{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T14:51:08Z","timestamp":1786114268066,"version":"3.56.0"},"reference-count":34,"publisher":"Emerald","issue":"3","license":[{"start":{"date-parts":[[2020,6,18]],"date-time":"2020-06-18T00:00:00Z","timestamp":1592438400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ITP"],"published-print":{"date-parts":[[2021,5,24]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title><jats:p>This paper investigates the European Union's General Data Protection Regulation (GDPR) in information systems (ISs). The GDPR consists of 99 articles, and two articles are emphasised \u2013 namely Article 15, which deals with rights of access by the data subject, and Article 20, which deals with the right to data portability.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title><jats:p>15 companies operating in the Norwegian consumer market were randomly selected. Each company received an inquiry pertaining to rights of access by the data subject (Article 15) and the right to data portability (Article 20). The research team carefully analysed the answers received and categorised the responses according to the two articles emphasised.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Findings<\/jats:title><jats:p>The findings show extensive variations among the companies in terms of response time, quality of feedback and how companies handle requests concerning rights of access by the data subject (Article 15) and the right to data portability (Article 20). Differences are also pertaining to the types of files, along with the content of these files. It should be noted, however, that most of the companies replied to the inquiry before the deadline. The findings show that companies comply better with Article 20 than Article 15. However, it appears that they do not differentiate between the two articles.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title><jats:p>This study explores a research topic that is relatively new. It addresses a gap in the extant research by highlighting how the GDPR works in practice from a consumer's perspective. In addition, guidelines are offered to the consumers and companies affected by the GDPR.<\/jats:p><\/jats:sec>","DOI":"10.1108\/itp-08-2019-0433","type":"journal-article","created":{"date-parts":[[2020,6,18]],"date-time":"2020-06-18T10:17:53Z","timestamp":1592475473000},"page":"912-929","source":"Crossref","is-referenced-by-count":20,"title":["Dude, where's my data? The GDPR in practice, from a consumer's point of view"],"prefix":"10.1108","volume":"34","author":[{"given":"Hanne","family":"S\u00f8rum","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wanda","family":"Presthus","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","published-online":{"date-parts":[[2020,6,18]]},"reference":[{"key":"key2021052115091108500_ref001","article-title":"GDPR - et hav av muligheter gjennom kontroll","year":"2017"},{"issue":"4","key":"key2021052115091108500_ref002","doi-asserted-by":"crossref","first-page":"1017","DOI":"10.2307\/41409971","article-title":"Privacy in the digital age: a review of information privacy research in information systems","volume":"35","year":"2011","journal-title":"MIS Quarterly"},{"key":"key2021052115091108500_ref003","first-page":"33","article-title":"A critical analysis of privacy design strategies","year":"2016"},{"key":"key2021052115091108500_ref004","doi-asserted-by":"crossref","unstructured":"Crockford, D. (2006), \u201cThe application\/JSON media type for Java script object notation (JSON)\u201d, available at: https:\/\/www.rfc-editor.org\/info\/rfc4627 (accessed 16 September 2019).","DOI":"10.17487\/rfc4627"},{"issue":"4","key":"key2021052115091108500_ref005","doi-asserted-by":"crossref","first-page":"673","DOI":"10.2307\/20650322","article-title":"How ethics can enhance organizational privacy: lessons from the choice point and TJX data breaches","volume":"33","year":"2009","journal-title":"MIS Quarterly"},{"key":"key2021052115091108500_ref006","volume-title":"Only Humans Need Apply: Winners and Losers