Résumé
Today, individuals operate within a vast digital surveillance network, where mass data collection, presented as a source of performance and convenience, increases risks to privacy. Modern marketing practices that use these data to generate value, reveal multiple paradoxes: concerns and lack of control for consumers, tension between performance and responsibility for businesses, and regulatory challenges to protect individuals without stifling innovation.In this context, this doctoral research examines the following question: how do privacy-related paradoxes manifest and evolve from the perspectives of consumers and organizations, and how do these dynamics influence individuals’ emotional and behavioral responses to violations concerning the management of their personal data? To answer this question, the thesis is structured around three complementary studies.The first study takes a consumer-centric approach, examining the evolution of concerns and behaviors in response to digital surveillance. Rather than treating the privacy paradox as a static phenomenon, it analyzes it as a dynamic one, based on a qualitative longitudinal study conducted with four pairs of students who lived for a year in an observatory apartment equipped with more than 70 sensors. The results indicate that while the privacy paradox is initially weak, it emerges progressively: despite high vigilance and protective strategies at the outset, individuals gradually relax their efforts due to habituation to surveillance.The second study focuses on organizations, analyzing the dilemmas encountered between regulatory compliance and economic exploitation of data. Using two complementary qualitative methodologies, it proposes a typology of General Data Protection Regulation (GDPR) violations, identifying five distinct types of infractions based on whether they are intentional or unintentional, and active or passive. This analysis also highlights the mechanisms explaining why some organizations do not fully comply with legal requirements: some infringements result from a cost-benefit calculus (privacy compliance calculus), while others result from a lack of awareness of the applicable rules (privacy compliance gap). The third study adopts an interactional approach, where consumer vulnerability is manifested through the discovery of an organizational privacy violation. Using a quantitative methodology, it examines consumer reactions and how they vary according to the type of violation identified in the second study. The results show that anger is a central response, particularly intense in the face of intentional violations, influencing both individual protection strategies and relational behaviors toward the brand. Habituation to surveillance, identified in the first study, plays an ambivalent role: it reduces proactive protective behaviors in normal situations, but reinforces the effect of anger on intentions to withdraw data when a violation is detected.Overall, this thesis clarifies the complex dynamics that shape privacy protection in the digital age, revealing changes in consumer behavior and the organizational and regulatory frameworks that govern data management. It provides a better understanding of the tensions between innovation, economic imperatives, and individual rights, while offering avenues for rethinking governance and data protection in a constantly changing digital environment.