Exploring the General Data Protection Regulation (GDPR) compliance in cloud services: insights from Swedish public organizations on privacy compliance
Awatef Issaoui,
Jenny Örtensjö and
M. Sirajul Islam ()
Additional contact information
Awatef Issaoui: Örebro University School of Business
Jenny Örtensjö: Örebro University School of Business
M. Sirajul Islam: Örebro University School of Business
Future Business Journal, 2023, vol. 9, issue 1, 1-13
Abstract:
Abstract The adoption of cloud services offers manifold advantages to public organizations; however, ensuring data privacy during data transfers has become increasingly complex since the inception of the General Data Protection Regulation (GDPR). This study investigates privacy concerns experienced by public organizations in Sweden, focusing on GDPR compliance. A qualitative interpretative approach was adopted, involving semi-structured interviews with seven employees from five public organizations in Sweden. Additionally, secondary data were gathered through an extensive literature review. The collected data were analyzed and classified using the seven privacy threat categories outlined in the LINDDUN framework. The key findings reveal several significant privacy issues when utilizing public cloud services, including unauthorized access, loss of confidentiality, lack of awareness, lack of trust, legal uncertainties, regulatory challenges, and loss of control. The study underscores the importance of implementing measures such as anonymization, pseudonymization, encryption, contractual agreements, and well-defined routines to ensure GDPR compliance. The findings emphasize the importance of implementing measures such as anonymization, pseudonymization, encryption, contractual agreements, and well-defined routines to ensure GDPR compliance. Furthermore, this research highlights the critical aspect of digital sovereignty in addressing privacy challenges associated with public cloud service adoption by public organizations in Sweden.
Keywords: Public cloud; GDPR; Public organizations; LINDDUN; Information privacy; Sweden (search for similar items in EconPapers)
Date: 2023
References: View references in EconPapers View complete reference list from CitEc
Citations:
Downloads: (external link)
http://link.springer.com/10.1186/s43093-023-00285-2 Abstract (text/html)
Access to the full text of the articles in this series is restricted.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:futbus:v:9:y:2023:i:1:d:10.1186_s43093-023-00285-2
Ordering information: This journal article can be ordered from
https://fbj.springeropen.com/
DOI: 10.1186/s43093-023-00285-2
Access Statistics for this article
Future Business Journal is currently edited by Soad Kamel Rizk and Hayam Wahba
More articles in Future Business Journal from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().