Last updated: 2021-09-15

Knit directory: myTidyTuesday/

This week’s #TidyTuesday dataset is on EU GDPR violations.

In addition, R version 4.0.0 Arbor Day was just released. I am re-installing packages as-required while going through projects like this one.

The R Studio team recently launched, a new central location with resources and documentation for tidymodels packages. Check out the official blog post for more details.

Julia Silge published a great blog post with another screencast demonstrating how to use tidymodels. She includes a good video for folks getting started with tidymodels.

Explore the data

Our modeling goal here is to understand what kind of GDPR violations are associated with higher fines in the #TidyTuesday dataset for this week. Before we start, what are the most common GDPR articles actually about? Roughly speaking:

Let’s get started by looking at the data on violations.

gdpr_raw <- readr::read_tsv("")

How are the fines distributed?

gdpr_raw %>%
  ggplot(aes(price + 1)) +
  geom_histogram(fill = "midnightblue", alpha = 0.7, bins = 40) +
  scale_x_log10(labels = scales::dollar_format(prefix = "€")) +
    title = "EU General Data Protection Regulation 2016/679 (GDPR) Fines",
    subtitle = "Scraped from",
    x = "GDPR fine (EUR)", y = "Number of GDPR violations",
    caption = "@Jim_Gruman | #TidyTuesday"

Some of the violations were fined zero EUR. Let’s make a one-article-per-row version of this dataset.

gdpr_tidy <- gdpr_raw %>%
    country = name,
    articles = str_extract_all(article_violated, "Art.[:digit:]+|Art. [:digit:]+")
  ) %>%
  mutate(total_articles = map_int(articles, length)) %>%
  unnest(articles) %>%
  add_count(articles) %>%
  filter(n > 10) %>%

gdpr_tidy %>%
  head() %>%
  knitr::kable("html") %>%
    bootstrap_options = c("striped", "condensed"),
    full_width = F, fixed_thead = T
id price country article_violated articles total_articles
2 2500 Romania Art. 12 GDPR|Art. 13 GDPR|Art. 5 (1) c) GDPR|Art. 6 GDPR Art. 13 4
2 2500 Romania Art. 12 GDPR|Art. 13 GDPR|Art. 5 (1) c) GDPR|Art. 6 GDPR Art. 5 4
2 2500 Romania Art. 12 GDPR|Art. 13 GDPR|Art. 5 (1) c) GDPR|Art. 6 GDPR Art. 6 4
3 60000 Spain Art. 5 GDPR|Art. 6 GDPR Art. 5 2
3 60000 Spain Art. 5 GDPR|Art. 6 GDPR Art. 6 2
5 150000 Romania Art. 32 GDPR Art. 32 1

How are the fines distributed by article?

gdpr_tidy %>%
    articles = str_replace_all(articles, "Art. ", "Article "),
    articles = fct_reorder(articles, price)
  ) %>%
  ggplot(aes(articles, price + 1, color = articles, fill = articles)) +
  geom_boxplot(alpha = 0.2, outlier.colour = NA, show.legend = FALSE) +
  geom_quasirandom(show.legend = FALSE) +
  scale_y_log10(labels = scales::dollar_format(prefix = "€")) +
    x = NULL, y = "GDPR fine (EUR)",
    title = "GDPR Fines Levied, by Article",
    subtitle = "For 250 violations in 25 countries",
    caption = "@Jim_Gruman | #TidyTuesday"

Now let’s create a dataset for predictive modeling.

gdpr_violations <- gdpr_tidy %>%
  mutate(value = 1) %>%
  select(-article_violated) %>%
    names_from = articles, values_from = value,
    values_fn = list(value = max), values_fill = list(value = 0)
  ) %>%

gdpr_violations %>%
  head() %>%
  knitr::kable("html") %>%
    bootstrap_options = c("striped", "condensed"),
    full_width = F, fixed_thead = T
id price country total_articles art_13 art_5 art_6 art_32 art_15
2 2500 Romania 4 1 1 1 0 0
3 60000 Spain 2 0 1 1 0 0
5 150000 Romania 1 0 0 0 1 0
6 20000 Romania 2 0 0 0 1 0
7 200000 Greece 2 0 1 0 0 0
9 30000 Spain 2 0 1 1 0 0

Build a model

Let’s preprocess our data to get it ready for modeling.

gdpr_rec <- recipe(price ~ ., data = gdpr_violations) %>%
  update_role(id, new_role = "id") %>%
  step_log(price, base = 10, offset = 1, skip = TRUE) %>%
  step_other(country, other = "Other") %>%
  step_dummy(all_nominal_predictors()) %>%

gdpr_prep <- prep(gdpr_rec)

Data Recipe


      role #variables
        id          1
   outcome          1
 predictor          7

Training data contained 219 data points and no missing data.


