This is a guest commentary by Dr. Nico Ebert from ZHAW School of Management and Law. The article was originally published in German on Privacy Bits.

In a lecture for the Fair Data Forum, I dealt with the question “What value does data protection have for individuals and what are they willing to pay for it?”

The three data privacy types

As always, there is not one “individual”, as everyone has different data protection preferences and thus, attributes different value to having personal data safeguarded. Therefore, in order to classify individuals, there are different “typologies”. For example, Westin distinguishes between data protection fundamentalists, data protection pragmatists and completely unconcerned individuals. In 2002, Sheehan (2002) selected 889 persons in the USA and classified them with a questionnaire. Conclusion: 16% of the respondents were completely unconcerned about data protection, 81% were classified as pragmatists, and 3% as fundamentalists.

Willingness to pay vs willingness to accept

Numerous experiments were carried out to find out which types of people are willing to pay for data privacy and which ones are willing to share their data freely with third parties. In these experiments, the “willingness to accept” or the “willingness to pay” were analyzed. Willingness to accept describes the reward that must be offered to an individual, so that she/he is willing to share personal data (usually monetary compensation or services). The willingness to pay examines how much the individual is willing to pay for data protection (compensation for data protection).

What the studies say

In 2017, an experiment with 3000 students from a US university concluded that a pizza was a sufficient incentive for them to share e-mail addresses of three fellow students. Conversely, the students were rarely willing to accept a small additional expense for better data protection.

A different result was produced by an experiment published by the city of Pittsburgh (USA) in 2011, where the willingness to pay was investigated. In the experiment, 272 participants were recruited from the population. The individuals received a sum of money to be used to shop in a laboratory setting. By using a search engine provided by the University, participants were asked to select a suitable provider for a) batteries (a good with little privacy concerns) and b) sex toys (a good with stronger privacy concerns) and to purchase an item. The search engine displayed the available products and their prices in the form of a list. However, some participants were additionally presented with a data protection rating of the seller (e.g. 4/4 stars or 1/4 stars). Conclusion: many participants chose a seller with a better rating and were willing to pay more for products with a high data protection rating. These results could be replicated in two further studies.

A third experiment was published in 2013, in which the willingness to pay was examined. In an American women’s clothing store, 349 women were randomly interviewed for a survey on spending behavior. As a reward, the participants were offered a voucher which they could use to shop. Two types of voucher were offered: an anonymous USD 10 voucher (A) and a USD 12 voucher (B), where the purchases were not anonymous, i.e. could be traced by third parties. Groups of participants were presented the two vouchers in different orders (A first or B first). The experiment showed that the willingness to pay (i.e. to accept the USD 2 reduction from B to A for an increase in privacy) strongly depends on the sequence in which the two options are presented, suggesting the existence of a strong endowment effect.

Main findings

The main finding from the three studies is that willingness to pay depends on various factors. Summarized, it depends very much on a) who is addressed but also b) how the individual is addressed. Individuals which are more sensitive about their data are probably willing to pay more than insensitive individuals. However, many individuals will not have a clear data protection preference that holds true in all situations. Under certain circumstances, influencing factors are whether a) the added value of data protection is communicated in an understandable way (e.g. via simple ratings or a “non-traceable” USD 10 voucher) or b) whether data protection is the standard option. If data protection is the default setting, individuals may forgo compensation, which they would receive for abandoning data protection.

Original Article

Sources:

Athey, S., Catalini, C., & Tucker, C. (2017). The digital privacy paradox: small money, small costs, small talk (No. w23488). National Bureau of Economic Research.

Acquisti, A., Taylor, C., & Wagman, L. (2016). The economics of privacy. Journal of Economic Literature, 54(2), 442-92.

Acquisti, A., John, L. K., & Loewenstein, G. (2013). What is privacy worth?. The Journal of Legal Studies, 42(2), 249-274.

Beresford, Alastair R., Dorothea Kübler, and Sören Preibusch. 2012. Unwillingness to Pay for Privacy: A Field Experiment. Economics Letters 117:25–27.

Jentzsch, Nicola, Sören Preibusch, and Andreas Harasser. 2012. Study on Monetising Privacy: An Economic Model for Pricing Personal Information. Report for the European Network and Information Security Agency. Heraklion: European Network and Information Security Agency.

Kumaraguru, P., & Cranor, L. F. (2005). Privacy indexes: a survey of Westin’s studies (pp. 368-394). Carnegie Mellon University, School of Computer Science, Institute for Software Research International.

Sheehan, K. B. (2002). Toward a typology of Internet users and online privacy concerns. The Information Society, 18(1), 21-32.

Tsai, J. Y., Egelman, S., Cranor, L., & Acquisti, A. (2011). The effect of online privacy information on purchasing behavior: An experimental study. Information Systems Research, 22(2), 254-268.