Applications like Enterprise Resource Planning (ERP) systems have become an indispensable part of the corporate digital infrastructure. These systems store sensitive data about customers, suppliers, and employees, and thus companies have to process these data in accordance with applicable regulations like the GDPR (the EU General Data Protection Regulation). This can be challenging due to a variety of reasons. For example, prior research has shown that developers sometimes lack knowledge about privacy. In this work, we focus on privacy in ERP systems in the context of an international consultancy firm. We investigate the privacy awareness regarding privacy-by-design and data minimization of two important populations: developers of ERP systems and managers and consultants responsible for services related to ERP systems. Applying thematic analysis, we elicit privacy behavioral models of these two populations using Fogg's Behavioral Model (FBM) framework. Our findings provide a means to stimulate more adequate privacy-related behaviors for developers and consultants.
翻译:企业资源规划(ERP)系统等应用程序已成为企业数字基础设施不可或缺的组成部分。这些系统存储着客户、供应商及员工的敏感数据,因此企业必须依据《通用数据保护条例》(GDPR)等适用法规处理这些数据。由于多种原因,合规实践可能面临挑战。例如,已有研究表明开发人员有时缺乏隐私保护相关知识。本研究聚焦于国际咨询公司场域下的ERP系统隐私问题。我们考察了两类关键群体对"隐私保护设计"与"数据最小化"原则的认知程度:ERP系统开发人员,以及负责ERP相关服务的经理与顾问。通过主题分析法,我们运用福格行为模型框架,分别构建了这两类群体的隐私行为模型。研究结果为促进开发人员与顾问采取更恰当的隐私相关行为提供了理论依据。