Show Abstract
This paper presents a longitudinal study investigating how the General Data Protection Regulation (GDPR) compliance of website privacy policies has evolved over a five-yearperiod. Using an automated privacy policy evaluation tool, we assessed ten core GDPR factors across a corpus of websites originally analyzed in 2020 and re-evaluated in 2025. Our analysis reveals a mixed progression: while user-facing compliance measures such as consent, data retention notification, and data sharing transparency showed measurable improvement, technically oriented factors—such as breach notification and data encryption—experienced a decline in explicit disclosure. These findings suggest a broader trend in which privacy policies increasingly emphasize legal rights and visible consent mechanisms, while de-emphasizing backend technical safeguards. The results point to a split in compliance communication, possibly influenced by regulatory clarity, enforcement pressure, and shifts in organizational privacy strategy. This study underscores the importance of continued policy auditing and the need for complementary methods that bridge the gap between stated policy and implemented practice in the context of evolving digital governance frameworks.
Access Publication: Download PDF of Report
A Longitudinal Look at GDPR Compliance
Brian Kim, Trista Cao, K.Suzanne Barber, UT CID Report #25-08, August 2025