Despite scholarly discussions of online privacy concern (OPC) in the digital information landscape, a notable trend is that users exhibit various non-statical privacy concerns and increasingly sophisticated coping behaviors during human–computer interactions. Therefore, this paper aims to explicitly examine this phenomenon and the relationships between OPC and coping strategies that users engage with. A cohesive review is developed to elucidate how OPC predicts users’ coping behavior.
This review leveraged a systematic literature review to synthesize 145 OPC research papers in information systems and proposed a nomological and analytical framework for OPC.
The study delineated a nomological network with antecedents, mechanisms and interventions in the relationship between OPC and user coping behavior. Prior studies had underexplored the non-statical nature of OPC and the user privacy status quo, overlooking that the coping responses could switch over time.
The paper integrates a literature review and framework approach to help comprehend OPC and users’ transitory coping behavior. A continuum of privacy status based on a control-and-threat equilibrium framework was proposed, consisting of four phases: adoption, continuance, modification and avoidance. By doing so, this study outlines four OPC research directions for future studies.
1. Introduction
Digitalization, automation, robotization and futuristic internet advancements (e.g. Web 4.0 and Metaverse) have heightened apprehensions among individuals who extensively disclose and transmit information online (Naz and Kashif, 2025; Song et al., 2025a). Digital systems provide a means of sharing information, stimulating knowledge exchange, learning and collaboration (Shatila et al., 2025). However, privacy has been a research focus for decades (Gómez-Hurtado et al., 2024; Liu et al., 2023; Shoukat et al., 2025), yielding substantial knowledge; however, one thing that perplexes scholars is how users’ privacy concerns could be used to predict their behavior (Balapour et al., 2020). Researchers have grappled with a notable incongruity between users’ stated privacy mental states (i.e. attitudes, concerns, desires) and actual responsive behavior. This discrepancy, compounded by the dynamic nature of privacy perceptions and behaviors that evolve, has produced mixed results, hindering firms’ understanding of users’ privacy management spanning from inaction to proactive actions (Acquisti et al., 2020; Song et al., 2025b). While current research has predominantly relied on static, binary frameworks that categorize user coping behavior as either immediate acceptance or rejection, this approach may insufficiently capture the complex nature of human-computer interactions, where users demonstrate dynamic coping strategies. Therefore, a continuum framework that encapsulates the temporal evolution of user coping responses to OPC is called for.
Online privacy concerns (OPC), which reflect users’ awareness and desire for privacy in virtual spaces (Hong and Thong, 2013), encompass individuals’ dispositional beliefs about the loss of control over personal information (Westin, 2003). Corresponding to different levels of privacy concern, user coping behaviors have been examined and traditionally categorized as either acceptance or rejection (Choi et al., 2018). However, this simplification has limited the understanding of the OPC outcomes. The dynamic nature of privacy perceptions has been insufficiently addressed. To date, no systematic review has consolidated the framework linking OPC and coping behaviors and a change-oriented approach to these responses is needed.
This study aims to establish a theoretically grounded and empirically informed framework that enables researchers and practitioners to understand user coping behaviors throughout the consumption experience, from intention formation to post-purchase. We conducted a systematic literature review (SLR) to identify the nomological network and constructs on OPC and outcome variables. Moreover, we formulated a continuum of user privacy status quo that hinges on the balance between their perceived control and perceived threat, highlighting corresponding coping strategies (adoption, continuance, modification and avoidance). Our proposed framework could advance existing literature by incorporating temporal evolution, psychological factors and the dynamic equilibrium of privacy-related decision-making. We based the research on three main points.
First, despite rapid evolution in OPC research (e.g. Hong and Thong, 2013), frameworks elucidating the antecedents, consequences and paradoxical effects of OPCs remain rare. Our research aims to supplement the literature by synthesizing the newest variables and theories in OPC research.
Second, moving beyond the binary view of user coping responses (avoidant or adoptive), we consider a transitory perspective that accounts for the balance between control and threat. When perceiving a threat to their privacy, individuals may not immediately avoid the technology/service but adopt “continuance” or “modification” behaviors.
Third, the present study explores a possible non-linear effect that OPC has on user coping behavior. This indicates the existence of a threshold and bias in privacy perception, which may delay coping responses, desensitize users to privacy concerns and shift their coping behavior.
Specifically, the following research questions were raised. “What are the theories/frameworks/models predominantly adopted in recent studies that relate users’ privacy concerns to their coping strategies?” (RQ1). “What is the nomological network informing the association between OPC and user coping responses, such as proposed antecedents, mechanisms, and interventions?” (RQ2). “How can user coping strategies be better understood dynamically?” (RQ3). “What future research agenda can be developed based on our research findings?” (RQ4).
