dc.contributor.author | Andersson von Geijer, Johan | |
dc.contributor.author | Broman, Marcus | |
dc.date.accessioned | 2019-09-23T12:52:09Z | |
dc.date.available | 2019-09-23T12:52:09Z | |
dc.date.issued | 2019-09-23 | |
dc.identifier.uri | http://hdl.handle.net/2077/61846 | |
dc.description.abstract | Municipalities of Sweden are facing challenges complying with the GDPR. New and changed management processes need to be implemented. We used an inductive quantitative approach applying a privacy maturity framework in a survey in May 2019 where 454 controllers in Swedish municipalities answered. Twenty-three measurable criteria are adopted from the technology-neutral international best-practice standard Generally accepted privacy principles (GAPP) and objective descriptions in the Privacy maturity model (PMM). The results are maturity estimates from level 1 to 5 on the 23 criteria, which we grouped in six attributes. Of the controllers, 52 percent are on level 1, 44 percent on level 2, and only 4 percent are above level 3. The survey also includes four significant findings: (1) Controllers in medium-large municipalities are estimating maturity higher than others. (2) Less than a third of the controllers have defined roles and responsibilities for privacy, except for the data protection officer (DPO). DPOs are estimating maturity even lower. (3) There is a risk for not detecting privacy breaches, due to lack of protection, monitoring and testing of safeguards, lack of controls on third-parties security practices, and treating privacy matters as IT-security queries. Controllers working with sensitive data are rating maturity higher in these areas. (4) Municipalities have prioritised visible processes like a privacy notice, meeting requests from registered and retention practices. There are two strategies found – one ambitious and one cautious. Several of these findings imply further research. | sv |
dc.language.iso | eng | sv |
dc.relation.ispartofseries | 2019:009 | sv |
dc.subject | Information privacy | sv |
dc.subject | Privacy | sv |
dc.subject | Maturity model | sv |
dc.subject | GDPR | sv |
dc.subject | Sweden | sv |
dc.subject | Municipalities | sv |
dc.subject | Benchmarking | sv |
dc.subject | GAPP | sv |
dc.title | PRIVACY MATURITY IN SWEDISH MUNICIPALITIES: A Quantitative Survey Based on a Privacy Maturity Framework | sv |
dc.type | Text | eng |
dc.setspec.uppsok | Technology | |
dc.type.uppsok | H2 | |
dc.contributor.department | Institutionen för tillämpad informationsteknologi | swe |
dc.contributor.department | Department of Applied Information Technology | eng |
dc.type.degree | Master theses | eng |