Policies and procedures as tools for ensuring data protection in rescue services: the case of Estonian Rescue Services Agency

Kate‐Riin Kont & Tormi Soekõrv

Transforming Government: People, Process and Policy2026https://doi.org/10.1108/tg-10-2025-0329article
AJG 2ABDC B
Weight
0.50

What the paper says

Purpose The purpose of this paper is to analyze the internal data security regulations of the Estonian Rescue Services Agency (hereinafter ERSA) and to explore and understand employees’ perceptions and interpretations of these guidelines mainly through qualitative analysis which supports the quantitative study. ERSA was selected due to its critical public role, extensive access to sensitive data and large number of general users. Understanding data protection within this context is essential, given the increasing prevalence of data-related threats. Design/methodology/approach To achieve the objective, this paper relies mainly on a qualitative methodology to achieve an in-depth understanding of human factors in data protection. Data were collected using a survey containing many open-ended questions designed to capture the experiences and sense-making of the employees. The analytical procedure follows the principles of thematic analysis and systematic coding, ensuring the transparency and credibility of the findings. Findings This study found that although the ERSA has valid rules for data protection, employee awareness is uneven. The documents are often unclear or overlapping, and while most employees value data security, their knowledge is generally modest. Training participation varies, indicating a need for clearer instructions and more consistent education. Practical implications This paper contributes to broader discussions on information security culture and compliance with the General Data Protection Regulation by offering a unique perspective on the awareness and behavior of employees of a vital critical service provider. The contribution lies in the analysis of a critical sector where data security breaches may have life-threatening consequences for public safety. Originality/value This research is novel in the Estonian context, as previous academic studies have not explored the perceptions of data protection regulations among employees of a vital service provider, nor analyzed the relationships between organizational policies and employee-described behaviors. Similarly, elsewhere in the world, this topic has been minimally studied.

Open paper page →

Cite this paper

https://doi.org/https://doi.org/10.1108/tg-10-2025-0329

Or copy a formatted citation

@article{kate‐riin2026,
  title        = {{Policies and procedures as tools for ensuring data protection in rescue services: the case of Estonian Rescue Services Agency}},
  author       = {Kate‐Riin Kont & Tormi Soekõrv},
  journal      = {Transforming Government: People, Process and Policy},
  year         = {2026},
  doi          = {https://doi.org/https://doi.org/10.1108/tg-10-2025-0329},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Policies and procedures as tools for ensuring data protection in rescue services: the case of Estonian Rescue Services Agency

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.