2. Methodology
2.1 Protocol
SLR is an appropriate tool for systematically assessing and evaluating a given body of literature and comprehensively synthesizing all relevant studies that meet specific eligibility criteria according to predetermined research questions (Siddaway et al., 2019). This study adopted the preferred reporting items for systematic reviews and meta-analyses (PRISMA) guidelines, which comprise four core steps: identification, screening, eligibility and inclusion (Hollebeek et al., 2023; Wang and Liu, 2023). Figure 1 shows the results from the process under the PRISMA framework.
2.1.1 Identification.
Data for the SLR were gathered from Web of Science and Science Direct, known for comprehensive coverage in information systems, computer science, business and management (Liu, 2021; Wang et al., 2023). Following the structure similar to Hernández-Tamurejo et al. (2025), this study first identified key research terms and then conducted the relevant searches. The following keywords were utilized to search: “online privacy concern”, “information privacy concern”, “privacy and coping”, “user privacy concern” and “coping behavior”. Keywords were combined using “OR” operators across titles, abstracts and keywords. To include the most current literature, we considered studies published between 2018 and 2023. Moreover, we specified the article type (research paper), language (English) and field of studies (information systems, computer science, business, management and social science). A total of 992 (Web of Science = 615, ScienceDirect = 377) results were returned.
2.1.2 Screening.
The screening process consisted of source quality control and duplication check (Kitchenham and Brereton, 2013). To ensure a high-quality data source, we included 278 articles that ranked 2nd or higher in the Association of Business Schools (ABS) rankings (Mwangi et al., 2024). Further, duplicate entries were systematically identified by manual cross-checks among co-authors, resulting in 260 papers proceeding to the eligibility stage.
2.1.3 Eligibility.
Eligible articles should focus on users’ online privacy concerns and their coping behaviors. In this step, 115 articles were excluded for various reasons, including 23 pure technical articles (e.g. modeling, algorithm), 19 mathematical computational articles, 56 papers on irrelevant topics (e.g. physical private spaces) and 17 papers with non-user perspectives (e.g. government).
2.1.4 Inclusion.
Final inclusion ensured papers meet all the above criteria, which clearly hypothesized privacy concern as an important component and the coping behavior/strategy as an outcome variable. With full text retrieved, a set of 145 articles was included for reviewing and answering the research questions.
3. Synthesis of studies
3.1 Employed methodologies
The overwhelming majority of methodologies used in OPC research are quantitative, as evident by the use of SEM, PLS-SEM and experiment-based analytical approaches, except for 5 qualitative studies involving semi-structured interviews (e.g. Cram et al., 2021), laddering interviews (e.g. Jung and Park, 2018) and focus groups (e.g. Lolich et al., 2019) and 16 mixed-methods studies (e.g. Agnihotri and Bhattacharya, 2023; Cheng et al., 2021; Lin and Armstrong, 2019). Particularly noteworthy is the longitudinal perspective that some studies have contributed, which validates that OPC and user responses change over time depending on adoption stages (Koohikamali et al., 2019) and launch time (Fox et al., 2021).
3.2 Major theories/models/frameworks
Recent research focusing on OPC and user coping behaviors has incorporated multiple facets of social psychology and individual attributes, extensively adopting Privacy Calculus Theory (PCT), Protection Motivation Theory (PMT) and the phenomenon/viewpoint of “privacy paradox” (Table 1). PCT explains that people cognitively evaluate the consequences of their privacy decision-making by weighing potential costs and benefits (Dinev and Hart, 2006). The level of privacy concern influences users’ attitudinal and behavioral responses to privacy protection. PMT suggests that individuals respond to threat communications through threat appraisal and coping appraisal, which has been widely applied to comprehend and predict motivations for online security behavior (Ogbanufe, 2023). Unlike PCT, which focuses on users’ processing of accurate information and taking proactive measures, PMT is more prevention-focused and explains how users are engaged in privacy-protective behaviors. In addition, the privacy paradox highlights incongruity in user behavior despite expressing privacy concerns, often failing to take protective actions in giving out data for immediate gratification and compensation (Adjerid et al., 2018).
Indeed, a multitude of IT theories have been utilized to address OPC, where the Technology acceptance model (TAM), theory of reasoned action (TRA) and diffusion of innovations theory (DOI) were comparatively more extensively applied. TAM highlights the effect of factors, such as perceived ease of use and usefulness on user attitudes, toward technology adoption (Davis et al., 1992). TRA predicts voluntary behavior, indicating that attitude and subjective norms shape one’s behavioral intention, which precedes actual behavior (Ajzen and Fishbein, 1973). DOI offers insights into the stages of technology adoption and identifies five influential predictors (relative advantage, compatibility, complexity, observability and trialability) (Rogers et al., 2014). Observing a rather similar distribution of IT theories applied to OPC, no single theory stood out as notably exceptional.
3.3 Nomological network informing the connection between online privacy concern and user-coping strategies
Considerable research has explored the antecedents, mechanisms, interventions and outcome variables that explain the relationship between OPC and user coping strategies, as illustrated in Figure 2. Further, Appendix summarizes selected papers to provide a panoramic overview and details about the theories, research context and major findings.
