data privacy]]></category>
		<category><![CDATA[Data protection]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[DeepSeek]]></category>
		<category><![CDATA[Gao Zhenyu]]></category>
		<category><![CDATA[Gao Zhenyu（高振宇）]]></category>
		<category><![CDATA[GenAI]]></category>
		<category><![CDATA[Generative AI]]></category>
		<category><![CDATA[Jiang Griffin Wenxi（江文熙）]]></category>
		<category><![CDATA[Jiang Wenxi]]></category>
		<guid isPermaLink="false">https://cbk.bschool.cuhk.edu.hk/?p=15179</guid>

					<description><![CDATA[<p>AI evolves rapidly, but some firms opt to wait and see until their ideal solutions emerge Featured faculty: Jiang Wenxi and Gao Zhenyu Written by Putro Harnowo The launch of ChatGPT in late 2022 by OpenAI was a turning point for artificial intelligence (AI) worldwide. While the chatbot was not officially available in China, enterprise partnerships [&#8230;]</p>
<p>The post <a href="https://cbk.bschool.cuhk.edu.hk/when-data-security-drives-ai-preference/">When data security drives AI preference</a> first appeared on <a href="https://cbk.bschool.cuhk.edu.hk">China Business Knowledge</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3 class="article__heading__content">AI evolves rapidly, but some firms opt to wait and see until their ideal solutions emerge</h3>
<p class="article_author">Featured faculty: <a href="https://www.bschool.cuhk.edu.hk/staff/jiang-wenxi-griffin/" target="_blank" rel="noopener">Jiang Wenxi</a> and <a href="https://www.bschool.cuhk.edu.hk/staff/gao-zhenyu/" target="_blank" rel="noopener">Gao Zhenyu</a><br />
Written by <a href="mailto:cbk@baf.cuhk.edu.hk" target="_blank" rel="noopener">Putro Harnowo</a></p>
<p class="article__paragraph">The launch of ChatGPT in late 2022 by OpenAI was a turning point for artificial intelligence (AI) worldwide. While the chatbot was not officially available in China, enterprise partnerships with <a href="https://www.scmp.com/tech/big-tech/article/3268233/microsoft-maintains-ai-services-hong-kong-openai-curbs-api-access-china">Microsoft Azure</a> and workarounds such as virtual private networks and third-party proxies have helped, to some extent, the ChatGPT moment reach the country.</p>
<p>However, that access closed when OpenAI decided to <a href="https://www.bloomberg.com/news/articles/2024-06-26/openai-s-china-block-to-reshape-ai-scene-as-big-players-like-alibaba-pounce">withdraw</a> completely from the country in 2024. Another AI giant, Anthropic, released Claude in 2023 but <a href="https://www.anthropic.com/news/updating-restrictions-of-sales-to-unsupported-regions">never made</a> it available to the Chinese market. Although it seems that American tech firms are pulling away, Chinese firms are equally hesitant to rely on foreign AI technology.</p>
<p>No wonder that <a href="https://www.channelnewsasia.com/business/deepseek-china-ai-chatbot-chatgpt-explainer-4900201">DeepSeek</a>’s debut in early 2025 sent another shockwave, the DeepSeek moment, and dramatically jump-started China’s AI adoption. “Technology adoption is not purely economic, but one deeply intertwined with strategic priorities,” says <a href="https://www.bschool.cuhk.edu.hk/staff/jiang-wenxi-griffin/">Jiang Wenxi</a>, Professor of Finance at the Chinese University of Hong Kong (CUHK) Business School.</p>
<p>In a paper titled <a href="https://dx.doi.org/10.2139/ssrn.5952978"><em>AI sovereignty</em></a>, Professors Jiang and <a href="https://www.bschool.cuhk.edu.hk/staff/gao-zhenyu/">Gao Zhenyu</a>, Associate Professor in the same department, in collaboration with Fudan University’s Ren Haohan, Wang Kemin, and Wu Yuezhi, examine more than 28,000 detailed dialogues between Chinese listed firms and their investors from January 2022 to June 2025 on investor interaction platforms. Investors frequently inquire whether firms use or plan to use specific AI models.</p>
<p><img decoding="async" class="aligncenter" src="/wp-content/uploads/CBK-AI-Sovereignty-2.png" alt="GenAI" width="1920" height="1125" /></p>
<p>As expected, ChatGPT and DeepSeek were discussed far more frequently than other models. The launch of both also triggered notable adoption spikes, and a consistent pattern appears: Many Chinese firms were hesitant to use AI at first, but once DeepSeek became available, they accelerated.</p>
<p>From an economic point of view, DeepSeek is significantly cheaper than ChatGPT, so this could be one of the main reasons for avoiding foreign AI models, but the study notes that cost has never been a problem. Rather, there is a bigger concern.</p>
<figure class="right" data-aos="fade-right">
