Date Approved

2026

Degree Type

Open Access Dissertation

Degree Name

Doctor of Philosophy (PhD)

Department or School

Leadership and Counseling

Committee Member

David Anderson, PhD

Committee Member

Tess Barker, JD, PhD

Committee Member

Ron Flowers, PhD

Committee Member

Michael McVey, PhD

Abstract

This qualitative research study used semi-structured interviews to ask directors of elearning at regional public universities about decision-making concerning new information technologies that affected the data privacy and security of students and staff. The institutional setting and target population were chosen to standardize the inquiry and allow focus on how privacy decisions were made. The conceptual framework drew on Helen Nissenbaum’s theory of contextual integrity for privacy and contributions of behavioral economists on expert decision-making including studies of heuristics and biases, naturalistic decision-making, and the failures of deliberative groups. Data collection involved a first interview and then a second follow-up interview for each subject. The results showed that many subjects did not believe their privacy views had changed over time. Additionally, as often as they described decision-making in deliberative groups, they also told stories about individuals who violated privacy norms with behavior that was viewed as outrageous. These themes of continuity and emotionally charged defense of privacy led to a new consideration of Gareth Morgan’s metaphor of the holographic brain, a characteristic of organizations that inculcate replication of knowledge and attitudes to support adaptability and growth. Subjects were found to articulate privacy minimum specs—cogent rules for thinking about privacy that helped individuals make quick decisions when faced with privacy issues. Subjects also displayed behaviors consistent with Michael Lipsky’s concept of street-level bureaucrats, who serve as mediators between policymakers and managers above, and the clients who rely on services. The directors of e-learning conducted many interactions with instructional staff and department chairs in this mode, and their efforts presented an

opportunity to make decisions about privacy that were vehicles for new attitudes. The theoretical impact of the study calls into question Nissenbaum’s decision heuristic, a systematic checklist of contextual factors to consider when making privacy policy. The evidence suggested most privacy decisions were made using privacy minimum specs as basic rules for privacy assessment. The impact of the study was to suggest favoring training and knowledge-sharing that disseminated easily remembered rules for following policy and practice, instead of detailed training driven by management values of control.

Share

COinS