3.3.1 Antecedents.
The antecedents of OPC fall into three main clusters: technology-, user- and context-specific factors. The first cluster emphasizes hard-core elements and interface/system design. Researchers have identified major scenarios in which OPC may manifest, including service permission (Degirmenci, 2020), information disclosure requests (Cheng et al., 2021), massive data collection and management (Hernández-Tamurejo et al., 2025) and anthropomorphism of applications (Agnihotri and Bhattacharya, 2023). Barriers within human–machine interactions that evoke privacy concerns include complexity, intrusiveness and transparency (Suen, 2018; Wu et al., 2020).
The second cluster comprises user factors, including subjective beliefs, cognition and emotion. OPC may be evoked by perceptions (e.g. perceived threat, perceived assurance, perceived justice and vulnerability) about a certain technology and IT-intervened environments, prior experience or emotional stimuli such as computer anxiety (Degirmenci, 2020) and embarrassment (Zhu and Kanjanamekanant, 2021). Users engage in appraisal processes and have a basic need for privacy, which stems from their personal motivation (Crossler and Bélanger, 2019), privacy disposition (Ioannou et al., 2020) and territorial feelings (Lin and Armstrong, 2019). Similar to the social exchange perspective, OPC was frequently identified as an outcome of risk-benefit evaluation (Shaw and Sergueeva, 2019), information ownership (Zhu and Kanjanamekanant, 2021) and expectations (Xiong and Zuo, 2023) in a privacy setting.
The third cluster pertains to contextual cues from the privacy environment. Online users can read privacy-related declarations, third-party certifications and other informational signals to form impressions about a context. Moreover, OPC is on the premise of organizational responses (Ou et al., 2022) or intervention strategies concerning particular privacy issues, such as security breach (Ou et al., 2022), ubiquity (Sandhu et al., 2023), or information asymmetry (Al-Natour et al., 2020).
3.3.2 Mechanisms.
Drawing from our review, the mechanisms linking OPC to coping behaviors primarily comprise cognitive and affective routes. Individuals engage in self-evaluation and external evaluation as a cognitive process when faced with privacy issues. The self-evaluation factors include self-efficacy (Ogbanufe, 2023), coping efficacy (Kim and Kim, 2018) and technology self-efficacy (Crossler and Bélanger, 2019), reflecting users’ capability to navigate situations wherein their information privacy is threatened. When evaluating external forces, researchers (e.g. Choi et al., 2018; Cheng et al., 2021) used the appraisal frameworks (e.g. cost-benefit, benefit-utility, risk-gain) to justify the connection between OPC and user coping behaviors. In addition, OPC may lead to users’ empowerment (Bandara et al., 2021) and the adoption of different angles for perceiving the source of information privacy threats. From an affective perspective, OPC can lead to user satisfaction, psychological comfort, trust and distrust, subsequently affecting coping responses. Additionally, Tseng et al. (2022) revealed that users actively seek emotional and informational support to address privacy risks.
3.3.3 Interventions.
This review categorized interventions that alter the effects and contexts of OPC into three groups. The first group considers human characteristics, such as users’ knowledge, awareness, dispositional privacy concern (Choi et al., 2018), reliance on the Internet (Park and Shin, 2020) and social identity (Farivar et al., 2018). For example, through self-efficacy enhancement and self-image congruency, Cichy et al. (2021) introduced an incentive design to compensate for users’ data sharing. Furthermore, the second group comprises pronounced variables that arise during human–technology interactions. These variables specify user status in terms of their position in the technology adoption curve (Ketelaar and Van Balen, 2018), psychological distance (Bandara et al., 2021), inertia or sensitivities (Wagner et al., 2021), the strength of their relationship with the service provider (Hayes et al., 2021) and their access to feedback and options for addressing privacy concerns (Liu et al., 2022). Finally, the third group concentrates on the IT environment, with a focus on data (e.g. data collection, data type and transparency) (Suen, 2018), IT interfaces (e.g. technicality and personification) (Sandhu et al., 2023; Zhu and Kanjanamekanant, 2021) and functional attributes (e.g. disruption, contextual manipulation and information sensitivity) (Balapour et al., 2020; Miltgen and Smith, 2019). For example, ubiquity is a functional indicator in mobile commerce and applications, comprising the sub-dimensions of time-saving, spatial flexibility, portability, immediacy and continuity (Sandhu et al., 2023).
3.3.4 Outcome variables.
OPC, identified as a source of stress and disturbance in user–technology interactions, has been explained by coping theory to understand how individuals implement cognitive appraisal and behavioral coping to deal with it (Folkman and Lazarus, 1985). Drawing from Liang et al. (2019), who investigated how users cope with IT security threats, the outcome variables in our analysis also include emotion- and problem-focused user coping responses through which users regain controllability and emotional stability when confronted with privacy threats. Furthermore, we identified temporality-focused responses devoid of clear emotional orientations.
