Building Situational Awareness of GDPR
Hirvonen, P., & Kari, M. J. (2023). Building Situational Awareness of GDPR. In A. Andreatos, & C. Douligeris (Eds.), Proceedings of the 22nd European Conference on Cyber Warfare and Security (pp. 575-583). Academic Conferences International. Proceedings of the European Conference on Cyber Warfare and Security, 22. https://doi.org/10.34190/eccws.22.1.1077
Date
2023Copyright
© 2023 European Conference on Cyber Warfare and Security
Because previous academic research does not comment sufficiently on how the relevant content of the European Union (EU) General Data Protection Regulation (GDPR has been properly communicated to the organisations, or how the situational awareness (SA) of GDPR has been built in the organisations, this qualitative empirical research was regarded as a valuable approach for gathering authentic research material on the practical bases of this phenomena. The aim of this empirical case study (CS) is to develop a picture of what processes organisations use to build SA of the GDPR requirements. To guide the CS, we asked how the SA for decision-making was constructed and how it was perceived in organisations. The experiences of eight Finnish organisations showed that the organisations’ practices of building SA and their experiences with the quality and adequacy of SA differed. However, building SA proved to be a critical step for organisations in the overall process of meeting GDPR requirements. Especially the data coming from inside the organisation became very relevant in the SA process, because it supported decision makers to determine how the GDPR requirements should be implemented in the organisation. As a main contribution of this article, based on best practices shared by organisations a model of building SA was built. The proposed model is threefold and was constructed by combining the findings of an empirical CS analysis, the steps of the intelligence process, and the essential elements of the model of creating information security SA. The result is potentially beneficial for building situational understanding of any complex or ambiguous issue, especially in complex and digitalised technological areas, where combining information management with accurate and efficient decision-making is a common challenge. The results can be used by any party who is looking to build SA of an abstract issue in a complex environment.
...
Publisher
Academic Conferences InternationalParent publication ISBN
978-1-914587-69-6Conference
European Conference on Cyber Warfare and SecurityIs part of publication
Proceedings of the 22nd European Conference on Cyber Warfare and SecurityISSN Search the Publication Forum
2048-8602Keywords
Publication in research information system
https://converis.jyu.fi/converis/portal/detail/Publication/183710989
Metadata
Show full item recordCollections
License
Related items
Showing items with similar title or keywords.
-
Organisational GDPR Investments and Impacts
Hirvonen, Pauliina (Academic Conferences International, 2023)The aim of this empirical multi-case study is to understand the GDPR investments and impacts of the organisations. Among these, the measuring experiences related to GDPR and information security (Isec), and the future ... -
Expectations And Mindsets Related To GDPR
Hirvonen, Pauliina (Academic Conferences International Ltd, 2022)The aim of this qualitative case study is to examine the initial expectations and assumptions related to General Data Protection Regulation (GDPR) of the European Union from the perspectives of selected Finnish organizations: ... -
How Are Situation Picture, Situation Awareness, and Situation Understanding Discussed in Recent Scholarly Literature?
Tikanmäki, Ilkka; Ruoslahti, Harri (SCITEPRESS Science And Technology Publications, 2019)There are several different definitions of situation awareness. However, all of them have in common is knowing and understanding of what is happening, an understanding of future changes or problems, and the prediction of ... -
Adapting data management practices in the face of evolving technological and data privacy landscapes
Botham, Alex (2022)Yritykset pyrkivät ylläpitämään tiedonhallintakäytäntöjään teknologisen kehityksen ja kehittyvän tietosuojalainsäädännön puitteissa. Ensinnäkin uudet ja kehittyvät teknologiat, kuten pilviteknologia, esineiden internet ja ... -
The contribution of public relations to organisational decision making and autopoiesis of organisations : the perspective of the Luhmannian social system paradigm
Mykkänen, Markus (University of Jyväskylä, 2018)This doctoral dissertation investigates the contribution of public relations professionals to organisational decision-making processes and autopoiesis of organisations. The research approach utilises Niklas Luhmann’s ...