PRV Flashcards
Privacy Concerns (Smith)
Collection: Concern that extensive amounts of personally identifiable data are being collected and stored in databases
Unauthorized Secondary Use:
Concern that information is collected for one purpose but is used for another, secondary purpose
Errors: Concern that protections against deliberate and accidental errors in personal data are inadequate
Improper Access:
Concern that data about individuals are readily available to people not properly authorized to view or work with this data
Privacy Concerns (Malhotra et al. 2004)
smith et al. noted that the dimensionality is neither absolute nor static since perception of advocates consumers and scholars shift over time
-> Malhotra et al. 2004 updated the concept of privacy concerns to account for the widespread adoption of the internet. Three core dimensions
Collection.
-degree to which a person is concerned about the amount of individual specific data possessed by others relative to the value of benefits received (more specific)
Control
- The degree to which an individual has control over personal information as manifested by the existence of voice or exit
(e. g opt-out)
Awareness
-The degree to which a consumer is concerned about his her awareness of organizational information privacy practices (want to be informed about their data usage)
Hong and Thong (2013)
- > Over time the use of there privacy concept got confusing
- > Hong and Thong aimed to remedy this issue by offering an integrated conceptualization of privacy concerns
IPC
IEM. IM
CSC. E IA A
Chief Privacy Officer
- primary responsibility of focusing and organizations attention on the right and wrong approaches to use personal information
- information role: constantly monitoring the environment for relevant information related to information privacy and distributing information to internal and external stakeholders
interpersonal role: developing and maintaining relationships with stakeholders within and outside the organization
- conflict management: resolving conflitcs in case of privacy violations as well as internal debates caused by conflicting interests
- strategic management: developing a corporate wide privacy strategy
GDPR
toughest privacy and security law in the world
drafted and passed by the European Union
put into effect on may 25
imposes obligations onto organizations anywhere as long as they target or collect data related to pople in the EU
E.g. GDPR manifests itself mainly through cookie consent notices when browsing online requiring a choice on how much information is to be disclosed
GDPR Data subjects privacy rights
right to be informed right of access right to rectification right to erasure right to be forgotten right restrict processing right to data protability right to data portability right to object right to automated decision making and profiling