Does personal data protection matter for ISO 9001 certification and firm performance?

被引:3
|
作者
Siougle, Efrosini [1 ,2 ]
Dimelis, Sophia [1 ,3 ]
Malevris, Nikolaos [1 ]
机构
[1] Athens Univ Econ & Business, Dept Informat, Athens, Greece
[2] Hellenic Data Protect Author, Athens, Greece
[3] Univ Econ, Fac Natl Econ, Dept Econ, Bratislava, Slovakia
关键词
ISO; 9001; certification; Firm performance; GDPR; Personal data security; Structural equation modeling; Difference-in-Differences; K00; L15; L25; STRUCTURAL EQUATION MODELS; ISO-9000; CERTIFICATION; BIG DATA; IMPACT; STANDARDS; SCALE; RELIABILITY; ANALYTICS; PRIVACY; SYSTEMS;
D O I
10.1108/IJPPM-07-2022-0345
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
PurposeThis study explores the link between ISO 9001 certification, personal data protection and firm performance using financial balance sheet and survey data. The security aspect of data protection is analyzed based on the major requirements of the General Data Protection Regulation and mapped to the relevant controls of the ISO/IEC 27001/27002 standards.Design/methodology/approachThe research analysis is based on 96 ISO 9001-certified and non-certified publicly traded manufacturing and service firms that responded to a structured questionnaire. The authors develop and empirically test their theoretical model using the structural equation modeling technique and follow a difference-in-differences econometric modeling approach to estimate financial performance differences between certified and non-certified firms accounting for the level of data protection.FindingsThe estimates indicate three core dimensions in the areas of "policies, procedures and responsibilities," "access control management" and "risk-reduction techniques" as desirable components in establishing the concept of data security. The estimates also suggest that the data protection level has significantly impacted the performance of certified firms relative to the non-certified. Controlling for the effect of industry-level factors reveals a positive relationship between data security and high-technological intensity.Practical implicationsThe results imply that improving the level of compliance to data protection enhances the link between certification and firm performance.Originality/valueThis study fills a gap in the literature by empirically testing the influence of data protection on the relationship between quality certification and firm performance.
引用
收藏
页码:749 / 774
页数:26
相关论文
共 50 条
  • [21] Impact of ISO 9000 certification on firm performance: evidence from Brazil
    Starke, Francisco
    Eunni, Rangamohan V.
    Fouto, Nuno Manoel Martins Dias
    de Angelo, Claudio Felisoni
    MANAGEMENT RESEARCH REVIEW, 2012, 35 (10): : 974 - 997
  • [22] Ownership concentration and firm performance in Indian firms: does investor protection quality matter?
    Altaf, Nufazil
    Shah, Farooq Ahamad
    JOURNAL OF INDIAN BUSINESS RESEARCH, 2018, 10 (01) : 33 - 52
  • [23] Busy directors and firm performance: Does firm location matter?
    James, Hui Liang
    Wang, Hongxia
    Xie, Yamin
    NORTH AMERICAN JOURNAL OF ECONOMICS AND FINANCE, 2018, 45 : 1 - 37
  • [24] Patenting Activities and Firm Performance: Does Firm Size Matter?
    Andries, Petra
    Faems, Dries
    JOURNAL OF PRODUCT INNOVATION MANAGEMENT, 2013, 30 (06) : 1089 - 1098
  • [25] Performance Evaluation of ISO9001 Certification Based on Non-structural Fuzzy Decision
    Yun, Xiaohong
    INTERNATIONAL CONFERENCE ON ENGINEERING AND BUSINESS MANAGEMENT (EBM2011), VOLS 1-6, 2011, : 86 - 89
  • [26] ISO-9000 Certification and Ownership Structure: Effects upon Firm Performance
    Lafuente, Esteban
    Bayo-Moriones, Alberto
    Garcia-Cestona, Miguel
    BRITISH JOURNAL OF MANAGEMENT, 2010, 21 (03) : 649 - 665
  • [27] ISO certification, financial constraints, and firm performance in Latin American and Caribbean countries
    Ullah, Barkat
    Wei, Zuobao
    Xie, Feixue
    GLOBAL FINANCE JOURNAL, 2014, 25 (03) : 203 - 228
  • [28] THE USE OF CERTIFICATION MECHANISMS AS AN EFFICIENT GUARANTEE OF PERSONAL DATA PROTECTION
    Viguri Cordero, Jorge Agustin
    REVISTA CATALANA DE DRET PUBLIC, 2021, (62): : 160 - 176
  • [29] Does ISO 9000 series certification matter for the financial performance of ports? Some preliminary findings from Europe
    Pantouvakis, Angelos
    Dimas, Athanassios
    MARITIME POLICY & MANAGEMENT, 2010, 37 (05) : 505 - 522
  • [30] Product innovation and firm performance: does the technology capacity of a firm matter?
    Khuong, Nguyen Vinh
    Ngan, Pham Thi Kim
    Phuong, Tran Thi Kieu
    Nguyen, Quynh
    Son, Pham Hoang
    Khanh, Nguyen Tuan
    GLOBAL KNOWLEDGE MEMORY AND COMMUNICATION, 2025,