{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T22:21:54Z","timestamp":1775773314647,"version":"3.50.1"},"reference-count":67,"publisher":"Emerald","issue":"4","license":[{"start":{"date-parts":[[2024,4,8]],"date-time":"2024-04-08T00:00:00Z","timestamp":1712534400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ITP"],"published-print":{"date-parts":[[2025,5,19]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title><jats:p>This paper aims to increase understanding of pertinent exogenous and endogenous antecedents that can reduce data privacy breaches.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title><jats:p>A cross-sectional survey was used to source participants' perceptions of relevant exogenous and endogenous antecedents developed from the Antecedents-Privacy Concerns-Outcomes (APCO) model and Social Cognitive Theory. A research model was proposed and tested with empirical data collected from 213 participants based in Canada.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Findings<\/jats:title><jats:p>The exogenous factors of external privacy training and external privacy self-assessment tool significantly and positively impact the study's endogenous factors of individual privacy awareness, organizational resources allocated to privacy concerns, and group behavior concerning privacy laws. Further, the proximal determinants of data privacy breaches (dependent construct) are negatively influenced by individual privacy awareness, group behavior related to privacy laws, and organizational resources allocated to privacy concerns. The endogenous factors fully mediated the relationships between the exogenous factors and the dependent construct.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Research limitations\/implications<\/jats:title><jats:p>This study contributes to the budding data privacy breach literature by highlighting the impacts of personal and environmental factors in the discourse.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Practical implications<\/jats:title><jats:p>The results offer management insights on mitigating data privacy breach incidents arising from employees' actions. Roles of external privacy training and privacy self-assessment tools are signified.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title><jats:p>Antecedents of data privacy breaches have been underexplored. This paper is among the first to elucidate the roles of select exogenous and endogenous antecedents encompassing personal and environmental imperatives on data privacy breaches.<\/jats:p><\/jats:sec>","DOI":"10.1108\/itp-07-2022-0516","type":"journal-article","created":{"date-parts":[[2024,4,5]],"date-time":"2024-04-05T09:28:13Z","timestamp":1712309293000},"page":"1712-1734","source":"Crossref","is-referenced-by-count":2,"title":["Reducing data privacy breaches: an\u00a0empirical study of relevant antecedents and an outcome"],"prefix":"10.1108","volume":"38","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7032-3532","authenticated-orcid":false,"given":"Princely","family":"Ifinedo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2040-3806","authenticated-orcid":false,"given":"Francine","family":"Vachon","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8240-1486","authenticated-orcid":false,"given":"Anteneh","family":"Ayanso","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","published-online":{"date-parts":[[2024,4,8]]},"reference":[{"issue":"2","key":"key2025051605564457400_ref001","doi-asserted-by":"publisher","first-page":"160","DOI":"10.1509\/jmr.09.0215","article-title":"The impact of relative standards on the propensity to disclose","volume":"49","year":"2012","journal-title":"Journal of Marketing Research"},{"key":"key2025051605564457400_ref002","doi-asserted-by":"publisher","first-page":"73","DOI":"10.2147\/jmdh.s183275","article-title":"Assessing staff awareness and effectiveness of educational training on IT security and privacy in a large healthcare organization","volume":"12","year":"2019","journal-title":"Journal of Multidisciplinary Healthcare"},{"issue":"1","key":"key2025051605564457400_ref003","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1108\/itp-04-2021-0262","article-title":"Understanding online information disclosure: examination of data breach victimization experience effect","volume":"36","year":"2022","journal-title":"Information Technology and People"},{"issue":"2","key":"key2025051605564457400_ref004","first-page":"74","article-title":"Information technology security leaders' solutions for mitigating data breaches in a multigenerational workforce","volume":"12","year":"2020","journal-title":"International