<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1d1 20130915//EN" "http://jats.nlm.nih.gov/publishing/1.1d1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" article-type="research-article" xml:lang="en">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">SAJIM</journal-id>
<journal-title-group>
<journal-title>South African Journal of Information Management</journal-title>
</journal-title-group>
<issn pub-type="ppub">2078-1865</issn>
<issn pub-type="epub">1560-683X</issn>
<publisher>
<publisher-name>AOSIS</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">SAJIM-22-1238</article-id>
<article-id pub-id-type="doi">10.4102/sajim.v22i1.1238</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Original Research</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Modelling the intended use of Facebook privacy settings</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-4167-6088</contrib-id>
<name>
<surname>Read</surname>
<given-names>Kimberley</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<contrib contrib-type="author" corresp="yes">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-2892-7954</contrib-id>
<name>
<surname>van der Schyff</surname>
<given-names>Karl</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<aff id="AF0001"><label>1</label>Department of Information Systems, Faculty of Commerce, Rhodes University, Grahamstown, South Africa</aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><bold>Corresponding author:</bold> Karl van der Schyff, <email xlink:href="k.vanderschyff@ru.ac.za">k.vanderschyff@ru.ac.za</email></corresp>
</author-notes>
<pub-date pub-type="epub"><day>27</day><month>10</month><year>2020</year></pub-date>
<pub-date pub-type="collection"><year>2020</year></pub-date>
<volume>22</volume>
<issue>1</issue>
<elocation-id>1238</elocation-id>
<history>
<date date-type="received"><day>08</day><month>04</month><year>2020</year></date>
<date date-type="accepted"><day>03</day><month>08</month><year>2020</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2020. The Authors</copyright-statement>
<copyright-year>2020</copyright-year>
<license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>Licensee: AOSIS. This work is licensed under the Creative Commons Attribution License.</license-p>
</license>
</permissions>
<abstract>
<sec id="st1">
<title>Background</title>
<p>The ineffective use of Facebook privacy settings has become commonplace. This has made it possible for corporates not only to harvest personal information but also to persuade or influence user behaviour in a manner that does not always protect Facebook users.</p>
</sec>
<sec id="st2">
<title>Objectives</title>
<p>The objective of this article was to develop a research model that could be used to evaluate the influence of subjective norms, information security awareness and the process of threat appraisal on the intention to use Facebook privacy settings.</p>
</sec>
<sec id="st3">
<title>Method</title>
<p>In this article, the authors made use of a qualitative approach. Literature pertaining to subjective norms, information security awareness and threat appraisal was thematically analysed using Atlas.ti. Through a process of inductive reasoning, three propositions were developed.</p>
</sec>
<sec id="st4">
<title>Results</title>
<p>This study found that it is likely that an individual&#x2019;s intention to use Facebook privacy settings will be influenced by subjective norms, information security awareness and the process of threat appraisal. To evaluate the behavioural influence of these selected constructs and relationships, a research model was developed based on both the theory of planned behaviour and protection motivation theory.</p>
</sec>
<sec id="st5">
<title>Conclusion</title>
<p>In this article, it is argued that the ineffective use of Facebook privacy settings may be because of the behavioural influence of subjective norms. This is compounded by the fact that most users are unaware of privacy threats. This makes these users vulnerable to Facebook-based privacy threats because the process of threat appraisal is conducted with incomplete, inaccurate or missing information.</p>
</sec>
</abstract>
<kwd-group>
<kwd>Facebook</kwd>
<kwd>information privacy</kwd>
<kwd>threat appraisal</kwd>
<kwd>theory of planned behaviour</kwd>
<kwd>information security awareness</kwd>
<kwd>norms</kwd>
<kwd>protection motivation theory</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s0001">
<title>Introduction</title>
