Purpose

Despite scholarly discussions of online privacy concern (OPC) in the digital information landscape, a notable trend is that users exhibit various non-statical privacy concerns and increasingly sophisticated coping behaviors during human–computer interactions. Therefore, this paper aims to explicitly examine this phenomenon and the relationships between OPC and coping strategies that users engage with. A cohesive review is developed to elucidate how OPC predicts users’ coping behavior.

Design/methodology/approach

This review leveraged a systematic literature review to synthesize 145 OPC research papers in information systems and proposed a nomological and analytical framework for OPC.

Findings

The study delineated a nomological network with antecedents, mechanisms and interventions in the relationship between OPC and user coping behavior. Prior studies had underexplored the non-statical nature of OPC and the user privacy status quo, overlooking that the coping responses could switch over time.

Originality/value

The paper integrates a literature review and framework approach to help comprehend OPC and users’ transitory coping behavior. A continuum of privacy status based on a control-and-threat equilibrium framework was proposed, consisting of four phases: adoption, continuance, modification and avoidance. By doing so, this study outlines four OPC research directions for future studies.

Digitalization, automation, robotization and futuristic internet advancements (e.g. Web 4.0 and Metaverse) have heightened apprehensions among individuals who extensively disclose and transmit information online (Naz and Kashif, 2025; Song et al., 2025a). Digital systems provide a means of sharing information, stimulating knowledge exchange, learning and collaboration (Shatila et al., 2025). However, privacy has been a research focus for decades (Gómez-Hurtado et al., 2024; Liu et al., 2023; Shoukat et al., 2025), yielding substantial knowledge; however, one thing that perplexes scholars is how users’ privacy concerns could be used to predict their behavior (Balapour et al., 2020). Researchers have grappled with a notable incongruity between users’ stated privacy mental states (i.e. attitudes, concerns, desires) and actual responsive behavior. This discrepancy, compounded by the dynamic nature of privacy perceptions and behaviors that evolve, has produced mixed results, hindering firms’ understanding of users’ privacy management spanning from inaction to proactive actions (Acquisti et al., 2020; Song et al., 2025b). While current research has predominantly relied on static, binary frameworks that categorize user coping behavior as either immediate acceptance or rejection, this approach may insufficiently capture the complex nature of human-computer interactions, where users demonstrate dynamic coping strategies. Therefore, a continuum framework that encapsulates the temporal evolution of user coping responses to OPC is called for.

Online privacy concerns (OPC), which reflect users’ awareness and desire for privacy in virtual spaces (Hong and Thong, 2013), encompass individuals’ dispositional beliefs about the loss of control over personal information (Westin, 2003). Corresponding to different levels of privacy concern, user coping behaviors have been examined and traditionally categorized as either acceptance or rejection (Choi et al., 2018). However, this simplification has limited the understanding of the OPC outcomes. The dynamic nature of privacy perceptions has been insufficiently addressed. To date, no systematic review has consolidated the framework linking OPC and coping behaviors and a change-oriented approach to these responses is needed.

This study aims to establish a theoretically grounded and empirically informed framework that enables researchers and practitioners to understand user coping behaviors throughout the consumption experience, from intention formation to post-purchase. We conducted a systematic literature review (SLR) to identify the nomological network and constructs on OPC and outcome variables. Moreover, we formulated a continuum of user privacy status quo that hinges on the balance between their perceived control and perceived threat, highlighting corresponding coping strategies (adoption, continuance, modification and avoidance). Our proposed framework could advance existing literature by incorporating temporal evolution, psychological factors and the dynamic equilibrium of privacy-related decision-making. We based the research on three main points.

First, despite rapid evolution in OPC research (e.g. Hong and Thong, 2013), frameworks elucidating the antecedents, consequences and paradoxical effects of OPCs remain rare. Our research aims to supplement the literature by synthesizing the newest variables and theories in OPC research.

Second, moving beyond the binary view of user coping responses (avoidant or adoptive), we consider a transitory perspective that accounts for the balance between control and threat. When perceiving a threat to their privacy, individuals may not immediately avoid the technology/service but adopt “continuance” or “modification” behaviors.

Third, the present study explores a possible non-linear effect that OPC has on user coping behavior. This indicates the existence of a threshold and bias in privacy perception, which may delay coping responses, desensitize users to privacy concerns and shift their coping behavior.

Specifically, the following research questions were raised. “What are the theories/frameworks/models predominantly adopted in recent studies that relate users’ privacy concerns to their coping strategies?” (RQ1). “What is the nomological network informing the association between OPC and user coping responses, such as proposed antecedents, mechanisms, and interventions?” (RQ2). “How can user coping strategies be better understood dynamically?” (RQ3). “What future research agenda can be developed based on our research findings?” (RQ4).

SLR is an appropriate tool for systematically assessing and evaluating a given body of literature and comprehensively synthesizing all relevant studies that meet specific eligibility criteria according to predetermined research questions (Siddaway et al., 2019). This study adopted the preferred reporting items for systematic reviews and meta-analyses (PRISMA) guidelines, which comprise four core steps: identification, screening, eligibility and inclusion (Hollebeek et al., 2023; Wang and Liu, 2023). Figure 1 shows the results from the process under the PRISMA framework.

Figure 1.
A flowchart showing the systematic process of identifying, screening, and including articles in a research review with criteria and exclusions.The flowchart illustrates the systematic process for selecting articles for a research review, starting with identification through Web of Science and ScienceDirect searches. Records are refined based on inclusion criteria, including document type, language, and field, leading to a screening process with further inclusion criteria and exclusions for duplication. After assessing full-text articles for eligibility, 145 final articles were selected for review, with exclusions based on technical papers, mathematical papers, relevance, and other criteria.

Search process

Figure 1.
A flowchart showing the systematic process of identifying, screening, and including articles in a research review with criteria and exclusions.The flowchart illustrates the systematic process for selecting articles for a research review, starting with identification through Web of Science and ScienceDirect searches. Records are refined based on inclusion criteria, including document type, language, and field, leading to a screening process with further inclusion criteria and exclusions for duplication. After assessing full-text articles for eligibility, 145 final articles were selected for review, with exclusions based on technical papers, mathematical papers, relevance, and other criteria.

Search process

Close Figure 1.

2.1.1 Identification.

Data for the SLR were gathered from Web of Science and Science Direct, known for comprehensive coverage in information systems, computer science, business and management (Liu, 2021; Wang et al., 2023). Following the structure similar to Hernández-Tamurejo et al. (2025), this study first identified key research terms and then conducted the relevant searches. The following keywords were utilized to search: “online privacy concern”, “information privacy concern”, “privacy and coping”, “user privacy concern” and “coping behavior”. Keywords were combined using “OR” operators across titles, abstracts and keywords. To include the most current literature, we considered studies published between 2018 and 2023. Moreover, we specified the article type (research paper), language (English) and field of studies (information systems, computer science, business, management and social science). A total of 992 (Web of Science = 615, ScienceDirect = 377) results were returned.

2.1.2 Screening.

The screening process consisted of source quality control and duplication check (Kitchenham and Brereton, 2013). To ensure a high-quality data source, we included 278 articles that ranked 2nd or higher in the Association of Business Schools (ABS) rankings (Mwangi et al., 2024). Further, duplicate entries were systematically identified by manual cross-checks among co-authors, resulting in 260 papers proceeding to the eligibility stage.

2.1.3 Eligibility.

Eligible articles should focus on users’ online privacy concerns and their coping behaviors. In this step, 115 articles were excluded for various reasons, including 23 pure technical articles (e.g. modeling, algorithm), 19 mathematical computational articles, 56 papers on irrelevant topics (e.g. physical private spaces) and 17 papers with non-user perspectives (e.g. government).

2.1.4 Inclusion.

Final inclusion ensured papers meet all the above criteria, which clearly hypothesized privacy concern as an important component and the coping behavior/strategy as an outcome variable. With full text retrieved, a set of 145 articles was included for reviewing and answering the research questions.

The overwhelming majority of methodologies used in OPC research are quantitative, as evident by the use of SEM, PLS-SEM and experiment-based analytical approaches, except for 5 qualitative studies involving semi-structured interviews (e.g. Cram et al., 2021), laddering interviews (e.g. Jung and Park, 2018) and focus groups (e.g. Lolich et al., 2019) and 16 mixed-methods studies (e.g. Agnihotri and Bhattacharya, 2023; Cheng et al., 2021; Lin and Armstrong, 2019). Particularly noteworthy is the longitudinal perspective that some studies have contributed, which validates that OPC and user responses change over time depending on adoption stages (Koohikamali et al., 2019) and launch time (Fox et al., 2021).

Recent research focusing on OPC and user coping behaviors has incorporated multiple facets of social psychology and individual attributes, extensively adopting Privacy Calculus Theory (PCT), Protection Motivation Theory (PMT) and the phenomenon/viewpoint of “privacy paradox” (Table 1). PCT explains that people cognitively evaluate the consequences of their privacy decision-making by weighing potential costs and benefits (Dinev and Hart, 2006). The level of privacy concern influences users’ attitudinal and behavioral responses to privacy protection. PMT suggests that individuals respond to threat communications through threat appraisal and coping appraisal, which has been widely applied to comprehend and predict motivations for online security behavior (Ogbanufe, 2023). Unlike PCT, which focuses on users’ processing of accurate information and taking proactive measures, PMT is more prevention-focused and explains how users are engaged in privacy-protective behaviors. In addition, the privacy paradox highlights incongruity in user behavior despite expressing privacy concerns, often failing to take protective actions in giving out data for immediate gratification and compensation (Adjerid et al., 2018).

Table 1.

Theories/frameworks/models of online privacy concern (OPC)

Theories/frameworks/modelsNo. of papers
Technology acceptance model (TAM)4
Elaboration likelihood model (ELM)2
Theory of reasoned action (TRA)4
Theory of planned behavior (TPB)1
Unified theory of acceptance and use of technology (UTAUT)2
Unified Theory of Acceptance and Use of Technology (UTAUT2)3
Goal-Directed behavior model (MGB)1
Value-based adoption model (VAM)1
Computer are social actors (CASA) theory1
Delone and McLean (D&M) information system (is) Success Model1
Diffusion of innovations theory (DOI)4
Innovation resistance theory3
Antecedents–privacy concerns–outcomes (APCO)1
Privacy–Trust–Behavioral intention (PTB) model1
Information processing theory1
Prominence–Interpretation theory1
Information–motivation–behavioral (IMB) skills model1
Extended parallel process model (EPPM)1
SERVQUAL or SERVPERF1
Multidimensional development theory (MDT)1
Theory of belief updating (TBU)1
Surveillance theory1
Privacy calculus theory27
Privacy regulation theory1
Regulatory focus theory3
Psychological ownership theory1
Social support theory2
Social role theory1
Social identity theory1
Social contract theory1
Social exchange theory2
Social cognition theory2
Social influence theory1
Social presence theory2
Stress-Coping theory1
Signaling theory2
Communication privacy management (CPM) theory3
Persuasion knowledge model (PKM)1
Trust–Commitment theory2
Self-efficacy theory1
Attitude formation theory1
Impression formation theory1
Use and gratifications theory3
Control agency theory1
Construal level theory (CLT)1
Coping theory2
Motivation theory1
Protection motivation theory10
Person–environment fit model1
Rational choice theory1
Agency theory1
Equity theory1
Utility theory1
Justice theory1
Surveillance theory1
Power-Responsibility equilibrium framework2
Stakeholder theory1
Consumer socialization theory1
Push–Pull–Mooring framework (PPP)2
Personalization–Privacy paradox6
Privacy fatigue4

Indeed, a multitude of IT theories have been utilized to address OPC, where the Technology acceptance model (TAM), theory of reasoned action (TRA) and diffusion of innovations theory (DOI) were comparatively more extensively applied. TAM highlights the effect of factors, such as perceived ease of use and usefulness on user attitudes, toward technology adoption (Davis et al., 1992). TRA predicts voluntary behavior, indicating that attitude and subjective norms shape one’s behavioral intention, which precedes actual behavior (Ajzen and Fishbein, 1973). DOI offers insights into the stages of technology adoption and identifies five influential predictors (relative advantage, compatibility, complexity, observability and trialability) (Rogers et al., 2014). Observing a rather similar distribution of IT theories applied to OPC, no single theory stood out as notably exceptional.