Leadership Journal"},{"key":"key2025051605564457400_ref005","volume-title":"Social Foundations of Thought and Action: A Social Cognitive Theory","year":"1986"},{"issue":"1","key":"key2025051605564457400_ref006","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1108\/13673270210417673","article-title":"Management strategies for individual knowledge and organizational knowledge","volume":"6","year":"2002","journal-title":"Journal of Knowledge Management"},{"issue":"3","key":"key2025051605564457400_ref007","doi-asserted-by":"publisher","first-page":"523","DOI":"10.2307\/25750690","article-title":"Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness","volume":"34","year":"2010","journal-title":"MIS Quarterly"},{"issue":"1","key":"key2025051605564457400_ref008","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1080\/10864415.2004.11044320","article-title":"The effect of internet security breach announcements on market value: capital market reactions for breached firms and internet security developers","volume":"9","year":"2004","journal-title":"International Journal of Electronic Commerce"},{"issue":"2","key":"key2025051605564457400_ref009","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1109\/TPC.2009.2017985","article-title":"Internet and online information privacy: an exploratory study of preteens and early teens","volume":"52","year":"2009","journal-title":"IEEE Transactions on Professional Communication"},{"key":"key2025051605564457400_ref010","first-page":"1","article-title":"Compliant, yet breached: compliance vs. Security","volume":"5","year":"2017","journal-title":"ISACA Journal"},{"issue":"4","key":"key2025051605564457400_ref011","doi-asserted-by":"publisher","first-page":"579","DOI":"10.1007\/s10796-010-9232-6","article-title":"Information systems resources and information security","volume":"13","year":"2011","journal-title":"Information Systems Frontiers"},{"key":"key2025051605564457400_ref012","unstructured":"CompTIA (2022), \u201cThe cost of a breach: 10 terrifying cybersecurity stats your MSP's customers need to know\u201d, available at: https:\/\/connect.comptia.org\/content\/articles\/the-cost-of-a-breach-10-terrifying-cybersecurity-stats-your-msp-s-customers-need-to-know (accessed 7 July 2022)."},{"issue":"4","key":"key2025051605564457400_ref013","doi-asserted-by":"publisher","first-page":"673","DOI":"10.2307\/20650322","article-title":"How ethics can enhance organizational privacy: lessons from the choice point and TJX data breaches","volume":"33","year":"2009","journal-title":"MIS Quarterly"},{"issue":"6","key":"key2025051605564457400_ref014","doi-asserted-by":"publisher","first-page":"982","DOI":"10.1002\/sec.1054","article-title":"Data privacy breach prevention framework for the cloud service","volume":"8","year":"2015","journal-title":"Security and Communication Networks"},{"issue":"4","key":"key2025051605564457400_ref015","doi-asserted-by":"publisher","first-page":"639","DOI":"10.1287\/isre.2015.0600","article-title":"Informing privacy research through information systems, psychology, and behavioral economics: thinking outside the \u2018APCO' box","volume":"26","year":"2015","journal-title":"Information Systems Research"},{"issue":"6","key":"key2025051605564457400_ref016","doi-asserted-by":"publisher","first-page":"1005","DOI":"10.1016\/j.leaqua.2010.10.006","article-title":"Self\u2013other rating agreement in leadership: a review","volume":"21","year":"2010","journal-title":"The Leadership Quarterly"},{"issue":"3","key":"key2025051605564457400_ref017","doi-asserted-by":"publisher","first-page":"382","DOI":"10.2307\/3150980","article-title":"Structural equation models with unobservable variables and measurement error: algebra and statistics","volume":"18","year":"1981","journal-title":"Journal of Marketing Research"},{"key":"key2025051605564457400_ref018","unstructured":"Global Cybersecurity Index (2020), available at: https:\/\/www.itu.int\/dms_pub\/itu-d\/opb\/str\/D-STR-GCI.01-2021-PDF-E.pdf (accessed 7 July 2022)."},{"issue":"2","key":"key2025051605564457400_ref019","doi-asserted-by":"publisher","first-page":"683","DOI":"10.1080\/07421222.2018.1451962","article-title":"The role of corporate reputation and crisis response strategies in data breach management","volume":"35","year":"2018","journal-title":"Journal of Management Information Systems"},{"key":"key2025051605564457400_ref020","article-title":"Information security awareness: its antecedents and mediating effects on security compliant behavior","year":"2013"},{"key":"key2025051605564457400_ref021","volume-title":"Multivariate Data Analysis","year":"2010","edition":"7th ed."