The emotion-focused variables represent users’ emotional appraisal from positive (e.g. acceptance, engagement and loyalty) to negative (e.g. avoidance, resistance and reactance). Different from a distinct emotion, fatigue has been considered an intriguing and complex emotional response (e.g. Dhir et al., 2019). Meanwhile, users concerned with information privacy exhibited different motivational orientations, such as protection (Mousavi et al., 2020) and rejection (Strycharz et al., 2021).
Problem-solving variables suggest that users may adopt proactive and passive responses. When faced with information disclosure/data collection requests, users may proactively disclose correct information, withhold information, or disclose false information (Miltgen and Smith, 2019); disable relevant settings to restrict tracking (Ketelaar and Van Balen, 2018); and control the level of access to and interaction within virtual territories (Lin and Armstrong, 2019). Conversely, some users may take no action, representing a passive response in either agreement or disagreement, which has been termed an inaction strategy (Choi et al., 2018). Fullwood et al. (2019) supplemented that lurking is not merely bystander behavior but can represent a transitional state depending on the life circumstances experienced.
Responses focused on temporality are categorized as either immediacy-based or future-based. Immediacy-based responses typically address users’ current needs and actions, encompassing behaviors such as adoption (Fox and Connolly, 2018), sharing, storage (Alsmadi and Prybutok, 2018) and purchasing (Zeng et al., 2020). Future-based strategies reflect a longer-term perspective, focusing on sustained engagement and continuity through re-purchase (Demmers et al., 2018) or re-transaction intention (Ou et al., 2022).
4. Predictive framework of user coping strategies
4.1 User coping behavior – from dichotomy to continuum
Prior researchers have predominantly associated OPC with either adoption-based responses (e.g. acceptance, purchase and usage) or avoidance-based responses (e.g. discontinuance, termination and rejection), assuming that users exhibit timely and assured coping to a privacy issue, which corresponds to the viewpoint of dichotomy. Acceptance is typically the opposite of rejection (Choi et al., 2018). The dichotomous patterns of user coping responses could be considered for simplicity (Bhattacherjee et al., 2018). However, users may simultaneously hold positive and negative responses. As individual–technology interactions deepen with the changing dynamics of privacy status during the different stages of technology/service adoption (i.e. pre-adoption, adoption and post-adoption), the actual evaluation performed and coping mechanisms adopted by users might be more complex. Emerging research has observed the coexistence of resistance and adoption of technological innovations (Laukkanen and Kiviniemi, 2010) and the non-linear patterns of protective responses to varying intensities of personal data concerns (Park, 2022). For instance, a study on voice-based digital assistants demonstrated that higher perceived privacy risks did not inherently inhibit technology adoption; rather, they interacted with trust to influence the final result (Vimalkumar et al., 2021). A few studies have revisited this coping concept and advocated for a continuum perspective (e.g. Turel, 2015), indicating that continuance and discontinuous usages are not opposite extremes on the same continuum. Fullwood et al. (2019) examined lurking as existing on a continuum rather than as a dichotomous variable in online communities. Ketelaar and Van Balen (2018) revealed that users’ position on the adoption curve moderates their privacy concerns about data tracking. Fox et al. (2021) conducted a longitudinal study and found that users’ coping responses depended on their prior adoption experience.
Concerning how OPC leads to varying coping responses, significant attention has been directed towards the privacy calculus, during which individuals engage in a trade-off between the cost of providing personal information and the benefit of information disclosure (Culnan and Bies, 2003). However, the framework does not account for the fact that privacy concerns develop over time through the intricate interplay between an individual and the environment, thereby underestimating how coping responses change in tandem with users’ privacy status (Bejar et al., 2023).
A continuum view of coping responses is essential for understanding how privacy concerns shape human–technology interactions and for developing effective post-hoc strategies from both individual and business perspectives. For example, users’ tendency to develop heightened privacy concerns and frustration could be alleviated and altered if effective resolutions are implemented before users move to the aversion and avoidance stage concerning a business.
To make the privacy status interpretative, this paper identified control and threat, built upon PMT (Rogers and Prentice-Dunn, 1997) and coping theory (Folkman and Lazarus, 1985) for controlling risks and assessing threats. Perceived control refers to individuals’ sense of competence, superiority and mastery over their surroundings, such as the ability to manage personal information and privacy risks in human–computer interactions (Folkman and Lazarus, 1985; Song et al., 2025a). Perceived threat encompasses one’s subjective appraisal of potential harm or loss associated with technology adoption and information disclosure (Folkman and Lazarus, 1985). Individuals possess both the need for control and the inclination to appraise threats. This combination fuels their motivation to respond to the privacy situations, whether to change or maintain the status quo, through actions that range from doing little to concrete efforts (e.g. Dietvorst et al., 2018; Mousavi et al., 2020). Thus, the privacy status quo is determined by the equilibrium between one’s perceived control and one’s perceived threat during user–technology interactions. The status is in a continuum and shifting, which helps predict user coping behavior.
4.2 Proposition of control–threat equilibrium
Based on the findings of SLR, a nuanced understanding of how control–threat equilibrium (CTE) could be used to predict user privacy-related coping behaviors is achieved (see Table 2 for summarization). Users may exhibit one of the four phases of CTE (Adoption, Continuance, Modification and Avoidance) that incorporate different thoughts, feelings and behavioral intents. From a longitudinal perspective, users differed in coping responses corresponding to their privacy status quo. Once the privacy status fails to reach their expectation, they might not immediately terminate the service/application but undergo a process of sustaining or changing, termed Continuance and Modification. This dynamic mirrors the dual-process model proposed by PMT (Rogers and Prentice-Dunn, 1997), where threat appraisal and coping appraisal determine the motivation to engage in protective behavior. For instance, users normally expect immediate gratification (i.e. access to service, free trial, monetary compensation), thus giving quick responses that discount privacy concerns for short-term benefits (Wottrich et al., 2018). Adoption-based coping frequently occurs when introducing a new technology/application/privacy intervention (e.g. Vimalkumar et al., 2021).
Continuance is a maintenance-based coping phase where users sustain their technology engagement despite experiencing privacy concerns because the control-threat equilibrium is still acceptable. As users’ OPC may be temporary, the predictive effect would be limited if it is not fully evoked, akin to a sleeper effect that may significantly amplify over time rather than immediately following a privacy exposure (Lariscy and Tinkham, 1999). Considering such a dynamic, Continuance-based coping occurs when users accumulate experience in privacy and adoption for a period. Users are exposed to privacy stimuli and gradually understand potential threats and how controllable the context is. A prerequisite for such a type of CTE is the continuous motivation of users to maintain their status after adoption, incorporating facilitators such as risk-benefit evaluation (e.g. Sandhu et al., 2023; Wagner et al., 2021). Despite privacy risks, the decision to continue adoption suggests a coping appraisal where the perceived benefits significantly outweigh the perceived risks. In this context, users may inadvertently train algorithms through prolonged engagement driven by dopamine with artificial intelligence (AI) systems that enable surveillance and data collection (Saura et al., 2024). This creates a paradox that, despite escalating privacy threats, users may remain in the Continuance phase, as the immediate gratification obscures the long-term privacy costs.
Moreover, Modification occurs when the control-threat equilibrium is disrupted but deemed to be properly managed. Users are anticipated to actively adjust their online footprints and interactions to restore privacy control. As users perceive increased privacy threats, they might engage in problem-focused coping (e.g. adjust privacy settings) or emotion-focused coping (e.g. manage emotional distress). This phase reflects a strategic shift where users hope to change the situation by restoring control through using customized privacy settings (Mousavi et al., 2020), minimizing engagement (Jozani et al., 2020) and preventing further risks by taking measures such as falsifying personal data (Miltgen and Smith, 2019) and using stronger passwords (Mamonov and Benbunan-Fich, 2018), instead of terminating the service/application. Ultimately, the escalation of perceived threats and diminishing perceived control or efficacy of previous coping strategies may lead users to engage in Avoidance-based coping. Users deliberately circumvent or abandon exposure to privacy-threatening content (Strycharz et al., 2021).
4.3 Application of control–threat equilibrium in predicting user coping responses
To generate a more dynamic view of CTE, as Figure 3 illustrates, Adoption and Continuance represent a control–threat surplus involving two end-situations: maximum surplus (i.e. users are unaware of privacy threats or perceive full controllability) and minimum surplus (i.e. privacy threat is nearing the marginal controllability of a given user). Furthermore, Modification and Avoidance represent a control–threat deficit involving two end-situations: minimum deficit (i.e. users perceive little loss of controllability but want to get back to the surplus status) and maximum deficit (i.e. users feel an abject lack of control because of ubiquitous privacy threats).
Despite the abundant research on dichotomous coping (Adoption and Avoidance), an intriguing concept emerges once users reach the equilibrium’s peak/threshold. At this juncture, they may switch to more transitory coping behaviors to Continuance, should they find the equilibrium still acceptable, or to Modification if the equilibrium is deemed unacceptable and, therefore, attempt to return it to acceptable levels. Figure 4 illustrates the U-shaped effect on user privacy coping behavior based on CTE.
Regarding Continuance, once users have downloaded, subscribed to, or adopted smart applications for which they have been charged time, money, or other inputs, they will be conservative and reluctant to relinquish their ownership and prior investments. Psychological perspectives such as sunk cost (Arkes and Blumer, 1985) and the endowment effect (Nunes and Dreze, 2006) explain users’ greater tendency to continue an endeavor after money, effort, or time has been invested, with them ascribing more value to things if they own them. Users with feelings of ownership over their data may seek to retain possession due to fear of loss (Cichy et al., 2021), supporting the idea of Continuance. Drawing from this, research heavily reliant on models that repeatedly measure variables such as satisfaction and perceived usefulness obtained from TAM (Davis et al., 1992) or the IT continuance model (Bhattacherjee, 2001) would be constrained in providing psychological insights. Taking culture for example, in societies with a conformist culture, users may continue to use risky applications/services, owing to the overwhelming trend and the group’s collective behavior or simply because they are accustomed to it or fatigued (Choi et al., 2018).
A few distinguished facts, including status quo bias (Samuelson and Zeckhauser, 1988) and privacy fatigue (Choi et al., 2018), also highlight users’ bias and subjectivity in Continuance responses. For example, although intensified privacy concerns push users to switch, inertia, as a critical component of status quo bias, will drive users to stay with incumbent applications (Wang et al., 2019). Privacy fatigue, a key component of cynicism, is closely relevant to user pre-adoption and privacy experience and primarily stems from a failure to manage privacy (Choi et al., 2018). Users with this psychological state might find themselves simultaneously enjoying the benefits and perceiving futility when considering privacy matters. As a result, they might invest less effort into privacy decision-making or do nothing to change the status.
However, the Continuance stage could be altered to the Modification stage when user privacy concerns are high. Even if consumers are comfortable with the status quo, awareness of privacy protection can persuade them to switch to another application/platform (Raddatz et al., 2023). Concerning Modification, users generally hold two forms of perceptions: restoring self-control by protection behavior (e.g. applying privacy-protecting heuristic and increasing IT- and privacy-related knowledge) and reducing threats from others through subversion behaviors (e.g. withholding information and falsifying personal data). As explained by cognitive dissonance theory (Festinger, 1962), users perceiving two psychologically dissonant states attempt to alleviate the mental tension by changing perceptions.
In our proposition, users who experience irreconcilable threat–control tensions are expected to alter their status quo of privacy to an acceptable level. Pirkkalainen et al. (2019) highlighted coping strategies that build resilience against IT-induced stress, including positive reinterpretation as a form of meaning-making (e.g. seeing technology in a more positive light) and IT control (e.g. increasing well-being by reducing tensions and fatigue) as a form of mastery. Dietvorst et al. (2018) indicated that even with imperfect algorithms, individuals who modify them are more likely to use them in the future, thereby reducing aversion. Moreover, Kumar et al. (2022) proposed that if a technical application provokes negative experiences, individuals can adapt by acknowledging knowledge insufficiency, recognizing the outperformance of technology over human beings and seeking other people to help.
4.4 Example scenarios of CTE
To exemplify the CTE framework in practical situations, the responses of Facebook users’ following the Cambridge Analytica data scandal in 2018 are used as an illustrative case. Facebook revealed that the security flaw exposed “almost 50 million” users when the crisis broke (BBC, 2018). The scandal has increased users’ perceived privacy threats and diminished their sense of control over personal data. However, many users did not simply abandon the platform or accept the risk, but showed diverse coping responses corresponding to our proposed phases in the CTE framework. Brown (2020) found that most young users continue to use the platform because they believe that social media participation requires an exchange of personal data. Indeed, they transitioned to the Continuance rather than the Avoidance phase. This is consistent with our proposition that sunk costs and status quo bias can produce maintenance-based coping despite elevated threats.
Furthermore, Cho et al. (2020) found that Facebook users actively adopt various coping strategies, including problem-focused (e.g. adjusting privacy settings), emotion-focused (e.g. disengagement) and communication-focused (e.g. complaining) strategies. This corresponded to the Modification phase in the CTE framework. Users attempted to restore control-threat equilibrium through strategic adjustments when coping approaches exist. Subsequently, Facebook paid a $5bn fine to institute new privacy standards and invested over $8bn in privacy improvements (Meta, 2025), which may help restore user confidence. Based on the steady growth of US Facebook users from 2019 to 2023 (Statista, 2024), users might return to the Adoption or Continuance phases rather than complete Avoidance. The case of Facebook shows that user coping responses evolve in response to the changes in the control-threat equilibrium, instead of remaining static at rejection or acceptance.
However, the above coping strategies primarily stem from one’s subjective perception. Those strategies also failed to clarify one’s goal orientation (i.e. increase controls vs decrease threats, protection-focused vs prevention-focused) when modifying the status quo. Given that, while the Modification is more change-oriented, the Continuance is more maintenance-oriented. Hence, users’ privacy preferences and compatibility with a certain privacy status could help predict which coping phases they will go through. Those intrinsically resistant to making changes may internalize their real feelings about privacy (Blunt, 1988). They may prioritize maintaining the status quo (Continuance) rather than attempting to change it (Modification) as a form of self-coherence.
5. Discussion and future research agenda
The SLR provided the nomological framework underpinning OPC to date, while the CTE framework enabled an interpretable and transitory overview of user coping behaviors based on their privacy status. Integrating these insights, we outline three sections: theoretical implications of our CTE framework in extending the dominant OPC theories, practical implications for technology designers, marketers and regulators and methodological constraints and potential directions for future research.
