How Do Information Systems Pose Challenges Due The Protection Of Individual Privacy?
Muda I, Gusnardi G, Pakpahan CMB and Laoli IF
Published on: 2025-01-02
Abstract
Individuals have the right to their own privacy, free from surveillance by other individuals or organizations, including the state. In Information Systems, contemporary advanced data storage and analysis technologies bring convenience in collecting personal data from various sources and creating detailed digital profiles about individuals, but also pose serious challenges of violating the privacy of individual information. Data flowing over the Internet can be monitored at many points and easily copied, thereby threatening the protection of personal data. Solutions discussed include regulatory improvements and stronger security measures to safeguard individual privacy in the digital era.
Keywords
Information systems technology; Privacy and freedom in the internet era; Solutions to privacy challengesIntroduction
The concept of information privacy existed long before information and communication technology changed its occurrence, impact, and management. In the mid-1980s, Mason stated that the emergence of increased use of information technology, or the Information Age, would give rise to four major concerns regarding information use: privacy, accuracy, property, and accessibility (PAPA). These predictions have proven accurate for every area, and especially privacy, which has become a subject of increasing concern over the years as monitoring of personal information via the internet becomes ubiquitous; the storage is so long-lasting that it makes one's past impossible to erase. Privacy is the ability of one or a group of individuals to keep their personal lives and affairs private from the public or to control the flow of information about them [1]. Privacy violations involve various types of harmful or problematic activities that give rise to fear and anxiety. Clarke states, "Privacy is often considered a moral or legal right." many researchers argue that privacy is a person's ability to control information about themselves [2].
Information systems technology is increasingly penetrating every aspect of every individual's personal and professional life. The issue of control over personal data has become closely linked to issues of personal choice, autonomy, and socio-economic power. Individuals manage the boundaries between their private and public spheres in various ways: through detachment, prudence, by protecting personal information. Advances in information technology have made the collection and use of personal data often invisible. As a result, individuals rarely have clear knowledge of what information other people, companies, and governments have about them how that information is used, and what the consequences are. To the extent that people do not have such information, or are aware of their ignorance, they are likely to be unsure about how much information to share. While there are so many laws addressing privacy issues, commentators often lament the law's inability to adequately protect privacy. Courts and policymakers often have a single view of privacy when they assess whether an activity violates privacy. So they mix up different privacy issues even though there are significant differences or fail to recognize the problem as a whole. Privacy issues are often misunderstood or not consistently recognized in the law. This paper aims to provide solutions to various danger challenges and privacy problems regarding advances in information system technology that have reached a significant level of social recognition.
Literature Review
Privacy is a form of human right to protect personal information and act privately or not be regulated by others. Alan Westin [4] himself defined privacy as the right of an individual or group to determine when, how, and to whom he will provide information about himself. In other words, privacy is a form of human autonomy towards themselves [3]. For this reason, privacy must be protected by two parties, namely individuals and the government. The government itself acts as the party that guarantees people's rights to life and is obliged to formulate and implement privacy regulations to protect the human rights of every individual in society.
Privacy in Indonesia itself is a basic right of citizens which is regulated in the UUD 1945 article 28G paragraph (1) which contains, “Every person has the right to protect himself, his family, honor, dignity, and property under his control, and has the right to a sense of security and protection from the threat of fear of doing or not doing something which is a human right." Apart from that, privacy protection is also regulated in the Personal Data Protection Bill and other laws. Apart from protecting human rights, all of these protection regulations are designed to prevent the misuse of personal data by other parties. These rules function to create transparency and accountability in data management. In addition, regulations provide clear legal protection for individuals, help build public trust, and create a balance between contemporary developments and privacy protection.
Technological developments have changed the way society obtains and manages information. The public can easily obtain other people's personal information without the individual's permission. Individual personal information that can be digitized causes a lack of public awareness regarding privacy on social media. People can easily spread and take other people's personal data and information without knowing how dangerous the consequences of spreading personal information are, such as identity theft and fraud, creating tension between groups, and can even damage the reputation of the person whose data is spread.
Information systems are an important concern due to the many privacy violations nowadays. Information systems often store, manage, and process personal information data in ways that can compromise individual privacy. To overcome this, information privacy is needed. Information privacy provides guidelines for individuals to control the dissemination of their personal information in facing challenges in this era of digitalization. This literature review aims to explore what challenges individuals experience in maintaining their privacy in the development of Information Systems.
