Reference health

Mapping the Empirical Evidence of the GDPR's (In-)Effectiveness: A Systematic Review

https://doi.org/10.2139/ssrn.4615186
CiteStamped reference-health badge
7/7 checkable references clean · checked 2026-08-29

Every reference with a DOI in the deposited reference list resolved to a known work in Crossref or DataCite at the dated check, and none carried a retraction, withdrawal, or removal notice.

102 without a DOI — not checked. A reference deposited without a DOI is never matched by title or guessed at; it stays outside the checked set, and this line discloses that.

The 7 checked references that resolve
resolves10.1007/978-3-030-15986-3_17
Measuring Cookies and Web Privacy in a Post-GDPR World
resolves10.14722/eurousec.2018.23012
"This Website Uses Cookies": Users' Perceptions and Reactions to the Cookie Disclaimer
resolves10.1145/3407023.3407080
An empirical study on the impact of GDPR and right to be forgotten - organisations and users perspective
resolves10.1145/3313831.3376511
"It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion Choices
resolves10.1007/978-3-030-58986-8_9
An Empirical Investigation of the Right to Explanation Under GDPR in Insurance
resolves10.5220/0007247500260037
Are You Ready When It Counts? IT Consulting Firm’s Information Security Incident Management
resolves10.1093/oso/9780198837718.001.0001
The Risk-Based Approach to Data Protection
The 102 references without a DOI — listed, not checked
no DOI — not checkedA Fait Accompli? An Empirical Study into the Absence of Consent to Third-Party Tracking in Android Apps
no DOI — not checkedHow Private Is Your Mental Health App Data? An Empirical Study of Mental Health App Privacy Policies and Practices
no DOI — not checkedThe Effect of Privacy Regulation on the Data Industry: Empirical Evidence from GDPR' (2023) 54 The RAND
no DOI — not checkedAre Consumers Concerned about Privacy? An Online Survey Emphasizing the General Data Protection Regulation' (2018) 138 Procedia Computer Science 603 <https
no DOI — not checkedref5
no DOI — not checkedConsumer Perspectives on Information Privacy Following the Implementation of the GDPR
no DOI — not checkedref7
no DOI — not checkedref8
no DOI — not checkedref9
no DOI — not checkedPrivacy, Data Protection and Ethics for Civil Drone Practice: A Survey of Industry, Regulators and Civil Society Organisations
no DOI — not checkedref11
no DOI — not checkedThe Exercisability of the Right to Data Portability in the Emerging Internet of Things (IoT) Environment' (2021) 23
no DOI — not checkedCompliance as a Service
no DOI — not checkedref14
no DOI — not checkedref15
no DOI — not checkedConsumer Consent and Firm Targeting After GDPR: The Case of a Large Telecom Provider' (2022) 68
no DOI — not checkedEmployers as Nightmare Readers: An Analysis of Ethical and Legal Concerns Regarding Employer-Employee Practices on SNS
no DOI — not checkedGDPR Implementation in Public Administrationin Poland -1.5 Year after: An Empirical Analysis' (2021)
no DOI — not checkedref19
no DOI — not checkedThe Effect of the GDPR on Privacy Policies: Recent Progress and Future Promise' (2020) 12
no DOI — not checkedref21
no DOI — not checkedref22
no DOI — not checkedref23
no DOI — not checkedref24
no DOI — not checkedref25
no DOI — not checkedref26
no DOI — not checkedFactors Determining the Extent of GDPR Implementation within Organizations: Empirical Evidence from Czech Republic' (2021)
no DOI — not checkedPrivacy Online: Fair Information Practices in the Electronic Marketplace
no DOI — not checkedref29
no DOI — not checkedReadability of Privacy Policies
no DOI — not checkedLaw in Books and Law in Action: The Readability of Privacy Policies and the GDPR
no DOI — not checkedChild-Friendly Transparency of Data Processing in the EU: From Legal Requirements to Platform Policies
no DOI — not checkedAn AI-Assisted Approach for Checking the Completeness of Privacy Policies against GDPR
no DOI — not checkedref35
no DOI — not checkedA Fait Accompli? An Empirical Study into the Absence of Consent to Third-Party Tracking in Android Apps A Fait Accompli? An Empirical Study into the Abs
no DOI — not checkedref37
no DOI — not checkedArticle 25
no DOI — not checkedref39
no DOI — not checkedref40
no DOI — not checkedThe Dark (Patterns) Side of UX Design
no DOI — not checkedref42
no DOI — not checkedCircumvention by Design -Dark Patterns in Cookie Consent for Online News Outlets
no DOI — not checkedref44
no DOI — not checkedref45
no DOI — not checkedref46
no DOI — not checkedThis Website Uses Nudging: MTurk Workers' Behaviour on Cookie Consent Notices
no DOI — not checkedref48
no DOI — not checkedConsent Management Platforms Under the GDPR: Processors and/or Controllers?