<p>Social interaction via the use of Facebook has become part of over 2 billion users&#x2019; daily lives (Symeonidis et al. <xref ref-type="bibr" rid="CIT0046">2018</xref>). In some respects, this may be attributed to the fact that users are able to build not only social relationships but also a shared personal identity. Such interaction enables users to engage with Facebook on a psychological level, which in turn satisfies that most users seek, namely recognition and belonging (Debatin et al. <xref ref-type="bibr" rid="CIT0014">2009</xref>). This is exemplified in a recent study, which revealed that, on average, Facebook users check their accounts roughly 14 times a day (Kusyanti et al. <xref ref-type="bibr" rid="CIT0030">2017</xref>). These users also tend to construct their Facebook identities based on the influence of their peers (Strater &#x0026; Lipford <xref ref-type="bibr" rid="CIT0044">2008</xref>). However, if not protected using Facebook privacy settings, such approaches to self-disclosure often lead to unintended consequences, one being the misuse of personal information. This is especially pertinent given that privacy threats are believed to be a composite result of oversharing personal information paired with the insufficient use of privacy settings. Subjective forces, such as the need to accumulate more Facebook friends, imply that in practice many platform users befriend others who are in actual fact absolute strangers (Govani &#x0026; Pashley <xref ref-type="bibr" rid="CIT0021">2014</xref>).</p>
<p>As a result, these so-called Facebook friends have access to a number of pieces of personal information. This includes not only those aspects that remain relatively static (i.e. a user&#x2019;s age and gender) but also their thoughts and ideas in the form of Facebook posts and likes. Together, these aspects of a user&#x2019;s profile not only make it possible to enhance Facebook&#x2019;s ability to sell advertising space, but also enable Facebook to monitor and, to some extent, predict a user&#x2019;s online behaviour.</p>
<p>Although targeted advertising has the potential to increase the revenues of social media companies, it is the prediction of user behaviour that allows Facebook to misuse user data. In fact, the ability to monitor content with the intent to manipulate user behaviour is profound (Amer &#x0026; Noujaim <xref ref-type="bibr" rid="CIT0005">2019</xref>). One only has to consider the numerous voter-profiling campaigns carried out by Cambridge Analytica to appreciate the significance of influencing behaviour by way of posting tailored content to users classified as <italic>persuadable</italic> (Amer &#x0026; Noujaim <xref ref-type="bibr" rid="CIT0005">2019</xref>). Such classification can only be carried out by harvesting as much personal information as is needed to determine a user&#x2019;s preferences, and possibly even their dominant personality traits. Given that companies like Cambridge Analytica have been able to harvest enough personal information to influence these co-called <italic>persuadables</italic>, it makes sense to understand the behavioural aspects that influence Facebook users&#x2019; intentions to enact protective behaviour.</p>
<p>Within the context of this article, such protective behaviour is understood as a Facebook user&#x2019;s intention to use privacy settings effectively. It is believed that the use of these settings would limit the inadvertent disclosure and misuse of personal information. To model this influence, the authors of this article have adapted the <italic>theory of planned behaviour</italic> (TPB) by replacing <italic>perceived behavioural control</italic> (PBC) with <italic>information security awareness</italic>, and also incorporated an element of <italic>protection motivation theory</italic> (PMT), namely <italic>threat appraisal</italic>. These constructs are conceptualised as follows: the authors argue that an individual&#x2019;s threat appraisal will influence their intention to use the privacy settings. If an individual is aware of privacy threats, they will likely be more inclined to use the privacy settings. Conversely, if they are not aware of privacy threats, they will be more likely to avoid using privacy settings. <italic>Information security awareness</italic> is conceptualised as the knowledge an individual possesses regarding privacy threats. It is therefore argued that information security awareness controls the effectiveness of an individual&#x2019;s threat appraisal. If they possess little or no knowledge of privacy threats, the process of threat appraisal will be ineffective.</p>
<p>The authors also argue in favour of the behavioural influence of subjective norms. In this context, <italic>subjective norms</italic> are conceptualised as an individual&#x2019;s susceptibility to the views of their peers with respect to the use of privacy settings. If an individual is influenceable, their peers&#x2019; privacy behaviour will likely influence theirs. In other words, if their peers avoid using privacy settings, so will they.</p>