Skinnier et al. put forward four main dimensions in identifying privacy, namely personal privacy, behavioral privacy, communication privacy, and data privacy. In line with Skinnier, Clarke stated that in the current concept of digitalization, data privacy and communication privacy merge because individual communication tools with other individuals have changed into digital tools. Personal information data can be taken from current human communication tools. Therefore, Belanger & Hiller [5] say that the main challenge in developing information systems today is control over this data, especially when technology can take data without individual permission.
Collecting personal data for secondary needs has become the fastest challenge in the development of Information Systems. Data is often taken and processed without the individual's knowledge by Information Systems to run applications on the computer. Even information data that individuals process and allow for other applications can be taken over by different applications. Therefore, Belanger et al. [7] stated that the use of data for other purposes that were not consented to by the individual when the data was collected can cause major privacy risks. Solove [6] also groups information privacy issues in a taxonomy that includes collection, processing, dissemination and violation of information.
Research on privacy challenges in information systems focuses on how information systems cause privacy challenges today. Apart from that, we also present what solutions can be provided to the challenges of protecting privacy in today's advances in Information Systems from a social and ethical perspective. However, it cannot be denied that the technical solution to this problem must be advanced studies regarding Information Systems development. Information systems must provide a sense of security to every individual by exploring how to manage and store the data of every technology user safely and in accordance with the concept of information privacy as one of the human rights that every individual must obtain. Information systems must build a sense of security and trust for each consumer in developing products that guarantee the privacy of each individual.
Methods
To find out how information systems can endanger privacy, research is needed regarding what violations of privacy occur when using information systems and the social and ethical views on them. This research aims to observe and analyze the impact of the use of Information Technology on user privacy. For this reason, we must measure how far the use of Information Systems can endanger user privacy data. In addition, this research aims to determine the social ethical perspective of the topic 'How Information Systems Can Create Challenges in Protecting Individual Privacy' as well as solutions to the social ethical view of this problem [8].
The research we conducted used qualitative methods. Qualitative data will be collected to provide insight into violations of privacy protection in Information Systems. After getting the information, we then analysed the social and ethical perspectives regarding privacy challenges in Information Systems. We will explore the phenomenon of privacy threats that arise due to the use of information systems today. We also conducted this research to gain a thorough understanding of the impact that the threat of privacy violations has had on users.
This research focuses on all users of information system products based on data storage. We will see how various individuals experience when submitting their personal data information to several Information System products. We will see how Information System product users perceive the use of personal information data to run applications. We collected qualitative data from many articles and previous studies regarding privacy violations in Information System products. We obtained this data from articles and previous research as a complement to our analysis of how Information Systems experience challenges in protecting privacy [12-13].
Researchers select and select previous research based on criteria, namely research published within the last 10 years, articles that specifically highlight challenges related to privacy in the context of information systems, studies that use a qualitative approach or focus on the experiences of users of information system products in facing challenges. Technology [10].
After the data is collected, we will interpret the data regarding patterns and perspectives of individuals and Information Systems in facing the challenges of managing privacy in Information Systems. We will draw conclusions regarding social and ethical views on how information systems face challenges in managing privacy. We will also provide suggestions and solutions from a social and ethical point of view in individual control in disseminating personal information data in Information System products [9].
Result
This research aims to explore how Information Systems provide challenges in managing Information Systems from a social and ethical perspective. We made observations and took data from previous studies and combined them into a collection of privacy challenges that society faces when using the Information Systems field. The first research result that we want to discuss is the anxiety of Information System users regarding their personal information provided to the Information System.
The challenges that occur can include challenges from individual users, challenges from Information System designers, and challenges from governments in protecting privacy in Information Systems. We collect data regarding how users lack self-control in disseminating their personal information, how users have limited knowledge about privacy in Information Systems, how designers do not design information data collection ethically, and how the government enforces regulations regarding users' personal information data in Information Systems.
Here are some of the most common privacy challenges we have found based on observations from previous research:
- Too long privacy policy
Meier et. al [4] said that many sources admitted that the privacy policies they received from several applications were too long and wordy. The privacy policy explains in detail how user personal information will be managed and stored. However, because the explanation of the privacy policy provided is too long, users tend to ignore it and not read the privacy policy [11].
- Weak security in the Information System
The most common thing that causes privacy challenges in Information Systems is data leakage in the Information System. This is based on weak security in the Information System which causes other parties to enter and take the information data. In several studies, it was stated that users have stored information data as well as possible, and have even read the privacy policy, but weak security of the Information System can cause leaks of personal information data.
