The General Data Protection Regulation (GDPR) has significantly reshaped how organisations handle personal data, yet its impact on universities' privacy policies within the European Union remains under-explored. Universities process large volumes of personal data - from student records to research participant information necessitating strict GDPR compliance. This paper adopts a mixed-methods approach, combining qualitative content analysis (QCA) to assess transparency, compliance with GDPR principles and the framing of user rights with quantitative analysis to track textual modifications across word, sentence, and paragraph levels. Our findings reveal that institutional privacy policies often rely on vague and broad language, creating ambiguity around data purposes and retention. Additionally, practices such as outsourcing responsibility and embedding third-party tools challenge core GDPR principles like purpose limitation and data protection by design.
Cloud-hosted environments are increasingly being adopted in both industry and academia alike, with marketing material and popular belief holding a myriad of conjectures as to why this adoption progresses. There is, however, a limited understanding of the factors that influence the decision to move to the cloud and the challenges encountered on this migration journey, grounded in data, specifically in the context of higher education. To address this gap, we perform an in-depth qualitative investigation to better understand the human factors of cloud adoption in universities. We engaged with 18 participants via semi-structured interviews and analysed the data using thematic analysis. We present our findings around three main themes-the decision matrix, the people-centric transition and the guardians of data-to comprehend the landscape of cloud migration (cloudscape) in higher education. Our findings highlight that cloud migrations go beyond a technical transformation. While they regularly encompass shifts in people's roles and mindsets, cloud adoption in the absence of such a shift may lead to patterns that triggered the move away from self-hosted and on-premise solutions in the first place. Furthermore, we find interaction effects between the technical depth of decision makers in contrast to necessary risk acceptance in the context of cloud adoption, thereby further adding to the broader discussion regarding the place of academia in monopolistic markets.
In the system and network administration domain, gender diversity remains a distant target. The experiences and perspectives of sysadmins who belong to marginalized genders (non cis-men) are not well understood beyond the fact that sysadmin work environments are generally not equitable. We address this knowledge gap in our study by focusing on the ways in which sysadmins from marginalized genders manage their work in men-dominated sysadmin work spaces and by understanding what an inclusive workplace would look like. Using a feminist research approach, we engaged with a group of 16 sysadmins who are not cis-men via six online focus groups. We found that managing the impact of gender identity in the sysadmin workplace means demonstrating excellence and going above and beyond in system administration tasks, and also requires performing additional care work not expected from cis men. Furthermore, our participants handle additional layers of work due to gender considerations and to actively find community in the workplace. We found that sysadmins manage by going above and beyond in their tasks, performing care work and doing extra layers of work because of gender considerations, and finding community in the workplace. To mitigate this additional workload, we recommend more care for care work. For future research, we recommend the use of feminist lenses when studying sysadmin work in order to provide more equitable solutions that ultimately contribute to improving system security by fostering a just workplace.
The ongoing global COVID-19 pandemic made working from home -- wherever working remotely is possible -- the norm for what had previously been office-based jobs across the world. This change in how we work created a challenging situation for system administrators (sysadmins), as they are the ones building and maintaining the digital infrastructure our world relies on. In this paper, we examine how system administration work changed early in the pandemic from sysadmins' personal perspectives, through semi-structured interviews and thematic analysis. We find that sysadmins faced a two-sided crisis: While sysadmins' own work environment changed, they also had to react to the new situation and facilitate stable options to work online for themselves and their colleagues, supporting their users in adapting to the crisis. This finding embeds into earlier work on the connection between IT (security) work and the notion of 'care', where we substantiate these earlier findings with results from a repeatable method grounded in coordination theory. Furthermore, while we find that sysadmins perceived no major changes in the way they work, by consecutively probing our interviewees, we find that they did experience several counter-intuitive effects on their work. This includes that while day-to-day communication became inherently more difficult, other tasks were streamlined by the remote working format and were seen as having become easier. Finally, by structuring our results according to a model of coordination and communication, we identify changes in sysadmins' coordination patterns. From these we derive recommendations for how system administration work can be coordinated, ranging beyond the immediate pandemic response and the transition to any 'new normal' way of working.
