An information privacy culture instrument to measure consumer privacy expectations and confidence

被引:14
作者
Da Veiga, Adele [1 ]
机构
[1] Univ South Africa Unisa Johannesburg, Sch Comp, Johannesburg, South Africa
基金
新加坡国家研究基金会;
关键词
Culture; Consumer protection; Information privacy; Data protection; Data privacy; Protection of personal information act (POPIA); General Data Protection Regulation (GDPR); Fair information practice principles (FIPPS); Organisation of Economic Coordination and Development (OECD);
D O I
10.1108/ICS-03-2018-0036
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose This paper aims to propose an information privacy culture index framework (IPCIF) with a validated information privacy culture index instrument (IPCII) to measure information privacy culture across nations. The framework is based on consumers' privacy expectations, their actual experiences when organisations process their personal information and their general privacy concerns. Design/methodology/approach A survey method was deployed to collect data in South Africa - the first participating country in the study - to start building a global information privacy culture index (IPCI) and to validate the questionnaire. Findings The IPCI revealed that there seems to be a disconnect between what consumers expect in terms of privacy and the way in which organisations are honouring (or failing to honour) those expectations, which results in a breach of trust and the social contract being violated. Practical implications Governments, information regulators and organisations can leverage the results of the privacy culture index to implement corrective actions and controls aimed at addressing the gaps identified from a consumer and compliance perspective. The validated IPCII can be used by both academia and industry to measure the information privacy culture of an institution, organisation or country to identify what to improve to address consumer privacy expectations and concerns. Originality/value The IPCIF and validated IPCII are the first tools that combine the concepts of consumer expectations and their confidence levels in whether organisations are meeting their privacy expectations, which are in line with the fair information practice principles and the privacy guidelines of the Organisation for Economic Cooperation and Development, to determine gaps and define improvement plans.
引用
收藏
页码:338 / 364
页数:27
相关论文
共 37 条
[1]  
Australian Government, 2018, OFF AUSTR INF COMM S
[2]   International differences in information privacy concerns: A global survey of consumers [J].
Bellman, S ;
Johnson, EJ ;
Kobrin, SJ ;
Lohse, GL .
INFORMATION SOCIETY, 2004, 20 (05) :313-324
[3]  
BREWERTON P, 2002, ORG RES METHODS
[4]  
Business Dictionary, 2018, NAT CULT
[5]  
Creswell J.W, 2017, RES DESIGN QUALITATI, V5th
[6]  
da Veiga A, 2017, SAIEE AFR RES J, V108, P56, DOI 10.23919/SAIEE.2017.8531627
[7]  
Da Veiga A, 2017, P 11 INT S HUMAN ASP, P196
[8]   Information security culture and information protection culture: A validated assessment instrument [J].
Da Veiga, Adele ;
Martins, Nico .
COMPUTER LAW & SECURITY REVIEW, 2015, 31 (02) :243-256
[9]  
Dell EMC, 2015, EMC PRIV IND GLOB IN
[10]  
Deloitte and Touche, 2017, AUSTR PRIV IND