<p>Together, the behavioural implications of the model described above enable this study to contribute to known theory because few Facebook privacy studies have merged PMT and the TPB in this manner. Although Stern and Salb (<xref ref-type="bibr" rid="CIT0043">2015</xref>) evaluated the influence of norms, they did so by incorporating both descriptive and subjective norms, modelling their influence on the intended use of Facebook instead of focusing on privacy settings.</p>
</sec>
<sec id="s0002">
<title>Facebook privacy settings in perspective</title>
<p>Facebook allows users to control their personal information (and profile) through an elaborate system of settings, commonly referred to as Facebook privacy settings. These settings allow users to control the extent to which their peers, and even strangers, can access their personal information (Lewis, Kaufman &#x0026; Christakis <xref ref-type="bibr" rid="CIT0032">2008</xref>). Users can also see the activities of other users and friends&#x2014;especially if the content is marked as public (Zlatolas et al. <xref ref-type="bibr" rid="CIT0053">2015</xref>). Some personal information is also made public by default. This includes a user&#x2019;s name, gender, profile picture, cover photo, language, country and age. These pieces of personal information are made available to individuals who may not even have a Facebook profile (Facebook <xref ref-type="bibr" rid="CIT0017">2019</xref>), hence the ease with which companies like Cambridge Analytica can find personal information to misuse or to persuade individuals. To make matters worse, many users are unaware that the default privacy settings allow this type of access.</p>
<p>Nevertheless, users still disclose personal information, making this a relevant and persistent problem. Several explanations have been put forward as possible reasons why the privacy settings are not being used. Some researchers argue in favour of social conformance, implicit trust, poor interface design and permissive default settings (Strater &#x0026; Lipford <xref ref-type="bibr" rid="CIT0044">2008</xref>). Given the use of <italic>threat appraisal</italic>, this article investigates an individual&#x2019;s perception of threats, specifically threats that pertain to the safety of individuals&#x2019; social media based personal information. To this extent, a study by Govani and Pashley (<xref ref-type="bibr" rid="CIT0021">2014</xref>) found that whilst students were aware of threats (i.e. identity theft, stalking and general misuse), they were still inclined to provide the information and failed to implement protective measures. Research points to three possible reasons why the Facebook privacy settings are not adequately used:</p>
<list list-type="bullet">
<list-item><p>Users are unaware of any threats.</p></list-item>
<list-item><p>Users are apathetically aware of privacy threats.</p></list-item>
<list-item><p>Facebook privacy settings are too difficult to use and are therefore avoided.</p></list-item>
</list>
<p>Dickinson and Holmes (<xref ref-type="bibr" rid="CIT0015">2008</xref>) found that individuals are likely to become more evasive and adopt maladaptive coping responses if the threat level is high, as opposed to proactively reducing the effect of the threat (Marett, Vedadi &#x0026; Durcikova <xref ref-type="bibr" rid="CIT0033">2019</xref>). Often, fear motivates action in these cases, which may take the form of self-protective or avoidant responses (Witte &#x0026; Allen <xref ref-type="bibr" rid="CIT0052">2000</xref>).</p>
<p>Whilst privacy options and settings have become more sophisticated (Haynes, Bawden &#x0026; Robinson <xref ref-type="bibr" rid="CIT0025">2016</xref>), research has found these tools to be underutilised (Boyd &#x0026; Hargittai <xref ref-type="bibr" rid="CIT0010">2010</xref>; Golbeck &#x0026; Mauriello <xref ref-type="bibr" rid="CIT0020">2016</xref>). Therefore, the technological aspects of security cannot solely guarantee a secure environment for personal information. Researchers also have to take human aspects into consideration (Safa &#x0026; Von Solms <xref ref-type="bibr" rid="CIT0041">2016</xref>). Overall, studies have found that users find the Facebook privacy settings confusing, time-consuming and challenging to use. This may in turn result in the accidental or unintentional disclosure of personal information regardless of the additional forms of control users have.</p>
</sec>
<sec id="s0003">
<title>Methodology</title>
<p>This article adopted a qualitative approach as the authors performed in-depth thematic analysis of secondary data.</p>
<sec id="s20004">
<title>Data collection</title>
