Skip to content
Open access

BALANCING ACCESS AND PRIVACY: REGULATORY GAPS, AUTHENTICATION, AND DATA SECURITY IN DIGITAL PRESERVATION OF INSTITUTIONAL RECORDS

Aug 2026 · International Journal of Science and Research Archive · 0 citations

TL;DR

In resource-constrained institutional settings, privacy protection is being improvised by end users and administrators in the absence of formal governance, a pattern with implications for institutions well beyond the case examined here.

Abstract

Digital preservation is often framed as a technical archival problem, yet the governance choices surrounding it carry direct consequences for information security and data privacy. This study draws on qualitative case-study data from a Ghanaian educational institution to examine how the absence of enforced legal and regulatory frameworks for digitized records shapes user authentication practices, data security, and privacy outcomes in a live school management information system. Twenty-five stakeholders, including parents, teachers, facilitators, and administrators, were interviewed about their experiences with user access, authentication, and data handling. Findings show that authentication mechanisms, including unique login credentials, QR-code verification, and digital signatures, were valued by users primarily as privacy safeguards, and that stakeholders explicitly requested encryption and non-disclosure of data to third parties, despite the absence of a specific institutional data-protection policy referencing Ghana’s regulatory framework. The findings are discussed in relation to Ghana’s Data Protection Act, 2012, and the Public Records and Archives Administration Act, 1997, alongside the growing role of artificial-intelligence-assisted compliance monitoring and cloud security posture management. The study concludes that in resource-constrained institutional settings, privacy protection is being improvised by end users and administrators in the absence of formal governance, a pattern with implications for institutions well beyond the case examined here.

Read PDF

Similar papers

Aug 2026

Data Privacy and Personal Information Protection in the Era of Digital Governance: A Comparative Legal Analysis

The rapid expansion of digital governance has transformed the manner in which governments and private organizations collect, process, store, and share personal information. Digital technologies such as cloud computing, artificial intelligence, big data analytics, blockchain, and the Internet of Things have enhanced administrative efficiency, improved public service delivery, and promoted transparency. At the same time, these technological advancements have intensified concerns regarding data privacy, surveillance, unauthorized data processing, cybersecurity, and cross-border data transfers. Consequently, the protection of personal information has emerged as a significant legal and policy challenge across jurisdictions. This paper presents a comparative legal analysis of major data protection regimes, focusing on the European Union's General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act, 2023, the California Consumer Privacy Act (CCPA), and selected international legal frameworks. It examines the fundamental principles governing personal data protection, including lawfulness, transparency, accountability, purpose limitation, data minimization, and individual rights. The study further explores the challenges posed by emerging technologies, governmental surveillance, algorithmic decision-making, and international data flows within the broader framework of digital governance. By critically comparing legislative approaches and regulatory mechanisms, the paper identifies best practices and existing legal gaps. It concludes that effective data governance requires harmonized legal standards, stronger institutional oversight, technological safeguards, and international cooperation to ensure that innovation and digital transformation are balanced with the protection of individual privacy and fundamental human rights.

Research Author · 0 citations
Review Open access 2022

Information Security and Privacy in Digital Ecosystems: Technologies, Policies, and Future Research Directions

The study concludes that trustworthy digital participation depends on the integration of technical safeguards, enforceable rights, organisational culture, and transparent governance, and recommends embedding security and privacy by design, strengthening incident preparedness, improving workforce competence, enhancing regulatory cooperation, and adopting measurable accountability mechanisms.

Bisola Akeju, Shalom Alugwe, Ayokunle Olamide Ijagbemi · 0 citations
Jul 2026

Digital Identity Systems: Privacy, Access, and State Capacity Outcomes

The analysis demonstrates that effective digital identity governance requires balancing state interests with citizens’ privacy rights through strong regulatory frameworks, transparent data practices, inclusive design, digital literacy initiatives, and accountable oversight mechanisms.

Kabiga Chelule Kwemoi · 0 citations
Review Open access Sep 2026

Digital Governance and Constitutional Rights in India: Reconciling Administrative Efficiency with Privacy, Equality and Due Process

