89
is also a legal responsibility as privacy legislation (e.g. the California
Consumer Privacy Act (CCPA) or the GDPR) mandates strict governance
over the processing of personal data. Carroll (1998) suggested that privacy
not only is a legal and financial responsibility but is also an ethical responsibility, as legislation lags behind ethics, and morality comes into play.
Privacy also meets Mason’s (1995) test of what constitutes an ethical
problem i.e. whenever one party in pursuit of its goals engages in behavior
that materially affects the ability of another party to pursue its goals. In
2018, the then EU Data Protection Supervisor (Giovanni Buttarelli)
argued that in order to address this ethical component of privacy, organizations should not overly rely on bare compliance with the letter of law,
and should adopt a ‘duty of care’ for consumer data (Buttarelli 2018).
CSR activities are most appropriate where existing legislation requires
compliance with the spirit as well as the letter of the law and where the
organization can fool stakeholders through superior knowledge
(Mintzberg 1983).
Finally, privacy can be described as a philanthropic responsibility, where
an organization’s privacy behaviors demonstrate a ‘duty of care’ (Buttarelli
2018) towards data owners and society that exceeds compliance.
Philanthropy presents itself in many forms e.g. cash contributions or
employee commitments (Smith 1994) and is often explained by social
exchange theory (Emerson 1962) where corporations use philanthropy to
expand the scope of their business initiatives, influence governments, and
position themselves as influential leaders (Jung et al. 2016). Both Husted
(2003) and Stannard-Stockton (2011) suggest three classifications of philanthropy; (1) “check-book philanthropy” i.e. making cash contributions
to a cause; (2) in-house projects and philanthropic investments; (3) strategic philanthropic collaboration between organizations and non-corporate
partners. True philanthropy matches the resources of the giver with the
needs of the recipient through a socially beneficial relation that is mobilized and governed by a force of morally armed entreaty (Schervish 1998).
As we could find no reference in the literature to philanthropic privacy,
based on definitions of CSR from McWilliams and Siegel (2001) we
describe it as: ‘Any privacy behavior(s) exceeding legislative requirements,
that furthers privacy as a societal good, beyond the interests of the organization’. Philanthropic privacy behaviors would therefore include behaviors
such as advising on government policy, developing open privacy standards
or tools, exceeding privacy laws for employees, even lobbying for strengthened privacy on behalf of the consumer or society. Whilst traditional
5 JUSTICE VS CONTROL IN CLOUD COMPUTING: A CONCEPTUAL…
is also a legal responsibility as privacy legislation (e.g. the California
Consumer Privacy Act (CCPA) or the GDPR) mandates strict governance
over the processing of personal data. Carroll (1998) suggested that privacy
not only is a legal and financial responsibility but is also an ethical responsibility, as legislation lags behind ethics, and morality comes into play.
Privacy also meets Mason’s (1995) test of what constitutes an ethical
problem i.e. whenever one party in pursuit of its goals engages in behavior
that materially affects the ability of another party to pursue its goals. In
2018, the then EU Data Protection Supervisor (Giovanni Buttarelli)
argued that in order to address this ethical component of privacy, organizations should not overly rely on bare compliance with the letter of law,
and should adopt a ‘duty of care’ for consumer data (Buttarelli 2018).
CSR activities are most appropriate where existing legislation requires
compliance with the spirit as well as the letter of the law and where the
organization can fool stakeholders through superior knowledge
(Mintzberg 1983).
Finally, privacy can be described as a philanthropic responsibility, where
an organization’s privacy behaviors demonstrate a ‘duty of care’ (Buttarelli
2018) towards data owners and society that exceeds compliance.
Philanthropy presents itself in many forms e.g. cash contributions or
employee commitments (Smith 1994) and is often explained by social
exchange theory (Emerson 1962) where corporations use philanthropy to
expand the scope of their business initiatives, influence governments, and
position themselves as influential leaders (Jung et al. 2016). Both Husted
(2003) and Stannard-Stockton (2011) suggest three classifications of philanthropy; (1) “check-book philanthropy” i.e. making cash contributions
to a cause; (2) in-house projects and philanthropic investments; (3) strategic philanthropic collaboration between organizations and non-corporate
partners. True philanthropy matches the resources of the giver with the
needs of the recipient through a socially beneficial relation that is mobilized and governed by a force of morally armed entreaty (Schervish 1998).
As we could find no reference in the literature to philanthropic privacy,
based on definitions of CSR from McWilliams and Siegel (2001) we
describe it as: ‘Any privacy behavior(s) exceeding legislative requirements,
that furthers privacy as a societal good, beyond the interests of the organization’. Philanthropic privacy behaviors would therefore include behaviors
such as advising on government policy, developing open privacy standards
or tools, exceeding privacy laws for employees, even lobbying for strengthened privacy on behalf of the consumer or society. Whilst traditional
5 JUSTICE VS CONTROL IN CLOUD COMPUTING: A CONCEPTUAL…
