Posted on June 5, 2026
The GDPR’s Afterlife: How a Privacy Law Quietly Reshaped Markets, Power, and Accountability
When the General Data Protection Regulation came into full force in May 2018, the spotlight fell, predictably, on consent banners, data subject access requests, and the suddenly visible plumbing of personal data processing. But the GDPR’s most durable mark may not sit within the privacy rights it codified. It lives, instead, in the way the regulation quietly rewired the architecture of digital markets, corporate accountability, and regulatory strategy across continents. See it only as a privacy framework, and you miss the deeper shifts it triggered—shifts that now reach into competition policy, organizational design, and how we think about power in the information economy.

From Data Protection to Market Regulation
The GDPR’s architects built into it a structural critique of contemporary capitalism—one that goes well beyond informational self-determination. Take Article 20, the right to data portability. On a first reading, it looks like a privacy provision: a tool for individuals to scoop up their personal data from one service and drop it into another. But the design reveals a competition logic. By lowering switching costs, the portability right pushes against the lock-in effects that keep dominant platforms dominant. It intervenes in market structure, not just in the relationship between controller and data subject.
This duality threads through the whole regulation. The demands around data protection by design and by default, set out in Article 25, require organizations to stitch protective measures into the architecture of products and systems from the start. In practice, that has forced product teams to rethink how data moves through their services. Often, it constrains the accumulation of behavioral profiles that fuel surveillance advertising. What comes out the other side isn’t just privacy compliance. It’s a quiet reengineering of the attention economy’s core engine.

Accountability as Organizational Discipline
Arguably the GDPR’s most underappreciated legacy is the accountability principle in Article 5(2). It doesn’t just ask controllers to comply with data protection principles. It requires them to demonstrate compliance, continuously. Moving from a static checklist to an ongoing evidentiary burden has reshaped internal governance structures far beyond the privacy office. Organizations that once treated data protection as a box-ticking legal function found themselves having to build cross-functional systems—pulling in engineering, product, security, and procurement teams.
The documentation requirements pile up: records of processing activities, data protection impact assessments, legitimate interest balancing tests. Together, they create an institutional memory that surfaces in unexpected places. When competition authorities investigate algorithmic collusion, or consumer protection agencies examine dark patterns, they increasingly draw on the paper trail the GDPR mandates. The regulation has become, in effect, an information-forcing mechanism. It makes opaque corporate practices legible to external scrutiny, even when the inquiry didn’t start with privacy at all.
The Brussels Effect and Its Discontents
The GDPR’s territorial scope, laid out in Article 3, reaches any organization that processes personal data of individuals in the Union—wherever the processing happens. Combine that extraterritorial reach with the size of the European market, and you get what Anu Bradford called the “Brussels Effect”: EU regulations become de facto global standards because multinational firms find it cheaper to adopt a single, strict compliance framework everywhere than to run separate regimes.
But the GDPR’s global diffusion is more textured than a simple story of regulatory export. In countries with weak domestic privacy traditions, the regulation has functioned as a bargaining chip in trade negotiations and a template for local legislation—think Brazil’s Lei Geral de Proteção de Dados or India’s evolving data protection framework. At the same time, it has met resistance. Some jurisdictions see the GDPR’s model as excessively bureaucratic, poorly matched to their constitutional traditions, or economically protectionist. The regulation has become a reference point in a wider struggle over who gets to write the rules for the global data economy—and on what terms.

Rethinking Consent and Its Limits
The GDPR gave consent a prominent seat at the table, but its most sophisticated move may be the recognition that consent is not a universal solvent for data processing legitimacy. The regulation lists five other legal bases—contractual necessity, legal obligation, vital interests, public task, and legitimate interests—that, in practice, carry much of the weight. By creating a hierarchy of lawful grounds and subjecting each to distinct tests of necessity and proportionality, the GDPR forces organizations to explain why they process data, not merely to get a nod.
This has had a subtle but deep effect on business models that depend on pervasive tracking. The “pay or consent” models recently adopted by some large platforms—offering users a choice between consenting to behavioral advertising or paying a subscription fee—test the boundaries of freely given consent under the GDPR. These developments are pushing a public conversation: can data protection law, or should it, serve as a vehicle for challenging the extractive logic of platform capitalism? Or does that task belong to sectoral regulation and competition enforcement?
Institutional Design and the Regulatory Laboratory
The GDPR’s governance architecture is a network of national supervisory authorities coordinated through the European Data Protection Board. It was a compromise born of political necessity, yet it has produced an unexpected dynamism. The one-stop-shop mechanism channels cross-border cases through a lead authority. Critics point to delays and uneven enforcement. But the system has also created a laboratory of regulatory approaches, where different national authorities test strategies that others watch and sometimes adopt.
Consider the Irish Data Protection Commission’s handling of major tech cases, the Hamburg authority’s focus on data minimization in advertising, and the French CNIL’s willingness to levy significant fines for cookie violations. Each represents a distinct enforcement philosophy. The variation frustrates those who want uniformity. But it also generates learning that a single centralized agency might never produce. For all its friction, the GDPR’s institutional design may prove more adaptive over time than a monolithic model.
Frequently Asked Questions
Does the GDPR apply to small businesses?
Yes, the GDPR applies to all organizations processing personal data of individuals in the EU, regardless of size. There are some exemptions for organizations with fewer than 250 employees regarding record-keeping requirements—unless the processing is likely to create a risk to individuals’ rights, isn’t occasional, or involves special categories of data. In practice, the core obligations—lawful basis for processing, data subject rights, security measures—apply universally.
How has the GDPR influenced competition policy?
The GDPR has intersected with competition policy in several ways. Data protection authorities and competition agencies increasingly recognize that concentrated data holdings can create barriers to entry and reinforce market dominance. The German Bundeskartellamt’s 2019 decision against Facebook, which linked GDPR violations to abuse of market power, was a landmark case. More broadly, the regulation’s data portability right and its transparency requirements have given competition investigators tools to understand market dynamics that were previously opaque.
What is the “Brussels Effect” in the context of data protection?
The Brussels Effect describes the process by which EU regulations become global standards because multinational companies adopt them across their operations worldwide. In data protection, many firms have extended GDPR-compliant practices globally instead of maintaining separate systems for European and non-European users. This has raised data protection standards in countries without strong domestic laws. But it has also generated debate about regulatory imperialism and whether it’s appropriate to apply European norms in different cultural and legal contexts.
Can the GDPR address algorithmic discrimination?
The GDPR addresses algorithmic decision-making mainly through Article 22, which gives individuals the right not to be subject to solely automated decisions that produce legal or similarly significant effects. It also requires meaningful information about the logic involved in such decisions. But the regulation wasn’t designed as a comprehensive anti-discrimination statute. Its provisions can surface problematic automated decisions and provide a basis for challenge. Addressing structural algorithmic bias usually requires complementary equality legislation and sectoral regulation.
The GDPR’s legacy, then, is not a stable endpoint. It’s an ongoing process of reinterpretation and renegotiation. The regulation has become a site where competing visions of the digital economy play out—through enforcement actions, regulatory guidance, and judicial interpretation. One vision treats the digital space as an area of individual choice. Another sees it as a domain of collective governance. A third approaches it as a market to be structured. Read the GDPR solely as a privacy text, and you see only the surface of a deeper current that continues to reshape institutions far from its original channel.
Recent Comments