<div class="img-container"><img loading="lazy" decoding="async" class="alignnone" src="/wp-content/uploads/shutterstock_2616708285.jpg" alt="AI model" width="900" height="600" /></div><figcaption>AI tools often require sending data to external servers, raising the risk of sensitive data leakage.</figcaption></figure>
<h2>Data is the lifeblood of AI</h2>
<p>Firms that are consistently reluctant to adopt foreign AI but show a greater preference for domestic AI often use data-related terms and keywords in their annual reports. This suggests that the data is highly valuable to them and any leaks or breaches will result in dire consequences.</p>
<p>AI tools often require sending data to external servers, which raises the risk of sensitive data leakage. Since Chinese firms handling critical data are subject to regulations on data handling and processing, sending data to a foreign AI’s servers could pose a compliance risk.</p>
<p>“Priority of safeguarding data security makes firms wary of foreign AI models that could inadvertently funnel proprietary or sensitive data out of China,” says Professor Jiang.</p>
<p>Data is a fundamental resource for training AI models. Without vast amounts of data, it would be impossible for AI models to perform analysis and generate outputs and predictions. Businesses also increasingly see data as a critical asset, much like oil or other resources, that can give them a technological edge.</p>
<p>Therefore, China has issued a series of laws, including the Cybersecurity Law (2017), the Data Security Law (2021), and the Personal Information Protection Law (2021), that provide a comprehensive framework for handling data. These laws require data to be stored on servers physically located within the country.</p>
<p>Cybersecurity Law laid the foundation for data protection and set broad rules for network security and critical information infrastructure. Data Security Law imposes strict rules on data collection, storage, use, and cross-border transfer. The Personal Information Protection Law dictates how personal data must be handled, including requirements for transferring outside of China.</p>
<p>Similar to many other countries, China’s data protection laws borrow heavily from the EU’s General Data Protection Regulation. While the EU does not impose a blanket requirement to keep all data locally, it sets very strict rules on how its citizens’ data must be protected, regardless of where the company processing the data is located.</p>
<blockquote><p><span class="quote quote--left">“</span>Technology adoption is not purely economic, but one deeply intertwined with strategic priorities.<span class="quote">”</span></p>
<p><cite>Professor Jiang Wenxi</cite></p></blockquote>
<h2>More than just supporting local technology</h2>
<p>China produces more top AI researchers and talent, but the US <a href="https://time.com/7358519/ai-china-us-race-graphs/">leads</a> in AI models and the critical chips for AI training. The discussions captured on investor interaction platforms also acknowledge this. Investors understand that a preference for domestic AI models may place Chinese firms at a competitive disadvantage.</p>
<p>Regardless, Chinese firms are keen to use domestic AI models to avoid compliance risks. “Although the best Chinese AI models still underperform the US ones, the gap is quite small and may not be significant when applied to specific business scenarios,” Professor Jiang adds.</p>
<p>Further analysis indicates that Chinese firms do not completely ignore foreign models but strategically limit their use to low-risk domains, such as customer service, translation, and other non-critical functions.</p>
<p>Moreover, the market supports this approach. When Chinese firms, especially those in strategic national sectors, announced their AI adoption, their stock prices rose significantly. Conversely, when these firms said they were using foreign AI, their stock performed worse or at least stayed unchanged.</p>
<figure class="left" data-aos="fade-right">
<div class="img-container"><img loading="lazy" decoding="async" class="alignnone" src="/wp-content/uploads/iStock-2202738325.jpg" alt="AI model" width="900" height="600" /></div><figcaption>Since data security influences AI adoption and development, the technology may evolve into two separate ecosystems.</figcaption></figure>
<h2>The future of AI ecosystems</h2>
<p>AI has become a foundational utility, much like the internet, and has driven exponential investment in China and the US, the dominant players in AI development. Alas, the two superpowers have locked in a head-to-head competition for years.</p>