Considerable research has explored the antecedents, mechanisms, interventions and outcome variables that explain the relationship between OPC and user coping strategies, as illustrated in Figure 2. Further,  Appendix summarizes selected papers to provide a panoramic overview and details about the theories, research context and major findings.

Figure 2.

Nomological network of OPC and coping responses

Figure 2.

Nomological network of OPC and coping responses

Close Figure 2.

3.3.1 Antecedents.

The antecedents of OPC fall into three main clusters: technology-, user- and context-specific factors. The first cluster emphasizes hard-core elements and interface/system design. Researchers have identified major scenarios in which OPC may manifest, including service permission (Degirmenci, 2020), information disclosure requests (Cheng et al., 2021), massive data collection and management (Hernández-Tamurejo et al., 2025) and anthropomorphism of applications (Agnihotri and Bhattacharya, 2023). Barriers within human–machine interactions that evoke privacy concerns include complexity, intrusiveness and transparency (Suen, 2018; Wu et al., 2020).

The second cluster comprises user factors, including subjective beliefs, cognition and emotion. OPC may be evoked by perceptions (e.g. perceived threat, perceived assurance, perceived justice and vulnerability) about a certain technology and IT-intervened environments, prior experience or emotional stimuli such as computer anxiety (Degirmenci, 2020) and embarrassment (Zhu and Kanjanamekanant, 2021). Users engage in appraisal processes and have a basic need for privacy, which stems from their personal motivation (Crossler and Bélanger, 2019), privacy disposition (Ioannou et al., 2020) and territorial feelings (Lin and Armstrong, 2019). Similar to the social exchange perspective, OPC was frequently identified as an outcome of risk-benefit evaluation (Shaw and Sergueeva, 2019), information ownership (Zhu and Kanjanamekanant, 2021) and expectations (Xiong and Zuo, 2023) in a privacy setting.

The third cluster pertains to contextual cues from the privacy environment. Online users can read privacy-related declarations, third-party certifications and other informational signals to form impressions about a context. Moreover, OPC is on the premise of organizational responses (Ou et al., 2022) or intervention strategies concerning particular privacy issues, such as security breach (Ou et al., 2022), ubiquity (Sandhu et al., 2023), or information asymmetry (Al-Natour et al., 2020).

3.3.2 Mechanisms.

Drawing from our review, the mechanisms linking OPC to coping behaviors primarily comprise cognitive and affective routes. Individuals engage in self-evaluation and external evaluation as a cognitive process when faced with privacy issues. The self-evaluation factors include self-efficacy (Ogbanufe, 2023), coping efficacy (Kim and Kim, 2018) and technology self-efficacy (Crossler and Bélanger, 2019), reflecting users’ capability to navigate situations wherein their information privacy is threatened. When evaluating external forces, researchers (e.g. Choi et al., 2018; Cheng et al., 2021) used the appraisal frameworks (e.g. cost-benefit, benefit-utility, risk-gain) to justify the connection between OPC and user coping behaviors. In addition, OPC may lead to users’ empowerment (Bandara et al., 2021) and the adoption of different angles for perceiving the source of information privacy threats. From an affective perspective, OPC can lead to user satisfaction, psychological comfort, trust and distrust, subsequently affecting coping responses. Additionally, Tseng et al. (2022) revealed that users actively seek emotional and informational support to address privacy risks.

3.3.3 Interventions.

This review categorized interventions that alter the effects and contexts of OPC into three groups. The first group considers human characteristics, such as users’ knowledge, awareness, dispositional privacy concern (Choi et al., 2018), reliance on the Internet (Park and Shin, 2020) and social identity (Farivar et al., 2018). For example, through self-efficacy enhancement and self-image congruency, Cichy et al. (2021) introduced an incentive design to compensate for users’ data sharing. Furthermore, the second group comprises pronounced variables that arise during human–technology interactions. These variables specify user status in terms of their position in the technology adoption curve (Ketelaar and Van Balen, 2018), psychological distance (Bandara et al., 2021), inertia or sensitivities (Wagner et al., 2021), the strength of their relationship with the service provider (Hayes et al., 2021) and their access to feedback and options for addressing privacy concerns (Liu et al., 2022). Finally, the third group concentrates on the IT environment, with a focus on data (e.g. data collection, data type and transparency) (Suen, 2018), IT interfaces (e.g. technicality and personification) (Sandhu et al., 2023; Zhu and Kanjanamekanant, 2021) and functional attributes (e.g. disruption, contextual manipulation and information sensitivity) (Balapour et al., 2020; Miltgen and Smith, 2019). For example, ubiquity is a functional indicator in mobile commerce and applications, comprising the sub-dimensions of time-saving, spatial flexibility, portability, immediacy and continuity (Sandhu et al., 2023).

3.3.4 Outcome variables.

OPC, identified as a source of stress and disturbance in user–technology interactions, has been explained by coping theory to understand how individuals implement cognitive appraisal and behavioral coping to deal with it (Folkman and Lazarus, 1985). Drawing from Liang et al. (2019), who investigated how users cope with IT security threats, the outcome variables in our analysis also include emotion- and problem-focused user coping responses through which users regain controllability and emotional stability when confronted with privacy threats. Furthermore, we identified temporality-focused responses devoid of clear emotional orientations.

The emotion-focused variables represent users’ emotional appraisal from positive (e.g. acceptance, engagement and loyalty) to negative (e.g. avoidance, resistance and reactance). Different from a distinct emotion, fatigue has been considered an intriguing and complex emotional response (e.g. Dhir et al., 2019). Meanwhile, users concerned with information privacy exhibited different motivational orientations, such as protection (Mousavi et al., 2020) and rejection (Strycharz et al., 2021).

Problem-solving variables suggest that users may adopt proactive and passive responses. When faced with information disclosure/data collection requests, users may proactively disclose correct information, withhold information, or disclose false information (Miltgen and Smith, 2019); disable relevant settings to restrict tracking (Ketelaar and Van Balen, 2018); and control the level of access to and interaction within virtual territories (Lin and Armstrong, 2019). Conversely, some users may take no action, representing a passive response in either agreement or disagreement, which has been termed an inaction strategy (Choi et al., 2018). Fullwood et al. (2019) supplemented that lurking is not merely bystander behavior but can represent a transitional state depending on the life circumstances experienced.

Responses focused on temporality are categorized as either immediacy-based or future-based. Immediacy-based responses typically address users’ current needs and actions, encompassing behaviors such as adoption (Fox and Connolly, 2018), sharing, storage (Alsmadi and Prybutok, 2018) and purchasing (Zeng et al., 2020). Future-based strategies reflect a longer-term perspective, focusing on sustained engagement and continuity through re-purchase (Demmers et al., 2018) or re-transaction intention (Ou et al., 2022).

Prior researchers have predominantly associated OPC with either adoption-based responses (e.g. acceptance, purchase and usage) or avoidance-based responses (e.g. discontinuance, termination and rejection), assuming that users exhibit timely and assured coping to a privacy issue, which corresponds to the viewpoint of dichotomy. Acceptance is typically the opposite of rejection (Choi et al., 2018). The dichotomous patterns of user coping responses could be considered for simplicity (Bhattacherjee et al., 2018). However, users may simultaneously hold positive and negative responses. As individual–technology interactions deepen with the changing dynamics of privacy status during the different stages of technology/service adoption (i.e. pre-adoption, adoption and post-adoption), the actual evaluation performed and coping mechanisms adopted by users might be more complex. Emerging research has observed the coexistence of resistance and adoption of technological innovations (Laukkanen and Kiviniemi, 2010) and the non-linear patterns of protective responses to varying intensities of personal data concerns (Park, 2022). For instance, a study on voice-based digital assistants demonstrated that higher perceived privacy risks did not inherently inhibit technology adoption; rather, they interacted with trust to influence the final result (Vimalkumar et al., 2021). A few studies have revisited this coping concept and advocated for a continuum perspective (e.g. Turel, 2015), indicating that continuance and discontinuous usages are not opposite extremes on the same continuum. Fullwood et al. (2019) examined lurking as existing on a continuum rather than as a dichotomous variable in online communities. Ketelaar and Van Balen (2018) revealed that users’ position on the adoption curve moderates their privacy concerns about data tracking. Fox et al. (2021) conducted a longitudinal study and found that users’ coping responses depended on their prior adoption experience.

Concerning how OPC leads to varying coping responses, significant attention has been directed towards the privacy calculus, during which individuals engage in a trade-off between the cost of providing personal information and the benefit of information disclosure (Culnan and Bies, 2003). However, the framework does not account for the fact that privacy concerns develop over time through the intricate interplay between an individual and the environment, thereby underestimating how coping responses change in tandem with users’ privacy status (Bejar et al., 2023).

A continuum view of coping responses is essential for understanding how privacy concerns shape human–technology interactions and for developing effective post-hoc strategies from both individual and business perspectives. For example, users’ tendency to develop heightened privacy concerns and frustration could be alleviated and altered if effective resolutions are implemented before users move to the aversion and avoidance stage concerning a business.

To make the privacy status interpretative, this paper identified control and threat, built upon PMT (Rogers and Prentice-Dunn, 1997) and coping theory (Folkman and Lazarus, 1985) for controlling risks and assessing threats. Perceived control refers to individuals’ sense of competence, superiority and mastery over their surroundings, such as the ability to manage personal information and privacy risks in human–computer interactions (Folkman and Lazarus, 1985; Song et al., 2025a). Perceived threat encompasses one’s subjective appraisal of potential harm or loss associated with technology adoption and information disclosure (Folkman and Lazarus, 1985). Individuals possess both the need for control and the inclination to appraise threats. This combination fuels their motivation to respond to the privacy situations, whether to change or maintain the status quo, through actions that range from doing little to concrete efforts (e.g. Dietvorst et al., 2018; Mousavi et al., 2020). Thus, the privacy status quo is determined by the equilibrium between one’s perceived control and one’s perceived threat during user–technology interactions. The status is in a continuum and shifting, which helps predict user coping behavior.

Based on the findings of SLR, a nuanced understanding of how control–threat equilibrium (CTE) could be used to predict user privacy-related coping behaviors is achieved (see Table 2 for summarization). Users may exhibit one of the four phases of CTE (Adoption, Continuance, Modification and Avoidance) that incorporate different thoughts, feelings and behavioral intents. From a longitudinal perspective, users differed in coping responses corresponding to their privacy status quo. Once the privacy status fails to reach their expectation, they might not immediately terminate the service/application but undergo a process of sustaining or changing, termed Continuance and Modification. This dynamic mirrors the dual-process model proposed by PMT (Rogers and Prentice-Dunn, 1997), where threat appraisal and coping appraisal determine the motivation to engage in protective behavior. For instance, users normally expect immediate gratification (i.e. access to service, free trial, monetary compensation), thus giving quick responses that discount privacy concerns for short-term benefits (Wottrich et al., 2018). Adoption-based coping frequently occurs when introducing a new technology/application/privacy intervention (e.g. Vimalkumar et al., 2021).

Table 2.

User coping responses based on CTE

 Control–threat equilibriumComponents
Coping phasePerceived controlPerceived threatThoughtsFeelingsIntended behaviorExample authors
AdoptionHighLowNeed for functionality; trust firms; immediate gratification;Curious; enjoyable; safe; feeling of desirable statusSeldom seek for value but often provide data; thoughtless authorization, download and subscription; willing to share and disclose; immediate response;Libaque-Sáenz et al., 2021; Vimalkumar et al., 2021;
ContinuanceMedium to highLow to mediumBenefit expectation; trust; fear of loss; valuation;Enjoyable with benefits; little worries about potential risks; feeling of engagementContinue to use/purchase; sustain ownership; biased/optimistic evaluation of potential risks; lurking; No-action;Sandhu et al., 2023; Wagner et al., 2021;
ModificationLow to mediumMedium to highImplicit negotiation with firms; restoration of control; prevention from threats; rebuilding of trust and confidence;Enjoyable with benefits but threatened when problems occur; feeling of empowerment;Withhold information; falsify personal data; apply protection heuristic; customize/disable settings; limit access/interaction/exposure;Jozani et al., 2020; Miltgen and Smith, 2019; Mousavi et al., 2020;
AvoidanceLowHighNo trust; need for privacy protection; punishment for irregulated and unethical firm act; isolation of self from risk exposure;Annoyed; anxious; feeling of out-of-control; Worry about privacy loss and continuous harm;Cancelation; termination; No repurchase; rejection; avoid any forms of data-based interventions; opt-out;Johnson et al., 2020; Strycharz et al., 2021;

Continuance is a maintenance-based coping phase where users sustain their technology engagement despite experiencing privacy concerns because the control-threat equilibrium is still acceptable. As users’ OPC may be temporary, the predictive effect would be limited if it is not fully evoked, akin to a sleeper effect that may significantly amplify over time rather than immediately following a privacy exposure (Lariscy and Tinkham, 1999). Considering such a dynamic, Continuance-based coping occurs when users accumulate experience in privacy and adoption for a period. Users are exposed to privacy stimuli and gradually understand potential threats and how controllable the context is. A prerequisite for such a type of CTE is the continuous motivation of users to maintain their status after adoption, incorporating facilitators such as risk-benefit evaluation (e.g. Sandhu et al., 2023; Wagner et al., 2021). Despite privacy risks, the decision to continue adoption suggests a coping appraisal where the perceived benefits significantly outweigh the perceived risks. In this context, users may inadvertently train algorithms through prolonged engagement driven by dopamine with artificial intelligence (AI) systems that enable surveillance and data collection (Saura et al., 2024). This creates a paradox that, despite escalating privacy threats, users may remain in the Continuance phase, as the immediate gratification obscures the long-term privacy costs.