<p>The purpose of this article was to collect data on the behavioural influence of <italic>subjective norms, information security awareness</italic> and <italic>threat appraisal</italic>. This entailed collecting and thematically analysing secondary data obtained from a variety of academic databases as part of a scoping review. These databases included ScienceDirect, Taylor &#x0026; Francis, Oxford Academic and the AIS Senior Scholars Basket, which include journals like the <italic>European Journal of Information Systems, Information Systems Journal, Information Systems Research</italic> and <italic>MIS Quarterly</italic>. A scoping review is generally used to identify and map available evidence as it relates to a topic of interest (Munn et al. <xref ref-type="bibr" rid="CIT0036">2018</xref>). This required a series of structured searches using phrases such as <italic>information security awareness, threat appraisal, subjective norms, Facebook privacy settings</italic> and <italic>social media</italic>. After screening the titles and abstracts, 42 articles were thematically analysed, as illustrated in the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) diagram shown in <xref ref-type="fig" rid="F0001">Figure 1</xref>.</p>
<fig id="F0001">
<label>FIGURE 1</label>
<caption><p>Preferred Reporting Items for Systematic Reviews and Meta-Analyses diagram illustrating the search process.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-22-1238-g001.tif"/>
</fig>
</sec>
<sec id="s20005">
<title>Method of analysis</title>
<p>As part of the analysis process, a series of thematic maps were created, one for each of the propositions. This process also involved a more focused review and rereading of the 42 articles &#x2013; a common practice when conducting thematic analysis (Bowen <xref ref-type="bibr" rid="CIT0009">2009</xref>). Such rereading not only illuminates prominent themes that were not apparent during the initial screening process (Joffe <xref ref-type="bibr" rid="CIT0027">2012</xref>) but also enables researchers to recognise specific patterns. In turn, these patterns may become categories to guide analysis within identified themes. For example, it is reasonable to assume that most (if not all) of the selected studies employed specific research methods. These methods of analysis may become one such analysis category. This entire process was conducted inductively so as to emphasise the researcher&#x2019;s understanding of the broader phenomena pertaining to the use of Facebook privacy settings (Braun &#x0026; Clarke <xref ref-type="bibr" rid="CIT0011">2006</xref>). A deductive approach was deemed inappropriate for this study, given that the objective of the article was to develop the research model and not to test it using statistical means. As part of the inductive analysis a five-phased approach was used, as outlined by Braun and Clarke (<xref ref-type="bibr" rid="CIT0011">2006</xref>). These phases are described as follows:</p>
<list list-type="bullet">
<list-item><p>becoming acquainted with the data by reading and rereading the selected articles</p></list-item>
<list-item><p>developing initial codes (short phrases) in Atlas.ti to describe one or more textual extracts from the selected articles (see <xref ref-type="table" rid="T0001">Table 1</xref>)</p></list-item>
<list-item><p>collating codes into potential (or candidate) themes (code groups in Atlas.ti)</p></list-item>
<list-item><p>reviewing themes in relation to coded extracts, as well as merging themes if required</p></list-item>
<list-item><p>defining and naming these themes, culminating in the development of thematic maps (networks in Atlas.ti).</p></list-item>
</list>
<table-wrap id="T0001">
<label>TABLE 1</label>
<caption><p>Example of coded extracts, associated themes and sources.</p></caption>
<table frame="hsides" rules="groups">
<thead valign="top">
<tr>
<th valign="top" align="left">Data extract</th>
<th valign="top" align="left">Atlas.ti codes</th>
<th valign="top" align="left">Candidate theme</th>
<th valign="top" align="left">Source</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td align="left">&#x2018;&#x2026; willingly reveal highly personal information if their friends do.&#x2019;</td>
<td align="left"><list list-type="bullet">
<list-item><p>++influence of norms: descriptive</p></list-item></list></td>
<td align="left">Normative influence</td>
<td align="left">Acquisti and Gross (<xref ref-type="bibr" rid="CIT0002">2006</xref>)</td>
</tr>
<tr>
<td align="left">&#x2018;&#x2026; Siponen (2000) suggested that information security policies should take into account the notion of morality and that they should appear to be moral to the employees.&#x2019;</td>
<td align="left"><list list-type="bullet">
