Paper Type

Short

Paper Number

PACIS2026-1243

Description

Organizations invest in GDPR competencies yet often struggle to deliver consistent execution of core accountability routines such as DSAR handling, RoPA/data mapping, DPIA, and breach response. This short paper conceptualizes GDPR compliance as performance, defined as execution quality that produces traceable evidence. Drawing on Dynamic Capabilities Theory (DCT), we propose a mechanism in which GDPR competencies enable dynamic privacy management capabilities (sensing, seizing, transforming) that sustain privacy management practices and, in turn, improve compliance performance. We define compliance performance across four dimensions (timeliness, completeness, consistency, and auditability) and outline how cross context comparison can be supported via normalized indicators in follow-up work. Methodologically, we develop a balanced 33-statement Q-set grounded in a structured scoping review and employ Q-method with nine privacy experts to identify shared expert viewpoints regarding capability-practice priorities and trade-offs. The resulting typology is expected to refine construct boundaries, strengthen the proposed mechanism, and inform subsequent confirmatory testing.

Comments

08-Security

Share

COinS
 
Jul 5th, 12:00 AM

GDPR Competencies and Dynamic Capabilities for GDPR Compliance Performance

Organizations invest in GDPR competencies yet often struggle to deliver consistent execution of core accountability routines such as DSAR handling, RoPA/data mapping, DPIA, and breach response. This short paper conceptualizes GDPR compliance as performance, defined as execution quality that produces traceable evidence. Drawing on Dynamic Capabilities Theory (DCT), we propose a mechanism in which GDPR competencies enable dynamic privacy management capabilities (sensing, seizing, transforming) that sustain privacy management practices and, in turn, improve compliance performance. We define compliance performance across four dimensions (timeliness, completeness, consistency, and auditability) and outline how cross context comparison can be supported via normalized indicators in follow-up work. Methodologically, we develop a balanced 33-statement Q-set grounded in a structured scoping review and employ Q-method with nine privacy experts to identify shared expert viewpoints regarding capability-practice priorities and trade-offs. The resulting typology is expected to refine construct boundaries, strengthen the proposed mechanism, and inform subsequent confirmatory testing.