},{"issue":"1","key":"key2025051605564457400_ref022","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1108\/EBR-11-2018-0203","article-title":"When to use and how to report the results of PLS-SEM","volume":"31","year":"2019","journal-title":"European Business Review"},{"issue":"2","key":"key2025051605564457400_ref023","doi-asserted-by":"publisher","first-page":"318","DOI":"10.1287\/isre.2020.0986","article-title":"The impact of executives' IT expertise on reported data security breaches","volume":"32","year":"2021","journal-title":"Information Systems Research"},{"key":"key2025051605564457400_ref024","unstructured":"Hanna, K.T., Ferguson, K. and Beaver, K. (2021), \u201cData breach\u201d, available at: https:\/\/www.techtarget.com\/searchsecurity\/definition\/data-breach (accessed 7 July 2022)."},{"issue":"4","key":"key2025051605564457400_ref025","doi-asserted-by":"publisher","first-page":"374","DOI":"10.1109\/tpc.2021.3110545","article-title":"User perception of data breaches","volume":"64","year":"2021","journal-title":"IEEE Transactions on Professional Communication"},{"issue":"1","key":"key2025051605564457400_ref026","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1007\/s11747-014-0403-8","article-title":"A new criterion for assessing discriminant validity in variance-based structural equation modeling","volume":"43","year":"2015","journal-title":"Journal of the Academy of Marketing Science"},{"issue":"6","key":"key2025051605564457400_ref027","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1145\/2184319.2184322","article-title":"Protecting against data breaches; living with mistakes","volume":"55","year":"2012","journal-title":"Communications of the ACM"},{"issue":"2","key":"key2025051605564457400_ref028","doi-asserted-by":"publisher","DOI":"10.1002\/spy2.66","article-title":"End user nonmalicious, counterproductive computer security behaviors: concept, development, and validation of an instrument","volume":"3","year":"2019","journal-title":"Security and Privacy"},{"issue":"2","key":"key2025051605564457400_ref029","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1108\/17465261111131794","article-title":"A snapshot of key information systems (IS) issues in Estonian organizations for the 2000s","volume":"6","year":"2011","journal-title":"Baltic Journal of Management"},{"issue":"6","key":"key2025051605564457400_ref030","doi-asserted-by":"publisher","first-page":"618","DOI":"10.1504\/ijmed.2006.010357","article-title":"Do top-and mid-level managers view enterprise resource planning (ERP) systems success measures differently?","volume":"3","year":"2006","journal-title":"International Journal of Management and Enterprise Development"},{"issue":"2","key":"key2025051605564457400_ref031","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1086\/376806","article-title":"A critical review of construct indicators and measurement model misspecification in marketing and consumer research","volume":"30","year":"2003","journal-title":"Journal of Consumer Research"},{"issue":"8","key":"key2025051605564457400_ref032","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1016\/S1361-3723(13)70071-X","article-title":"Data breaches: the enemy within","volume":"2","year":"2013","journal-title":"Computer Fraud and Security"},{"issue":"4","key":"key2025051605564457400_ref033","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4018\/ijec.2015100101","article-title":"Common method bias in PLS-SEM: a full collinearity assessment approach","volume":"11","year":"2015","journal-title":"International Journal of E-Collaboration"},{"key":"key2025051605564457400_ref034","unstructured":"Kock, N. (2020), \u201cWarpPLS user manual: version 7.0 - ScriptWarp systems\u201d, available at: https:\/\/www.scriptwarp.com\/warppls\/UserManual_v_7_0.pdf (accessed 7 July 2022)."},{"issue":"5","key":"key2025051605564457400_ref035","doi-asserted-by":"publisher","first-page":"597","DOI":"10.1016\/j.im.2003.08.001","article-title":"Why there aren't more information security research studies","volume":"41","year":"2004","journal-title":"Information and Management"},{"issue":"6","key":"key2025051605564457400_ref036","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1016\/j.jisa.2014.10.012","article-title":"A methodology for estimating the tangible cost of data breaches","volume":"19","year":"2014","journal-title":"Journal of Information Security and Applications"},{"issue":"1","key":"key2025051605564457400_ref037","doi-asserted-by":"publisher","first-page":"28","DOI":"10.17705\/1CAIS.02828","article-title":"Empirical studies on online information privacy concerns: literature