5.1 Theoretical implications
The SLR has several theoretical contributions to the privacy literature. First, although social psychology theories (e.g. PCT and PMT) have signified a shift from technology and systems to the human aspect, primarily governing the analysis of users’ OPC, our CTE framework advances this discourse by challenging the assumptions of static rationality. PCT assumes users engage in rational cost-benefit calculations (Dinev and Hart, 2006), and PMT posits threat appraisal and coping appraisal as determinants of individual motivation to protective behaviors (Rogers and Prentice-Dunn, 1997). However, the current CTE framework repositions user coping behaviors as dynamic equilibrium management rather than static economic calculation.
In addition, the computers-are-social-actors (CASA) paradigm, which suggests that users treat computer technology as a social actor and adhere to social norms during interactions, is a case in point (Nass et al., 1996). Agnihotri and Bhattacharya (2023) investigated chatbots via CASA and revealed that chatbots being anthropomorphic, empathetic and posing less privacy concerns make them appear trustworthy to users, thus reducing negative word-of-mouth (WOM) and increasing their forgiveness of firm failure. Moreover, prior research that focused on calculus, social exchange, belief-and-cognition and coping appraisal when examining the mechanisms of OPC and coping responses has failed to address changing dynamics of user perceptions, such as user privacy knowledge, causal attribution, time of exposure (Park, 2022), (in)congruity between individual and contextual norms (Bélanger and James, 2020). Further investigation should be conducted on a more interactive and dynamic approach to OPC.
Although studies in privacy coping behaviors have predominantly assumed the rational process during which individuals have stable preferences, Adjerid et al. (2018) identified the malleability of user privacy preferences through cognitive heuristics and subjectivity. The deviations from a reference point in perceived risks and benefits significantly predict their decision-making concerning privacy. Janakiraman et al. (2018) also observed varying consumer reactions to data breaches, influenced by prior expectations of data protection and sensitivity to breaches. Instead of termination, privacy-threatened individuals may switch from a breached channel to a safer one. This aligns with the central argument of the current study, which suggests that users may not disengage immediately when feeling threatened but might instead slightly adjust their privacy settings (Continuance) or occasionally switch channels (Modification) as a coping strategy.
Second, the CTE framework recontextualizes the privacy paradox not as a cognitive failure or behavioral inconsistency, but as adaptive rationality within dynamic control-threat configurations. For instance, users’ coping responses vary contingent upon their control status: those in high-control phases (Adoption and Continuance) exhibit reduced risk sensitivity because of agency confidence in managing potential threats, whereas users in low-control phases (Modification and Avoidance) amplify protective responses as their capacity for threat mitigation diminishes. Thus, researchers should adopt a transitory perspective on user privacy coping behaviors. As Acquisti et al. (2020) indicated, individuals overwhelmingly exhibit a “present bias” when they take actions that do not offer them their desirable level of privacy, prioritizing immediate benefits while overlooking longer-term costs and threats. Delayed OPC represents the temporal disjuncture between when concerns arise and when actions are taken, often sequentially (i.e. from acceptance to continuance or avoidance).
Third, the framework’s emphasis on transitional phases suggests that digital agency is continuously negotiated through users’ evolving control–threat equilibrium. This offers a more sophisticated lens for understanding human autonomy in digital ecosystems. It is reasonable to predict that the relationship between OPC and user coping behaviors is non-linear. Research has shown that users may exhibit subjectivity and bias while maintaining their current status (Bejar et al., 2023) or rationally ignore potential privacy threats if learning a new situation is not worthwhile (Acquisti et al., 2020). Our proposition suggests that individuals with a control–threat surplus may remain in the “Continuance” stage, tolerating privacy interventions until threats become untenable, triggering the “Modification” stage, where users take substantial measures to restore their control. If successful, these efforts pull them back to the prior stage; failure leads to avoidance behaviors.
Specifically, Park (2022) explored the non-linear pattern of user behavior in response to varying levels of privacy concern, uncovering that beyond a certain threshold, higher privacy concerns paradoxically lead to increased user disclosure. This corroborates the CTE framework, which states that users might remain accepting their existing privacy status despite escalating threats and diminishing control. Similarly, Hew et al. (2019) found that privacy concerns share a positive non-linear relationship with the usage intention of mobile social commerce platforms, implying that privacy concerns do not necessarily deter usage intention.
5.2 Practical implications
The CTE framework can offer practical implications for business strategy and regulatory design. First, privacy regulations can focus on empowering user control rather than simply penalizing privacy violations. Privacy regulators should expand users’ control and facilitate seamless transitions between engagement phases, creating more resilient digital ecosystems that benefit both consumers and businesses. International coordination is essential to set a common privacy regulation that can enable economic development (Sánchez, 2022). Privacy regulations such as the General Data Protection Regulation (GDPR) have created new forms of user empowerment through “right to erasure” and data portability provisions (GDPR.EU, 2018). These regulatory tools enable users to shift along the proposed continuum. For instance, users who previously operated in the Avoidance phase due to perceived lack of control may now move to the Modification phase, actively negotiating privacy controls with companies rather than simply accepting or rejecting services.