Moreover, Modification occurs when the control-threat equilibrium is disrupted but deemed to be properly managed. Users are anticipated to actively adjust their online footprints and interactions to restore privacy control. As users perceive increased privacy threats, they might engage in problem-focused coping (e.g. adjust privacy settings) or emotion-focused coping (e.g. manage emotional distress). This phase reflects a strategic shift where users hope to change the situation by restoring control through using customized privacy settings (Mousavi et al., 2020), minimizing engagement (Jozani et al., 2020) and preventing further risks by taking measures such as falsifying personal data (Miltgen and Smith, 2019) and using stronger passwords (Mamonov and Benbunan-Fich, 2018), instead of terminating the service/application. Ultimately, the escalation of perceived threats and diminishing perceived control or efficacy of previous coping strategies may lead users to engage in Avoidance-based coping. Users deliberately circumvent or abandon exposure to privacy-threatening content (Strycharz et al., 2021).

To generate a more dynamic view of CTE, as Figure 3 illustrates, Adoption and Continuance represent a controlthreat surplus involving two end-situations: maximum surplus (i.e. users are unaware of privacy threats or perceive full controllability) and minimum surplus (i.e. privacy threat is nearing the marginal controllability of a given user). Furthermore, Modification and Avoidance represent a controlthreat deficit involving two end-situations: minimum deficit (i.e. users perceive little loss of controllability but want to get back to the surplus status) and maximum deficit (i.e. users feel an abject lack of control because of ubiquitous privacy threats).

Figure 3.
A flow diagram illustrating control-threat surplus and deficit in relation to adoption, continuance, modification, and avoidance.The diagram shows the relationship between perceived control and perceived threat, leading to different behavioural outcomes. The flow illustrates that when perceived control exceeds perceived threat, the outcomes are adoption and continuance, whereas when perceived threat exceeds perceived control, the outcomes are modification and avoidance, demonstrating the psychological balance between control and threat.

Controlthreat equilibrium of privacy

Figure 3.
A flow diagram illustrating control-threat surplus and deficit in relation to adoption, continuance, modification, and avoidance.The diagram shows the relationship between perceived control and perceived threat, leading to different behavioural outcomes. The flow illustrates that when perceived control exceeds perceived threat, the outcomes are adoption and continuance, whereas when perceived threat exceeds perceived control, the outcomes are modification and avoidance, demonstrating the psychological balance between control and threat.

Controlthreat equilibrium of privacy

Close Figure 3.

Despite the abundant research on dichotomous coping (Adoption and Avoidance), an intriguing concept emerges once users reach the equilibrium’s peak/threshold. At this juncture, they may switch to more transitory coping behaviors to Continuance, should they find the equilibrium still acceptable, or to Modification if the equilibrium is deemed unacceptable and, therefore, attempt to return it to acceptable levels. Figure 4 illustrates the U-shaped effect on user privacy coping behavior based on CTE.

Figure 4.
A graph showing the relationship between control-threat equilibrium and acceptance level with perceived threat and perceived control curves.The graph illustrates the relationship between control-threat equilibrium and acceptance level, where the x-axis represents control-threat equilibrium and the y-axis represents acceptance level. The curves show perceived threat and perceived control across different levels of equilibrium, with perceived threat being high on the left side and perceived control increasing as the equilibrium moves towards the right, illustrating how these factors influence the acceptance level.

The U-shaped effect on user privacy coping behavior based on CTE

Figure 4.
A graph showing the relationship between control-threat equilibrium and acceptance level with perceived threat and perceived control curves.The graph illustrates the relationship between control-threat equilibrium and acceptance level, where the x-axis represents control-threat equilibrium and the y-axis represents acceptance level. The curves show perceived threat and perceived control across different levels of equilibrium, with perceived threat being high on the left side and perceived control increasing as the equilibrium moves towards the right, illustrating how these factors influence the acceptance level.

The U-shaped effect on user privacy coping behavior based on CTE

Close Figure 4.

Regarding Continuance, once users have downloaded, subscribed to, or adopted smart applications for which they have been charged time, money, or other inputs, they will be conservative and reluctant to relinquish their ownership and prior investments. Psychological perspectives such as sunk cost (Arkes and Blumer, 1985) and the endowment effect (Nunes and Dreze, 2006) explain users’ greater tendency to continue an endeavor after money, effort, or time has been invested, with them ascribing more value to things if they own them. Users with feelings of ownership over their data may seek to retain possession due to fear of loss (Cichy et al., 2021), supporting the idea of Continuance. Drawing from this, research heavily reliant on models that repeatedly measure variables such as satisfaction and perceived usefulness obtained from TAM (Davis et al., 1992) or the IT continuance model (Bhattacherjee, 2001) would be constrained in providing psychological insights. Taking culture for example, in societies with a conformist culture, users may continue to use risky applications/services, owing to the overwhelming trend and the group’s collective behavior or simply because they are accustomed to it or fatigued (Choi et al., 2018).

A few distinguished facts, including status quo bias (Samuelson and Zeckhauser, 1988) and privacy fatigue (Choi et al., 2018), also highlight users’ bias and subjectivity in Continuance responses. For example, although intensified privacy concerns push users to switch, inertia, as a critical component of status quo bias, will drive users to stay with incumbent applications (Wang et al., 2019). Privacy fatigue, a key component of cynicism, is closely relevant to user pre-adoption and privacy experience and primarily stems from a failure to manage privacy (Choi et al., 2018). Users with this psychological state might find themselves simultaneously enjoying the benefits and perceiving futility when considering privacy matters. As a result, they might invest less effort into privacy decision-making or do nothing to change the status.

However, the Continuance stage could be altered to the Modification stage when user privacy concerns are high. Even if consumers are comfortable with the status quo, awareness of privacy protection can persuade them to switch to another application/platform (Raddatz et al., 2023). Concerning Modification, users generally hold two forms of perceptions: restoring self-control by protection behavior (e.g. applying privacy-protecting heuristic and increasing IT- and privacy-related knowledge) and reducing threats from others through subversion behaviors (e.g. withholding information and falsifying personal data). As explained by cognitive dissonance theory (Festinger, 1962), users perceiving two psychologically dissonant states attempt to alleviate the mental tension by changing perceptions.

In our proposition, users who experience irreconcilable threat–control tensions are expected to alter their status quo of privacy to an acceptable level. Pirkkalainen et al. (2019) highlighted coping strategies that build resilience against IT-induced stress, including positive reinterpretation as a form of meaning-making (e.g. seeing technology in a more positive light) and IT control (e.g. increasing well-being by reducing tensions and fatigue) as a form of mastery. Dietvorst et al. (2018) indicated that even with imperfect algorithms, individuals who modify them are more likely to use them in the future, thereby reducing aversion. Moreover, Kumar et al. (2022) proposed that if a technical application provokes negative experiences, individuals can adapt by acknowledging knowledge insufficiency, recognizing the outperformance of technology over human beings and seeking other people to help.

To exemplify the CTE framework in practical situations, the responses of Facebook users’ following the Cambridge Analytica data scandal in 2018 are used as an illustrative case. Facebook revealed that the security flaw exposed “almost 50 million” users when the crisis broke (BBC, 2018). The scandal has increased users’ perceived privacy threats and diminished their sense of control over personal data. However, many users did not simply abandon the platform or accept the risk, but showed diverse coping responses corresponding to our proposed phases in the CTE framework. Brown (2020) found that most young users continue to use the platform because they believe that social media participation requires an exchange of personal data. Indeed, they transitioned to the Continuance rather than the Avoidance phase. This is consistent with our proposition that sunk costs and status quo bias can produce maintenance-based coping despite elevated threats.

Furthermore, Cho et al. (2020) found that Facebook users actively adopt various coping strategies, including problem-focused (e.g. adjusting privacy settings), emotion-focused (e.g. disengagement) and communication-focused (e.g. complaining) strategies. This corresponded to the Modification phase in the CTE framework. Users attempted to restore control-threat equilibrium through strategic adjustments when coping approaches exist. Subsequently, Facebook paid a $5bn fine to institute new privacy standards and invested over $8bn in privacy improvements (Meta, 2025), which may help restore user confidence. Based on the steady growth of US Facebook users from 2019 to 2023 (Statista, 2024), users might return to the Adoption or Continuance phases rather than complete Avoidance. The case of Facebook shows that user coping responses evolve in response to the changes in the control-threat equilibrium, instead of remaining static at rejection or acceptance.

However, the above coping strategies primarily stem from one’s subjective perception. Those strategies also failed to clarify one’s goal orientation (i.e. increase controls vs decrease threats, protection-focused vs prevention-focused) when modifying the status quo. Given that, while the Modification is more change-oriented, the Continuance is more maintenance-oriented. Hence, users’ privacy preferences and compatibility with a certain privacy status could help predict which coping phases they will go through. Those intrinsically resistant to making changes may internalize their real feelings about privacy (Blunt, 1988). They may prioritize maintaining the status quo (Continuance) rather than attempting to change it (Modification) as a form of self-coherence.

The SLR provided the nomological framework underpinning OPC to date, while the CTE framework enabled an interpretable and transitory overview of user coping behaviors based on their privacy status. Integrating these insights, we outline three sections: theoretical implications of our CTE framework in extending the dominant OPC theories, practical implications for technology designers, marketers and regulators and methodological constraints and potential directions for future research.

The SLR has several theoretical contributions to the privacy literature. First, although social psychology theories (e.g. PCT and PMT) have signified a shift from technology and systems to the human aspect, primarily governing the analysis of users’ OPC, our CTE framework advances this discourse by challenging the assumptions of static rationality. PCT assumes users engage in rational cost-benefit calculations (Dinev and Hart, 2006), and PMT posits threat appraisal and coping appraisal as determinants of individual motivation to protective behaviors (Rogers and Prentice-Dunn, 1997). However, the current CTE framework repositions user coping behaviors as dynamic equilibrium management rather than static economic calculation.

In addition, the computers-are-social-actors (CASA) paradigm, which suggests that users treat computer technology as a social actor and adhere to social norms during interactions, is a case in point (Nass et al., 1996). Agnihotri and Bhattacharya (2023) investigated chatbots via CASA and revealed that chatbots being anthropomorphic, empathetic and posing less privacy concerns make them appear trustworthy to users, thus reducing negative word-of-mouth (WOM) and increasing their forgiveness of firm failure. Moreover, prior research that focused on calculus, social exchange, belief-and-cognition and coping appraisal when examining the mechanisms of OPC and coping responses has failed to address changing dynamics of user perceptions, such as user privacy knowledge, causal attribution, time of exposure (Park, 2022), (in)congruity between individual and contextual norms (Bélanger and James, 2020). Further investigation should be conducted on a more interactive and dynamic approach to OPC.