Abstract India's shift towards digitally mediated governance has reshaped the citizen-administrative state dynamics. Biometric identity framework (Aadhaar), faceless assessment in the income tax administration, direct benefit transfer system and the Digital Personal Data Protection Act, 2023 are expected to be efficient, leak-proof and targeted, but leave questions unanswered before the court. This article questions whether the digital governance ecosystem in India has sufficiently harmonized the efficiency of administration with the fundamental rights of privacy, equality of substantive rights, and procedural rights in Article 21, 14 and due process. The article uses the doctrinal approach to examine the jurisprudence of the Supreme Court of India on 'informational privacy' and 'proportionality', as well as the statutory framework of the Aadhaar Act, 2016, the Information Technology Act, 2000, and Digital Personal Data Protection Act, 2023; and the administrative practice of algorithmic and automated decision-making in welfare and taxation. It believes that the judiciary has created a functional test of proportionality for privacy interests, but this test continues to be under-respected when it comes to algorithmic exclusion and automated adjudication, where reasoned decision making and meaningful review are often lacking. The article then envisions a calibrated approach that combines proportionality review with a compulsory duty of explaining algorithms and a system of independent institutional oversight, ensuring that enhanced efficiency in government does not sacrifice constitutionally protected rights. Keywords: Right to privacy; Due Process; Digital Personal Data Protection Act; 2023; Keywords: digital governance; Aadhaar; algorithmic discrimination; administrative law

Tangutur Aparna · 0 citations
2026

Reader Privacy Under the Digital Personal Data Protection Act, 2023: Contextual Integrity and the Obligations of Indian Academic Libraries

The Digital Personal Data Protection Rules, 2025, notified in November 2025, brought India’s first comprehensive data protection statute into operation, with full compliance required by May 2027. Every academic library in India is a processor of digital personal data on a substantial scale, and most are constituent units of institutions that will be data fiduciaries under the Act, yet the professional literature contains almost no analysis of what the statute requires of them. This paper provides that analysis. It applies Nissenbaum’s theory of contextual integrity, together with the proportionality standard established in Puttaswamy, to argue that library records are not simply personal data among other categories but records of intellectual inquiry, whose disclosure produces a chilling effect that a consent-based compliance regime does not by itself prevent. The method is documentary policy and legal-instrument analysis, conducted through a transparent selection protocol yielding a corpus of 81 documents. The paper develops a systematic inventory of the personal data processed by a typical Indian academic library across four categories, maps each category against the requirements of the Act, and analyses four hard cases: users under the age of eighteen, where section 9 forbids the tracking and monitoring of behaviour despite consent; federated authentication under the One Nation One Subscription scheme, which hands over institutional identity to commercial publishers; vendor and publisher analytics, where the library asserts it has no control over data it has caused to be created; and closed-circuit television and biometric attendance, where a proportionality analysis is necessary and is not often conducted. It is argued that the Act protects library users less than the professional standards of IFLA and the American Library Association, that its amendment of the Right to Information Act weakens rather than strengthens accountability, and that compliance alone will not discharge the profession’s obligation. Twelve recommendations follow.

Dheeraj, Sapna Sharma · 0 citations
Open access Aug 2026

PRIVACY AS A PUBLIC GOOD: A PHILOSOPHICAL EXAMINATION OF DATA GOVERNANCE PRACTICES AMONG INDUSTRIAL SECURITY AGENCIES IN REGION IV-A, PHILIPPINES

Privacy has increasingly emerged as a public good that extends beyond individual rights to encompass organizational accountability, public trust, and ethical governance. Within industrial security agencies, the growing reliance on personal data in security operations necessitates robust data governance practices that protect individuals while ensuring operational effectiveness. This study explored the lived experiences of industrial security personnel in implementing data governance practices, examining how privacy is understood and practiced as a public good among industrial security agencies in Region IV-A, Philippines. The study employed a qualitative phenomenological research design to capture the meanings and experiences of those directly involved in data governance implementation. Twenty-one informants, purposively selected from industrial security agencies in Region IV-A, participated in in-depth interviews. Data were analyzed using Braun and Clarke's thematic analysis to identify recurring patterns and essential themes that characterized participants' experiences. The findings revealed that data privacy governance has become an increasingly institutionalized component of daily security operations, with confidentiality, controlled access, proper records management, monitoring, and responsible information handling embedded in routine organizational practices. Informants associated effective privacy implementation with professionalism, accountability, ethical responsibility, and the preservation of client trust. Training programs, supervisory support, and organizational culture were identified as key mechanisms reinforcing privacy compliance. However, the study likewise uncovered persistent implementation challenges, including inconsistencies in policy application, varying levels of personnel awareness and competence, technological vulnerabilities, operational pressures, resource limitations, and the need to balance efficient security operations with privacy protection. Participants emphasized that effective data governance requires not only legal compliance but also sustained leadership commitment, continuous capacity building, adequate technological safeguards, systematic monitoring, and an organizational culture that recognizes privacy as a collective responsibility. Drawing from these findings, the study proposed a comprehensive Data Privacy Governance Policy designed specifically for industrial security agencies, which establishes standardized procedures for the lawful collection, processing, storage, access, disclosure, retention, and disposal of personal data while strengthening organizational accountability, privacy governance structures, training programs, monitoring mechanisms, and incident response protocols in accordance with the Data Privacy Act of 2012.

Modesto T. Claur · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.