However, emerging AI governance challenges have complicated this regulatory landscape. Exploring more innovative privacy issues in AI-generated content (AIGC) is crucial as privacy risks from extensive data collection during and after model training are severe in the AIGC sector (Wang et al., 2023). Moreover, research suggested that AI deployment could enable governments to collect massive citizen data through digital surveillance systems and predictive algorithms and possibly modify user behavior (Saura et al., 2022). It is also vital to explore the macro impact of regulatory privacy frameworks (i.e. the European Data Act, effective 11 January 2024). The Act focused on enhancing transparency and user control over data (European Commission, 2024), offering a relevant backdrop for future research into the nuanced interplay between privacy environments, OPC and user coping.
Second, this transitory perspective challenges the common assumption that firms, once they have lost customers’ trust, cannot recover (Turjeman and Feinberg, 2023). Marketers should resolve the power imbalance by restoring the user agency. For instance, marketers should develop strategies to retain users who have moved into the Avoidance phase to mitigate privacy harm (Saavedra et al., 2024). In commercial sectors such as online travel agencies, while AI enhances operational efficiency via personalized recommendations and dynamic pricing, it simultaneously raises significant privacy and cybersecurity risks due to massive data collection and management (Hernández-Tamurejo et al., 2025). In such cases, marketers should leverage transparent privacy to build trust and retain consumers (Kaman and Deshmukh, 2025).
Third, given the transitional nature of user coping outcomes, technology designers should build adaptive privacy ecosystems that support users’ transitions across the control–threat continuum. For instance, when users enter the Modification phase, designers should proactively offer transparent and personalized data management options to prevent progression to the Avoidance phase.
5.3 Limitations and future research directions
Several limitations should be noted. First, following rigorous PRISMA guidelines, the SLR focused on two major databases and ABS-ranked journals to ensure quality. However, subjectivity and selection bias may exist in the inclusion and exclusion processes. Subjective judgments during article screening may result in a potential loss of important insights (e.g. Gao et al., 2023; Song et al., 2025c). The exclusion of non-English sources may have also limited the cultural and geographical diversity of the reviewed literature. Second, the reviewed literature has predominantly used self-reported questionnaire surveys and structural equation modeling analysis, except for a few recent studies (e.g. Cichy et al., 2021). However, these approaches often fail to solidify the causality and observe long-term effect patterns, not to mention their inadequacy in examining the nonlinear relationships among constructs. Third, though the conceptual framework of CTE enables a transitory and continuum perspective of user coping responses, the interpretive proxies of user privacy status by threat and control are simplified. Nevertheless, the authors expect the SLR, proposed framework and research recommendations to benefit academics and practitioners who desire a more comprehensive understanding of OPC.
Accordingly, we encourage scholars to further develop the CTE framework. Future research should employ behavioral tracking methods or longitudinal studies to evaluate the CTE framework, thereby expanding the scope of research and enhancing the depth of knowledge. This may assist in forecasting across various phases. Though researchers tend to evaluate new technologies and applications from a longitudinal standpoint throughout their lifespan, few have examined technology-induced privacy problems and dynamics longitudinally. Indeed, a longitudinal design facilitates researchers’ understanding of how proposed relationships change over time, which is crucial for capturing changes in perceptions, behaviors and attitudes. All of these are necessary for evaluating the impact of OPC. For example, Koohikamali et al. (2019) have investigated how privacy trade-off perceptions changed over time and how they related to usage behavior during pre-use, initial use and continued use periods. Furthermore, the longitudinal design enables better forecasting of the patterns in the effects of multiple threats on OPC and the corresponding user behavior. Tsay-Vogel et al. (2018) studied the attitude and disclosure behavior of SNS users over five years and observed convergence in risk perceptions between light and heavy users. A ceiling effect was identified with perceived privacy risk, which explained the diminished negative effect of OPC on user coping responses, and users’ potential desensitization following prolonged use of social media. To make results more generalizable, researchers could also consider conducting cross-cultural, especially non-English literature, and cross-sectional studies to explore whether the results are still consistent across countries and sectors.
6. Conclusion
The present study addressed a prevailing problem in contemporary business and information system research, specifically OPC and user coping behavior, through an SLR of 145 relevant articles in the recent five years, formulating a nomological framework of the association between OPC and user responses and proposing a CTE framework for OPC research. It thoroughly answered four research questions by presenting the results of theories/models/frameworks used; analyzing the nomological framework of OPC and user coping responses by clustering antecedents, mechanisms, interventions and user responses; formulating a transitory view in privacy research, from dichotomy to continuum, with propositions of CTE focused on privacy surplus and privacy deficit; suggesting future research, with emphasis on the mechanisms, transitional perspective of OPC, potential non-linearity in results and methodological design.