no DOI — not checkedThe Data Subject's Right of Access and to Be Informed in Finland: An Experimental Study' (2006) 14
no DOI — not checkedA Study on Subject Data Access in Online Advertising After the GDPR
no DOI — not checkedObtaining Personal Data and Asking for Erasure: Do App Vendors and Website Owners Honour Your Privacy Rights?
no DOI — not checkedref54
no DOI — not checkedref55
no DOI — not checkedref56
no DOI — not checkedref57
no DOI — not checkedThe Honest Data Protection Officer's Guide to Enable Citizens to Exercise Their Subject Access Rights: Lessons from a Ten-Country European Study
no DOI — not checkedExperiences of Accessing CCTV Data: The Urban Topologies of Subject Access Requests
no DOI — not checkedref60
no DOI — not checkedMeasuring the Brussels Effect through Access Requests
no DOI — not checkedref62
no DOI — not checkedFrom Theory To Practice: Exercising The Right Of Access Under The Law Enforcement And PNR Directives' (2017) 11 JIPITEC
no DOI — not checkedref64
no DOI — not checkedref65
no DOI — not checkedref66
no DOI — not checkedref67
no DOI — not checkedref68
no DOI — not checkedGDPR-Reality Check on the Right to Access Data
no DOI — not checkedref70
no DOI — not checkedPersonal Information Leakage by Abusing the GDPR "Right of Access
no DOI — not checkedAn Empirical Analysis of Data Deletion and Opt-Out Choices on 150 Websites
no DOI — not checkedIf I Press Delete, It's Gone": User Understanding of Online Data Deletion and Expiration
no DOI — not checkedref76
no DOI — not checkedref77
no DOI — not checkedHow Portable Is Portable?: Exercising the GDPR's Right to Data Portability
no DOI — not checkedref79
no DOI — not checkedData Portability as a Tool for Audit
no DOI — not checkedref81
no DOI — not checkedref82
no DOI — not checkedref83
no DOI — not checkedref85
no DOI — not checkedref86
no DOI — not checkedDigital Markets, Data, and Privacy: Competition Law, Consumer Law and Data Protection' (2016) 11 Journal of Intellectual Property Law & Practice 856 <https
no DOI — not checkedThe Perfect Match? A Closer Look at the Relationship between EU Consumer Law and Data Protection Law
no DOI — not checkedImplications of the New EU Directive on Data Protection for Multinational Corporations
no DOI — not checkedThe Impact of the General Data Protection Regulation on the Financial Services' Industry of Small European States
no DOI — not checkedPrivacy Regulation and Online Advertising' (2011) 57 Management Science 57 <http
no DOI — not checkedRegulating Privacy Online: An Economic Evaluation of the GDPR' (2024) 16
no DOI — not checkedPrivacy & Market Concentration: Intended & Unintended Consequences of the GDPR
no DOI — not checkedThe Competitive Effects of the GDPR
no DOI — not checkedref95
no DOI — not checkedref96
no DOI — not checkedref97
no DOI — not checkedImpacts of the Implementation of the General Data Protection Regulations (GDPR) in SME Business Models-An Empirical Study with a Quantitative Design
no DOI — not checkedImpacts of the New General Data Protection Regulation for Smalland Medium-Sized Enterprises
no DOI — not checkedAre We There yet? Understanding the Challenges Faced in Complying with the General Data Protection Regulation (GDPR)
no DOI — not checkedref101
no DOI — not checkedref102
no DOI — not checkedEmpirical Results on the Collaboration between Enterprise Architecture and Data Protection Management during the Implementation of the GDPR
no DOI — not checkedref104
no DOI — not checkedPrivacy by Design" Implementation: Information System Engineers' Perspective' (2020) 53
no DOI — not checkedData Protection by Design: Promises and Perils in Crossing the Rubicon Between Law and Engineering
no DOI — not checkedref109
What this badge says. CiteStamped means the CHECKABLE references of this work were clean at the dated check: each resolved to a known work in a public registry, and none carried a retraction notice at that time. It says nothing about the quality, findings, or importance of the work itself, and nothing about references deposited without a DOI.

checked 2026-08-29 — re-checked daily as this page is visited; titles and statuses come from Crossref and DataCite and are not part of the signed record

Embed this badge

Both snippets point at the live badge image and link back to this page. The badge re-renders from the daily check, so an embed never goes stale by more than a day of visits.

<a href="https://citestamp.com/citestamped/10.2139/ssrn.4615186"><img src="https://citestamp.com/citestamped/10.2139/ssrn.4615186/badge.svg" alt="CiteStamped reference-health badge" width="460" height="64"></a>
[![CiteStamped reference-health badge](https://citestamp.com/citestamped/10.2139/ssrn.4615186/badge.svg)](https://citestamp.com/citestamped/10.2139/ssrn.4615186)