Résumé
Although the General Data Protection Regulation is a legal requirement, itsimplementation by companies remains inconsistent. This study aims to (1) categorize GDPRviolations through a qualitative study with digital marketing professionals and (2) assess theirimpact on customer relationships through an experimental study. Five violation types areidentified and classified as intentional/unintentional and active/passive. Results show thatunintentional failures (due to error or incapacity) lead to weaker retaliation intentions thanomissions or malicious acts. However, ignorance is not considered more acceptable thanomissions. Consumers expect companies to stay informed about data regulations, highlightingthe need for tools supporting GDPR compliance.