Although studies in privacy coping behaviors have predominantly assumed the rational process during which individuals have stable preferences, Adjerid et al. (2018) identified the malleability of user privacy preferences through cognitive heuristics and subjectivity. The deviations from a reference point in perceived risks and benefits significantly predict their decision-making concerning privacy. Janakiraman et al. (2018) also observed varying consumer reactions to data breaches, influenced by prior expectations of data protection and sensitivity to breaches. Instead of termination, privacy-threatened individuals may switch from a breached channel to a safer one. This aligns with the central argument of the current study, which suggests that users may not disengage immediately when feeling threatened but might instead slightly adjust their privacy settings (Continuance) or occasionally switch channels (Modification) as a coping strategy.

Second, the CTE framework recontextualizes the privacy paradox not as a cognitive failure or behavioral inconsistency, but as adaptive rationality within dynamic control-threat configurations. For instance, users’ coping responses vary contingent upon their control status: those in high-control phases (Adoption and Continuance) exhibit reduced risk sensitivity because of agency confidence in managing potential threats, whereas users in low-control phases (Modification and Avoidance) amplify protective responses as their capacity for threat mitigation diminishes. Thus, researchers should adopt a transitory perspective on user privacy coping behaviors. As Acquisti et al. (2020) indicated, individuals overwhelmingly exhibit a “present bias” when they take actions that do not offer them their desirable level of privacy, prioritizing immediate benefits while overlooking longer-term costs and threats. Delayed OPC represents the temporal disjuncture between when concerns arise and when actions are taken, often sequentially (i.e. from acceptance to continuance or avoidance).

Third, the framework’s emphasis on transitional phases suggests that digital agency is continuously negotiated through users’ evolving control–threat equilibrium. This offers a more sophisticated lens for understanding human autonomy in digital ecosystems. It is reasonable to predict that the relationship between OPC and user coping behaviors is non-linear. Research has shown that users may exhibit subjectivity and bias while maintaining their current status (Bejar et al., 2023) or rationally ignore potential privacy threats if learning a new situation is not worthwhile (Acquisti et al., 2020). Our proposition suggests that individuals with a control–threat surplus may remain in the “Continuance” stage, tolerating privacy interventions until threats become untenable, triggering the “Modification” stage, where users take substantial measures to restore their control. If successful, these efforts pull them back to the prior stage; failure leads to avoidance behaviors.

Specifically, Park (2022) explored the non-linear pattern of user behavior in response to varying levels of privacy concern, uncovering that beyond a certain threshold, higher privacy concerns paradoxically lead to increased user disclosure. This corroborates the CTE framework, which states that users might remain accepting their existing privacy status despite escalating threats and diminishing control. Similarly, Hew et al. (2019) found that privacy concerns share a positive non-linear relationship with the usage intention of mobile social commerce platforms, implying that privacy concerns do not necessarily deter usage intention.

The CTE framework can offer practical implications for business strategy and regulatory design. First, privacy regulations can focus on empowering user control rather than simply penalizing privacy violations. Privacy regulators should expand users’ control and facilitate seamless transitions between engagement phases, creating more resilient digital ecosystems that benefit both consumers and businesses. International coordination is essential to set a common privacy regulation that can enable economic development (Sánchez, 2022). Privacy regulations such as the General Data Protection Regulation (GDPR) have created new forms of user empowerment through “right to erasure” and data portability provisions (GDPR.EU, 2018). These regulatory tools enable users to shift along the proposed continuum. For instance, users who previously operated in the Avoidance phase due to perceived lack of control may now move to the Modification phase, actively negotiating privacy controls with companies rather than simply accepting or rejecting services.

However, emerging AI governance challenges have complicated this regulatory landscape. Exploring more innovative privacy issues in AI-generated content (AIGC) is crucial as privacy risks from extensive data collection during and after model training are severe in the AIGC sector (Wang et al., 2023). Moreover, research suggested that AI deployment could enable governments to collect massive citizen data through digital surveillance systems and predictive algorithms and possibly modify user behavior (Saura et al., 2022). It is also vital to explore the macro impact of regulatory privacy frameworks (i.e. the European Data Act, effective 11 January 2024). The Act focused on enhancing transparency and user control over data (European Commission, 2024), offering a relevant backdrop for future research into the nuanced interplay between privacy environments, OPC and user coping.

Second, this transitory perspective challenges the common assumption that firms, once they have lost customers’ trust, cannot recover (Turjeman and Feinberg, 2023). Marketers should resolve the power imbalance by restoring the user agency. For instance, marketers should develop strategies to retain users who have moved into the Avoidance phase to mitigate privacy harm (Saavedra et al., 2024). In commercial sectors such as online travel agencies, while AI enhances operational efficiency via personalized recommendations and dynamic pricing, it simultaneously raises significant privacy and cybersecurity risks due to massive data collection and management (Hernández-Tamurejo et al., 2025). In such cases, marketers should leverage transparent privacy to build trust and retain consumers (Kaman and Deshmukh, 2025).

Third, given the transitional nature of user coping outcomes, technology designers should build adaptive privacy ecosystems that support users’ transitions across the control–threat continuum. For instance, when users enter the Modification phase, designers should proactively offer transparent and personalized data management options to prevent progression to the Avoidance phase.

Several limitations should be noted. First, following rigorous PRISMA guidelines, the SLR focused on two major databases and ABS-ranked journals to ensure quality. However, subjectivity and selection bias may exist in the inclusion and exclusion processes. Subjective judgments during article screening may result in a potential loss of important insights (e.g. Gao et al., 2023; Song et al., 2025c). The exclusion of non-English sources may have also limited the cultural and geographical diversity of the reviewed literature. Second, the reviewed literature has predominantly used self-reported questionnaire surveys and structural equation modeling analysis, except for a few recent studies (e.g. Cichy et al., 2021). However, these approaches often fail to solidify the causality and observe long-term effect patterns, not to mention their inadequacy in examining the nonlinear relationships among constructs. Third, though the conceptual framework of CTE enables a transitory and continuum perspective of user coping responses, the interpretive proxies of user privacy status by threat and control are simplified. Nevertheless, the authors expect the SLR, proposed framework and research recommendations to benefit academics and practitioners who desire a more comprehensive understanding of OPC.

Accordingly, we encourage scholars to further develop the CTE framework. Future research should employ behavioral tracking methods or longitudinal studies to evaluate the CTE framework, thereby expanding the scope of research and enhancing the depth of knowledge. This may assist in forecasting across various phases. Though researchers tend to evaluate new technologies and applications from a longitudinal standpoint throughout their lifespan, few have examined technology-induced privacy problems and dynamics longitudinally. Indeed, a longitudinal design facilitates researchers’ understanding of how proposed relationships change over time, which is crucial for capturing changes in perceptions, behaviors and attitudes. All of these are necessary for evaluating the impact of OPC. For example, Koohikamali et al. (2019) have investigated how privacy trade-off perceptions changed over time and how they related to usage behavior during pre-use, initial use and continued use periods. Furthermore, the longitudinal design enables better forecasting of the patterns in the effects of multiple threats on OPC and the corresponding user behavior. Tsay-Vogel et al. (2018) studied the attitude and disclosure behavior of SNS users over five years and observed convergence in risk perceptions between light and heavy users. A ceiling effect was identified with perceived privacy risk, which explained the diminished negative effect of OPC on user coping responses, and users’ potential desensitization following prolonged use of social media. To make results more generalizable, researchers could also consider conducting cross-cultural, especially non-English literature, and cross-sectional studies to explore whether the results are still consistent across countries and sectors.

The present study addressed a prevailing problem in contemporary business and information system research, specifically OPC and user coping behavior, through an SLR of 145 relevant articles in the recent five years, formulating a nomological framework of the association between OPC and user responses and proposing a CTE framework for OPC research. It thoroughly answered four research questions by presenting the results of theories/models/frameworks used; analyzing the nomological framework of OPC and user coping responses by clustering antecedents, mechanisms, interventions and user responses; formulating a transitory view in privacy research, from dichotomy to continuum, with propositions of CTE focused on privacy surplus and privacy deficit; suggesting future research, with emphasis on the mechanisms, transitional perspective of OPC, potential non-linearity in results and methodological design.

Acquisti
,
A.
,
Brandimarte
,
L.
and
Loewenstein
,
G.
(
2020
), “
Secrets and likes: the drive for privacy and the difficulty of achieving it in the digital age
”,
Journal of Consumer Psychology
, Vol.
30
No.
4
, pp.
736
-
758
.
Adjerid
,
I.
,
Peer
,
E.
and
Acquisti
,
A.
(
2018
), “
Beyond the privacy paradox: objective versus relative risk in privacy decision making
”,
MIS Quarterly
, Vol.
42
No.
2
, pp.
465
-
488
.
Agnihotri
,
A.
and
Bhattacharya
,
S.
(
2023
), “
Chatbots’ effectiveness in service recovery
”,
International Journal of Information Management
, Vol.
76
, p.
102679
.
Ajzen
,
I.
and
Fishbein
,
M.
(
1973
), “
Attitudinal and normative variables as predictors of specific behavior
”,
Journal of Personality and Social Psychology
, Vol.
27
No.
1
, pp.
41
-
57
.
Al-Natour
,
S.
,
Cavusoglu
,
H.
,
Benbasat
,
I.
and
Aleem
,
U.
(
2020
), “
An empirical investigation of the antecedents and consequences of privacy uncertainty in the context of mobile apps
”,
Information Systems Research
, Vol.
31
No.
4
, pp.
1037
-
1063
.
Alraja
,
M.
(
2022
), “
Frontline healthcare providers’ behavioural intention to Internet of Things (IoT)-enabled healthcare applications: a gender-based, cross-generational study
”,
Technological Forecasting and Social Change
, Vol.
174
, p.
121256
.
Alsmadi
,
D.
and
Prybutok
,
V.
(
2018
), “
Sharing and storage behavior via cloud computing: security and privacy in research and practice
”,
Computers in Human Behavior
, Vol.
85
, pp.
218
-
226
.
Ameen
,
N.
,
Hosany
,
S.
and
Paul
,
J.
(
2022
), “
The personalisation-privacy paradox: consumer interaction with smart technologies and shopping mall loyalty
”,
Computers in Human Behavior
, Vol.
126
, p.
106976
.
Arkes
,
H.R.
and
Blumer
,
C.
(
1985
), “
The psychology of sunk cost
”,
Organizational Behavior and Human Decision Processes
, Vol.
35
No.
1
, pp.
124
-
140
.
Balapour
,
A.
,
Nikkhah
,
H.R.
and
Sabherwal
,
R.
(
2020
), “
Mobile application security: role of perceived privacy as the predictor of security perceptions
”,
International Journal of Information Management
, Vol.
52
, p.
102063
.
Bandara
,
R.
,
Fernando
,
M.
and
Akter
,
S.
(
2021
), “
Construing online consumers’ information privacy decisions: the impact of psychological distance
”,
Information and Management
, Vol.
58
No.
7
, p.
103497
.
BBC
(
2018
), “
Facebook security breach: up to 50m accounts attacked
”,
available at:
Link to Facebook security breach: up to 50m accounts attackedLink to the cited article. (
accessed
13 June 2025).
Bejar
,
A.H.C.
,
Ray
,
S.
and
Huang
,
Y.H.
(
2023
), “
Fighting for the status quo: threat to tech self-esteem and opposition to competing smartphones
”,
Information and Management
, Vol.
60
No.
2
, p.
103748
.
Bélanger
,
F.
and
James
,
T.L.
(
2020
), “
A theory of multilevel information privacy management for the digital era
”,
Information Systems Research
, Vol.
31
No.
2
, pp.
510
-
536
.
Bhattacherjee
,
A.
(
2001
), “
Understanding information systems continuance: an expectation-confirmation model
”,
MIS Quarterly
, Vol.
25
No.
3
, pp.
351
-
370
.
Bhattacherjee
,
A.
,
Davis
,
C.J.
,
Connolly
,
A.J.
and
Hikmet
,
N.
(
2018
), “
User response to mandatory IT use: a coping theory perspective
”,
European Journal of Information Systems
, Vol.
27
No.
4
, pp.
395
-
414
.
Blunt
,
P.
(
1988
), “
Cultural consequences for organization change in a southeast Asian state: Brunei
”,
Academy of Management Perspectives
, Vol.
2
No.
3
, pp.
235
-
240
.
Brown
,
A.J.
(
2020
), “
Should I stay or should I leave?’: exploring (dis) continued Facebook use after the Cambridge Analytica scandal
”,
Social Media + Society
, Vol.
6
No.
1
, p.
2056
.
Chen
,
Q.
,
Feng
,
Y.
,
Liu
,
L.
and
Tian
,
X.
(
2019
), “
Understanding consumers’ reactance of online personalized advertising: a new scheme of rational choice from a perspective of negative effects
”,
International Journal of Information Management
, Vol.
44
, pp.
53
-
64
.
Cheng
,
X.
,
Hou
,
T.
and
Mou
,
J.
(
2021
), “
Investigating perceived risks and benefits of information privacy disclosure in IT-enabled ride-sharing
”,
Information and Management
, Vol.
58
No.
6
, p.
103450
.
Cho
,
H.
,
Li
,
P.
and
Goh
,
Z.H.
(
2020
), “
Privacy risks, emotions, and social media: a coping model of online privacy
”,
ACM Transactions on Computer-Human Interaction (TOCHI)
, Vol.
27
No.
6
, pp.
1
-
28
.
Choi
,
B.
,
Wu
,
Y.
,
Yu
,
J.
and
Land
,
L.P.W.
(
2018
), “
Love at first sight: the interplay between privacy dispositions and privacy calculus in online social connectivity management
”,
Journal of the Association for Information Systems
, Vol.
19
No.
3
, pp.
124
-
151
.
Cichy
,
P.
,
Salge
,
T.O.
and
Kohli
,
R.
(
2021
), “
Privacy concerns and data sharing in the internet of things: mixed methods evidence from connected cars
”,
MIS Quarterly
, Vol.
45
No.
4
, p.
1863
.
Cram
,
W.A.
,
Proudfoot
,
J.G.
and
D’Arcy
,
J.
(
2021
), “
When enough is enough: investigating the antecedents and consequences of information security fatigue
”,
Information Systems Journal
, Vol.
31
No.
4
, pp.
521
-
549
.
Crossler
,
R.E.
and
Bélanger
,
F.
(
2019
), “
Why would I use location-protective settings on my smartphone? Motivating protective behaviors and the existence of the privacy knowledge–belief gap
”,
Information Systems Research
, Vol.
30
No.
3
, pp.
995
-
1006
.
Culnan
,
M.J.
and
Bies
,
R.J.
(
2003
), “
Consumer privacy: balancing economic and justice considerations
”,
Journal of Social Issues
, Vol.
59
No.
2
, pp.
323
-
342
.
Davis
,
F.D.
,
Bagozzi
,
R.P.
and
Warshaw
,
P.R.
(
1992
), “
Extrinsic and intrinsic motivation to use computers in the workplace 1
”,
Journal of Applied Social Psychology
, Vol.
22
No.
14
, pp.
1111
-
1132
.
Degirmenci
,
K.
(
2020
), “
Mobile users’ information privacy concerns and the role of app permission requests
”,
International Journal of Information Management
, Vol.
50
, pp.
261
-
272
.
Demmers
,
J.
,
Van Dolen
,
W.M.
and
Weltevreden
,
J.W.
(
2018
), “
Handling consumer messages on social networking sites: customer service or privacy infringement?
”,
International Journal of Electronic Commerce
, Vol.
22
No.
1
, pp.
8
-
35
.
Dhir
,
A.
,
Kaur
,
P.
,
Chen
,
S.
and
Pallesen
,
S.
(
2019
), “
Antecedents and consequences of social media fatigue
”,
International Journal of Information Management
, Vol.
48
, pp.
193
-
202
.
Dietvorst
,
B.J.
,
Simmons
,
J.P.
and
Massey
,
C.
(
2018
), “
Overcoming algorithm aversion: people will use imperfect algorithms if they can (even slightly) modify them
”,
Management Science
, Vol.
64
No.
3
, pp.
1155
-
1170
.
Dinev
,
T.
and
Hart
,
P.
(
2006
), “
An extended privacy calculus model for e-commerce transactions
”,
Information Systems Research
, Vol.
17
No.
1
, pp.
61
-
80
.
European Commission
(
2024
), “
Data act
”,
available at:
Link to Data actLink to the cited article. (
accessed
6 April 2024).
Farivar
,
S.
,
Turel
,
O.
and
Yuan
,
Y.
(
2018
), “
Skewing users’ rational risk considerations in social commerce: an empirical examination of the role of social identification
”,
Information & Management
, Vol.
55
No.
8
, pp.
1038
-
1048
.
Festinger
,
L.
(
1962
), “
Cognitive dissonance
”,
Scientific American
, Vol.
207
No.
4
, pp.
93
-
106
.
Folkman
,
S.
and
Lazarus
,
R.S.
(
1985
), “
If it changes it must be a process: study of emotion and coping during three stages of a college examination
”,
Journal of Personality and Social Psychology
, Vol.
48
No.
1
, pp.
150
-
170
.
Fox
,
G.
and
Connolly
,
R.
(
2018
), “
Mobile health technology adoption across generations: narrowing the digital divide
”,
Information Systems Journal
, Vol.
28
No.
6
, pp.
995
-
1019
.
Fox
,
G.
,
Clohessy
,
T.
,
van der Werff
,
L.
,
Rosati
,
P.
and
Lynn
,
T.
(
2021
), “
Exploring the competing influences of privacy concerns and positive beliefs on citizen acceptance of contact tracing mobile applications
”,
Computers in Human Behavior
, Vol.
121
, p.
106806
.
Fullwood
,
C.
,
Chadwick
,
D.
,
Keep
,
M.
,
Attrill-Smith
,
A.
,
Asbury
,
T.
and
Kirwan
,
G.
(
2019
), “
Lurking towards empowerment: explaining propensity to engage with online health support groups and its association with positive outcomes
”,
Computers in Human Behavior
, Vol.
90
, pp.
131
-
140
.
Gao
,
B.M.
,
Liu
,
M.T.
and
Chu
,
R.
(
2023
), “
Information disclosing willingness in mobile internet contexts
”,
Asia Pacific Journal of Marketing and Logistics
, Vol.
35
No.
1
, pp.
108
-
129
.
GDPR
,
E.U.
(
2018
), “
What is GDPR, the EU’s new data protection law?
”,
available at:
Link to What is GDPR, the EU’s new data protection law?Link to the cited article. (
accessed
12 June 2025).
Gómez-Hurtado
,
C.
,
Gálvez-Sánchez
,
F.J.
,
Prados-Peña
,
M.B.
and
Ortíz-Zamora
,
A.F.
(
2024
), “
Adoption of e-wallets: trust and perceived risk in generation Z in Colombia
”,
Spanish Journal of Marketing - ESIC
.
Hayes
,
J.L.
,
Brinson
,
N.H.
,
Bott
,
G.J.
and
Moeller
,
C.M.
(
2021
), “
The influence of consumer–brand relationship on the personalized advertising privacy calculus in social media
”,
Journal of Interactive Marketing
, Vol.
55
No.
1
, pp.
16
-
30
.
Hernández-Tamurejo
,
Á.
,
González-Padilla
,
