Compliance to personal data protection principles: A study of how organizations frame privacy policy notices

被引:41
作者
Chua, Hui Na [1 ]
Herbland, Anthony [2 ]
Wong, Siew Fan [1 ]
Chang, Younghoon [3 ]
机构
[1] Sunway Univ, Dept Comp & Informat Syst, Subang Jaya, Selangor, Malaysia
[2] Univ Hertfordshire, Sch Hlth & Social Work, Hatfield AL10 9AB, Herts, England
[3] BNU HKBU United Int Coll, Div Business & Management, Zhuhai, Peoples R China
关键词
Personal Data Protection Act; Privacy policy; Compliance; Personal data; Information privacy; CONSUMER WILLINGNESS; ONLINE; INTERNET; MODEL; INTENTION; READ;
D O I
10.1016/j.tele.2017.01.008
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
This study examines how organizations in Malaysia frame their privacy policy notice to comply with the Personal Data Protection Act (PDPA, 2010) and if these organizations differ in their level of compliance and the readability of their privacy notices. We collected the online privacy polices of 306 organizations from 12 sectors to assess their readability and compliance with PDPA requirements. The results show that private-owned organizations have higher compliance level compared to public-owned organizations. Sectors that hold more personal sensitive data obtain higher compliance scores. Non-governmental organizations demonstrate higher compliance level compared to government-owned organizations. Despite differences in the compliance scores, most organizations fail to meet the requirements of the PDPA. Our study also reveals that readability has a negative correlation with the compliance score because simple and shorter version of the privacy policies often lack detailed information. Our findings provide valuable insights into organizations' privacy policy compliance across different sectors in Malaysia. Specifically, the Malaysian authority should implement more effective mechanisms to enforce the compliance of the PDPA. Organizations should also take corrective actions to improve the compliance scores of their online privacy policies. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:157 / 170
页数:14
相关论文
共 51 条
[31]   The Economic Impact of Privacy Violations and Security Breaches A Laboratory Experiment [J].
Nofer, Michael ;
Hinz, Oliver ;
Muntermann, Jan ;
Rossnagel, Heiko .
BUSINESS & INFORMATION SYSTEMS ENGINEERING, 2014, 6 (06) :339-348
[32]   An expectation-confirmation model of continuance intention to use mobile instant messaging [J].
Oghuma, Apollos Patricks ;
Fernando Libaque-Saenz, Christian ;
Wong, Siew Fan ;
Chang, Younghoon .
TELEMATICS AND INFORMATICS, 2016, 33 (01) :34-47
[33]   Notices of privacy practices - A survey of the health insurance portability and accountability act of 1996 documents presented to patients at US hospitals [J].
Paasche-Orlow, MK ;
Jacob, DM ;
Powell, JN .
MEDICAL CARE, 2005, 43 (06) :558-564
[34]  
Parks R.F., 2014, Journal of Information Privacy and Security, V10, P203
[35]  
Peslak A.R., 2005, Proceedings of the 2005 ACM SIGMIS CPR conference on Computer personnel research, P104, DOI DOI 10.1145/1055973.1055997
[36]   Internet Privacy Policies of the Largest International Companies [J].
Peslak, Alan R. .
JOURNAL OF ELECTRONIC COMMERCE IN ORGANIZATIONS, 2006, 4 (03) :46-62
[37]   Privacy concerns and consumer willingness to provide personal information [J].
Phelps, J ;
Nowak, G ;
Ferrell, E .
JOURNAL OF PUBLIC POLICY & MARKETING, 2000, 19 (01) :27-41
[38]   THE DISPARITY BETWEEN PUBLIC AND PRIVATE-SECTOR EMPLOYEE PRIVACY PROTECTIONS - A CALL FOR LEGITIMATE PRIVACY RIGHTS FOR PRIVATE-SECTOR WORKERS [J].
PINCUS, LB ;
TROTTER, C .
AMERICAN BUSINESS LAW JOURNAL, 1995, 33 (01) :51-&
[39]   Your privacy is sealed: Effects of web privacy seals on trust and personal disclosures [J].
Rifon, NJ ;
LaRose, R ;
Choi, SM .
JOURNAL OF CONSUMER AFFAIRS, 2005, 39 (02) :339-362
[40]  
Schwaig K.S., 2005, The Database for Advances in Information Systems, V36, P49