<list-item><p>++influence of norms</p></list-item>
<list-item><p>infosec compliance</p></list-item></list></td>
<td align="left">Normative influence</td>
<td align="left">Ahluwalia and Merhi (<xref ref-type="bibr" rid="CIT0003">2018</xref>)</td>
</tr>
<tr>
<td align="left">&#x2018;ISA can lead to improved IS behaviour and ISP compliance.&#x2019;</td>
<td align="left"><list list-type="bullet">
<list-item><p>++influence of awareness</p></list-item></list></td>
<td align="left">Information security awareness</td>
<td align="left">Bauer, Bernroider and Chudzikowski (<xref ref-type="bibr" rid="CIT0007">2017</xref>)</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>ISA, Information security awareness; IS, Information security; ISP, Information security policy.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>As part of phase 1, the articles were read in detail to develop an overall understanding of the core aspects (influence of subjective norms and information security awareness) of this study. In phase 2, interesting codes were identified based on the nature and the additional behavioural understanding gained after executing phase 1.</p>
<p>Following this, several codes were collated into candidate themes. Phase 3 culminated in the development of three candidate themes, namely threat appraisal, normative influence and the influence of information security awareness. Using these candidate themes as a starting point, phase 4 further refined these themes by removing extraneous coded extracts. This culminated in the formal specification of three thematic maps (see <xref ref-type="fig" rid="F0002">Figure 2</xref> for one example). It is from these thematic maps that the resultant propositions were developed (i.e. as part of phase 5).</p>
<fig id="F0002">
<label>FIGURE 2</label>
<caption><p>Partial thematic map used to argue the behavioural influence of subjective norms.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-22-1238-g002.tif"/>
</fig>
</sec>
</sec>
<sec id="s0006">
<title>Development of propositions</title>
<p>This section first provides an outline of how the TPB (amongst others) and PMT have been used in related studies, followed by a discussion that outlines the development of the propositions for this study.</p>
<sec id="s20007">
<title>Theoretical framework</title>
<p>This study utilised both the TPB and PMT. Ajzen (<xref ref-type="bibr" rid="CIT0004">1985</xref>), who developed the TPB, conceptualised the strength of intention as an immediate antecedent of behaviour (Kautonen, Van Gelderen &#x0026; Fink <xref ref-type="bibr" rid="CIT0029">2015</xref>). Thus, the TPB is based on the assumption that most human behaviour takes place as a result of intent, as influenced by personal attitudes, subjective norms and PBC (Grimes &#x0026; Marquardson <xref ref-type="bibr" rid="CIT0022">2019</xref>; Ham, Jeger &#x0026; Ivkovi&#x0107; <xref ref-type="bibr" rid="CIT0023">2015</xref>).</p>
<p>Within the context of this study, attitude is defined as the extent to which an individual either positively or negatively value the use of Facebook privacy settings. <italic>Subjective norms</italic> is defined as the social pressure that influences whether an individual will make use of the Facebook privacy settings. <italic>Information security awareness</italic> is defined as the extent to which an individual is aware of the privacy threats that their personal information is exposed to. Protection motivation theory, on the other hand, proposes that behavioural intentions are motivated by the processes of both threat and coping appraisal (Rogers <xref ref-type="bibr" rid="CIT0039">1975</xref>). Note that this study only argues in favour of the behavioural influence of threat appraisal. In this context, threat appraisal necessitates judging the severity of and the vulnerability attached to not making use of Facebook privacy settings. For example, if a Facebook user determines that their level of self-efficacy is particularly high, they may forgo the privacy settings because they believe they are adequately equipped to ameliorate future threats (i.e. misuse of personal information). Additionally, PMT has been found to adequately explain individuals&#x2019; behavioural intention to engage in protective actions (Ifinedo <xref ref-type="bibr" rid="CIT0026">2012</xref>).</p>
<p>The research model for this study merges these two theories by arguing the influence of <italic>threat appraisal</italic>, specifically in terms of the role played by fear appeals in the appraisal process. In other words, the research model posits that it is likely that an individual will increase their knowledge of (in terms of avoidance) specific threats as they become aware of vulnerabilities. For example, a Facebook user may wish to find out how they can avoid inadvertently sharing personal information because they fear that it may be misused.</p>
<p>This combination of theoretical constructs not only contributes theoretically but also enables researchers to evaluate the role of fear appeals (one part of threat appraisal) within the context of Facebook privacy settings. The integration of subjective norms further increases the explanatory power of the research model (Tsai et al. <xref ref-type="bibr" rid="CIT0049">2016</xref>). Having said this, other studies have also combined these two theories (Grimes &#x0026; Marquardson <xref ref-type="bibr" rid="CIT0022">2019</xref>; Ifinedo <xref ref-type="bibr" rid="CIT0026">2012</xref>).</p>
<p>The process by which individuals <italic>weigh up</italic> the costs and benefits of using privacy settings can also be explained by <italic>deterrence theory</italic> (DT) or simply cost&#x2013;benefit analysis, both of which involve a cognitive process of weighing up the potential costs and benefits of enacting specific behaviour (Min &#x0026; Kim <xref ref-type="bibr" rid="CIT0035">2015</xref>). More specifically, DT is based on the belief that sanctions affect an individual&#x2019;s intention to participate in deviant behaviour, depending on the sanction severity, celerity and certainty of the particular behaviour (Abed &#x0026; Weistroffer <xref ref-type="bibr" rid="CIT0001">2016</xref>). As such, individual behaviour is assumed to be driven by some punishment associated with not performing the required behaviour. Because the use of Facebook privacy settings cannot be enforced, theories that imply forms of sanction (such as DT) are not deemed relevant in this context.</p>
</sec>
<sec id="s20008">
<title>The behavioural influence of subjective norms</title>
<p>Research provides evidence of two distinct sub-types of social norms, namely subjective and descriptive norms (Lapinski &#x0026; Rimal <xref ref-type="bibr" rid="CIT0031">2005</xref>). Descriptive norms are those perceptions of the behaviour that an individual&#x2019;s peers are enacting. As such, they describe a behaviour that has taken or is taking place. Conversely, subjective norms are those behaviours believed to be desired by an individual&#x2019;s peers (Kautonen et al. <xref ref-type="bibr" rid="CIT0029">2015</xref>). Subjective norms therefore assume that individuals are more likely to enact a behaviour that they believe is desired or expected by their peers (Saeri et al. <xref ref-type="bibr" rid="CIT0040">2014</xref>).</p>
<p>Both descriptive and subjective norms are believed to drive an individual&#x2019;s behaviour towards social acceptance (Min &#x0026; Kim <xref ref-type="bibr" rid="CIT0035">2015</xref>). Such acceptance even takes place to the extent that individuals may adjust their norms if they differ from the normative required behaviour. These adjustments may reinforce or counter the normative behaviour depending on how closely individuals identify with their peers (White et al. <xref ref-type="bibr" rid="CIT0051">2009</xref>). If, for example, an individual&#x2019;s peers do not place much emphasis on sustainability, they may avoid associated behaviours.</p>
<p>It should be noted that although subjective norms influence behaviour, they depend on the user population (and use case) in question. For example, subjective norms have been found to significantly influence game use but not the use of blogs (Baek, Kim &#x0026; Bae <xref ref-type="bibr" rid="CIT0006">2014</xref>). Because the use of games and blogs includes voluntary settings, Baek et al.&#x2019;s argument relates to how strongly individuals perceive general behavioural rules to exist within these contexts. Individuals might perceive sanctions to exist if normative behaviour is not followed in gaming, which is not the case when using blogs.</p>
<p>From a social media perspective, subjective norms have been found to affect the problematic use of Facebook, specifically amongst adolescents (Marino et al. <xref ref-type="bibr" rid="CIT0034">2016</xref>). Some research suggests that this is the result of adolescents being more concerned about having their personal information accessed by people who hold immediate power over them (i.e. parents or teachers) (Boyd &#x0026; Hargittai <xref ref-type="bibr" rid="CIT0010">2010</xref>). To substantiate the latter, Foltz Newkirk and Schwager (<xref ref-type="bibr" rid="CIT0019">2016</xref>) found that although subjective norms positively influenced Master of Business Administration (MBA) students&#x2019; intention to use social media privacy settings, they exerted a relatively weak influence on intent.</p>