P.
and
Sepúlveda
,
Á.S.
(
2025
), “
The economics of AI adoption in OTAs: market dynamics and future research
”,
Global Economics Research
, Vol.
1
No.
1
, p.
100001
.
Hew
,
J.J.
,
Leong
,
L.Y.
,
Tan
,
G.W.H.
,
Ooi
,
K.B.
and
Lee
,
V.H.
(
2019
), “
The age of mobile social commerce: an artificial neural network analysis on its resistances
”,
Technological Forecasting and Social Change
, Vol.
144
, pp.
311
-
324
.
Hollebeek
,
L.D.
,
Sarstedt
,
M.
,
Menidjel
,
C.
,
Sprott
,
D.E.
and
Urbonavicius
,
S.
(
2023
), “
Hallmarks and potential pitfalls of customer‐and consumer engagement scales: a systematic review
”,
Psychology and Marketing
, Vol.
40
No.
6
, pp.
1074
-
1088
.
Hong
,
W.
and
Thong
,
J.Y.
(
2013
), “
Internet privacy concerns: an integrated conceptualization and four empirical studies
”,
MIS Quarterly
, Vol.
37
No.
1
, pp.
275
-
298
.
Ioannou
,
A.
,
Tussyadiah
,
I.
and
Lu
,
Y.
(
2020
), “
Privacy concerns and disclosure of biometric and behavioral data for travel
”,
International Journal of Information Management
, Vol.
54
, p.
102122
.
Janakiraman
,
R.
,
Lim
,
J.H.
and
Rishika
,
R.
(
2018
), “
The effect of a data breach announcement on customer behavior: evidence from a multichannel retailer
”,
Journal of Marketing
, Vol.
82
No.
2
, pp.
85
-
105
.
Johnson
,
G.A.
,
Shriver
,
S.K.
and
Du
,
S.
(
2020
), “
Consumer privacy choice in online advertising: who opts out and at what cost to industry?
”,
Marketing Science
, Vol.
39
No.
1
, pp.
33
-
51
.
Jozani
,
M.
,
Ayaburi
,
E.
,
Ko
,
M.
and
Choo
,
K.K.R.
(
2020
), “
Privacy concerns and benefits of engagement with social media-enabled apps: a privacy calculus perspective
”,
Computers in Human Behavior
, Vol.
107
, p.
106260
.
Jung
,
Y.
and
Park
,
J.
(
2018
), “
An investigation of relationships among privacy concerns, affective responses, and coping behaviors in location-based services
”,
International Journal of Information Management
, Vol.
43
, pp.
15
-
24
.
Kaman
,
K.
and
Deshmukh
,
A.K.
(
2025
), “
Navigating the digital frontier: understanding shopping behavior in the metaverse through an SLR lens
”,
Spanish Journal of Marketing-ESIC
.
Ketelaar
,
P.E.
and
Van Balen
,
M.
(
2018
), “
The smartphone as your follower: the role of smartphone literacy in the relation between privacy concerns, attitude and behaviour towards phone-embedded tracking
”,
Computers in Human Behavior
, Vol.
78
, pp.
174
-
182
.
Kim
,
K.H.
,
Kim
,
K.J.
,
Lee
,
D.H.
and
Kim
,
M.G.
(
2019
), “
Identification of critical quality dimensions for continuance intention in mHealth services: case study of onecare service
”,
International Journal of Information Management
, Vol.
46
, pp.
187
-
197
.
Kim
,
M.S.
and
Kim
,
S.
(
2018
), “
Factors influencing willingness to provide personal information for personalized recommendations
”,
Computers in Human Behavior
, Vol.
88
, pp.
143
-
152
.
Kitchenham
,
B.
and
Brereton
,
P.
(
2013
), “
A systematic review of systematic review process research in software engineering
”,
Information and Software Technology
, Vol.
55
No.
12
, pp.
2049
-
2075
.
Koohang
,
A.
,
Sargent
,
C.S.
,
Nord
,
J.H.
and
Paliszkiewicz
,
J.
(
2022
), “
Internet of Things (IoT): from awareness to continued use
”,
International Journal of Information Management
, Vol.
62
, p.
102442
.
Koohikamali
,
M.
,
French
,
A.M.
and
Kim
,
D.J.
(
2019
), “
An investigation of a dynamic model of privacy trade-off in use of mobile social network applications: a longitudinal perspective
”,
Decision Support Systems
, Vol.
119
, pp.
46
-
59
.
Kumar
,
V.
,
Rajan
,
B.
,
Salunkhe
,
U.
and
Joag
,
S.G.
(
2022
), “
Relating the dark side of new‐age technologies and customer technostress
”,
Psychology and Marketing
, Vol.
39
No.
12
, pp.
2240
-
2259
.
Lariscy
,
R.A.W.
and
Tinkham
,
S.F.
(
1999
), “
The sleeper effect and negative political advertising
”,
Journal of Advertising
, Vol.
28
No.
4
, pp.
13
-
30
.
Laukkanen
,
T.
and
Kiviniemi
,
V.
(
2010
), “
The role of information in mobile banking resistance
”,
International Journal of Bank Marketing
, Vol.
28
No.
5
, pp.
372
-
388
.
Liang
,
H.
,
Xue
,
Y.
,
Pinsonneault
,
A.
and
Wu
,
Y.A.
(
2019
), “
What users do besides problem-focused coping when facing IT security threats: an emotion-focused coping perspective
”,
MIS Quarterly
, Vol.
43
No.
2
, pp.
373
-
394
.
Libaque-Sáenz
,
C.F.
,
Wong
,
S.F.
,
Chang
,
Y.
and
Bravo
,
E.R.
(
2021
), “
The effect of Fair information practices and data collection methods on privacy-related behaviors: a study of Mobile apps
”,
Information & Management
, Vol.
58
No.
1
, p.
103284
.
Lin
,
S.
and
Armstrong
,
D.
(
2019
), “
Beyond information: the role of territory in privacy management behavior on social networking sites
”,
Journal of the Association for Information Systems
, Vol.
20
No.
4
, pp.
434
-
475
.
Lin
,
X.
and
Wang
,
X.
(
2020
), “
Examining gender differences in people’s information sharing decisions on social networking sites
”,
International Journal of Information Management
, Vol.
50
, pp.
45
-
56
.
Liu
,
B.
,
Miltgen
,
C.L.
and
Xia
,
H.
(
2022
), “
Disclosure decisions and the moderating effects of privacy feedback and choice
”,
Decision Support Systems
, Vol.
155
, p.
113717
.
Liu
,
M.T.
,
Xue
,
J.
and
Chen
,
A.N.
(
2023
), “
Influencing factors of e-payment behavior: an empirical study in Macau’s Y and Z generations
”,
International Journal of Mobile Communications
, Vol.
21
No.
1
, pp.
74
-
94
.
Liu
,
J.
(
2021
), “
Deconstructing search tasks in interactive information retrieval: a systematic review of task dimensions and predictors
”,
Information Processing and Management
, Vol.
58
No.
3
, p.
102522
.
Lolich
,
L.
,
Riccò
,
I.
,
Deusdad
,
B.
and
Timonen
,
V.
(
2019
), “
Embracing technology? Health and social care professionals’ attitudes to the deployment of e-health initiatives in elder care services in Catalonia and Ireland
”,
Technological Forecasting and Social Change
, Vol.
147
, pp.
63
-
71
.
McLean
,
G.
and
Osei-Frimpong
,
K.
(
2019
), “
Hey Alexa… examine the variables influencing the use of artificial intelligent in-home voice assistants
”,
Computers in Human Behavior
, Vol.
99
, pp.
28
-
37
.
Mamonov
,
S.
and
Benbunan-Fich
,
R.
(
2018
), “
The impact of information security threat awareness on privacy-protective behaviors
”,
Computers in Human Behavior
, Vol.
83
, pp.
32
-
44
.
Meta
(
2025
), “
Reflecting on Meta’s $8 billion investment in privacy
”,
available at:
Link to Reflecting on Meta’s $8 billion investment in privacyLink to the cited article. (
accessed
13 June 2025).
Miltgen
,
C.L.
and
Smith
,
H.J.
(
2019
), “
Falsifying and withholding: exploring individuals’ contextual privacy-related decision-making
”,
Information and Management
, Vol.
56
No.
5
, pp.
696
-
717
.
Mousavi
,
R.
,
Chen
,
R.
,
Kim
,
D.J.
and
Chen
,
K.
(
2020
), “
Effectiveness of privacy assurance mechanisms in users’ privacy protection on social networking sites from the perspective of protection motivation theory
”,
Decision Support Systems
, Vol.
135
, p.
113323
.
Mwangi
,
V.N.
,
Millard
,
R.
and
Histon
,
W.
(
2024
), “
Prevalent elements of consumer wellbeing in wearable technology use: an interdisciplinary systematic review and future research agenda
”,
Psychology and Marketing
, Vol.
41
No.
5
, pp.
973
-
1188
.
Nass
,
C.
,
Fogg
,
B.J.
and
Moon
,
Y.
(
1996
), “
Can computers be teammates?
”,
International Journal of Human-Computer Studies
, Vol.
45
No.
6
, pp.
669
-
678
.
Naz
,
H.
and
Kashif
,
M.
(
2025
), “
Artificial intelligence and predictive marketing: an ethical framework from managers’ perspective
”,
Spanish Journal of Marketing - ESIC
, Vol.
29
No.
1
, pp.
22
-
45
.
Nunes
,
J.C.
and
Dreze
,
X.
(
2006
), “
The endowed progress effect: how artificial advancement increases effort
”,
Journal of Consumer Research
, Vol.
32
No.
4
, pp.
504
-
512
.
Ogbanufe
,
O.
(
2023
), “
Securing online accounts and assets: an examination of personal investments and protection motivation
”,
International Journal of Information Management
, Vol.
68
, p.
102590
.
Ortiz
,
J.
,
Chih
,
W.H.
and
Tsai
,
F.S.
(
2018
), “
Information privacy, consumer alienation, and lurking behavior in social networking sites
”,
Computers in Human Behavior
, Vol.
80
, pp.
143
-
157
. "
Ou
,
C.X.
,
Zhang
,
X.
,
Angelopoulos
,
S.
,
Davison
,
R.M.
and
Janse
,
N.
(
2022
), “
Security breaches and organization response strategy: exploring consumers’ threat and coping appraisals
”,
International Journal of Information Management
, Vol.
65
, p.
102498
.
Park
,
Y. J.
and
Shin
,
D.D.
(
2020
), “
Contextualizing privacy on health-related use of information technology
”,
Computers in Human Behavior
, Vol.
105
, p.
106204
.
Park
,
Y.J.
(
2022
), “
Personal data concern, behavioral puzzle and uncertainty in the age of digital surveillance
”,
Telematics and Informatics
, Vol.
66
, p.
101748
.
Pirkkalainen
,
H.
,
Salo
,
M.
,
Tarafdar
,
M.
and
Makkonen
,
M.
(
2019
), “
Deliberate or instinctive? Proactive and reactive coping for technostress
”,
Journal of Management Information Systems
, Vol.
36
No.
4
, pp.
1179
-
1212
.
Prakash
,
A.V.
and
Das
,
S.
(
2022
), “
