Data Privacy in the Cloud: Trends, Risks, and Organizational Practices
DOI:
https://doi.org/10.69728/jst.v12.141Keywords:
Cloud Computing, Data Privacy, Encryption, Governance, Risk ManagementAbstract
Cloud computing is increasingly leveraged by Bangladeshi organizations, including utilities, financial institutions, and technology firms, for scalable data storage and analytic capabilities. However, migrating sensitive operational and personal data to cloud environments introduces serious privacy challenges. This study investigates the evolving trends, risks, and organizational practices related to data privacy in the cloud within the Bangladeshi context. We conducted a cross-sectional survey of 132 IT and security decision-makers such as CISOs, cloud architects, and compliance officers to assess perceived risks, governance maturity, and technical control adoption. Key findings reveal that misconfiguration, insider threat, and weak key management are viewed as the most significant risks, while regulatory compliance (e.g., under Bangladesh’s new Personal Data Protection Ordinance) is also a major concern. On the governance front, 70% of organizations report having a formal data-governance framework, with over half using shared-responsibility matrices and including audit and breach-notification clauses in contracts. Technically, encryption (at-rest and in-transit) is widely used, but only a small fraction of firms has adopted advanced privacy-preserving technologies, such as homomorphic encryption or TEEs. Trust in cloud service providers is moderate (mean score ~3.6/5) and correlates strongly with governance maturity and external audits. Based on these insights and the regulatory landscape in Bangladesh, we organize organizational cloud privacy practices into a five-phase risk-management framework (Assessment, Design, Implementation, Monitoring, Review) to help organizations enhance their cloud privacy posture which is grounded theory in institutional and IT governance logic.
References
Abdulsalam, Y. S., & Hedabou, M. (2021). Security and privacy in cloud computing: technical review. Future Internet, 14(1), 11. https://doi.org/10.3390/fi14010011
Abed, Y., & Chavan, M. (2019). The challenges of institutional distance: Data privacy issues in cloud computing. Science, Technology and Society, 24(1), 161-181. https://doi.org/10.1177/0971721818806088
Agrawal, D., El Abbadi, A., & Wang, S. (2012). Secure and privacy-preserving data services in the cloud: A data centric view. Proceedings of the VLDB Endowment, 5(12), 2028-2029. https://doi.org/10.14778/2367502.2367569
Akhtar, S.I., Rauf, A., Abbas, H. et al. Compliance and feedback based model to measure cloud trustworthiness for hosting digital twins. J Cloud Comp., 13, 132 (2024). https://doi.org/10.1186/s13677-024-00690-0
AlGhamdi, S., Win, K. T., & Vlahu-Gjorgievska, E. (2020). Information security governance challenges and critical success factors: Systematic review. Computers & security, 99, 102030. https://doi.org/10.1016/j.cose.2020.102030
Alsmadi, D., Halawani, M., Prybutok, V., & Al-Smadi, R. (2022), Intention, trust and risks as core determinants of cloud computing usage behavior. Journal of Systems and Information Technology, 24(3), 178–201. https://doi.org/10.1108/JSIT-09-2020-0180
Bangladesh Bank. (2023). Guidelines on Cloud Computing. BRPD Circular No. 05, 16 March 2023. Available: https://share.google/kn74AZ3RqYswwXWQM [Accessed: Dec. 18, 2025].
Calder, A. (2021). The EU data protection code of conduct for cloud service providers: a guide to compliance.
Chauhan, M., & Shiaeles, S. (2023). An analysis of cloud security frameworks, problems and proposed solutions. Network, 3(3), 422-450. https://doi.org/10.3390/network3030018
De Hert, P., Papakonstantinou, V., & Kamara, I. (2016). The cloud computing standard ISO/IEC 27018 through the lens of the EU legislation on data protection. Computer Law & Security Review, 32(1), 16-30. https://doi.org/10.1016/j.clsr.2015.12.005
Gangwar, H., Date, H., & Ramaswamy, R. (2015). Understanding determinants of cloud computing adoption using an integrated TAM-TOE model. Journal of enterprise information management, 28(1), 107-130. https://doi.org/10.1108/JEIM-08-2013-0065
Garrison, G., Rebman Jr, C. M., & Kim, S. H. (2018). An identification of factors motivating individuals’ use of cloud-based services. Journal of Computer Information Systems, 58(1), 19-29. https://doi.org/10.1080/08874417.2016.1180653
Gholami, A., & Laure, E. (2016). Security and privacy of sensitive data in cloud computing: a survey of recent developments. https://doi.org/10.48550/arXiv.1601.01498
GuptaK. P. (2025). Technology Adoption: Evidence from an E-Government Cloud Service. Foresight and STI Governance, 19(1), 93-103. https://doi.org/10.17323/fstig.2025.24832
Han, Y., Wang, Y., Wu, L., Feng, H., Wu, X., & Li, R. (2025). Survey of privacy-preserving data aggregation schemes in smart grid. Journal of King Saud University Computer and Information Sciences, 37(9), 263. https://doi.org/10.1007/s44443-025-00179-z
Hanif, M. S., Khurshid, A., Kulibaba, D., & Sajid, A. (2025). Adoption and Actual Usage of SaaS-Based Cloud Applications Among the Swedish SMEs—A TAM-TOE Integrated Perspective. Human Behavior and Emerging Technologies, 2025(1), 2730400. https://doi.org/10.1155/hbe2/2730400
Jagonews24. (2025, October 9). Cabinet nods Personal Data Protection Ordinance 2025. Jagonews24. Available: https://www.jagonews24.com/en/national/news/86241. [Accessed: Dec. 18, 2025].
Rahmika, A. R., Muhammad Akbar, Deni Luvi Jayanto, & Joshua Reska Bu’tu. (2025). Cloud Governance Frameworks: CIA-Based Security and Compliance. Journal of Embedded Systems, Security and Intelligent Systems, 6(3), 379–389.
Silva, P., Monteiro, E., & Simoes, P. (2021). Privacy in the cloud: A survey of existing solutions and research challenges. IEEE access, 9, 10473-10497. https://doi.org/10.1109/ACCESS.2021.3049599
Soofi, A. A., Khan, M. I., & Amin, F. E. (2017). A review on data security in cloud computing. International Journal of Computer Applications, 96(2), 95-96. DOI:10.5120/16338-5625
Sprague, Robert, Cloud Privacy: Normative Standards Needed to Foster Innovation (June 1, 2010). Department of Commerce Internet Policy Task Force, Information Privacy and Innovation in the Internet Economy, Docket No. 100402174-0175-01, Available at SSRN: http://dx.doi.org/10.2139/ssrn.1585376
The Daily Star. (2025, October 9). Shielding personal data: Govt brings big tech under local courts’ purview. The Daily Star. Available: https://www.thedailystar.net/news/bangladesh/news/shielding-personal-data-govt-brings-big-tech-under-m-4006206. [Accessed: Dec. 18, 2025].
Turan, F., Roy, S. S., & Verbauwhede, I. (2020). HEAWS: An accelerator for homomorphic encryption on the Amazon AWS FPGA. IEEE Transactions on Computers, 69(8), 1185-1196. https://doi.org/10.1109/TC.2020.2988765
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Moskura Hoque, Mostofa Kamal Nasir (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.




