Umeå University's logo

umu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Are there two sides toevery coin; even GDPR?: A Qualitative Study on theImpact of GDPR within theHealth Tech Industry
Umeå University, Faculty of Social Sciences, Umeå School of Business and Economics (USBE), Business Administration. Handelshögskolan i Umeå.
Umeå University, Faculty of Social Sciences, Umeå School of Business and Economics (USBE), Business Administration.
2023 (English)Independent thesis Advanced level (degree of Master (Two Years)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

The General Data Protection Regulation has undoubtedly affected our society, both on anindividual everyday level as well as from the greater perspective of companies, the publicsector, and nations. The purpose of the GDPR is to protect the data of European citizens byputting further responsibility on organizations that store individual data. However, as withevery decision, this has had implications that might not have been predicted or accountedfor and which can disrupt its initial cause. Certain industries have been highly regulatedwhen it comes to data even before the GDPR, one of these is the health-tech industry whichmanages medical data which is perceived to be very sensitive and has for example beenregulated through the Patient Data Act.There is currently a research gap regarding how the GDPR has affected organizations andtheir journey toward compliance. This qualitative study was conducted using a criticalrealism perspective with a critical constructivist approach. The study is done incollaboration with the Swedish Kubernetes platform service provider Elastisys. Byconducting interviews with both the company itself and also with some of their health-techclients, as well as looking into cases where healthcare organizations have been fined underGDPR this thesis aimed towards answering the question of, “What effects have the GDPRlegislation had on the health-tech market and how have the organizations within itadapted?”.The result of this thesis show that the organizations have been able to reach compliance andmanage the process, however the implications have been clearer and more understandableas time has passed. This could be partly explained by the growing number of support-toolsand -organizations available today. Furthermore, due to the strong regulations and changingconditions within this particular industry the organizations are used to rapid transitions.Something that has implicated the general digital development of the industry but also madethem more adaptable to changing conditions. When it comes to the health-tech industrythere have been a higher pressure for compliance for those that work with the public sectorin comparison to those working against end users.Alongside the prohibited digital development, the GDPR has had other implications, suchas a gap between legal and technical expertise and conflicts between legal compliance andgeneral data security. Which, if not handled correctly can lead to less secure solutions.Another interesting implication of the GDPR is the indifference of individuals regardingtheir data. In light of this finding, this thesis also aspires to further elaborate on the currentdebate of digital sovereignty and its importance in the context of national negotiations withforeign powers.

Place, publisher, year, edition, pages
2023. , p. 81
Keywords [en]
GDPR, compliance, digitalization, health-tech, digital sovereignty & change management
National Category
Business Administration Other Medical Engineering
Identifiers
URN: urn:nbn:se:umu:diva-211310OAI: oai:DiVA.org:umu-211310DiVA, id: diva2:1778304
External cooperation
Anonymous
Educational program
Master's program in Business Development and Internationalisation
Supervisors
Available from: 2023-07-03 Created: 2023-06-30 Last updated: 2023-07-03Bibliographically approved

Open Access in DiVA

fulltext(940 kB)309 downloads
File information
File name FULLTEXT01.pdfFile size 940 kBChecksum SHA-512
8090b3dc96d3e4b49cf8247f1b01d33d684d3714f68e3dbb3937775bdd14f4cd27649a49dd88824b82aea5d932382fb8f5d94fffe0653ef2e573bd9d6fab23fc
Type fulltextMimetype application/pdf

By organisation
Business Administration
Business AdministrationOther Medical Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 309 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 469 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf