Regulatory Competition: A Perspective from Data Protection Law
摘要
This paper examines the extent to which there is regulatory competition in the area of EU data protection law and whether this analytical perspective can explain the dynamics of legislative developments. It finds that due to the broad territorial scope of application of the General Data Protection Regulation (GDPR) and its spillover effects, the so-called Brussels effect, companies do not have the possibility to influence the applicable law. Thus, there is no regulatory competition between the EU and third countries. However, if the focus is shifted to the relationship between Member States, some regulatory competition can be observed in terms of the level of public enforcement. While companies cannot opt out of the application of the GDPR as such, they may be able to influence the competent lead supervisory authority by choosing the location of their establishment within the EU. Finally, it is discussed and answered in the negative whether the theory of regulatory competition can be applied to contractual relationships between a data controller and a data subject, such as the operator of a social network and a consumer.