Responses to trust repair after privacy breach incidents

  • PDF / 391,712 Bytes
  • 32 Pages / 595 x 791 pts Page_size
  • 12 Downloads / 144 Views

DOWNLOAD

REPORT


Responses to Trust Repair After Privacy Breach Incidents

Lili Wan, Chao Zhang

Received: 21 June 2014 / Accepted: 15 December 2014 / Published: 31 December 2014 © The Society of Service Science and Springer 2014

ABSTRACT The occurrence of information privacy breaches is increasing recently in both private companies and public organizations in many countries. These incidents have raised public concerns and made an organization’s response more and more important. This research categorizes responses by companies in case of privacy breach incidents into four kinds: apology, compensation, managerial step, and information provision. By reviewing existing research about trust repair, this study proposes possible research suggestions about repair after privacy breach incidents.

KEYWORDS Privacy Breach, Trust Repair, Repair Tactic, Response, Attribution Theory.

Lili Wan College of Business Administration, Hankuk University of Foreign Studies e-mail: [email protected] Chao Zhang (∗) Department of Digital Management, Korea University e-mail: [email protected]

194 Lili Wan, Chao Zhang

1. INTRODUCTION Thanks to the development of advanced information technologies, organizations are collecting more personal information from increased online and mobile activities than ever before. This extensive data is the basis for an organization to understand an individual customer, personalize products or services for each customer, and eventually create a competitive advantage. Customers also get many benefits by giving personal information to organizations they trust. Although there are significant benefits from storing and analyzing customer data for both organizations and customers, the increasing number of information privacy breach incidents exposes organizations to the danger of losing trust from customers and devaluating the market value (Malhotra & Malhotra 2011). There have been many news articles and research reports that indicate incidents of information privacy breach. A non-profit organization called PRC (Privacy Rights Clearinghouse) reported 736 million records were leaked in 4,482 breaches from 2005 until 2014 in the United States (See Figure 1). Another institute (ITRC: Identity Theft Resource Center) reported that 783 breaches involving over 85 million records occurred in 2014 (ITRC 2014). 783

800 600

482

452

400 200

596

598

680

2010

2011

2012

622

2013

354 251

136

0 2005

2006

2007

2008

2009

2014

Figure 1. Number of Privacy Breaches in the US Source: PRC. The number of confirmed breaches represents only a small portion of what really happened, since many breaches are not reported or under-reported (McAfee & SAIC 2011). The breach incidents took place in diverse organizations including retailers, banks, schools, hospitals, governments, and so on. Just a few well known incidents are summarized below. © The Society of Service Science and Springer

Responses To Trust Repair After Privacy Breach Incidents 195

Target, a retailing company, admitted that 42 million credit or debit card informatio