In this paper, we propose a Bidirectional Attention Network (BANet), an end-to-end framework for monocular depth estimation (MDE) that addresses the limitation of effectively integrating local and global information in convolutional neural networks. The structure of this mechanism derives from a strong conceptual foundation of neural machine translation, and presents a light-weight mechanism for adaptive control of computation similar to the dynamic nature of recurrent neural networks. We introduce bidirectional attention modules that utilize the feed-forward feature maps and incorporate the global context to filter out ambiguity. Extensive experiments reveal the high degree of capability of this bidirectional attention model over feed-forward baselines and other state-of-the-art methods for monocular depth estimation on two challenging datasets - KITTI and DIODE. We show that our proposed approach either outperforms or performs at least on a par with the state-of-the-art monocular depth estimation methods with less memory and computational complexity.
B2B marketing differs substantially from the marketing of consumer goods or services since the purchasers themselves don't utilize the items or services.In contrast to consumer markets, where the people who purchase products and services directly consume, the essence of business markets is the consumption of particular companies.This work is based on this key idea that has major consequences for organizational purchasers' satisfaction for marketing strategies and associated programs.The buying methods used to buy products and services is another key component of B2B's marketing.Decisions are taken relatively rapidly in consumer markets, the amount of risk is modest, at least for common products, and the focus is mostly on the emotional components of a purchase.Potential risks are typically fairly significant in B2B marketplaces; thus, choices take far longer and involve far more individuals.The type and manner of connection between organizations therefore relies on an awareness of the demands of individual consumers and the willingness to offer and exchange information.
Instead of only considering technology, computer security research now strives to also take into account the human factor by studying regular users and, to a lesser extent, experts like operators and developers of systems. We focus our analysis on the research on the crucial population of experts, whose human errors can impact many systems at once, and compare it to research on regular users. To understand how far we advanced in the area of human factors, how the field can further mature, and to provide a point of reference for researchers new to this field, we analyzed the past decade of human factors research in security and privacy, identifying 557 relevant publications. Of these, we found 48 publications focused on expert users and analyzed all in depth. For additional insights, we compare them to a stratified sample of 48 end-user studies. In this paper we investigate: (i) The perspective on human factors, and how we can learn from safety science (ii) How and who are the participants recruited, and how this -- as we find -- creates a western-centric perspective (iii) Research objectives, and how to align these with the chosen research methods (iv) How theories can be used to increase rigor in the communities scientific work, including limitations to the use of Grounded Theory, which is often incompletely applied (v) How researchers handle ethical implications, and what we can do to account for them more consistently Although our literature review has limitations, new insights were revealed and avenues for further research identified.
Restorative justice is an approach that aims to replace hurt by healing in the understanding that the perpetrators of pain are also victims of the incident themselves. In 2016, Mersey Care, an NHS community and mental health trust in the Liverpool region, implemented restorative justice (or what it termed a 'Just and Learning Culture') to fundamentally change its responses to incidents, patient harm, and complaints against staff. Although qualitative benefits from this implementation seemed obvious, it was also thought relevant to identify the economic effects of restorative justice. Through interviews with Mersey Care staff and collecting data pertaining to costs, suspensions, and absenteeism, an economic model of restorative justice was created. We found that the introduction of restorative justice has coincided with many qualitative improvements for staff, such as a reduction in suspensions and dismissals, increase in the reporting of adverse events, increase in the number of staff that feel encouraged to seek support and a slowing down of the upward trend in absence due to illness. It also improved staff retention. The economic benefits of restorative justice appear significant. After corrections for inflation, acquisitions and anomalies, we found that the salary costs averaged over two fiscal years were reduced by £ 4 million per year, coinciding with the introduction of a just and learning culture in 2016. In addition, Mersey Care reaped around £ 1 million in saved legal and termination expenses. We conservatively attribute half of these savings to the introduction of a just and learning culture itself, and the other half to non-related factors. Using this assumption, we estimate the total economic benefit of restorative justice in the case of Mersey Care NHS Foundation Trust to be about £ 2.5 million or approximately 1% of the total costs and 2% of the labour costs.