<p>Most recently, the US <a href="https://www.channelnewsasia.com/world/us-takes-step-halt-nvidia-ai-chip-shipments-chinese-firms-outside-china-6153111">has banned</a> the sale of its advanced AI processors to Chinese firms and their subsidiaries, while China intervened in the acquisition of a Chinese-founded AI firm, <a href="https://www.bloomberg.com/news/articles/2026-05-21/manus-weighs-raising-1-billion-to-unwind-meta-takeover">Manus</a>, to prevent the outflow of proprietary technology and AI talent to the US.</p>
<p>The available data and privacy frameworks determine how AI models are trained, which then shapes the next wave of AI innovations. Since data security influences AI adoption and development, this loop may lead to AI models from two dominant powers evolving differently.</p>
<p>“The development of AI technology may evolve into two separate approaches and ecosystems,” Professor Jiang says. “However, Chinese models are open source, so firms can fine-tune them locally to meet specific needs with greater data control for developers to adopt. This gives some hope that the separation might not be exacerbated.”</p>
<div class="article__related">
<div class="article__related__label">RELATED ARTICLE</div>
<p><a href="https://cbk.bschool.cuhk.edu.hk/can-force-adoption-solve-ai-resistance/" target="_blank" rel="noopener">Can force adoption solve AI resistance?</a></p>
</div>
<p>Ultimately, with the growing calls for global AI governance to safely advance the technology, collaborative frameworks may emerge to mitigate the risks of a fragmented ecosystem and ensure that the benefits of AI technologies are shared universally.</p><p>The post <a href="https://cbk.bschool.cuhk.edu.hk/when-data-security-drives-ai-preference/">When data security drives AI preference</a> first appeared on <a href="https://cbk.bschool.cuhk.edu.hk">China Business Knowledge</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Tech rivalry erodes your privacy</title>
		<link>https://cbk.bschool.cuhk.edu.hk/tech-rivalry-erodes-your-privacy/</link>
		
		<dc:creator><![CDATA[Putro]]></dc:creator>
		<pubDate>Thu, 06 Nov 2025 01:30:27 +0000</pubDate>
				<category><![CDATA[Innovation & Technology]]></category>
		<category><![CDATA[big data]]></category>
		<category><![CDATA[Data breach]]></category>
		<category><![CDATA[Data leak]]></category>
		<category><![CDATA[Data privacy]]></category>
		<category><![CDATA[Data protection]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Jesse Yao]]></category>
		<category><![CDATA[Jesse Yao Yunfei]]></category>
		<category><![CDATA[Personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Yao Jesse Yunfei（姚雲飛）]]></category>
		<guid isPermaLink="false">https://cbk.bschool.cuhk.edu.hk/?p=14506</guid>

					<description><![CDATA[<p>A new study reveals how reputation, competition, and regulation shape the way businesses treat your personal data Featured faculty: Jesse Yao Written by Sally Ho It’s fair to say that no one has been spared from the universal nuisance of scam calls and messages. Bad actors often find the targets from data brokers that collect [&#8230;]</p>
<p>The post <a href="https://cbk.bschool.cuhk.edu.hk/tech-rivalry-erodes-your-privacy/">Tech rivalry erodes your privacy</a> first appeared on <a href="https://cbk.bschool.cuhk.edu.hk">China Business Knowledge</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3 class="article__heading__content">A new study reveals how reputation, competition, and regulation shape the way businesses treat your personal data</h3>
<p class="article_author">Featured faculty: <a href="https://www.bschool.cuhk.edu.hk/staff/yao-jesse/">Jesse Yao</a><br />
Written by <a href="mailto:cbk@baf.cuhk.edu.hk" target="_blank" rel="noopener">Sally Ho</a></p>
<p class="article__paragraph">It’s fair to say that no one has been spared from the universal nuisance of scam calls and messages. Bad actors often find the targets from data brokers that collect personal data illicitly or purchase it from platforms to which users have entrusted their information.</p>
<p>Companies collect vast information about their customers to personalise advertisements and product offerings, yet many users are unaware of how valuable their personal data is. While the exact market value of personal data remains obscure, the global data broker industry is estimated to be worth <a href="https://www.cnet.com/tech/services-and-software/data-brokers-how-your-personal-data-becomes-business/">US$277 billion</a> in 2024.</p>
<figure class="right" data-aos="fade-left">