Explaining citizens’ resistance to use digital contact tracing apps: a mixed-methods study
”,
International Journal of Information Management
, Vol.
63
, p.
102468
.
Raddatz
,
N.
,
Coyne
,
J.
,
Menard
,
P.
and
Crossler
,
R.E.
(
2023
), “
Becoming a blockchain user: understanding consumers’ benefits realisation to use blockchain-based applications
”,
European Journal of Information Systems
, Vol.
32
No.
2
, pp.
287
-
314
.
Rogers
,
E.M.
,
Singhal
,
A
, and
Quinlan
,
M.M.
(
2014
), “Diffusion of innovations”,
Stacks
,
D.W.
and
Salwen
,
M.B.
(Eds),
An Integrated Approach to Communication Theory and Research
,
Routledge, New York, NY
, pp.
432
-
448
.
Rogers
,
R.W.
and
Prentice-Dunn
,
S.
(
1997
), “Protection motivation theory”,
Gochman
,
D. S.
(Ed.),
Handbook of Health Behavior Research 1: Personal and Social Determinants
,
Plenum Press
,
New York, NY
, pp.
113
-
132
.
Saavedra
,
Á.
,
Chocarro
,
R.
,
Cortiñas
,
M.
and
Rubio
,
N.
(
2024
), “
Impact of process and outcome quality on intention for continued use of voice assistants
”,
Spanish Journal of Marketing - ESIC
, Vol.
28
No.
4
, pp.
402
-
419
.
Samuelson
,
W.
and
Zeckhauser
,
R.
(
1988
), “
Status quo bias in decision making
”,
Journal of Risk and Uncertainty
, Vol.
1
No.
1
, pp.
7
-
59
.
Sánchez
,
M.
(
2022
), “
A general approach on privacy and its implications in the digital economy
”,
Journal of Economic Issues
, Vol.
56
No.
1
, pp.
244
-
258
.
Sandhu
,
R.K.
,
Vasconcelos-Gomes
,
J.
,
Thomas
,
M.A.
and
Oliveira
,
T.
(
2023
), “
Unfolding the popularity of video conferencing apps–a privacy calculus perspective
”,
International Journal of Information Management
, Vol.
68
, p.
102569
.
Saura
,
J.R.
,
Ribeiro-Soriano
,
D.
and
Palacios-Marqués
,
D.
(
2022
), “
Assessing behavioral data science privacy issues in government artificial intelligence deployment
”,
Government Information Quarterly
, Vol.
39
No.
4
, p.
101679
.
Saura
,
J.R.
,
Škare
,
V.
and
Dosen
,
D.O.
(
2024
), “
Is AI-based digital marketing ethical? Assessing a new data privacy paradox
”,
Journal of Innovation and Knowledge
, Vol.
9
No.
4
, p.
100597
.
Shatila
,
K.
,
Aránega
,
A.Y.
and
Urueña
,
R.C.
(
2025
), “
The role of digital transformation in shaping academic entrepreneurship
”,
Global Economics Research
, Vol.
1
No.
1
, p.
100002
.
Shaw
,
N.
and
Sergueeva
,
K.
(
2019
), “
The non-monetary benefits of mobile commerce: extending UTAUT2 with perceived value
”,
International Journal of Information Management
, Vol.
45
, pp.
44
-
55
.
Shin
,
D.
,
Kee
,
K. F.
and
Shin
,
E.Y.
(
2022
), “
Algorithm awareness: why user awareness is critical for personal privacy in the adoption of algorithmic platforms?
”,
International Journal of Information Management
, Vol.
65
, p.
102494
.
Shoukat
,
M.H.
,
Elgammal
,
I.
,
Selem
,
K.M.
and
Shehata
,
A.E.
(
2025
), “
Fostering social media user intentions: AI-enabled privacy and intrusiveness concerns
”,
Spanish Journal of Marketing - ESIC
, Vol.
29
No.
2
, pp.
253
-
269
.
Siddaway
,
A.P.
,
Wood
,
A.M.
and
Hedges
,
L.V.
(
2019
), “
How to do a systematic review: a best practice guide for conducting and reporting narrative reviews, meta-analyses, and meta-syntheses
”,
Annual Review of Psychology
, Vol.
70
No.
1
, pp.
747
-
770
.
Song
,
X.
,
Liu
,
M.T.
,
Lee
,
V.
and
Mo
,
Z.
(
2025a
), “
Recommendation agents (RAs) in interactive online retailing: an investigation on consumers’ shunning recommended products
”,
Journal of Research in Interactive Marketing
.
Song
,
X.
,
Liu
,
M.T.
,
McCartney
,
G.J.
,
Xian
,
X.
and
Chang
,
A.
(
2025b
), “
Revisiting privacy in interactive marketing: perspectives from Asian consumers
”,
Journal of Research in Interactive Marketing
, Vol.
19
No.
8
.
Song
,
X.
,
Liu
,
M.T.
and
Sajtos
,
L.
(
2025c
), “
Privacy with multi-dimensions: a literature review with text-mining approach
”,
Journal of Research in Interactive Marketing. Ahead-of-Print
.
Statista
(
2024
), “
Number of facebook users in the United States from 2019 to 2028
”,
available at:
Link to Number of facebook users in the United States from 2019 to 2028Link to the cited article. (
accessed
16 June 2025).
Strycharz
,
J.
,
Smit
,
E.
,
Helberger
,
N.
and
van Noort
,
G.
(
2021
), “
No to cookies: empowering impact of technical and legal knowledge on rejecting tracking cookies
”,
Computers in Human Behavior
, Vol.
120
, p.
106750
.
Suen
,
H.Y.
(
2018
), “
How passive job candidates respond to social networking site screening
”,
Computers in Human Behavior
, Vol.
85
, pp.
396
-
404
.
Tang
,
Y.
and
Ning
,
X.
(
2023
), “
Understanding user misrepresentation behavior on social apps: the perspective of privacy calculus theory
”,
Decision Support Systems
, Vol.
165
, p.
113881
.
Tsay-Vogel
,
M.
,
Shanahan
,
J.
and
Signorielli
,
N.
(
2018
), “
Social media cultivating perceptions of privacy: a 5-year analysis of privacy attitudes and self-disclosure behaviors among Facebook users
”,
New Media & Society
, Vol.
20
No.
1
, pp.
141
-
161
.
Tseng
,
H.T.
,
Ibrahim
,
F.
,
Hajli
,
N.
,
Nisar
,
T.M.
and
Shabbir
,
H.
(
2022
), “
Effect of privacy concerns and engagement on social support behaviour in online health community platforms
”,
Technological Forecasting and Social Change
, Vol.
178
, p.
121592
.
Turel
,
O.
(
2015
), “
Quitting the use of a habituated hedonic information system: a theoretical model and empirical examination of facebook users
”,
European Journal of Information Systems
, Vol.
24
No.
4
, pp.
431
-
446
.
Turjeman
,
D.
and
Feinberg
,
F.M.
(
2023
), “
When the data are out: measuring behavioral changes following a data breach
”,
Marketing Science
, Vol.
43
No.
2
, pp.
440
-
461
.
Vimalkumar
,
M.
,
Sharma
,
S.K.
,
Singh
,
J.B.
and
Dwivedi
,
Y.K.
(
2021
), “
Okay google, what about my privacy?’: user’s privacy perceptions and acceptance of voice based digital assistants
”,
Computers in Human Behavior
, Vol.
120
, p.
106763
.
Wagner
,
A.
,
Wessels
,
N.
,
Brakemeier
,
H.
and
Buxmann
,
P.
(
2021
), “
Why free does not mean fair: investigating users’ distributive equity perceptions of data-driven services
”,
International Journal of Information Management
, Vol.
59
, p.
102333
.
Wang
,
L.
,
Luo
,
X.R.
,
Yang
,
X.
and
Qiao
,
Z.
(
2019
), “
Easy come or easy go? Empirical evidence on switching behaviors in mobile payment applications
”,
Information and Management
, Vol.
56
No.
7
, p.
103150
.
Wang
,
S.
and
Liu
,
M.T.
(
2023
), “
Celebrity endorsement in marketing from 1960 to 2021: a bibliometric review and future agenda
”,
Asia Pacific Journal of Marketing and Logistics
, Vol.
35
No.
4
, pp.
849
-
873
.
Wang
,
S.
,
Liu
,
M.T.
and
Pérez
,
A.
(
2023
), “
A bibliometric analysis of green marketing in marketing and related fields: from 1991 to 2021
”,
Asia Pacific Journal of Marketing and Logistics
, Vol.
35
No.
8
, pp.
1857
-
1882
.
Wang
,
Y.
,
Pan
,
Y.
,
Yan
,
M.
,
Su
,
Z.
and
Luan
,
T.H.
(
2023
), “
A survey on ChatGPT: AI-generated contents, challenges, and solutions
”,
IEEE Open Journal of the Computer Society
, Vol.
4
, pp.
280
-
302
.
Westin
,
A.F.
(
2003
), “
Social and political dimensions of privacy
”,
Journal of Social Issues
, Vol.
59
No.
2
, pp.
431
-
453
.
Wottrich
,
V.M.
,
van Reijmersdal
,
E.A.
and
Smit
,
E.G.
(
2018
), “
The privacy trade-off for mobile app downloads: the roles of app value, intrusiveness, and privacy concerns
”,
Decision Support Systems
, Vol.
106
, pp.
44
-
52
.
Wu
,
D.
,
Moody
,
G.D.
,
Zhang
,
J.
and
Lowry
,
P.B.
(
2020
), “
Effects of the design of mobile security notifications and mobile app usability on users’ security perceptions and continued use intention
”,
Information and Management
, Vol.
57
No.
5
, p.
103235
.
Xiao
,
L.
and
Mou
,
J.
(
2019
), “
Social media fatigue-technological antecedents and the moderating roles of personality traits: the case of WeChat
”,
Computers in Human Behavior
, Vol.
101
, pp.
297
-
310
.
Xiong
,
J.
and
Zuo
,
M.
(
2023
), “
Factors influencing health care professionals’ adoption of mobile platform of medical and senior care in China
”,
Information and Management
, Vol.
60
No.
5
, p.
103798
.
Yang
,
Q.
,
Gong
,
X.
,
Zhang
,
K.Z.
,
Liu
,
H.
and
Lee
,
M.K.
(
2020
), “
Self-disclosure in mobile payment applications: common and differential effects of personal and proxy control enhancing mechanisms
”,
International Journal of Information Management
, Vol.
52
, p.
102065
.
Zeng
,
F.
,
Ye
,
Q.
,
Yang
,
Z.
,
Li
,
J.
and
Song
,
Y.A.
(
2020
), “
Which privacy policy works, privacy assurance or personalization declaration? An investigation of privacy policies and privacy concerns
”,
Journal of Business Ethics
, Vol.
176
No.
4
, pp.
781
-
798
.
Zhang
,
J.
,
Luximon
,
Y.
and
Li
,
Q.
(
2022
), “
Seeking medical advice in mobile applications: how social cue design and privacy concerns influence trust and behavioral intention in impersonal patient–physician interactions
”,
Computers in Human Behavior
, Vol.
130
, p.
107178
.
Zhu
,
Y.Q.
and
Kanjanamekanant
,
K.
(
2021
), “
No trespassing: exploring privacy boundaries in personalized advertisement and its effects on ad attitude and purchase intentions on social media
”,
Information and Management
, Vol.
58
No.
2
, p.
103314
.
Table A1.

