GDPR and the cloud: examining readability deficiencies in cloud computing providers' privacy policies

被引:3
|
作者
Gao, Lei [1 ]
Eller, C. Kevin [2 ]
Eggers, Austin F. [2 ]
机构
[1] Univ North Florida, Coggin Coll Business, Jacksonville, FL USA
[2] Appalachian State Univ, Walker Coll Business, 3133 Peacock Hall, Boone, NC 28608 USA
关键词
GDPR; cloud computing; privacy policy; confidentiality; readability; TEXTUAL ANALYSIS;
D O I
10.1080/01442872.2022.2129046
中图分类号
C93 [管理学]; D035 [国家行政管理]; D523 [行政管理]; D63 [国家行政管理];
学科分类号
12 ; 1201 ; 1202 ; 120202 ; 1204 ; 120401 ;
摘要
There have been concerns about data privacy and protection internationally. This has led to the development of policy tools, such as the General Data Protection Regulations (GDPR), but there remains limited evaluation of the effectiveness of the policies. The purpose of this study is to examine cloud computing privacy policies in order to determine how they changed in response to GDPR. Specifically, we focus on the EU's mandate for "clear and plain language" by scrutinizing various content characteristics. In order to examine the response to the changes enacted by GDPR, we conduct a content analysis of cloud computing firm privacy policies from three periods. Results indicate that despite a mandate for "clear and plain language," the readability of the privacy policies post-GDPR did not improve. Surprisingly, many privacy policies examined showed a significant decrease in readability. Additionally, the use of uncertainty language and litigious language also increased in certain areas. The findings outlined in this study are informative for policy makers, businesses interested in minimizing risks associated with GDPR noncompliance, and individuals whose data is subject to GDPR. These findings also point to the challenges faced by organizations in developing effective policies in the realm of digital governance.
引用
收藏
页码:832 / 854
页数:23
相关论文
共 50 条
  • [1] Cloud privacy: an empirical study of 20 cloud providers' terms and privacy policies-Part I
    Kamarinou, Dimitra
    Millard, Christopher
    Hon, W. Kuan
    INTERNATIONAL DATA PRIVACY LAW, 2016, 6 (02) : 79 - 101
  • [2] Cloud privacy: an empirical study of 20 cloud providers' terms and privacy policies-Part II
    Kamarinou, Dimitra
    Millard, Christopher
    Hon, W. Kuan
    INTERNATIONAL DATA PRIVACY LAW, 2016, 6 (03) : 170 - 194
  • [3] A Content Analysis of the Privacy Policies of Cloud Computing Services
    Gao, Lei
    Brink, Alisa G.
    JOURNAL OF INFORMATION SYSTEMS, 2019, 33 (03) : 93 - 115
  • [4] Measuring Semantic Similarity across EU GDPR Regulation and Cloud Privacy Policies
    Elluri, Lavanya
    Joshi, Karuna Pande
    Kotal, Anantaa
    2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 3969 - 3978
  • [5] An effective cloud computing model enhancing privacy in cloud computing
    Chawki, Mohamed
    INFORMATION SECURITY JOURNAL, 2024, 33 (06): : 635 - 658
  • [6] A Unified Framework for GDPR Compliance in Cloud Computing
    Pattakou, Argyri
    Diamantopoulou, Vasiliki
    Kalloniatis, Christos
    Gritzalis, Stefanos
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [7] Implementing Privacy Policies in the Cloud
    Caimi, Claudio
    D'Errico, Michela
    Gambardella, Carmela
    Manea, Mirko
    Wainwright, Nick
    CYBER SECURITY AND PRIVACY, CSP INNOVATION FORUM 2015, 2015, 530 : 3 - 13
  • [8] Towards a GDPR-compliant cloud architecture with data privacy controlled through sticky policies
    Cambronero, M. Emilia
    Martinez, Miguel A.
    Llana, Luis
    Rodriguez, Ricardo J.
    Russo, Alejandro
    PEERJ COMPUTER SCIENCE, 2024, 10
  • [9] Privacy-Aware Cloud Ecosystems and GDPR Compliance
    Barati, Masoud
    Rana, Omer
    Theodorakopoulos, George
    Burnap, Peter
    2019 7TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2019), 2019, : 117 - 124
  • [10] Security and Privacy in Cloud Computing
    Tari, Zahir
    IEEE CLOUD COMPUTING, 2014, 1 (01): : 54 - 57