An information privacy culture instrument to measure consumer privacy expectations and confidence

被引:14
作者
Da Veiga, Adele [1 ]
机构
[1] Univ South Africa Unisa Johannesburg, Sch Comp, Johannesburg, South Africa
基金
新加坡国家研究基金会;
关键词
Culture; Consumer protection; Information privacy; Data protection; Data privacy; Protection of personal information act (POPIA); General Data Protection Regulation (GDPR); Fair information practice principles (FIPPS); Organisation of Economic Coordination and Development (OECD);
D O I
10.1108/ICS-03-2018-0036
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose This paper aims to propose an information privacy culture index framework (IPCIF) with a validated information privacy culture index instrument (IPCII) to measure information privacy culture across nations. The framework is based on consumers' privacy expectations, their actual experiences when organisations process their personal information and their general privacy concerns. Design/methodology/approach A survey method was deployed to collect data in South Africa - the first participating country in the study - to start building a global information privacy culture index (IPCI) and to validate the questionnaire. Findings The IPCI revealed that there seems to be a disconnect between what consumers expect in terms of privacy and the way in which organisations are honouring (or failing to honour) those expectations, which results in a breach of trust and the social contract being violated. Practical implications Governments, information regulators and organisations can leverage the results of the privacy culture index to implement corrective actions and controls aimed at addressing the gaps identified from a consumer and compliance perspective. The validated IPCII can be used by both academia and industry to measure the information privacy culture of an institution, organisation or country to identify what to improve to address consumer privacy expectations and concerns. Originality/value The IPCIF and validated IPCII are the first tools that combine the concepts of consumer expectations and their confidence levels in whether organisations are meeting their privacy expectations, which are in line with the fair information practice principles and the privacy guidelines of the Organisation for Economic Cooperation and Development, to determine gaps and define improvement plans.
引用
收藏
页码:338 / 364
页数:27
相关论文
共 37 条
[21]  
Information Systems Audit and Control Association (ISACA), 2016, ISACA PRIV PRINC PRO
[22]   THE APPLICATION OF ELECTRONIC-COMPUTERS TO FACTOR-ANALYSIS [J].
KAISER, HF .
EDUCATIONAL AND PSYCHOLOGICAL MEASUREMENT, 1960, 20 (01) :141-151
[23]   Privacy [J].
Kemp, Randy ;
Moore, Adam D. .
LIBRARY HI TECH, 2007, 25 (01) :58-78
[24]  
KPMG, 2016, SURV REV CONS DAT PR
[25]  
Kumaraguru P., 2005, CMUISRI5138
[26]   Internet users' information privacy concerns (IUIPC): Tthe construct, the scale, and a causal model [J].
Malhotra, NK ;
Kim, SS ;
Agarwal, J .
INFORMATION SYSTEMS RESEARCH, 2004, 15 (04) :336-355
[27]  
Miltgen C., 2009, INT J NETWORKING VIR, V6, P574, DOI DOI 10.1504/IJNV0.2009.027790
[28]   Defining Privacy [J].
Moore, Adam .
JOURNAL OF SOCIAL PHILOSOPHY, 2008, 39 (03) :411-428
[29]  
Morton A, 2014, ANN CONF PRIV SECUR, P102, DOI 10.1109/PST.2014.6890929
[30]  
NCSA, 2016, TRUSTE NCSA CONS PRI