Reframing Substantive Privacy Compliance as Dynamic Capabilities – An Integrated Conceptual Model

Authors

DOI:

https://doi.org/10.34190/eckm.27.2.4914

Keywords:

Privacy compliance, Dynamic Capabilities, Technology-Organization-Environment model, Institutional Theory

Abstract

Despite the widespread introduction of privacy protection laws globally, many organizations continue to treat privacy compliance as an administrative practice focusing on compulsory policies and documentations. However, many organizations have treated privacy protection compliance as a way to enhancing organizational dynamic capabilities from effectively using technology, people and processes required to implement privacy protection. Drawing on the Technology-Organization-Environment (TOE) model, Institutional Theory, and the Dynamic Capabilities View (DCV), the paper proposes that developing Substantive Privacy Compliance (SPC) through meeting regulatory, organizational, and technological requirements enables organizations enhance their dynamic capabilities. Theoretically, it fills the gap between the institutional legitimacy view and the dynamic capabilities lens, providing a comprehensive explanation of how external pressures can develop adaptive organizational capabilities. Practically, the model emphasizes the critical role of integrating privacy governance in both strategic and operational activities in enriching the firm’s resilience and sustainable competitiveness.

Downloads

Published

2026-08-25