65
While these privacy measures are commonly deployed in other contexts, the majority of extant cloud computing privacy studies do not use
validated measures of privacy concern but instead explore privacy and
security issues together using open-ended questions or single-item ranking questions. For example, in a study conducted by Scholtz et al. (2016),
90% of participants rated the privacy of data as important or very important. However, two related studies adapted Dinev and Hart’s (2006) PC
measure (Nikkhah et al. 2018; Nikkhah and Sabherwal 2017). Validated
measures of information privacy concern warrant consideration in future
cloud computing privacy studies to provide a more nuanced view of privacy in the cloud and to allow comparisons to be drawn with privacy concerns in other contexts. Indeed, many of these dimensions represent core
privacy issues highlighted by cloud researchers (e.g. Pearson and Benameur
2010). However, the extant empirical literature has not yet encompassed
these dimensions. The relevance of these dimensions is briefly noted in
terms of understanding consumers’ perceptions of privacy.
The collection dimension focuses on individuals’ concerns regarding an
organisation’s collection and storage of a great deal of their personal information (Smith et al. 1996). Consumers often lack an awareness of how
their data stored in the cloud is used and disseminated, and whether it is
used for purposes other than those it was collected for (Nikkhah et al.
2018). For example, in some cases such as Google Drive or Dropbox, the
storage of personal information in the cloud is the primary purpose of the
service and therefore use is transparent. Other applications such as those
in the Internet of Things (IoT) domain, are less clear. Data may be stored
on the device, somewhere locally, or in the cloud, or a combination of one
or more these. Consumers may not even be aware of where data is stored.
It is important to explore whether cloud data storage generates consumer
privacy concern and how this differs across applications and information types.
The Unauthorised Secondary Use dimension focuses on individuals’
concerns that information collected for one purpose is subsequently used
for a secondary purpose without obtaining the individual’s permission
(Smith et al. 1996). Consumer perceptions of unauthorised secondary use
in the cloud context are highlighted in extant research (Pearson and
Benameur 2010). The Improper Access dimension covers individuals’
concerns that an organisation does not have the measures in place to prevent unauthorised individuals from accessing their information (Smith
et al. 1996). The recent media coverage around large cloud data breaches
4 UNDERSTANDING AND ENHANCING CONSUMER PRIVACY PERCEPTIONS…
While these privacy measures are commonly deployed in other contexts, the majority of extant cloud computing privacy studies do not use
validated measures of privacy concern but instead explore privacy and
security issues together using open-ended questions or single-item ranking questions. For example, in a study conducted by Scholtz et al. (2016),
90% of participants rated the privacy of data as important or very important. However, two related studies adapted Dinev and Hart’s (2006) PC
measure (Nikkhah et al. 2018; Nikkhah and Sabherwal 2017). Validated
measures of information privacy concern warrant consideration in future
cloud computing privacy studies to provide a more nuanced view of privacy in the cloud and to allow comparisons to be drawn with privacy concerns in other contexts. Indeed, many of these dimensions represent core
privacy issues highlighted by cloud researchers (e.g. Pearson and Benameur
2010). However, the extant empirical literature has not yet encompassed
these dimensions. The relevance of these dimensions is briefly noted in
terms of understanding consumers’ perceptions of privacy.
The collection dimension focuses on individuals’ concerns regarding an
organisation’s collection and storage of a great deal of their personal information (Smith et al. 1996). Consumers often lack an awareness of how
their data stored in the cloud is used and disseminated, and whether it is
used for purposes other than those it was collected for (Nikkhah et al.
2018). For example, in some cases such as Google Drive or Dropbox, the
storage of personal information in the cloud is the primary purpose of the
service and therefore use is transparent. Other applications such as those
in the Internet of Things (IoT) domain, are less clear. Data may be stored
on the device, somewhere locally, or in the cloud, or a combination of one
or more these. Consumers may not even be aware of where data is stored.
It is important to explore whether cloud data storage generates consumer
privacy concern and how this differs across applications and information types.
The Unauthorised Secondary Use dimension focuses on individuals’
concerns that information collected for one purpose is subsequently used
for a secondary purpose without obtaining the individual’s permission
(Smith et al. 1996). Consumer perceptions of unauthorised secondary use
in the cloud context are highlighted in extant research (Pearson and
Benameur 2010). The Improper Access dimension covers individuals’
concerns that an organisation does not have the measures in place to prevent unauthorised individuals from accessing their information (Smith
et al. 1996). The recent media coverage around large cloud data breaches
4 UNDERSTANDING AND ENHANCING CONSUMER PRIVACY PERCEPTIONS…