<div class="img-container"><img loading="lazy" decoding="async" class="alignnone" src="/wp-content/uploads/shutterstock_2428405741.jpg" alt="privacy" width="2048" height="1365" /></div><figcaption>Companies have a strong motivation to sell data for immediate profits and may not realise the long-term benefit from consumer loyalty.</figcaption></figure>
<p>Although countries around the world have issued stringent data protection laws, data misuse and breaches are increasingly common. Many companies mention their commitment to keep users’ data private in their privacy policies, but end up sharing or selling it to third parties without consent.</p>
<p>“Companies have a strong motivation to sell users’ data for immediate profits, and may not realise that they can actually gain consumer trust and loyalty by honouring their commitments to user privacy,” says <a href="https://www.bschool.cuhk.edu.hk/staff/yao-jesse/">Jesse Yao</a>, Assistant Professor at the Chinese University of Hong Kong (CUHK) Business School. “Data sales are often not transparent or directly observable. Consumers can’t easily verify if a company is truly keeping its privacy promises.”</p>
<p>Ultimately, the nature of data collection creates a conundrum, where consumers are unsure about sharing their information as companies juggle between keeping and selling data. In his latest paper, <a href="https://doi.org/10.1287/mksc.2024.1006"><em>Reputation for privacy</em></a>, Professor Yao explains that such a dilemma is called the “holdup problem,” where two parties hesitate to cooperate due to concern about the opportunistic behaviour of the other party.</p>
<div class="clearfix">
<h1>Can reputation protect data privacy?</h1>
<p>Consumers who believe that a firm values its reputation over immediate profits are more confident in entrusting their personal data with the said firm. Building on this idea, Professor Yao models various scenarios of firm and consumer data interactions and then compares the outcomes in different market structures.</p>
<blockquote><p><span class="quote quote--left">“</span>Companies have a strong motivation to sell users’ data for immediate profits, and may not realise that they can actually gain consumer trust and loyalty by honouring their commitments to user privacy.<span class="quote">”</span></p>
<p><cite>Professor Jesse Yao</cite></p></blockquote>
<p>The analyses find that privacy protection thrives in a monopoly setting, where one firm dominates. In this setting, customers quickly find out which firm to blame for any data sales. Considering the risks of permanent reputational damage by selling or recklessly handling user data, the firm has a strong incentive to protect data to keep consumer trust and loyalty.</p>
<p>In a competitive market with multiple firms relentlessly trying to outmanoeuvre each other, reputation fails to serve as a privacy gatekeeper. Since consumers cannot easily identify which company leaks or sells their data, and individual firms do not bear the full consequences of harming consumer trust, the repercussions for the offenders are weak and temporary.</p>
<p>Take Apple’s operating system iOS, for instance. The company has quasi-monopoly power over its closed ecosystem and tight controls on both hardware and software. Consumers cannot install software from other manufacturers and will easily point fingers for any data breaches. Since Apple cares so much about reputation, it has strong incentives not to misuse users’ data.</p>
<figure class="right" data-aos="fade-right">
<div class="img-container"><img loading="lazy" decoding="async" class="alignnone" src="/wp-content/uploads/shutterstock_2417533493.jpg" alt="privacy" width="2048" height="1365" /></div><figcaption>Privacy protection thrives in a monopoly setting, where customers can quickly find out which firm to blame for any data sales.</figcaption></figure>
<p>On the other hand, the open Android ecosystem has numerous hardware manufacturers and software developers sharing the market. Consumers often cannot tell which apps were responsible for privacy violations due to noisy data flows and shared infrastructure, making the environment more prone to privacy risks, as evident in many news <a href="https://www.forbes.com/sites/zakdoffman/2025/04/11/new-iphone-and-android-security-alert-1-billion-users-now-at-risk/">reports</a>.</p>
<p>“We even find situations where two competing companies at first wanted to stick to their privacy commitment and were very willing to keep their reputations, but the temptation was so strong that they eventually failed to do so,” says Professor Yao.</p>
<h1>Why privacy policy and regulation matter</h1>
