Name: | Description: | Size: | Format: | |
---|---|---|---|---|
6.05 MB | Adobe PDF |
Advisor(s)
Abstract(s)
The General Data Protection Regulation entered into force on 25 May 2018, but was approved on 27 April 2016. The General Data Protection Regulation (GDPR) aims to ensure the coherence of natural persons’ protection within the European Union (EU), comprising very important innovative rules that will be applied across the EU and will directly affect every Member State. The organizations/Institutions had two years to implement it. Despite this, it has been observed that, in several sectors of activity, the number of organi-zations having adopted that control is low. This study aimed to identify the factors which condition the implementation the GDPR by organizations. Methodologically, the study involved interviewing the officials in charge of information systems in 18 health clinics in Portugal. The factors facilitating and inhibiting the implementation of GDPR are presented and discussed. Based on these factors, a set of recommendations to enhance the implemen-tation of the measures proposed by the regulation is made. The study used Institutional Theory as a theoretical framework. The results are discussed in light of the data collected in the survey and possible future works are identi-fied.
Description
Keywords
Regulation (EU) 2016/679 General data protection regulation Institutional theory Health clinics
Citation
Lopes, Isabel Maria; Guarda T.; Oliveira, P. (2019). EU general data protection regulation Implementation: an institutional theory view. In Rocha, Álvaro (eds.) New Knowledge in Information Systems and Technologies. WorldCIST'19. Advances in Intelligent Systems and Computing. Springer, Cham. 1: 930, p. 383-393