跨越大西洋:美国公司董事会如何适应《通用数据保护条例》的通过

Across the Pond: How US Firms' Boards of Directors Adapted to the Passage of the General Data Protection Regulation

Contemporary Accounting Research · 2021
被引 18
人大 A-FT50ABS 4

中文导读

研究利用欧盟GDPR作为准外生冲击,发现受影响的美国公司董事会增加了对网络风险的关注、聘请更多网络/IT专家董事,并更频繁地将网络风险监督分配给董事会或其委员会,这些变化降低了未来网络攻击和数据泄露的风险。

Abstract

ABSTRACT One of the prime responsibilities of the board of directors is to understand and oversee its firm's risk profile. We exploit a recent European Union (EU) regulation, the General Data Protection Regulation (GDPR), as a quasi‐exogenous shock to the cyber risk landscape to assess whether boards of US firms changed their focus and governance structures to deal with this new challenge. The GDPR encompasses a sweeping set of regulations aimed at protecting EU citizens from unwanted uses of their personal Internet data. Although an EU regulation, the GDPR applies to all US public firms with at least one EU user. Adopting a difference‐in‐differences methodology, we use firms that already fall under a US data privacy regulation as a control group and find that boards of treated US firms, on average, increase their focus on cyber risk, add more directors with cyber/IT expertise, and more frequently assign cyber risk oversight to the board or to a board committee. In cross‐sectional tests, we show that these changes are positively associated with a firm's ex ante cyber risk, but are unrelated to whether a firm had a large EU presence, suggesting a more global reaction to the GDPR. In addition, we examine some of the consequences of these board changes. We find boards that promptly responded by changing their board focus, expertise, and monitoring assignment of cyber risk around the passage of GDPR had fewer future cyberattacks/data breaches and less related media attention. Our findings suggest that, on average, American corporate boards promptly responded to changes in the cyber risk environment in ways that reduced their firms' overall future cyber risk. Our results have implications for the efficacy and flexibility of US corporate boards to respond to unexpected changes in risk.

GDPR董事会网络风险数据隐私公司治理