review and an integrative framework","volume":"28","year":"2011","journal-title":"Communications of the Association for Information Systems"},{"issue":"1","key":"key2025051605564457400_ref038","doi-asserted-by":"publisher","first-page":"317","DOI":"10.25300\/misq\/2022\/15713","article-title":"Where is IT in information security? The interrelationship among IT investment, security awareness, and data breaches","volume":"47","year":"2023","journal-title":"MIS Quarterly"},{"issue":"44","key":"key2025051605564457400_ref039","doi-asserted-by":"publisher","first-page":"542","DOI":"10.1016\/j.jretai.2012.08.001","article-title":"Common method bias in marketing: causes, mechanisms, and procedural remedies","volume":"88","year":"2012","journal-title":"Journal of Retailing"},{"key":"key2025051605564457400_ref040","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1016\/j.chb.2018.01.028","article-title":"The impact of information security threat awareness on privacy-protective behaviors","volume":"83","year":"2018","journal-title":"Computers in Human Behavior"},{"issue":"1","key":"key2025051605564457400_ref041","first-page":"81","article-title":"Data protection and cybersecurity in Canada","volume":"39","year":"2019","journal-title":"Franchise Law Journal"},{"issue":"3","key":"key2025051605564457400_ref042","first-page":"1","article-title":"Testing mediation via indirect effects in PLSSEM: a social networking site illustration","volume":"1","year":"2020","journal-title":"Data Analysis Perspectives Journal"},{"issue":"3","key":"key2025051605564457400_ref043","doi-asserted-by":"publisher","first-page":"495","DOI":"10.1108\/IMDS-03-2018-0101","article-title":"The influence of chief data officer presence on firm performance: does firm size matter?","volume":"119","year":"2019","journal-title":"Industrial Management and Data Systems"},{"key":"key2025051605564457400_ref044","unstructured":"Office of the Privacy Commissioner of Canada (OPC of Canada) (2008a), \u201cPIPEDA self-assessment tool\u201d, available at: https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/pipeda-compliance-help\/pipeda-compliance-and-training-tools\/pipeda_sa_tool_200807\/ (accessed 7 July 2022)."},{"key":"key2025051605564457400_ref045","unstructured":"Office of the Privacy Commissioner of Canada (OPC of Canada) (2008b), \u201cPrivacy laws in Canada\u201d, available at: https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/ (accessed 7 July 2022)."},{"key":"key2025051605564457400_ref046","unstructured":"Office of the Privacy Commissioner of Canada (OPC of Canada) (2019), \u201c2018-19 survey of Canadians on privacy\u201d, available at: https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/research\/explore-privacy-research\/2019\/por_2019_ca\/ (accessed 7 July 2022)."},{"key":"key2025051605564457400_ref047","unstructured":"Office of the Privacy Commissioner of Canada (OPC of Canada) (2020), \u201c2019-20 survey of Canadians on privacy\u201d, available at: https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/research\/explore-privacy-research\/2020\/por_2019-20_bus\/ (accessed 7 July 2022)."},{"key":"key2025051605564457400_ref048","unstructured":"Office of the Privacy Commissioner of Canada (OPC of Canada) (2021), \u201c2020-21 survey of Canadians on privacy-related issues\u201d, available at: https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/research\/explore-privacy-research\/2021\/por_2020-21_ca\/ (accessed 7 July 2022)."},{"issue":"4","key":"key2025051605564457400_ref049","doi-asserted-by":"publisher","first-page":"623","DOI":"10.2307\/25148814","article-title":"Specifying formative constructs in information systems research","volume":"31","year":"2007","journal-title":"MIS Quarterly"},{"key":"key2025051605564457400_ref050","unstructured":"Pwc com (2022), \u201c2022 Canadian digital trust insights\u201d, available at: https:\/\/www.pwc.com\/ca\/en\/services\/consulting\/cybersecurity-privacy\/digital-trust-insights.html (accessed 7 July 2022)."