To Örebro University

oru.seÖrebro University Publications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Exploring the General Data Protection Regulation (GDPR) compliance in cloud services: Insights from Swedish public organizations on privacy compliance
Örebro University School of Business, Örebro, Sweden.
Örebro University School of Business, Örebro, Sweden.
Örebro University, Örebro University School of Business. Alfaisal University, Riyadh, Kingdom of Saudi Arabia.ORCID iD: 0000-0002-7907-6037
2023 (English)In: Future Business Journal, E-ISSN 2314-7210, Vol. 9, no 1, article id 107Article in journal (Refereed) Published
Abstract [en]

The adoption of cloud services offers manifold advantages to public organizations; however, ensuring data privacy during data transfers has become increasingly complex since the inception of the General Data Protection Regulation (GDPR). This study investigates privacy concerns experienced by public organizations in Sweden, focusing on GDPR compliance. A qualitative interpretative approach was adopted, involving semi-structured interviews with seven employees from five public organizations in Sweden. Additionally, secondary data were gathered through an extensive literature review. The collected data were analyzed and classified using the seven privacy threat categories outlined in the LINDDUN framework. The key findings reveal several significant privacy issues when utilizing public cloud services, including unauthorized access, loss of confidentiality, lack of awareness, lack of trust, legal uncertainties, regulatory challenges, and loss of control. The study underscores the importance of implementing measures such as anonymization, pseudonymization, encryption, contractual agreements, and well-defined routines to ensure GDPR compliance. The findings emphasize the importance of implementing measures such as anonymization, pseudonymization, encryption, contractual agreements, and well-defined routines to ensure GDPR compliance. Furthermore, this research highlights the critical aspect of digital sovereignty in addressing privacy challenges associated with public cloud service adoption by public organizations in Sweden.

Place, publisher, year, edition, pages
Springer, 2023. Vol. 9, no 1, article id 107
Keywords [en]
Public cloud, GDPR, Public organizations, LINDDUN, Information privacy, Sweden
National Category
Information Systems, Social aspects Human Aspects of ICT Information Systems
Identifiers
URN: urn:nbn:se:oru:diva-110382DOI: 10.1186/s43093-023-00285-2ISI: 001125061100001OAI: oai:DiVA.org:oru-110382DiVA, id: diva2:1820134
Available from: 2023-12-15 Created: 2023-12-15 Last updated: 2024-01-22Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full text

Authority records

Islam, M. Sirajul

Search in DiVA

By author/editor
Islam, M. Sirajul
By organisation
Örebro University School of Business
Information Systems, Social aspectsHuman Aspects of ICTInformation Systems

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 89 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf