Policies and procedures as tools for ensuring data protection in rescue services: the case of Estonian Rescue Services Agency
Kate‐Riin Kont & Tormi Soekõrv
What the paper says
Purpose The purpose of this paper is to analyze the internal data security regulations of the Estonian Rescue Services Agency (hereinafter ERSA) and to explore and understand employees’ perceptions and interpretations of these guidelines mainly through qualitative analysis which supports the quantitative study. ERSA was selected due to its critical public role, extensive access to sensitive data and large number of general users. Understanding data protection within this context is essential, given the increasing prevalence of data-related threats. Design/methodology/approach To achieve the objective, this paper relies mainly on a qualitative methodology to achieve an in-depth understanding of human factors in data protection. Data were collected using a survey containing many open-ended questions designed to capture the experiences and sense-making of the employees. The analytical procedure follows the principles of thematic analysis and systematic coding, ensuring the transparency and credibility of the findings. Findings This study found that although the ERSA has valid rules for data protection, employee awareness is uneven. The documents are often unclear or overlapping, and while most employees value data security, their knowledge is generally modest. Training participation varies, indicating a need for clearer instructions and more consistent education. Practical implications This paper contributes to broader discussions on information security culture and compliance with the General Data Protection Regulation by offering a unique perspective on the awareness and behavior of employees of a vital critical service provider. The contribution lies in the analysis of a critical sector where data security breaches may have life-threatening consequences for public safety. Originality/value This research is novel in the Estonian context, as previous academic studies have not explored the perceptions of data protection regulations among employees of a vital service provider, nor analyzed the relationships between organizational policies and employee-described behaviors. Similarly, elsewhere in the world, this topic has been minimally studied.
Evidence weight
Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40
| F · citation impact | 0.50 × 0.4 = 0.20 |
| M · momentum | 0.50 × 0.15 = 0.07 |
| V · venue signal | 0.50 × 0.05 = 0.03 |
| R · text relevance † | 0.50 × 0.4 = 0.20 |
† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.