Understanding Organizational Approach towards End User Privacy
نویسندگان
چکیده
Abstract—End user privacy is a critical concern for all organizations that collect, process and store user data as a part of their business. Privacy concerned users, regulatory bodies and privacy experts continuously demand organizations provide users with privacy protection. Current research lacks an understanding of organizational characteristics that affect an organization’s motivation towards user privacy. This has resulted in a “one solution fits all” approach, which is incapable of providing sustainable solutions for organizational issues related to user privacy. In this work, we have empirically investigated 40 diverse organizations on their motivations and approaches towards user privacy. Resources such as newspaper articles, privacy policies and internal privacy reports that display information about organizational motivations and approaches towards user privacy were used in the study. We could observe organizations to have two primary motivations to provide end users with privacy as voluntary driven inherent motivation, and risk driven compliance motivation. Building up on these findings we developed a taxonomy of organizational privacy approaches and further explored the taxonomy through limited exclusive interviews. With his work, we encourage authorities and scholars to understand organizational characteristics that define an organization’s approach towards privacy, in order to effectively communicate regulations that enforce and encourage organizations to consider privacy within their business practices.End user privacy is a critical concern for all organizations that collect, process and store user data as a part of their business. Privacy concerned users, regulatory bodies and privacy experts continuously demand organizations provide users with privacy protection. Current research lacks an understanding of organizational characteristics that affect an organization’s motivation towards user privacy. This has resulted in a “one solution fits all” approach, which is incapable of providing sustainable solutions for organizational issues related to user privacy. In this work, we have empirically investigated 40 diverse organizations on their motivations and approaches towards user privacy. Resources such as newspaper articles, privacy policies and internal privacy reports that display information about organizational motivations and approaches towards user privacy were used in the study. We could observe organizations to have two primary motivations to provide end users with privacy as voluntary driven inherent motivation, and risk driven compliance motivation. Building up on these findings we developed a taxonomy of organizational privacy approaches and further explored the taxonomy through limited exclusive interviews. With his work, we encourage authorities and scholars to understand organizational characteristics that define an organization’s approach towards privacy, in order to effectively communicate regulations that enforce and encourage organizations to consider privacy within their business practices.
منابع مشابه
Bridging the gap between organizational and user perspectives of security in the clinical domain
An understanding of ‘communities of practice’ can help to make sense of existing security and privacy issues within organisations; the same understanding can be used proactively to help bridge the gap between organisational and end-user perspectives on these matters. Findings from two studies within the health domain reveal contrasting perspectives on the ‘enemy within’ approach to organisation...
متن کاملAddressing End-User Privacy Concerns
Organizations engaged in electronic transactions have a social, and often legal, responsibility to adopt and disclose a policy for protecting customer information. Guidelines for establishing an organizational privacy policy frequently emphasize the inclusion of the fair information practice (FIP) principles that were established in 1973. The increasingly diverse population of Internet users su...
متن کاملIP Bouncer: An End-User Network Privacy Enhancing Tool
Internet Protocol (IP) Bouncer is a novel Information Technology (IT) artifact that exposes unexpected and unwanted network communication initiated by trusted “insider” applications. It closely follows design science guidelines illustrated in the five design principles of the artifact. One of the novel aspects of the design is the key-pair approach used for assessing appropriate or inappropriat...
متن کاملTowards User-Oriented Control of End-User Computing in Large Organizations
Control is a major issue in end-user computing. The migration of responsibility, resources and authority from IT departments to user departments is frequently seen as a loss of power by the IT departments and an erosion of cost control by senior management. Reactions to this situation tend to focus on technology and formal control mechanisms. This paper contrasts such an IT-oriented view with a...
متن کاملPrivacy Broker: Message-Oriented Middleware to implement Privacy Controls in Schibsted’s Ecosystem of Services (Industry Article)
Schibsted is a global media and classified ads conglomerate with more than 200 million unique users per month, operating mainly from Europe. The company is currently being transformed away from traditional paper media and siloed sites towards a unified global media giant. As part of this transformation, Schibsted needs to collect a wide variety of datasets such as profile, behavior, location, p...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1710.03890 شماره
صفحات -
تاریخ انتشار 2017