Log transformation on price [trained]
Collapsing factor levels for country [trained]
Dummy variables from country [trained]
Zero variance filter removed no terms [trained]

Let’s walk through the steps in this recipe.

Before using prep() these steps have been defined but not actually run or implemented. The prep() function is where everything gets evaluated.

Now it’s time to specify our model. I am using a workflow() in this example for convenience; these are objects that can help you manage modeling pipelines more easily, with pieces that fit together like Lego blocks. This workflow() contains both the recipe and the model (a straightforward Ordinary Least Squares linear regression).

gdpr_wf <- workflow() %>%
  add_recipe(gdpr_rec) %>%
  add_model(linear_reg() %>%

== Workflow ====================================================================
Preprocessor: Recipe
Model: linear_reg()

-- Preprocessor ----------------------------------------------------------------
4 Recipe Steps

* step_log()
* step_other()
* step_dummy()
* step_zv()

-- Model -----------------------------------------------------------------------
Linear Regression Model Specification (regression)

Computational engine: lm 

You can fit() a workflow, much like you can fit a model, and then you can pull out the fit object and tidy() it to work with the estimates of the linear coefficients.

gdpr_fit <- gdpr_wf %>%
  fit(data = gdpr_violations)

extract_fit_engine(gdpr_fit) %>%
  tidy() %>%
# A tibble: 13 x 5
   term                   estimate std.error statistic  p.value
   <chr>                     <dbl>     <dbl>     <dbl>    <dbl>
 1 (Intercept)              3.77       0.409     9.21  3.82e-17
 2 total_articles           0.480      0.166     2.90  4.20e- 3
 3 country_Spain            0.430      0.364     1.18  2.40e- 1
 4 country_Other            0.234      0.355     0.660 5.10e- 1
 5 country_Germany          0.0597     0.419     0.143 8.87e- 1
 6 art_32                  -0.153      0.315    -0.487 6.27e- 1
 7 country_Hungary         -0.155      0.479    -0.324 7.46e- 1
 8 country_Romania         -0.346      0.433    -0.799 4.25e- 1
 9 art_5                   -0.419      0.283    -1.48  1.40e- 1
10 art_6                   -0.560      0.295    -1.90  5.91e- 2
11 country_Czech.Republic  -0.650      0.467    -1.39  1.66e- 1
12 art_13                  -0.763      0.407    -1.87  6.27e- 2
13 art_15                  -1.57       0.465    -3.37  8.97e- 4

GDPR violations of more than one article have higher fines.

Explore results

Lots of those coefficients have big p-values (for example, all the countries) but I think the best way to understand these results will be to visualize some predictions. You can predict on new data in tidymodels with either a model or a workflow().

Let’s create some example new data that we are interested in.

new_gdpr <- crossing(
  country = "Other",
  art_5 = 0:1,
  art_6 = 0:1,
  art_13 = 0:1,
  art_15 = 0:1,
  art_32 = 0:1
) %>%
    id = row_number(),
    total_articles = art_5 + art_6 + art_13 + art_15 + art_32

new_gdpr %>%
  head() %>%
  knitr::kable("html") %>%
    bootstrap_options = c("striped", "condensed"),
    full_width = F, fixed_thead = T
country art_5 art_6 art_13 art_15 art_32 id total_articles
Other 0 0 0 0 0 1 0
Other 0 0 0 0 1 2 1
Other 0 0 0 1 0 3 1
Other 0 0 0 1 1 4 2
Other 0 0 1 0 0 5 1
Other 0 0 1 0 1 6 2

Let’s find both the mean predictions and the confidence intervals.

mean_pred <- predict(gdpr_fit,
  new_data = new_gdpr

conf_int_pred <- predict(gdpr_fit,
  new_data = new_gdpr,
  type = "conf_int"

gdpr_res <- new_gdpr %>%
  bind_cols(mean_pred) %>%

gdpr_res %>%
  head() %>%
  knitr::kable("html") %>%
    bootstrap_options = c("striped", "condensed"),
    full_width = F, fixed_thead = T
country art_5 art_6 art_13 art_15 art_32 id total_articles .pred .pred_lower .pred_upper
Other 0 0 0 0 0 1 0 4.000446 3.410428 4.590464
Other 0 0 0 0 1 2 1 4.326841 3.922444 4.731237
Other 0 0 0 1 0 3 1 2.912359 2.245405 3.579314
Other 0 0 0 1 1 4 2 3.238753 2.407347 4.070160
Other 0 0 1 0 0 5 1 3.717506 2.992813 4.442199
Other 0 0 1 0 1 6 2 4.043900 3.336772 4.751029