in the Age of Smart Machines","year":"2016"},{"issue":"2","key":"key2021052115091108500_ref007","doi-asserted-by":"crossref","first-page":"193","DOI":"10.1016\/j.clsr.2017.10.003","article-title":"The right to data portability in the GDPR: towards user-centric interoperability of digital services","volume":"34","year":"2018","journal-title":"Computer Law and Security Review"},{"issue":"4","key":"key2021052115091108500_ref008","doi-asserted-by":"crossref","first-page":"9","DOI":"10.1080\/07421222.2003.11045748","article-title":"The DeLone and McLean model of information systems success: a ten-year update","volume":"19","year":"2003","journal-title":"Journal of Management Information Systems"},{"issue":"1","key":"key2021052115091108500_ref009","first-page":"1","article-title":"The right to data portability in the GDPR and EU competition law: odd couple or dynamic duo?","volume":"8","year":"2017","journal-title":"European Journal of Law and Technology"},{"key":"key2021052115091108500_ref010","volume-title":"Personvern Og GDPR I Praksis","year":"2019"},{"key":"key2021052115091108500_ref011","unstructured":"Kampanje.no (2019), \u201cDatatilsynet varsler flere GDPR b\u00f8ter fremover\u201d, available at: https:\/\/kampanje.com\/tech\/2019\/04\/datatilsynet-varsler-flere-gdpr-boter-fremover (accessed 14 May 2019)."},{"issue":"3","key":"key2021052115091108500_ref012","first-page":"229","article-title":"Forgetting footprints, shunning shadows: a critical analysis of the right to be forgotten in big data practice","volume":"8","year":"2011","journal-title":"SCRIPT-ed"},{"issue":"2","key":"key2021052115091108500_ref013","doi-asserted-by":"crossref","first-page":"159","DOI":"10.1080\/13600869.2013.801589","article-title":"Privacy regulation cannot be hardcoded. A critical comment on the \u2018privacy by design\u2019 provision in data-protection law","volume":"28","year":"2014","journal-title":"International Review of Law, Computers and Technology"},{"key":"key2021052115091108500_ref014","volume-title":"Experiencing MIS","year":"2008"},{"issue":"6","key":"key2021052115091108500_ref015","doi-asserted-by":"crossref","first-page":"546","DOI":"10.1057\/s41303-017-0066-x","article-title":"Why security and privacy research lies at the centre of the information systems (IS) artefact: proposing a bold research agenda","volume":"26","year":"2017","journal-title":"European Journal of Information Systems"},{"issue":"October 2012","key":"key2021052115091108500_ref016","first-page":"59","article-title":"Big data: the management revolution","volume":"26","year":"2012","journal-title":"Harvard Business Review"},{"issue":"4","key":"key2021052115091108500_ref017","doi-asserted-by":"crossref","first-page":"442","DOI":"10.1108\/09593840410570285","article-title":"Are they really listening? An investigation into published online privacy policies at the beginning of the third millennium","volume":"17","year":"2004","journal-title":"Information Technology and People"},{"key":"key2021052115091108500_ref018","volume-title":"Qualitative Data Analysis","year":"1994"},{"issue":"6","key":"key2021052115091108500_ref019","doi-asserted-by":"crossref","first-page":"741","DOI":"10.1016\/j.im.2015.06.006","article-title":"Exploring information privacy regulation, risks, trust, and behavior","volume":"52","year":"2015","journal-title":"Information and Management"},{"key":"key2021052115091108500_ref020","first-page":"25","article-title":"2000 personvernklager","author":"NTB","year":"2019","journal-title":"Aftenposten"},{"issue":"4","key":"key2021052115091108500_ref021","doi-asserted-by":"crossref","first-page":"775","DOI":"10.1108\/ITP-08-2015-0191","article-title":"Slow tech: bridging computer ethics and business ethics","volume":"28","year":"2015","journal-title":"Information Technology and People"},{"key":"key2021052115091108500_ref022","volume-title":"Information Systems for Managers: With Cases","year":"2018","edition":"4.0 ed."