Understanding Privacy Policy Compliance in Digital SMEs: The Role of TOE Factors, Compliance Readiness, and BPM Capability
DOI:
https://doi.org/10.35877/soshum5132Keywords:
TOE Framework, Compliance Reeadiness, BPM Capability, Privacy Policy Compliance, Digital SMEsAbstract
Digital SMEs increasingly process customer data through social media, marketplaces, digital payment systems, and other online applications, yet privacy compliance often remains informal and inconsistently embedded in daily operations. This study examines how technological, organizational, and environmental conditions influence privacy policy compliance through compliance readiness and Business Process Management capability. Its novelty lies in integrating the TOE framework, organizational readiness, and BPM capability within a sequential mediation model, thereby explaining how contextual conditions are converted into operational compliance practices. A quantitative cross-sectional survey was conducted among 174 owners, managers, and staff of Indonesian digital SMEs selected through purposive sampling. The data were analyzed using PLS-SEM with SmartPLS, including measurement model assessment, bootstrapping with 5,000 resamples, and predictive relevance testing. The results show that TOE Factors strongly influence Compliance Readiness and also improve BPM Capability. Compliance Readiness positively affects both BPM Capability and Privacy Policy Compliance, while BPM Capability further strengthens Privacy Policy Compliance. The model explains 54.9% of the variance in privacy policy compliance. The indirect effects through Compliance Readiness, BPM Capability, and their sequential combination were all significant. These findings indicate that favorable technology, organizational support, and environmental pressure do not automatically produce consistent privacy practices. Digital SMEs must first develop internal readiness and then translate that readiness into documented, monitored, and repeatable business processes. The study concludes that sustainable privacy compliance is best understood as a capability-building process rather than merely a regulatory or technological response.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Putri Pradnyawidya Sari, Munir Munir, Chairul Furqon, Asep Wahyudin, Erwin Sutomo

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.