- Lack of user knowledge about privacy
Users often underestimate personal information and disseminate their personal information to the public via social media. This lack of user knowledge can lead to privacy challenges. In addition, users' ignorance about the retrieval of personal data in Information Systems, such as cookie in tracking location, allowing cameras, even capturing data that is personal data can be a privacy challenge in the use of Information Systems.
- Non-transparent use of user information data by the Information System
Users often complain about how the data they provide is used for other purposes, such as advertising and financial systems. Users often complain about advertisements from several Information System products that can reach their personal information, such as email, telephone numbers, and other social media even though users do not provide information directly about these products. Apart from that, sometimes it often happens that credit or debit cards are linked in several shopping applications without the user's consent. This data is thought to be obtained from the shopping application that the user has registered with.
- The gap between Information Systems ethics and government regulations
Information System Users explain that privacy regulations are not strong enough to catch privacy violations. Government regulations sometimes cannot fulfill the privacy rights of Information System users. There is no action that is strict enough to punish violators of privacy ethics. Users also say that sometimes privacy laws are not adapted to current developments in Information Systems, such as AI and big data. In fact, in Indonesia itself, the Information System established by the government, for example to manage BPJS Health, can experience privacy leaks due to weak regulations and enforcement of privacy laws set by the government.
Apart from exploring the challenges of privacy in Information Systems, this research also focuses on social and ethical solutions for how privacy challenges in Information Systems can be minimized. We collect results by analyzing previous challenges and predicting possible solutions to minimize these challenges. We also look at previous research regarding solutions to privacy challenges in Information Systems from a social and ethical perspective. Below are the results of our elaboration regarding what social and ethical solutions can be taken to minimize privacy challenges?
- Educate on the importance of privacy as a human right
Judging from users' ignorance regarding self-control over their personal information and regarding data protection of that information, it is necessary to educate the public using Information Systems regarding privacy. Users can be taught to know and sort what personal data can and cannot be shared, how to manage privacy policy permissions, and data security risks in Information Systems.
- Use simple language in the privacy policy
Information System Designers can use simple language that the public can understand in privacy policy warnings so that all users from all walks of life can understand how their personal data will be managed and stored. This solution can also increase user trust in Information System designers because users know the transparency of managing their personal data.
- Designing features to control personal data by users
Users say they expect flexible features so that users can save data when needed and delete it when they don't need it. This also minimizes the occurrence of non-transparent data use because users can regulate when and what personal information they will store in the Information System according to the user's needs and convenience.
- Enforcement of laws and regulations regarding privacy in Information Systems
The government must create and enforce regulations regarding information privacy that are adaptive at all times. With this, data leaks can be minimized because the law protects the privacy rights of Information System users. This also includes providing severe sanctions for ethical violators in the Information System to provide a deterrent to the perpetrators.
- Development of regulations regarding AI (Artificial Intelligence)
The development of AI can harm the intellectual rights and privacy of users. However, proper regulations have not been created for this. AI regulations were created to protect the privacy of users and parties who are references in AI. It should also set out the parties' agreement regarding how their data will be stored and managed. This is to ensure that there is no bias towards some parties and harm to some parties.
Discussion
The results of this research provide important insights into various privacy challenges in Information Systems (IS) management from a social and ethical perspective. These challenges show that the use of IS can raise several critical problems that need to be addressed by various stakeholders, including users, system designers, and policy makers, regarding the protection of users' personal information, especially with problems originating from lack of control, weak regulations, to non-transparent practices by IS designers.
User Concerns about Personal Information
Users tend to be concerned about how their personal information is used, especially when the privacy policy is unclear or too long and difficult to understand. This challenge is caused by users not knowing how to read and understand privacy policies, which are often presented in complex language and are not easily accessible.
- Lack of User Self-Control and Knowledge
Lack of user self-control in sharing personal information online. Ignorance about the risks of data dissemination, as well as minimal awareness of features such as cookies or access permissions, add to privacy challenges. Users are often unaware that their data can be tracked or exploited without explicit consent.
- Weak Information System Security
Frequent data leaks, even in popular applications, show that even if the privacy policy is read, weaknesses in the IS security architecture remain a major threat. This shows the important role of cyber security in protecting personal information.
- Incompatibility of Information Systems Ethics with Government Regulations
From a social and ethical perspective, the mismatch between technological developments, such as artificial intelligence (AI) and big data, and existing regulations adds another dimension to the challenge. Regulations that are unable to keep up with technological changes cause user privacy protection to become vulnerable.
