Personal data protection compliance assessment: A privacy policy scoring approach and empirical evidence from Thailand's SMEs

被引:1
|
作者
Chatsuwan, Panchapawn [1 ]
Phromma, Tanawat [1 ]
Surasvadi, Navaporn [1 ]
Thajchayapong, Suttipong [1 ]
机构
[1] NSTDA, Natl Elect & Comp Technol Ctr NECTEC, 111 Phahonyothin Rd, Khlong Luang 12120, Pathum Thani, Thailand
关键词
Privacy policy; Scoring model; Personal data protection; PDPA; Small and medium-sized enterprises; SMEs; ONLINE PRIVACY; MULTIPLE COMPARISONS; INFORMATION PRIVACY; MANAGEMENT; RESPONSES; TRUST; POWER; RISK;
D O I
10.1016/j.heliyon.2023.e20648
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Privacy policies, intended to provide information to individuals regarding how their personal data is processed, are often complex and challenging for users to understand. Businesses often demonstrate non-compliance with personal data protection laws, ranging from the absence of privacy policies to the existence of policies that do not adhere to legal requirements. This paper aims to (1) develop a quantitative and systematic tool for evaluating privacy policies' compliance with the Personal Data Protection Act (PDPA), (2) assess compliance among Small and Medium Enterprises (SMEs) in Thailand, and (3) provide recommendations for enhancing compliance practices. To achieve this, we proposed a multi-criteria privacy policy scoring model integrated with comprehensive statistical data analyses. The privacy policy scoring model consists of ten privacy principles and 31 privacy criteria, providing a structured framework for evaluating privacy policies. During a two-year postponement period for enforcing the PDPA law, we conducted a stratified random-sampling survey of 384 SMEs to evaluate their privacy policies using the proposed scoring model. The accomplished results revealed significantly lower scores than anticipated, with the nationwide average score of SMEs reaching only 6.1909 out of 100 points. More than half of the SMEs collected personal data without announcing privacy policies, and those with privacy policies adhered to an average of only 12.15 out of 31 privacy criteria. These findings highlight the pressing need to improve compliance practices among SMEs in Thailand. The proposed methodology can be customized and applied to align with the requirements of personal data protection laws in other countries. Additionally, our findings indicate that compliance with the PDPA is influenced by the Thailand Standard Industrial Classification (TSIC) sections, suggesting the adoption of tailored approaches by policymakers to address the specific needs of different TSIC sections.
引用
收藏
页数:30
相关论文
共 11 条
  • [1] Compliance to personal data protection principles: A study of how organizations frame privacy policy notices
    Chua, Hui Na
    Herbland, Anthony
    Wong, Siew Fan
    Chang, Younghoon
    [J]. TELEMATICS AND INFORMATICS, 2017, 34 (04) : 157 - 170
  • [2] Children's reflections on privacy and the protection of their personal data: A child-centric approach to data protection information formats
    Milkaite, Ingrida
    De Wolf, Ralf
    Lievens, Eva
    De Leyn, Tom
    Martens, Marijn
    [J]. CHILDREN AND YOUTH SERVICES REVIEW, 2021, 129
  • [3] Financial policy and capital structure choice in UK SMEs: Empirical evidence from company panel data
    Michaelas, N
    Chittenden, F
    Poutziouris, P
    [J]. SMALL BUSINESS ECONOMICS, 1999, 12 (02) : 113 - 130
  • [4] China's personal information protection in a data-driven economy: A privacy policy study of Alibaba, Baidu and Tencent
    Fu, Tao
    [J]. GLOBAL MEDIA AND COMMUNICATION, 2019, 15 (02) : 195 - 213
  • [5] Financial Policy and Capital Structure Choice in U.K. SMEs: Empirical Evidence from Company Panel Data
    Nicos Michaelas
    Francis Chittenden
    Panikkos Poutziouris
    [J]. Small Business Economics, 1999, 12 : 113 - 130
  • [6] Reviewing the Privacy Implications of India's Digital Personal Data Protection Act (2023) from Library Contexts
    Bareh, Chanlang Ki
    [J]. DESIDOC JOURNAL OF LIBRARY & INFORMATION TECHNOLOGY, 2024, 44 (01): : 50 - 58
  • [7] Farmland protection and fertilization intensity: Empirical evidence from preservation policy of Heilongjiang's black soil
    Tang, Zhipeng
    Song, Wenming
    Zou, Jialing
    [J]. JOURNAL OF ENVIRONMENTAL MANAGEMENT, 2024, 356
  • [8] Can digital policy improve corporate sustainability? Empirical evidence from China's national comprehensive big data pilot zones
    Wang, Wei
    Zhang, Hongguang
    Sun, Ziyuan
    Wang, Lihong
    Zhao, Jianying
    Wu, Fengzhi
    [J]. TELECOMMUNICATIONS POLICY, 2023, 47 (09)
  • [9] The Impact of the Digital Economy on Urban Ecological Resilience: Empirical Evidence from China's Comprehensive Big Data Pilot Zone Policy
    Zhang, Youzhi
    Wang, Jingyi
    Liu, Yinke
    Zhao, Jing
    [J]. SUSTAINABILITY, 2024, 16 (09)
  • [10] Digital economy drives regional industrial structure upgrading: Empirical evidence from China's comprehensive big data pilot zone policy
    Yang, Caihong
    [J]. PLOS ONE, 2023, 18 (12):