Identifying critical success factors for the General Data Protection Regulation implementation in higher education institutions

被引:3
作者
Fernandes, Jose [1 ]
Machado, Carolina [1 ]
Amaral, Luis [2 ]
机构
[1] Univ Minho, Sch Econ & Management, Braga, Portugal
[2] Univ Minho, Sch Engn, Guimaraes, Portugal
关键词
GDPR; Critical success factors; Organizational change management; Higher education institutions; UNIVERSITY CULTURE; MANAGEMENT; SYSTEMS; ERA;
D O I
10.1108/DPRG-03-2021-0041
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Purpose On May 25, 2018, the General Data Protection Regulation (GDPR) became mandatory for all organizations that handle the personal data of European Union citizens. This exploratory study aims to determine the critical success factors (CSFs) related to implementing the GDPR in Portuguese public higher education institutions (HEIs). Design/methodology/approach This study adopts a multimethod methodology with qualitative and quantitative methods. A multiple case study was carried out in Portuguese public universities. As procedures for data collecting and analysis, semistructured interviews with 26 questions were conducted with the data protection officers of these universities during May and July 2019 to derive a set of CSFs. Next, the Delphi method has been applied to determine the ranking of the CSFs. The hierarchical clusters analysis has also been applied to determine the cluster with essential CSFs. To derive the CSF, the method by Caralli et al. (2004) has been applied. Findings This study has identified the list of 16 CSFs related to the implementation of GDPR in HEIs, among which we can highlight, for instance, empower workers on the GDPR; commit top management with the GDPR; implement the GDPR with the involvement of management and workers; create a culture for data protection; and create a decentralized team of pivots for data protection. Research limitations/implications It could have been more enriching in the CSF determination process if all Portuguese public universities had participated in this study. In fact, within their many similarities, universities are also very different in approaching privacy and data protection. New studies are needed to determine whether the CSFs identified apply equally to other organizations, namely, private HEIs with less bureaucracy. Originality/value Identifying CSFs related to GDPR implementation in Portuguese public universities is a new area of study. This paper is a contribution to its development.
引用
收藏
页码:355 / 379
页数:25
相关论文
共 85 条
[1]  
A&L Goodbody, 2016, The GDPR: A guide for businesses.
[2]  
Aldenderfer M. S., 1984, Cluster Analysis
[3]   Investigating the Critical Success Factors for Implementing Electronic Document Management Systems in Governments: Evidence From Jordan [J].
Alshibly, Haitham ;
Chiong, Raymond ;
Bao, Yukun .
INFORMATION SYSTEMS MANAGEMENT, 2016, 33 (04) :287-301
[4]  
[Anonymous], 2016, SUPP SUIC GUID PROV
[5]  
[Anonymous], 2007, PRACT ASSESS RES EVA
[6]  
[Anonymous], 2018, GDPR for Education
[7]   Back to the future: revisiting Kotter's 1996 change model [J].
Appelbaum, Steven H. ;
Habashy, Sally ;
Malo, Jean-Luc ;
Shafiq, Hisham .
JOURNAL OF MANAGEMENT DEVELOPMENT, 2012, 31 (08) :764-782
[8]   Complying with Privacy Legislation: From Legal Text to Implementation of Privacy-Aware Location-Based Services [J].
Ataei, Mehrnaz ;
Degbelo, Auriol ;
Kray, Christian ;
Santos, Vitor .
ISPRS INTERNATIONAL JOURNAL OF GEO-INFORMATION, 2018, 7 (11)
[9]  
Avella J. R., 2016, Int. J. Dr. Stud, V11, P305, DOI [10.28945/3561, DOI 10.28945/3561]
[10]   "The Grace Period Has Ended": An Approach to Operationalize GDPR Requirements [J].
Ayala-Rivera, Vanessa ;
Pasquale, Liliana .
2018 IEEE 26TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE 2018), 2018, :136-146