Summary of selected recent research of OPC in human–computer interactions

Author (year)ContextTheoretical underpinNomologic network of OPC: A = antecedent ME = mediator MO = moderator O = outcomeMajor findingsJournal in abbr.
Agnihotri and Bhattacharya (2023) ChatbotComputer are social actors (CASA) theoryA: Perceived privacy concern, anthropomorphism, perceived empathy ME: Perceived trustworthiness MO: NA O: Consumer forgiveness, WOMPerceived privacy concern influenced only perceived ability and not benevolence and integrity of the chatbot to influence consumer forgiveness and spread negative word of mouthInt. J. Inf. Manage
Xiong and Zuo (2023) Medical and senior care service platformValue-based adoption modelA: Privacy concerns, legal concerns, perceived efforts, outcome expectations, perceived mobility ME: Perceived value MO: NA O: Intention to adoptPerceived value and legal concerns can predict health care professionals’ intention to adopt. Outcome expectations, perceived mobility, perceived effort and privacy concerns can predict perceived valueInf. Manage
Sandhu et al. (2023) Video conferencing appPrivacy calculus theory; Social presence theoryA: Mobile user information privacy concerns, ubiquity, social presence ME: Trust, perceived risks, perceived value, perceived benefits MO: Ubiquity, technicality O: Continuance intentionThe study emphasizes the promotion of privacy protection at the organizational level, control mechanisms that motivate employees to actively engage in privacy protection behavior and a multi-faceted approach for data transparency within the VC app platformsInt. J. Inf. Manage
Ogbanufe (2023) Online accountProtection motivation theoryA: Investment size ME: Perceived threat severity, perceived threat vulnerability, self-efficacy, response cost, response efficiency MO: NA O: Protection motivation, useInvestment size influences threat and coping appraisals, which in turn increases protection motivation and use. These results highlight the importance of eliciting individuals’ personal investments to improve their protective security behaviorsInt. J. Inf. Manage
Tang and Ning (2023) Social appPrivacy calculus theoryA: Perceived privacy control, disposition to value privacy, app permission sensitivity, perceived effectiveness of privacy policy ME: Privacy concerns, social rewards, personalized benefits MO: NA O: Misinterpretation behaviorBoth privacy concerns and social rewards motivate users to engage in misrepresentation behavior, while personalized benefits discourage users from doing so.  Perceived privacy control and app permission sensitivity influence privacy concerns significantly, while disposition to value privacy and perceived effectiveness of privacy policies have nonsignificant effects on privacy concernsDecis. Support syst
Tseng et al. (2022) Online health community platformSocial support theoryA: Perceived control of information, perceived privacy risk, community engagement ME: Informational support, Emotional support MO: NA O: Intention to participateCommunity engagement and privacy concerns can influence certain social support (e.g. information or emotional support), leading to OHC members’ intention to participateTechnol. Forecast. Soc. Change
Prakash and Das (2022) Digital contact tracing appsInnovation resistance theory; distrust theoryA: Information privacy concern, government surveillance concern, security risk, usage barrier, complexity barrier, value barrier ME: Distrust MO: NA O: Resistance, intention to useDistrust, value barrier, information privacy concerns and usage barrier predicted the resistance to the DCT app, and resistance, in turn, predicted intention to use. Distrust was a key mediator between innovation barriers and resistanceInt. J. Inf. Manage
Shin et al. (2022) Personalized algorithmsPrivacy calculus theoryA: Algorithm awareness (AA) ME: Privacy concerns, efficacy MO: NA O: User self-disclosureAA leads users to envisage, understand and interact with algorithms depending on their efficacy of understanding. AA influences the trust of algorithmic processes and the way users evaluate privacy concerns and self-disclosuresInt. J. Inf. Manage
Liu et al. (2022) Mobile commerceJustice theoryA: Perceived justice, privacy invasion experience ME: Perceived privacy MO: Privacy feedback, choice (presence/absence) O: User self-disclosurePerceived justice determines perceived privacy, which shapes disclosure intentions. Privacy feedback enhances the positive effect of perceived justice on perceived privacy and the effect of trust propensity on disclosure intention and alleviates the negative effect of privacy experience on perceived privacyDecis. Support syst
Ou et al. (2022) Breach securityProtection motivation theoryA: Security breach, response strategy ME: Perceived risk, perceived severity, response efficacy MO: NA O: Re-transaction intentionThe variations in the response strategy of organization after a security breach can lead to significantly different consumers’ reactionsInt. J. Inf. Manage
Zhang et al. (2022) Mobile medical consultationSocial presence theoryA: Social presence of the interface, social presence of the interaction, social validation ME: Privacy concerns, trust in physicians, trust in applications MO: NA O: Intention to disclose, intention to continuously use, intention to follow adviceThe social cue design factors influence Two types of trust and decrease privacy concerns. Privacy concerns hinder both types of trust. The impacts of the Two types of trust on patients’ intention to continue using the service, disclose information and follow medical advice are revealedComput. Hum. Behav
Koohang et al. (2022) IoTA: IoT awareness ME: IoT privacy knowledge, IoT security knowledge, trust MO: NA O: Continued intention to useIoT awareness can positively influence users’ knowledge of IoT privacy and security. The users’ knowledge of IoT privacy and security can positively influence users’ IoT trust and subsequently, the users’ IoT trust can positively influence continued intention to use IoTInt. J. Inf. Manage
Alraja (2022) IoT-based health application (HA)Privacy calculus theory; theory of planned behaviorA: Privacy, security, trust ME: Risk perception, attitude MO: Gender O: Behavioral intentionThere were gender differences in gen Y, but there was little evidence that risk perception affects any of the cohort’s behavioral intention towards the use of IoT-enabled HATechnol. Forecast. Soc. Change
Ameen et al. (2022) Smart shopping mallTrust-commitment theory; privacy calculus theoryA: Interface design, trust, consumer peer interaction, relationship commitment ME: Personalization MO: Privacy concerns O: LoyaltyThere were significant mediating effects of personalization on the positive relationships between interface design, trust, consumer peer interaction and relationship commitment and shopping mall loyalty. Privacy concerns, unlike prior research, do not exert a moderating roleComput. Hum. Behav
Cichy et al. (2021) IoT-based connected carProposed extended model from privacy calculusA: Psychological ownership, relational trust, data sensitivity, data security ME: Privacy concerns MO: Self-efficacy enhancement, self-image congruency O: Sharing of personal dataOur findings highlight the interplay between virtual and physical risks in shaping drivers’ privacy concerns and data sharing decisions—with information privacy and data security emerging as discrete yet closely interrelated concepts. Psychological ownership is an important addition to established privacy calculus models of data sharingMIS Q
Wagner et al. (2021) Data-driven service appEquity theoryA: Users’ net value, providers’ net value ME: Distributive equity MO: Information sensitivity O: Continuance intention; satisfactionUsers balance their own net value (benefits minus risks) as well as providers’ net value from monetizing users’ data The relationship between provider’s net value based on users’ information and distributive equity is moderated by information sensitivityInt. J. Inf. Manage
Zhu and Kanjanamekanant (2021) Personalized adsCommunication privacy management theoryA: Information co-ownership, personification, internal data source, ad embarrassment ME: Perceived privacy, ad attitude MO: Information co-ownership, personification O: Purchase intentionPersonalized ads based on internal data source, perceived personification and co-ownership of facebook are positively related to perceived privacy, which leads to better ad attitude and higher purchase intentions. Perceived personification and co-ownership further moderate the relationship between internal data source and embarrassment to perceived privacyInf. Manage
Libaque-Sáenz et al. (2021) Mobile appsA: Fair information practices (FIPs), automatic data collection (AUTO) ME: Perceived data control, perceived information risks MO: FIPs, AUTO O: Behavioral intentionBoth intervention strategies (FIPs and AUTO) have a significant effect on perceived data control and perceived risks and in turn on behavioral intentionInf. Manage
Cheng et al. (2021) Ride-sharing platformPrivacy calculus theoryA: Privacy awareness, previous online privacy invasion, mobile payment security, negative media exposure, personal information disclosure requirements, immediate gratification ME: Perceived risks/benefits of information privacy disclosure MO: NA O: Intention to disclosure, disclosurePrivacy awareness, previous online privacy invasion, mobile payment security and negative media exposure influence information disclosure’s perceived risks and that perceived risks and benefits are significantly related to immediate gratificationInf. Manage
Bandara et al. (2021) E-commerceConstrual level theory; power-responsibility equilibrium frameworkA: Privacy concerns ME: Privacy empowerment MO: Psychological distance O: Defensive behaviorPsychological distance moderates the relationship between privacy concerns and privacy behavior.  Empowered consumers’ privacy behavior does not vary despite the degree of psychological distanceInf. Manage
Balapour et al. (2020) Mobile appCommunication privacy management theoryA: Perceived effectiveness of privacy policy ME: Perceived privacy risk MO: Information sensitivity, perceived privacy awareness O: Perceived mobile app securityPerceived privacy risk negatively influences the perceived security of the mobile apps; perceived effectiveness of a privacy policy positively influences user perceptions of mobile app security. Perceived privacy awareness moderates the effect of perceived privacy risk on the perceived security of mobile apps. Users have different privacy-security perceptions based on the information sensitivity of the mobile appsInt. J. Inf. Manage
Ioannou et al. (2020) Online traveling servicePrivacy calculus theoryA: Disposition to privacy, privacy awareness, perceived privacy control, trust, privacy experience, privacy knowledge, privacy protection regulation ME: Online privacy concerns MO: NA O: Willingness to shareTravelers are concerned over their information privacy they are still willing to share their behavioral data. In the case of biometric information, the disclosure decision is dependent upon expected benefits rather than privacy concernsInt. J. Inf. Manage
Degirmenci (2020) App permission requestAntecedents–privacy concerns–outcomes (APCO)A: Prior privacy experience, computer anxiety, perceived control, app permission concerns ME: Privacy concerns, trust, privacy calculus MO: NA O: Intention to acceptPrior privacy experience, computer anxiety and perceived control have significant effects on privacy concerns. However, concerns for app permission requests have approximately twice as much predictive value than the other factors put together to explain mobile users’ overall information privacy concernsInt. J. Inf. Manage
Al-Natour et al. (2020) Mobile appsAgency theory; signaling theoryA: Informational signals, information asymmetry ME: Privacy uncertainty (collection, use, protection), seller uncertainty, product uncertainty MO: NA O: Intention to usePrivacy uncertainty significantly influences users’ intention to use an app above and beyond their uncertainty about the seller and the product. It also affects the perceived risk associated with using an app and the price consumers are willing to payInf. Syst. Res
Zeng et al. (2020) Online privacy policyMotivation theoryA: Privacy assurance, personalization declaration ME: Privacy concerns MO: NA O: Purchase responsesPrivacy assurance negatively affects customers’ purchase probability and purchase amount. Personalization declaration positively affects customers’ purchase probability and purchase amount. Privacy concerns significantly mediate above relationsJ. Bus. Ethics
Lin and Wang (2020) SNSSocial role theory; theory of reasoned actionA: Social presence, privacy risk, social ties, commitment ME: Attitude towards sharing information MO: Gender O: Intention to share informationPrivacy risks, social ties and commitment were more important in the formation of attitudes toward information sharing for women than men. Gender significantly moderates the relationship between people’s perceptions of information sharing and their intention to share informationInt. J. Inf. Manage
Yang et al. (2020) Mobile paymentPrivacy calculus theory; control agency theoryA: Perceived benefits, perceived effectiveness of privacy setting, perceived effectiveness of privacy policy ME: Perceived value, psychological comfort MO: NA O: Intention to disclosePerceived benefits, perceived effectiveness of privacy setting, perceived effectiveness of privacy policy and perceived risks together predict perceived value and psychological comfort, which further determine consumers’ self-disclosureInt. J. Inf. Manage
Wu et al. (2020) Mobile security notificationA: Intrusiveness, app interface usability ME: Perceived security, irritation MO: Disruption O: Continued intention to useBoth app interface usability and the design of MSNs significantly impacted users’ perceived security, which, in turn, has a positive influence on users’ intention to continue using the appInf. Manage
Jozani et al. (2020) Social media appPrivacy calculus theoryA: Privacy risk, privacy control, information sensitivity ME: Institutional privacy concerns, social privacy concerns MO: NA O: EngagementBoth institutional and social privacy concerns decrease engagement. Information sensitivity increases institutional privacy concerns. However, social privacy concerns are influenced by the perception of risk and controlComput. Hum. Behav
Park and Shin (2020) Health-related ITA: Privacy attitudes, perception, evaluation ME: Interest in sharing MO: Medical condition, internet reliance for health  O: EngagementPrivacy concern and confidence are mediated through One’s interest in sharing information with health professionals and moderated by One’s medical condition and the reliance on internetComput. Hum. Behav
Shaw and Sergueeva (2019) Mobile commerceUTAUT2A: Perceived privacy risk, perceived transaction risk, perceived privacy protection ME: Perceived privacy concerns, perceived value MO: Personal innovativeness O: Intention to useBoth paths (perceived privacy concerns to perceived value and performance expectancy to perceived value) were significant. Perceived value motivates customers to use m-commerce and shapes perceptions as they evaluate the trade-off they are makingInt. J. Inf. Manage
Chen et al. (2019) Personalized adsRational choice theoryA: Ownership, vulnerability ME: Privacy concerns, perceived cost of non-personalization, opportunity cost MO: NA O: ReactanceThree rational choice factors from a negative-effect perspective have significant impacts on consumer reactance. Affective factors such as ownership and vulnerability are dominant determinants of these rational choice factorsInt. J. Inf. Manage
Wang and Herrand (2019)S-commercePrivacy-trust-behavioral intention (PTB) modelA: Perceived effectiveness of privacy policy, perceived effectiveness of industry-self regulation ME: Trust MO: NA O: Intention of purchaseInstitutional privacy assurance positively influences institutional-based trust, which, in turn, affects online social interactions and consequently increases the likelihood of product purchases on s-commerce sitesInt. J. Inf. Manage
Crossler and Bélanger (2019) App privacy settingsSelf-efficacy theory; information–motivation–behavioral (IMB) skills modelA: Privacy risk awareness, privacy knowledge, technology knowledge, sharing preference, subjective norm ME: Privacy self-efficacy, technology self-efficacy MO: Privacy knowledge O: Privacy behaviorPersonal motivation is One of the strongest determinants of utilizing privacy-protective settings, and social motivation is not significant. Privacy knowledge and self-efficacy constructs determine One’s use of privacy-protective settings, but knowledge and self-efficacy about smartphone technology do not. An interaction effect exists between privacy knowledge and privacy self-efficacy on privacy behaviorInf. Syst. Res
Lin and Armstrong (2019) SNSCommunication privacy management theoryA: Information privacy concerns, territory privacy concerns ME: Information trusting beliefs, information privacy risk beliefs, territory privacy risk beliefs, territory trusting beliefs MO: NA O: Privacy disclosure, territory coordinationPerceptions of trespassing over agreed-upon virtual boundaries within SNSs affects risk beliefs regarding information privacy and territory privacy differently. These distinct privacy risk beliefs, in turn, influence Two privacy management behaviorsJ. Assoc. Inf. Syst
Kim et al. (2019) Mobile healthRefined SERVQUAL and SERVPERFA: Privacy, content quality, engagement, reliability, usability ME: Satisfaction MO: NA O: Continuance intentionThe quality dimensions (engagement followed by content quality and reliability) have the most considerable effect on continuance intention. By contrast, the effects of usability and privacy on continuance intention were insignificantInt. J. Inf. Manage
Suen (2018) SNS screeningSignaling theoryA: Employer use of SNS screening ME: Perception of privacy violation MO: Ability to control SNS information, transparency level of data collection O: Withdraw intentionA candidate who can better control his/her SNS information is less likely to perceive privacy violation during SNS screening by potential employers, thus mitigating his/her perception of procedural unfairness.  When SNS screening is more transparent, the candidate is less likely to perceive procedural unfairness, which will reduce his/her intention to withdrawComput. Hum. Behav
McLean and Osei-Frimpong (2019) In-home voice assistantUses and gratification theoryA: Utilitarian benefits, hedonic benefits, symbolic benefits, social presence, social attraction ME: NA MO: Perceived privacy risk O: UsageIndividuals are motivated by the utilitarian benefits, symbolic benefits and social benefits. Hedonic benefits only motivate the use of in-home voice assistants in smaller households. The research establishes a moderating role of perceived privacy risks in dampening and negatively influencing the use of in-home voice assistantsComput. Hum. Behav
Ketelaar and Van Balen (2018) Phone-embedded trackingPsychological ownership theory; innovation diffusion theoryA: Privacy concerns ME: Attitude MO: Position on adoption curve O: BehaviorThe more privacy concerns users experience, the more negative their attitudes are towards the collection of location data and that they adjust the settings to prevent being tracked.  Users’ earlier position on the adoption curve, and with that their smartphone literacy, decreases the strength of the connection between privacy concerns and attitudeComput. Hum. Behav
Miltgen and Smith (2019) Commercial websitePrivacy calculus theoryA: Perceived relevance ME: Perceived benefits, perceived risks, trust MO: Manipulated context O: Withholding, falsificationTrust is the most important driver of both withholding and falsification decisions.  Perceived relevance influenced perceived benefits, risks and trustInf. Manage
Xiao and Mou (2019) Social appPerson-environment fit modelA: Anonymity, flexibility, presenteeism ME: Privacy invasion, invasion of life MO: Neuroticism, extraversion O: Social media fatigueAnonymity and presenteeism significantly influence privacy invasion and invasion of life, both of which are determinants of social media fatigue. Neuroticism strengthens the effect of social media characteristics on privacy invasion and invasion of life, while extraversion weakens these effectsComput. Hum. Behav
Farivar et al. (2018) Social commerceSocial identity theoryA: Perceived commerce risk, perceived participation risk ME: NA MO: Social identity O: Intention to purchase, intention to postPerceived commerce risk reduces intentions to purchase, and that perceived participation risk curtails intentions to post comments on social commerce forums. The influence of these risk assessments is reduced when the degree of social identification with the website community increasesInf. Manage
Choi et al. (2018) SNSImpression formation theory; privacy calculus theoryA: Network mutuality, profile diagnosticity ME: Privacy risks, expected social capital gains MO: Dispositional privacy concerns O: No-action, acceptanceIndividuals utilize Two key types of social information: network mutuality and profile diagnosticity in evaluating privacy risks and expected social capital gains. Privacy risks and expected social capital gains powerfully predict the likelihood of no-action and the likelihood of accepting friend requests on SNSJ. Assoc. Inf. Syst
Fox and Connolly (2018) Mobile healthProtection motivation theory; social cognitive theoryA: Ability to adopt, risk beliefs trust beliefs ME: Health information privacy concerns MO: NA O: Adoption intentionHealth digital divide is deepening due to older adults’ perceived inability to adopt and their unwillingness to adopt stemming from mistrust, high risk perceptions and strong desire for privacyInf. Syst. J
Ortiz et al. (2018) SNSPrivacy calculus theoryA: Information security awareness ME: Concern for information privacy, consumer alienation, privacy risk belief MO: Perceived privacy empowerment O: Lurking, self-concealmentInformation security awareness significantly and positively influences concern for information privacy, consumer alienation and privacy risk belief.  Concerns for information privacy and consumer alienation significantly and positively affect privacy risk belief.  Privacy risk belief has a significant and positive effect on lurking and self-concealment.  Perceived privacy empowerment moderates the relation between privacy risk belief and lurking as well as that between privacy risk belief and self-concealment
Published by Emerald Publishing Limited. This article is published under the Creative Commons Attribution (CC BY 4.0) licence. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this licence maybe seen at Link to the terms of the CC BY 4.0 licenceLink to the terms of the CC BY 4.0 licence.

or Create an Account

Close subscription notice
Close access options