<p>Unfortunately, there is no purely monopolistic market in the real world, and people nowadays use multiple apps on various devices. Companies can easily gain short-term profits by selling data, and customers will find it hard to track down the responsible party. This lack of accountability reduces firms’ incentives to protect privacy. In this case, regulation plays a vital role in ensuring consumers’ rights.</p>
<p>Sound regulation can extend benefits for both consumers and companies. Protecting data privacy will make consumers more confident to share their information and to get better product offerings. At the same time, companies benefit from enhanced reputations and sustainable profits from loyal customers.</p>
<p>“Consumers and companies actually share the same interest, but the companies might be tempted to act against consumers’ interest by selling their data for short-term gains,” says Professor Yao. “Therefore, well-designed regulations are important to encourage businesses to behave responsibly, which benefits both consumers and companies in the long run.”</p>
<p>On top of that, regulators shall impose fines to deter firms from violating privacy commitments. “Liability fines by themselves are not enough, but liability fines with regulatory monitoring could do the trick,” he says.</p>
<div class="clearfix">
<div class="article__related">
<div class="article__related__label">RELATED ARTICLE</div>
<p><a href="https://cbk.bschool.cuhk.edu.hk/how-privacy-rights-affect-personal-data-markets-and-firm-profit/" target="_blank" rel="noopener">How privacy rights affect personal data markets and firm profit</a></p>
</div>
<p>The study offers a general framework for future exploration on the effectiveness of different policy tools and business practices, especially on how emerging technologies like AI will shape privacy dynamics.</p>
<p>As technology advancements tend to increase the benefits and complexity of data use, enforcing privacy in ever competitive markets becomes challenging. Regulators may use AI-based monitoring and enforcement, alongside liability fines, to encourage firms to maintain privacy commitments. Without strong and enhanced regulatory interventions, enforcing data privacy may become more and more difficult as technology progresses.</p>
</div>
</div><p>The post <a href="https://cbk.bschool.cuhk.edu.hk/tech-rivalry-erodes-your-privacy/">Tech rivalry erodes your privacy</a> first appeared on <a href="https://cbk.bschool.cuhk.edu.hk">China Business Knowledge</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How Privacy Rights Affect Personal Data Markets and Firm Profit</title>
		<link>https://cbk.bschool.cuhk.edu.hk/how-privacy-rights-affect-personal-data-markets-and-firm-profit/</link>
		
		<dc:creator><![CDATA[Putro]]></dc:creator>
		<pubDate>Thu, 26 Oct 2023 02:00:50 +0000</pubDate>
				<category><![CDATA[Consumer Behaviour]]></category>
		<category><![CDATA[Marketing]]></category>
		<category><![CDATA[Data protection]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Ke Tony T.（柯特）]]></category>
		<category><![CDATA[Personal data]]></category>
		<category><![CDATA[Privacy rights]]></category>
		<category><![CDATA[Tony Ke]]></category>
		<guid isPermaLink="false">https://cbk.bschool.cuhk.edu.hk/?p=11109</guid>

					<description><![CDATA[<p>Striking the right balance between data regulation and consumer benefits is crucial for trust and successful data sharing, a new study finds By Pete Sabine Data protection is everything in a world that is run on and by the internet. The enactment of the EU’s General Data Protection Regulation (GDPR) in 2018 heralded a new [&#8230;]</p>
<p>The post <a href="https://cbk.bschool.cuhk.edu.hk/how-privacy-rights-affect-personal-data-markets-and-firm-profit/">How Privacy Rights Affect Personal Data Markets and Firm Profit</a> first appeared on <a href="https://cbk.bschool.cuhk.edu.hk">China Business Knowledge</a>.</p>]]></description>
										<content:encoded><![CDATA[<h3 class="article__heading__content">Striking the right balance between data regulation and consumer benefits is crucial for trust and successful data sharing, a new study finds</h3>
<p class="article_author">By <a href="mailto:cbk@baf.cuhk.edu.hk">Pete Sabine</a></p>
<p class="article__paragraph">Data protection is everything in a world that is run on and by the internet. The enactment of the EU’s General Data Protection Regulation (GDPR) in 2018 heralded a new era of personal data privacy. Its comprehensive framework for protecting individuals’ personal data and ensuring their privacy rights has inspired countries to adopt similar regulations in recent years.</p>
