Data Entitlement Granularity and Corporate Personal Data Protection Efficacy
收藏资源简介:
This study utilizes a sample of Chinese A-share listed firms covering the period from 2016 to 2023, with data obtained from the China Stock Market and Accounting Research database, which offers comprehensive firm-level data including fundamentals, financial statements, and corporate governance attributes. The choice of 2016 as the initial year aligns with Chen et al. (2024a), recognizing its pivotal role in marking the formal initiation of China's digital strategy. Specifically, the 2016 G20 Initiative on Digital Economy Development and Cooperation introduced key concepts such as the "digital economy" and "corporate digital transformation" into China's national strategic framework. Subsequently, the issuance of the 2019 Draft Measures for Data Security Management, the promulgation of the 2021 PIPL, along with the 2022 Cybersecurity Classified Protection System 2.0, collectively enhanced the regulatory environment concerning data security and privacy compliance. This progressive institutional evolution provides a solid foundation and theoretically justified context for investigating PDPE. Sample construction follows a rigorous screening protocol. (1) Financial institutions are excluded due to their distinct regulatory frameworks and balance sheet structures; (2) Firms classified under Special Treatment status are omitted to prevent potential distortions arising from financial distress or operational anomalies; (3) Firm-year observations with incomplete data for critical model variables are removed to ensure the integrity and robustness of the analysis. Consequently, the final dataset comprises 26,893 firm-year observations, representing 4,684 unique listed firms.
本研究选取2016年至2023年的中国A股上市公司作为研究样本,数据来源于中国股票市场与会计研究数据库(China Stock Market and Accounting Research),该数据库提供涵盖企业基本面、财务报表及公司治理特征的全面企业层面微观数据。本研究以2016年作为样本起始年份,该选择与Chen等人(2024a)的研究保持一致,原因在于这一年是中国数字战略正式启动的关键节点。具体而言,2016年G20数字经济发展与合作倡议将“数字经济”与“企业数字化转型”等核心概念正式纳入中国国家战略框架。后续,2019年《数据安全管理办法(征求意见稿)》的发布、2021年《个人信息保护法》(PIPL)的颁布,以及2022年《网络安全等级保护制度2.0》的出台,共同完善了我国数据安全与隐私合规的监管环境。这一渐进式的制度演进为探究PDPE提供了坚实的实践基础与具有理论支撑的研究语境。样本构建遵循严格的筛选流程:(1)剔除金融类上市公司,因其监管框架与资产负债表结构具有特殊性;(2)剔除被实施特别处理(Special Treatment)状态的企业,以规避财务困境或经营异常可能引发的估计偏差;(3)剔除关键模型变量数据缺失的公司-年度观测值,以保障研究分析的完整性与稳健性。最终,本数据集共包含26893个公司-年度观测值,涵盖4684家独立A股上市公司。




