{"title":"Understanding challenges of GDPR implementation in business enterprises: a systematic literature review","authors":"Yelena Smirnova, Victoriano Travieso-Morales","doi":"10.1108/ijlma-08-2023-0170","DOIUrl":null,"url":null,"abstract":"<h3>Purpose</h3>\n<p>The general data protection regulation (GDPR) was designed to address privacy challenges posed by globalisation and rapid technological advancements; however, its implementation has also introduced new hurdles for companies. This study aims to analyse and synthesise the existing literature that focuses on challenges of GDPR implementation in business enterprises, while also outlining the directions for future research.</p><!--/ Abstract__block -->\n<h3>Design/methodology/approach</h3>\n<p>The methodology of this review follows the preferred reporting items for systematic reviews and meta-analysis guidelines. It uses an extensive search strategy across Scopus and Web of Science databases, rigorously applying inclusion and exclusion criteria, yielding a detailed analysis of 16 selected studies that concentrate on GDPR implementation challenges in business organisations.</p><!--/ Abstract__block -->\n<h3>Findings</h3>\n<p>The findings indicate a predominant use of conceptual study methodologies in prior research, often limited to specific countries and technology-driven sectors. There is also an inclination towards exploring GDPR challenges within small and medium enterprises, while larger enterprises remain comparatively unexplored. Additionally, further investigation is needed to understand the implications of emerging technologies on GDPR compliance.</p><!--/ Abstract__block -->\n<h3>Research limitations/implications</h3>\n<p>This study’s limitations include reliance of the search strategy on two databases, potential exclusion of relevant research, limited existing literature on GDPR implementation challenges in business context and possible influence of diverse methodologies and contexts of previous studies on generalisability of the findings.</p><!--/ Abstract__block -->\n<h3>Originality/value</h3>\n<p>The originality of this review lies in its exclusive focus on analysing GDPR implementation challenges within the business context, coupled with a fresh categorisation of these challenges into technical, legal, organisational, and regulatory dimensions.</p><!--/ Abstract__block -->","PeriodicalId":46125,"journal":{"name":"International Journal of Law and Management","volume":"22 1","pages":""},"PeriodicalIF":1.3000,"publicationDate":"2024-01-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Law and Management","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1108/ijlma-08-2023-0170","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"LAW","Score":null,"Total":0}
引用次数: 0
Abstract
Purpose
The general data protection regulation (GDPR) was designed to address privacy challenges posed by globalisation and rapid technological advancements; however, its implementation has also introduced new hurdles for companies. This study aims to analyse and synthesise the existing literature that focuses on challenges of GDPR implementation in business enterprises, while also outlining the directions for future research.
Design/methodology/approach
The methodology of this review follows the preferred reporting items for systematic reviews and meta-analysis guidelines. It uses an extensive search strategy across Scopus and Web of Science databases, rigorously applying inclusion and exclusion criteria, yielding a detailed analysis of 16 selected studies that concentrate on GDPR implementation challenges in business organisations.
Findings
The findings indicate a predominant use of conceptual study methodologies in prior research, often limited to specific countries and technology-driven sectors. There is also an inclination towards exploring GDPR challenges within small and medium enterprises, while larger enterprises remain comparatively unexplored. Additionally, further investigation is needed to understand the implications of emerging technologies on GDPR compliance.
Research limitations/implications
This study’s limitations include reliance of the search strategy on two databases, potential exclusion of relevant research, limited existing literature on GDPR implementation challenges in business context and possible influence of diverse methodologies and contexts of previous studies on generalisability of the findings.
Originality/value
The originality of this review lies in its exclusive focus on analysing GDPR implementation challenges within the business context, coupled with a fresh categorisation of these challenges into technical, legal, organisational, and regulatory dimensions.
期刊介绍:
The International Journal of Law and Management is a leading journal addressing all aspects of regulation and law as they impact on organisational development, operations and leadership. Organisations and their leaders operate in an increasingly complex world of emerging regulation across national and international boundaries. The International Journal of Law and Management seeks to acknowledge the dynamics of that environment and provide a platform for articles and contributions to stimulate scholarly debate in the development of law and practice. The International Journal of Law and Management seeks to present the latest research on policy, practice and theoretical perspectives and their impact on the development and leadership of organisations. Contributions of a multi-disciplinary nature are welcome. Coverage includes, but is not limited to: -Employment and industrial law- Corporate governance and social responsibility- Intellectual property- Corporate law and finance- Insolvency- Commercial law and consumer protection- Environmental law- Taxation- Competition law- Regulatory theory