<p>There is a tightrope to walk when it comes to protecting consumers. Data can indicate many things about a person’s information, habits, and activities, which could be misused if they fall into the wrong hands, leading to identity theft, fraud, or other damaging consequences. On the other hand, consumers do enjoy the benefits of data sharing, such as better services and prices.</p>
<p>In the digital realm, where data is currency, the answer beckons. How does GDPR impact the personal data markets? Are there any situations where both companies and consumers can benefit?</p>
<blockquote><p><span class="quote quote--left">“</span>With the data, firms can provide better personalisation or product recommendation, which will better cater to consumers’ preferences.<span class="quote">”</span></p>
<p><cite>Prof. Tony Ke</cite></p></blockquote>
<p>“GDPR consists of two key components, including endowing consumers with privacy rights – the rights to control their data – and imposing data security mandates on companies,” says <a href="https://www.bschool.cuhk.edu.hk/staff/ke-tony/">Tony Ke</a>, Associate Professor at the Department of Marketing at The Chinese University of Hong Kong (CUHK) Business School.</p>
<p>A new paper by Prof. Ke and Prof. K. Sudhir at Yale School of Management titled <a href="https://pubsonline.informs.org/doi/full/10.1287/mnsc.2022.4614"><em>Privacy Rights and Data Security: GDPR and Personal Data Markets</em></a> represents a fascinating dive into this subject of vital importance. The team employed a game theoretic analysis to examine the long-term impact of the GDPR on personal data markets, consumer well-being, and firm profitability.</p>
<p>“We found that the first component [privacy rights] mostly decreases data availability in the market because consumers now have the option of opting out of data collection and some of them will exercise this right,” says Prof. Ke. “On the other hand, the second component [data security mandates] increases data availability in the market because it enables trust between consumers and companies or data collectors.”</p>
<div class="clearfix">
<h2>Conundrum of Equilibrium</h2>
<p>While GDPR is recognised as the gold standard on personal data protection, its long-term impact on personal data markets, consumer well-being, and firm profitability is unclear. The likes of British Airways, Google and Marriott have already been hit with massive fines for data breaches. Critics say innovation and consumer welfare are taking a huge hit, while smaller firms are unable to compete, and venture capital funding to tech firms may also be suffering.</p>
<p>Some observers believe that the GDPR hurts digital marketing, and reduces the ability of marketers to effectively work. Other studies show that this has not been the case, suggesting that the legislation and opt-in increased at a European telecommunications firm.</p>
<figure class="left" data-aos="fade-right">
<div class="img-container"><img loading="lazy" decoding="async" src="/wp-content/uploads/Data-privacy-iStock-1317933536-600x400.jpg" alt="data-privacy-gdpr" width="1000" height="667" /></div><figcaption>Data can reveal personal information, habits, and activities, risking misuse or enabling identity theft, while also benefiting consumers with improved services and prices.</figcaption></figure>
<p>An argument could be made that consumers are being deprived as they are not being effectively targeted, and the personalisation of products and services is lessened. There is a fine balance at play: consumers want it all – personalisation can bring a world of advantages, but privacy lessens the ability by limiting access to purchase, data opt-in, erasure, and transfer decisions.</p>
<p>“Game theory is a useful tool to capture agents’ strategic incentives, be it a consumer or a firm, along with different agents’ interactions in the long run,” says Prof. Ke. “As privacy concerns become more prominent, consumers may be more careful and thoughtful in managing their privacy rights.”</p>
<p>“The firms’ reactions and changes in their decisions will further influence the consumers’ choices over privacy control. This feedback loop will eventually converge to an equilibrium, as predicted by the Nash equilibrium, a general concept in game theory.”</p>
<p>The team’s analysis implies that GDPR effectively reduces consumer opt-in and data availability, which in turn lessens the firm’s ability to personalise product recommendations or services to cater to consumers’ personal interests, and has the additional effect of raising prices for consumers due to higher security mandates.</p>
