Show simple item record

dc.contributor.authorAndersson von Geijer, Johan
dc.contributor.authorBroman, Marcus
dc.date.accessioned2019-09-23T12:52:09Z
dc.date.available2019-09-23T12:52:09Z
dc.date.issued2019-09-23
dc.identifier.urihttp://hdl.handle.net/2077/61846
dc.description.abstractMunicipalities of Sweden are facing challenges complying with the GDPR. New and changed management processes need to be implemented. We used an inductive quantitative approach applying a privacy maturity framework in a survey in May 2019 where 454 controllers in Swedish municipalities answered. Twenty-three measurable criteria are adopted from the technology-neutral international best-practice standard Generally accepted privacy principles (GAPP) and objective descriptions in the Privacy maturity model (PMM). The results are maturity estimates from level 1 to 5 on the 23 criteria, which we grouped in six attributes. Of the controllers, 52 percent are on level 1, 44 percent on level 2, and only 4 percent are above level 3. The survey also includes four significant findings: (1) Controllers in medium-large municipalities are estimating maturity higher than others. (2) Less than a third of the controllers have defined roles and responsibilities for privacy, except for the data protection officer (DPO). DPOs are estimating maturity even lower. (3) There is a risk for not detecting privacy breaches, due to lack of protection, monitoring and testing of safeguards, lack of controls on third-parties security practices, and treating privacy matters as IT-security queries. Controllers working with sensitive data are rating maturity higher in these areas. (4) Municipalities have prioritised visible processes like a privacy notice, meeting requests from registered and retention practices. There are two strategies found – one ambitious and one cautious. Several of these findings imply further research.sv
dc.language.isoengsv
dc.relation.ispartofseries2019:009sv
dc.subjectInformation privacysv
dc.subjectPrivacysv
dc.subjectMaturity modelsv
dc.subjectGDPRsv
dc.subjectSwedensv
dc.subjectMunicipalitiessv
dc.subjectBenchmarkingsv
dc.subjectGAPPsv
dc.titlePRIVACY MATURITY IN SWEDISH MUNICIPALITIES: A Quantitative Survey Based on a Privacy Maturity Frameworksv
dc.typeTexteng
dc.setspec.uppsokTechnology
dc.type.uppsokH2
dc.contributor.departmentInstitutionen för tillämpad informationsteknologiswe
dc.contributor.departmentDepartment of Applied Information Technologyeng
dc.type.degreeMaster theseseng


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record