There are lots of things we can do wtih these results! For example, what are the predicted GDPR fines for violations of each article type (violating only one article)?

gdpr_res %>%
  filter(total_articles == 1) %>%
  pivot_longer(art_5:art_32) %>%
  filter(value > 0) %>%
    name = str_replace_all(name, "art_", "Article "),
    name = fct_reorder(name, .pred)
  ) %>%
  ggplot(aes(name, 10^.pred, color = name)) +
  geom_point(size = 3.5) +
    ymin = 10^.pred_lower,
    ymax = 10^.pred_upper
  width = 0.2, alpha = 0.7
  ) +
    x = NULL, y = "Increase in fine (EUR)",
    title = "Predicted Fine for each Type of GDPR Article Violation",
    subtitle = "Modeling based on 250 violations in 25 countries",
    caption = "@Jim_Gruman | #TidyTuesday"
  ) +
  scale_y_log10(labels = scales::dollar_format(prefix = "€", accuracy = 1))

We can see here that violations such as data breaches have higher fines on average than violations about rights of access.

David Sjoberg built this incredible chart

gdpr_df <- gdpr_raw %>%
  group_by(name) %>%
    price = sum(price),
    .groups = "drop"

sdf <- rnaturalearthdata::countries50 %>%
  st_as_sf() %>%
  st_make_valid() %>%
  st_crop(xmin = -24, xmax = 31, ymin = 33, ymax = 73) %>%
  filter(admin %in% gdpr_df$name) %>%
  left_join(gdpr_df, by = c("admin" = "name")) %>%
    price_cap = price / pop_est,
    admin = case_when(
      admin == "United Kingdom" ~ "UK",
      admin == "Czech Republic" ~ "Czech",
      TRUE ~ admin

ranking <- st_geometry(sdf) %>%
  st_point_on_surface() %>%
  st_coordinates() %>%
  as_tibble() %>%
    fine_cap = BBmisc::normalize(rank(sdf$price_cap), range = c(40.12161, 66.12161), method = "range"),
    country = sdf$admin,
    xend = 60,
    x_axis_start = xend + 10,
    fine_cap_x = BBmisc::normalize(sdf$price_cap, range = c(first(x_axis_start), 100), method = "range"),
    val_txt = paste0(format(sdf$price_cap, digits = 0, nsmall = 2)),
    val_txt2 = if_else(country == "Austria", paste0(val_txt, "€ per capita"), val_txt)

sdf <- sdf %>%
  bind_cols(ranking %>% select(fine_cap))

ggplot() +
    data = sdf,
    size = .3,
    fill = "transparent",
    color = "gray17"
  ) +
  # Sigmoid from country to start of barchart
    data = ranking,
      x = X,
      y = Y,
      xend = x_axis_start - .2,
      yend = fine_cap,
      group = country,
      color = fine_cap
    alpha = .6,
    smooth = 10,
    size = 1
  ) +
  # Line from xstart to value
    data = ranking,
      x = x_axis_start,
      y = fine_cap,
      xend = fine_cap_x,
      yend = fine_cap,
      color = fine_cap
    alpha = .6,
    size = 1,
    lineend = "round"
  ) +
  # Y axis - black line
    data = ranking,
      x = x_axis_start,
      y = 40,
      xend = x_axis_start,
      yend = 67
    alpha = .6,
    size = 1.3,
    color = "black"
  ) +
  # dot on centroid of country in map
    data = ranking,
    aes(x = X, y = Y, color = fine_cap),
    size = 2
  ) +
  # Country text
    data = ranking,
      x = x_axis_start - .5,
      y = fine_cap,
      label = country,
      color = fine_cap
    hjust = 1,
    size = 2.5,
    nudge_y = .5
  ) +
  # Value text
    data = ranking,
      x = fine_cap_x,
      y = fine_cap,
      label = val_txt2,
      color = fine_cap
    hjust = 0,
    size = 2,
    nudge_x = .4
  ) +
  coord_sf(clip = "off") +
  scale_fill_viridis_c(option = "H") +
  scale_color_viridis_c(option = "H") +
  theme_void() +
    title = "GDPR fines per capita",
    subtitle = str_wrap(
      "The General Data Protection Regulation (EU) 2016/679 (GDPR) is a regulation in EU law on data protection and privacy in the European Union (EU) and the European Economic Area (EEA).",
    caption = "Source: TidyTuesday & Wikipedia"
  ) +
    plot.margin = unit(c(0.5, 1, 0.5, 0.5), "cm"),
    legend.position = "none",
    plot.background = element_rect(fill = "black"),
    plot.caption = element_text(color = "white"),
    plot.title = element_text(
      color = "white",
      size = 16,
      family = "Helvetica",
      face = "bold"
    plot.subtitle = element_text(color = "white", size = 8)