},{"issue":"2","key":"key2025051605564457400_ref051","doi-asserted-by":"publisher","first-page":"314","DOI":"10.1080\/07421222.2015.1063315","article-title":"Estimating the contextual risk of data breach: an empirical approach","volume":"32","year":"2015","journal-title":"Journal of Management Information Systems"},{"issue":"2","key":"key2025051605564457400_ref052","doi-asserted-by":"publisher","first-page":"167","DOI":"10.2307\/249477","article-title":"Information privacy: measuring individuals' concerns about organizational practices","volume":"20","year":"1996","journal-title":"MIS Quarterly"},{"issue":"4","key":"key2025051605564457400_ref053","doi-asserted-by":"publisher","first-page":"989","DOI":"10.2307\/41409970","article-title":"Information privacy research: an interdisciplinary review","volume":"35","year":"2011","journal-title":"MIS Quarterly"},{"issue":"2","key":"key2025051605564457400_ref054","doi-asserted-by":"publisher","first-page":"290","DOI":"10.2307\/270723","article-title":"Asymptotic confidence intervals for indirect effects in structural equation models","volume":"13","year":"1982","journal-title":"Sociological Methodology"},{"key":"key2025051605564457400_ref055","volume-title":"Understanding Privacy","year":"2008"},{"key":"key2025051605564457400_ref056","unstructured":"Solove, D. (2019), \u201cWhat should privacy awareness training include?\u201d, available at: https:\/\/teachprivacy.com\/what-should-privacy-awareness-training-include\/ (accessed 7 July 2022)."},{"issue":"3","key":"key2025051605564457400_ref057","first-page":"539","article-title":"Direct and vicarious liability for tort claims involving violation of privacy","volume":"96","year":"2018","journal-title":"Canadian Bar Review"},{"issue":"4","key":"key2025051605564457400_ref058","doi-asserted-by":"publisher","first-page":"381","DOI":"10.1080\/10919392.2020.1818521","article-title":"Financial loss due to a data privacy breach: an empirical analysis","volume":"30","year":"2020","journal-title":"Journal Of Organizational Computing and Electronic Commerce"},{"issue":"3","key":"key2025051605564457400_ref059","doi-asserted-by":"publisher","first-page":"227","DOI":"10.2308\/isys-52379","article-title":"Much ado about nothing: the (lack of) economic impact of data privacy breaches","volume":"33","year":"2019","journal-title":"Journal of Information Systems"},{"key":"key2025051605564457400_ref060","volume-title":"Methods and Data Analysis for Cross-Cultural Research","year":"1997"},{"issue":"6","key":"key2025051605564457400_ref061","doi-asserted-by":"publisher","first-page":"1679","DOI":"10.1108\/ITP-01-2018-0020","article-title":"Retaining users after privacy invasions: the roles of institutional privacy assurances and threat-coping appraisal in mitigating privacy concerns","volume":"32","year":"2019","journal-title":"Information Technology and People"},{"key":"key2025051605564457400_ref062","unstructured":"Whoa.com (n.d.), \u201cData breach 101: top 5 reasons it happens\u201d, available at: https:\/\/www.whoa.com\/data-breach-101-top-5-reasons-it-happens\/ (accessed 7 July 2022)."},{"key":"key2025051605564457400_ref063","article-title":"Security technology and awareness training; do they affect behaviors and thus reduce breaches? A quantitative study","year":"2019"},{"issue":"3","key":"key2025051605564457400_ref064","doi-asserted-by":"publisher","first-page":"361","DOI":"10.5465\/amr.1989.4279067","article-title":"Social cognitive theory of organizational management","volume":"14","year":"1989","journal-title":"Academy of Management Review"},{"issue":"12","key":"key2025051605564457400_ref065","doi-asserted-by":"publisher","first-page":"798","DOI":"10.17705\/1jais.00281","article-title":"Information privacy concerns: linking individual perceptions with institutional privacy assurances","volume":"12","year":"2011","journal-title":"Journal of the Association for Information Systems"},{"issue":"1","key":"key2025051605564457400_ref066","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1080\/08874417.2020.1712269","article-title":"Cyber security awareness, knowledge and behavior: a comparative study","volume":"62","year":"2022","journal-title":"Journal of Computer Information Systems"},{"key":"key2025051605564457400_ref067","unstructured":"CyberEdge Group (2021), \u201c2021 cyberthreat report\u201d, available at: https:\/\/cyber-edge.com\/wp-content\/uploads\/2021\/04\/CyberEdge-2021-CDR-Report-v1.1-1.pdf (accessed 7 July 2022)."}],"container-title":["Information Technology &amp; People"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ITP-07-2022-0516\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ITP-07-2022-0516\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T21:55:14Z","timestamp":1753394114000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/itp\/article\/38\/4\/1712-1734\/1263684"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,8]]},"references-count":67,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2024,4,8]]},"published-print":{"date-parts":[[2025,5,19]]}},"alternative-id":["10.1108\/ITP-07-2022-0516"],"URL":"https:\/\/doi.org\/10.1108\/itp-07-2022-0516","relation":{},"ISSN":["0959-3845"],"issn-type":[{"value":"0959-3845","type":"print"}],"subject":[],"published":{"date-parts":[[2024,4,8]]}}}