88
• Data accessibility and retention: Guaranteeing availability of cloud
data when migrating from one CSP to another has become a primary
concern for CSCs (Xue et al. 2017). In the CSP environment, personal data accessibility, retention and deletion become fundamental
requirements to prevent CSCs being ‘locked in’ to a given CSP.
• Physical Storage Location: CSPs may store data in multiple geographically dispersed jurisdictional locations. Often this presents a
challenge to identify which legislation takes precedence where laws
conflict, particularly where there is conflict between the laws applying to the physical location of a CSP data centre and the physical
location of the CSC (Abed and Chavan 2019).
5.4 the PrIvacy orIentatIon Framework
In the early years of privacy, organizations understood their responsibilities toward privacy to be legal and financial responsibilities. In the 70’s
discretionary frameworks such as FIPPs emerged—combining privacy
standards with due process, consumer rights, and equality protections
(Westin 2003). From the turn of the century Westin (2003) suggests that
privacy became a first-level social and political issue in response to 9/11,
the Internet, the cell phone, the human genome project, data mining,
automation of government public records amongst others. In the last
decade organizations began to respond to these fundamental changes to
concern for privacy, with initiatives that exceeded their legal, financial and
ethical responsibilities—ranging from privacy-by-design standards, developing open privacy standards, to collaborating with privacy advocacy
groups. Given their association with justice and improved privacy protection, our framework was concerned with those privacy behaviors exceeding legislation. Much of the literature investigating privacy beyond
legislation (Pollach 2011; Allen and Peloza 2015) explored privacy as a
Corporate Social Responsibility (CSR). McWilliams and Siegel (2001)
define CSR as those actions that appear to further some social good,
beyond the interests of the organization and ‘beyond that which is required
by law’.
Carroll’s model of CSR is the most commonly known model for CSR
(Visser 2006). Carroll (1979) identified four pillars of CSR (financial
responsibilities, legal responsibilities, ethical responsibilities, and philanthropic responsibilities). Privacy is a financial responsibility as organizations can be fined significant sums of money for non-compliance. Privacy
V. LYONS
Précédent

- 106/166

Suivant