Paper Type
Short
Paper Number
PACIS2026-1243
Description
Organizations invest in GDPR competencies yet often struggle to deliver consistent execution of core accountability routines such as DSAR handling, RoPA/data mapping, DPIA, and breach response. This short paper conceptualizes GDPR compliance as performance, defined as execution quality that produces traceable evidence. Drawing on Dynamic Capabilities Theory (DCT), we propose a mechanism in which GDPR competencies enable dynamic privacy management capabilities (sensing, seizing, transforming) that sustain privacy management practices and, in turn, improve compliance performance. We define compliance performance across four dimensions (timeliness, completeness, consistency, and auditability) and outline how cross context comparison can be supported via normalized indicators in follow-up work. Methodologically, we develop a balanced 33-statement Q-set grounded in a structured scoping review and employ Q-method with nine privacy experts to identify shared expert viewpoints regarding capability-practice priorities and trade-offs. The resulting typology is expected to refine construct boundaries, strengthen the proposed mechanism, and inform subsequent confirmatory testing.
Recommended Citation
Christiani, Ingrid; Hidayanto, Achmad Nizar; and Shihab, Muhammad Rifki Rifki, "GDPR Competencies and Dynamic Capabilities for GDPR Compliance Performance" (2026). PACIS 2026 Proceedings. 3.
https://aisel.aisnet.org/pacis2026/dig_sec/dig_sec/3
GDPR Competencies and Dynamic Capabilities for GDPR Compliance Performance
Organizations invest in GDPR competencies yet often struggle to deliver consistent execution of core accountability routines such as DSAR handling, RoPA/data mapping, DPIA, and breach response. This short paper conceptualizes GDPR compliance as performance, defined as execution quality that produces traceable evidence. Drawing on Dynamic Capabilities Theory (DCT), we propose a mechanism in which GDPR competencies enable dynamic privacy management capabilities (sensing, seizing, transforming) that sustain privacy management practices and, in turn, improve compliance performance. We define compliance performance across four dimensions (timeliness, completeness, consistency, and auditability) and outline how cross context comparison can be supported via normalized indicators in follow-up work. Methodologically, we develop a balanced 33-statement Q-set grounded in a structured scoping review and employ Q-method with nine privacy experts to identify shared expert viewpoints regarding capability-practice priorities and trade-offs. The resulting typology is expected to refine construct boundaries, strengthen the proposed mechanism, and inform subsequent confirmatory testing.
Comments
08-Security