},{"issue":"6","key":"key2021052115091108500_ref023","doi-asserted-by":"crossref","first-page":"1247","DOI":"10.1016\/j.clsr.2018.08.006","article-title":"Backups and the right to be forgotten in the GDPR: an uneasy relationship","volume":"34","year":"2018","journal-title":"Computer Law and Security Review"},{"key":"key2021052115091108500_ref024","article-title":"Information privacy","volume-title":"MIS Quarterly Research Curations","year":"2018"},{"key":"key2021052115091108500_ref025","doi-asserted-by":"crossref","first-page":"603","DOI":"10.1016\/j.procs.2018.10.081","article-title":"Are consumers concerned about privacy? An online survey emphasizing general data protection regulation","volume":"138","year":"2018","journal-title":"Procedia Computer Science"},{"key":"key2021052115091108500_ref026","article-title":"GDPR compliance in Norwegian Companies","volume-title":"Norsk Konferanse for Organisasjoners Bruk Av IT (NOKOBIT) in Svalbard, Norway, 2018, 18-20 Open Journal Systems","year":"2018"},{"key":"key2021052115091108500_ref027","unstructured":"Sticos.no (2018), \u201cGDPR brudd ga 16 millioner kroner i bot\u201d, [Norwegian], available at: https:\/\/www.sticos.no\/fagstoff\/personvern\/kategori\/personvern\/gdpr-brudd-ga-16-millioner-kroner-i-bot (accessed 14 May 2019)."},{"key":"key2021052115091108500_ref034","first-page":"402","article-title":"The critical success factors of GDPR implementation: a systematic literature review","volume-title":"Digital Policy, Regulation and Governance","year":"2019"},{"key":"key2021052115091108500_ref028","first-page":"1","article-title":"Regulation (eu) 2016\/679 of the European parliament and of the Council of 27 April 2016","author":"The European Parliament and the Council","year":"2016","journal-title":"Official Journal of the European Union"},{"key":"key2021052115091108500_ref029","unstructured":"The Norwegian Data Protection Authority (2018), \u201cRetten til dataportabilitet\u201d, [Norwegian], available at: https:\/\/www.datatilsynet.no\/regelverk-og-verktoy\/veiledere\/retten-til-dataportabilitet\/?id=9820 (accessed 16 September 2019)."},{"issue":"5","key":"key2021052115091108500_ref030","doi-asserted-by":"crossref","first-page":"1047","DOI":"10.1108\/ITP-02-2017-0052","article-title":"Are users competent to comply with information security policies? An analysis of professional competence models","volume":"31","year":"2018","journal-title":"Information Technology and People"},{"issue":"1","key":"key2021052115091108500_ref031","doi-asserted-by":"crossref","first-page":"39","DOI":"10.17705\/1jais.00420","article-title":"Organizational violations of externally governed privacy and security rules: explaining and predicting selective violations under conditions of strain and excess","volume":"17","year":"2016","journal-title":"Journal of the Association for Information Systems"},{"issue":"21","key":"key2021052115091108500_ref032","first-page":"364","article-title":"Update tutorial: big data analytics: concepts, technology, and applications","volume":"44","year":"2019","journal-title":"Communications of the Association for Information Systems"},{"issue":"1","key":"key2021052115091108500_ref033","first-page":"488","article-title":"Addressing the growing need for algorithmic transparency","volume":"45","year":"2019","journal-title":"Communications of the Association for Information Systems"}],"container-title":["Information Technology &amp; People"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ITP-08-2019-0433\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ITP-08-2019-0433\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T21:55:21Z","timestamp":1753394121000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/itp\/article\/34\/3\/912-929\/435011"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,18]]},"references-count":34,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2020,6,18]]},"published-print":{"date-parts":[[2021,5,24]]}},"alternative-id":["10.1108\/ITP-08-2019-0433"],"URL":"https:\/\/doi.org\/10.1108\/itp-08-2019-0433","relation":{},"ISSN":["0959-3845"],"issn-type":[{"value":"0959-3845","type":"print"}],"subject":[],"published":{"date-parts":[[2020,6,18]]}}}