83
common theme across many privacy studies (Belanger and Crossler 2011;
Belanger et al. 2002). Control can refer to the ‘controls’ used to manage
privacy (Belanger et al. 2002) or refer to the dynamic of ‘power’ over data
(Johnson 2009). Both CSCs and CSPs implement ‘controls’ to manage
privacy (Belanger et al. 2002) in the form of privacy enhancing tools, network access controls, authorization and authentication controls, privileged
identity management controls etc. When privacy controls fail, a privacy
incident is said to occur (a privacy incident is defined as the loss of control,
compromise, unauthorized disclosure, unauthorized acquisition, or any
similar occurrence where an authorized user accesses or potentially accesses
personal information (DHS 2017, p. 8)). Johnson (2009) on the other
hand refers to control as an organization’s need for power over information, while the consumer has to balance the good achieved through information processing against their need for privacy.
Providing the CSC with increased control over their data can result in
the CSP not being able to maximize data storage efficiency, require the
implementation of costly technical tools by the CSP, or necessitate costly
legal indemnification of risk away from the CSP. Greenaway et al. (2015)
describe this tension as the pursuit of interests such as profitability or market share, at the expense of those who provide information or pay for a
service. This need for a CSP to dominate control is enshrined in the concept of information ownership, and it is this concept of control and power
that we apply in this chapter, as reflected by Xu et al. (2012) who distinguish privacy control between individual and organization, with the organization increasingly becoming the ‘control agent’.
However, privacy is not solely about control but also about information
being authorized to flow to specific agents at specific times (Moor 1997).
Moor (1997) argues that in a highly digital culture it is simply not possible
to control all information. Therefore, he argues, the best way to protect
privacy is to ensure the right people have access to relevant information at
the right time, giving individuals as much control over their data as realistically possible (labelling his theory the “control/restricted access” theory
of privacy). With the emerging complexity of organizational networks,
such as those constructed by CSPs, such levels of control are not realistically possible. Greenaway et al. (2015) classify organizations who provide
little control to their consumers as ‘low control’. However, aligning to the
concepts of control that we draw on in this paper, we would classify these
organizations as ‘high control’, as they essentially dominate ‘power’ over
the consumers’ information.
5 JUSTICE VS CONTROL IN CLOUD COMPUTING: A CONCEPTUAL…
common theme across many privacy studies (Belanger and Crossler 2011;
Belanger et al. 2002). Control can refer to the ‘controls’ used to manage
privacy (Belanger et al. 2002) or refer to the dynamic of ‘power’ over data
(Johnson 2009). Both CSCs and CSPs implement ‘controls’ to manage
privacy (Belanger et al. 2002) in the form of privacy enhancing tools, network access controls, authorization and authentication controls, privileged
identity management controls etc. When privacy controls fail, a privacy
incident is said to occur (a privacy incident is defined as the loss of control,
compromise, unauthorized disclosure, unauthorized acquisition, or any
similar occurrence where an authorized user accesses or potentially accesses
personal information (DHS 2017, p. 8)). Johnson (2009) on the other
hand refers to control as an organization’s need for power over information, while the consumer has to balance the good achieved through information processing against their need for privacy.
Providing the CSC with increased control over their data can result in
the CSP not being able to maximize data storage efficiency, require the
implementation of costly technical tools by the CSP, or necessitate costly
legal indemnification of risk away from the CSP. Greenaway et al. (2015)
describe this tension as the pursuit of interests such as profitability or market share, at the expense of those who provide information or pay for a
service. This need for a CSP to dominate control is enshrined in the concept of information ownership, and it is this concept of control and power
that we apply in this chapter, as reflected by Xu et al. (2012) who distinguish privacy control between individual and organization, with the organization increasingly becoming the ‘control agent’.
However, privacy is not solely about control but also about information
being authorized to flow to specific agents at specific times (Moor 1997).
Moor (1997) argues that in a highly digital culture it is simply not possible
to control all information. Therefore, he argues, the best way to protect
privacy is to ensure the right people have access to relevant information at
the right time, giving individuals as much control over their data as realistically possible (labelling his theory the “control/restricted access” theory
of privacy). With the emerging complexity of organizational networks,
such as those constructed by CSPs, such levels of control are not realistically possible. Greenaway et al. (2015) classify organizations who provide
little control to their consumers as ‘low control’. However, aligning to the
concepts of control that we draw on in this paper, we would classify these
organizations as ‘high control’, as they essentially dominate ‘power’ over
the consumers’ information.
5 JUSTICE VS CONTROL IN CLOUD COMPUTING: A CONCEPTUAL…