- Non-Transparent Use of Data by SI Planners
Many applications utilize users' personal information for commercial purposes without their knowledge. This includes practices such as advertising based on user data that is not directly approved, or automatic linking of financial information that is concerning to users.
To overcome the challenges above, the solution proposed in this paper emphasizes education, improving IS design practices, and stronger regulatory enforcement. Some of the important solutions proposed are as follows:
- Privacy Education as a Human Right
Education about the importance of privacy needs to be improved to prevent users from sharing personal information carelessly. This education can help increase users' understanding of how they can protect themselves in the digital world, including understanding risks and privacy rights.
- Plain Language in Privacy Policy
Using simpler and clearer language in the privacy policy will make it easier for users to understand how their data is used. This not only increases transparency, but can also build trust between users and IS service providers.
- Data Control Features by User
Users need to be given more control over their data through features that allow them to save or delete personal information as needed. This will reduce the risk of unwanted or non-transparent data use.
- Strong Enforcement of Privacy Regulations
The government must strengthen regulations and enforce strict sanctions for privacy violations to protect individual rights. This includes regulatory adaptation to new technologies such as AI, which often involve the use of personal data without explicit consent.
- Regulatory Development Regarding AI
The emergence of AI adds a new dimension to challenges and privacy. The development of AI means that special regulations need to be applied to the technology to protect user privacy. Unregulated AI can pose major privacy risks, so strict regulation is needed to ensure that data collection and use is done ethically and legally.
Conclusion
This research makes a valuable contribution in identifying privacy challenges in information systems and proposes potential solutions from both social, ethical and regulatory viewpoints. Users, Information Systems designers and governments must work together to create a safer and fairer digital environment, where data privacy is respected and properly protected. Law enforcement, user education, and increased security are important steps in minimizing these challenges. However, the complexity of the issue means that further research and ongoing dialogue between all stakeholders is needed to develop an effective and ethical approach to privacy in the digital age.
References
- Sibuea AY and Panjaitan lF. Protecting the Privacy of Customer’s Personal in the Era of Cloud Computing. Turkish Online J Qualitative Inqu. 2020; 11: 741- 745.
- Bélanger F and Crossler RE. Privacy in the Digital Age: A Review of Information Privacy Research in Information. In Source MIS Quarterly. 2011; 35.
- Darmawan R, Gumiwa GT, Sjuchro DW and Atmanegara AW. Information Systems Audit Model Privacy and Confidentiality on Start up the Go Food Business. In Intelligent and Reliable Engineering Systems. CRC Press. 2021; 167-170.
- Meier Y, Schäwel J and Krämer NC. The shorter the better Effects of privacy policy length on online privacy decision-making. Media and Communication. 2020; 8: 291-301.
- Acequisti A, Brandimarte L and Loewenstein G. Privacy and Human Behavior in the Age of Information. Science. 2015; 347: 509-514.
- Bertino E. Introduction to data security and privacy. Data Sci Eng. 2016; 1; 125-126.
- Gunduz MZ and Das R. Cyber-security on smart grid: threats and potential solutions. Comput Netw. 2020; 169: 107094.
- Rannenberg K, Soares Barbosa L, Neuhold EJ, Kreps D and Malaka R. (n.d.) IFIP Advances in Information and Communication Technology 625 Editor-in-Chief.
- Sibuea AY and Panjaitan lF. Protecting the Privacy of Customer’s Personal in the Era of Cloud Computing. Turkish Online J Quali Inqu. 2020; 11: 741-745.
- Smith HJ, Dinev T and Xu H. (n.d.). An Interdisciplinary Review.
- Stahl BC and Wright D. Ethics and Privacy in AI and Big Data: Implementing Responsible Research and Innovation.
- Williamson SM and Prybutok V. Balancing Privacy and Progress: A Review of Privacy Challenges Systemic Oversight and Patient Perceptions in AI-Driven Healthcare. Appl Sci. 2024; 14: 675.
- Yusnanto T, Mustofa K, Mahmudi A, Wahyudiono S, Stmik I and Patria B. Jurnal TRANSFORMASI (Informasi & Pengembangan Iptek) (STMIK BINA PATRIA) Fenomena Keamanan Informasi Pasca Era Revolusi Industri 5.0. Jurnal TRANSFORMASI. 2021; 17: 24-35.