<p>In terms of the firm profit, the study found that privacy rights and data security mandates have differing effects.</p>
<p>“Privacy rights will increase firm profitability when consumers face high data breach costs or have low trust in data collection. In this case, privacy rights help separate goods transactions with data transfer so it ensures trade and benefits the firm,” he adds.</p>
<p>However, when consumers face low data breach costs or have high trust in data collection, privacy rights will decrease firm profit. This is because in the case without privacy rights, the firm cannot help but offer a low-price basic product to those who haven’t bought anything yet as the firm can only easily identify and keep those who have already made a purchase. This makes people less likely to buy something in the beginning, which hurts the firm profits.</p>
<figure class="right" data-aos="fade-left">
<div class="img-container"><img loading="lazy" decoding="async" src="https://cbk.bschool.cuhk.edu.hk/wp-content/uploads/Data-privacy-iStock-520229134-600x450.jpg" alt="data-privacy-gdpr" width="2048" height="1365" /></div><figcaption>The study found GDPR reduces privacy breach risk, benefiting consumers and firm profitability, increasing security, consumer and firm surplus, and data transparency.</figcaption></figure>
<p>People often share data when the benefits outweigh the risks, and there is confidence in data security protection. When this trust is gone, consumers will quickly cancel their relationships with firms. The onus is thus on companies to create an environment where people do trust them, and hence privacy rights and data sharing can be increased in a win-win situation – consumers willingly share data to get benefits, and companies offer the highest standards of protection.</p>
<div class="clearfix">
<h2>Win-Win Situation</h2>
<p>Overall, the research found that GDPR can reduce consumers’ privacy breach risk, benefiting consumers and giving a boost to firm profitability. When firms increase their security capabilities, the result can be an increase in both consumer and firm surplus. Additionally, consumer surplus is increased by data transparency and reduced price discrimination.</p>
<p>While GDPR has a complex impact on consumers, the study showed that it can be beneficial in the right circumstances, protecting consumers and offering the best services and prices. However, the impact on firms is dependent on market conditions and mitigation of breach costs.</p>
<p>“The GDPR works better in competitive markets because in competitive markets, consumers in general benefit from privacy regulations. By contrast, consumers could get hurt from privacy regulations in monopolistic markets,” says Prof Ke.</p>
<p>“This is because the society can benefit from the availability of consumer data,” he adds. “With the data, firms can provide better personalisation or product recommendation, which will better cater to consumers’ preferences. GDPR decreases data availability and thus could hurt both consumers and firms when consumers face relatively low data breach costs.”</p>
<div class="article__related">
<div class="article__related__label">RELATED ARTICLE</div>
<p><a href="https://cbk.bschool.cuhk.edu.hk/should-online-platforms-share-market-data-with-sellers/" target="_blank" rel="noopener noreferrer">Should Online Platforms Share Market Data with Sellers?</a></p>
</div>
<p>Furthermore, Prof. Ke sees the need for more studies on similar regulations being implemented in different regions. For instance, Hong Kong’s Personal Data (Privacy) Ordinance (PDPO), one of Asia’s longest-standing comprehensive data protection laws passed in 1995, share a number of common features with GDPR as it was drafted in reference to the Organisation for Economic Co-operation and Development’s Privacy Guidelines 1980 and the EU Directive.</p>
<p>“Given that the GDPR constitutes significant developments from EU directive, there are also important differences between PDPO and GDPR,” says Prof. Ke. “For example, GDPR is built on the ‘privacy by design’ principle that gives data subjects more specific control of their data, and also imposes wider responsibilities in data protection on data controllers [compared to PDPO].”</p>
</div>
</div><p>The post <a href="https://cbk.bschool.cuhk.edu.hk/how-privacy-rights-affect-personal-data-markets-and-firm-profit/">How Privacy Rights Affect Personal Data Markets and Firm Profit</a> first appeared on <a href="https://cbk.bschool.cuhk.edu.hk">China Business Knowledge</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