<p>Previous research has reported mixed outcomes regarding the behavioural influence of subjective norms; specifically, whether it negatively or positively influences intent. Whilst some research has found subjective norms to be the weakest predictor of intention (Ham et al. <xref ref-type="bibr" rid="CIT0023">2015</xref>; Min &#x0026; Kim <xref ref-type="bibr" rid="CIT0035">2015</xref>), other studies have concluded that they have a significant influence on intention (Grimes &#x0026; Marquardson <xref ref-type="bibr" rid="CIT0022">2019</xref>) and that they shape not only behavioural intentions but also the subsequent behaviour of an individual (Chung &#x0026; Rimal <xref ref-type="bibr" rid="CIT0013">2016</xref>). This discrepancy in the literature may depend on the type of behaviour under consideration, the individual involved or how closely the individual identifies with significant others (White et al. <xref ref-type="bibr" rid="CIT0051">2009</xref>). It may also depend on perceptions regarding the perceived costs of non-conformance (Min &#x0026; Kim <xref ref-type="bibr" rid="CIT0035">2015</xref>). Previous studies also suggest that norms are only meaningful to the extent that individuals perceive that their violation will result in some punishment or repercussion (e.g. the misuse of their personal information) (Chalub, Santos &#x0026; Pacheco <xref ref-type="bibr" rid="CIT0012">2006</xref>). Given the discussion thus far, the following proposition is made:</p>
<disp-quote>
<p><bold>Proposition 1 (P1):</bold> Subjective norms will influence an individual&#x2019;s intention to use Facebook privacy settings.</p>
</disp-quote>
</sec>
<sec id="s20009">
<title>The influence of information security awareness</title>
<p>The literature is replete with evidence that information security awareness influences behaviour as a form of control (hence substituting it for PBC in this article). The more aware and knowledgeable a user becomes with regard to possible privacy threats, the more control they might wish to have in this regard, one such control mechanism being the Facebook privacy settings. The authors therefore argue that individuals can only take adequate protective measures once they have been made aware of the threats associated with exercising no control over their personal information (&#x00D6;&#x0287;&#x00FC;t&#x00E7;&#x00FC;, Testik &#x0026; Chouseinoglou <xref ref-type="bibr" rid="CIT0037">2016</xref>). If users are not aware of the tools to protect them against threats (i.e. misuse of personal information), they will not acquire the requisite knowledge to adopt effective protective measures. Instead, these users may be unaware that Facebook provides them with tools such as the <italic>Privacy Checkup</italic> tool. This may lead to protective behaviours being enacted under false assumptions of security (Golbeck &#x0026; Mauriello <xref ref-type="bibr" rid="CIT0020">2016</xref>), which may increase overall vulnerability. This affects not only these individuals but also their peers (i.e. the bidirectional relationship indicated by the dotted lines in <xref ref-type="fig" rid="F0003">Figure 3</xref>). Conversely, it stands to reason that if a Facebook user acts on the information received from peers (therefore increasing awareness), they may develop intentions to use the privacy settings. In doing so, this individual also inadvertently influences their peers to enact the same protective behaviour.</p>
<fig id="F0003">
<label>FIGURE 3</label>
<caption><p>Proposed research model.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-22-1238-g003.tif"/>
</fig>
<p>Although the bidirectional relationship between an individual&#x2019;s attitude towards privacy and awareness is not argued in this article, it plays a vital role when viewing the use of privacy settings holistically. In other words, the behavioural influence of the various theoretical constructs proposed by this study does not affect the intended use in a mutually exclusive manner. In general, awareness has been found to contribute to the behaviour of individuals in several contexts. Park, Kim and Park (<xref ref-type="bibr" rid="CIT0038">2017</xref>) found that awareness of patient privacy amongst nursing students has a significant impact on behaviours to enact protective behaviour when considering the security of patients&#x2019; personal information. Within the context of this article, awareness is assumed to have the same effect on the use of privacy settings.</p>
<p>Therefore, information security awareness measures the extent to which users are informed about their privacy on social networking sites, as well as the extant privacy problems, policies, violations and procedures (Zlatolas et al. <xref ref-type="bibr" rid="CIT0053">2015</xref>). Uninformed users fail to evaluate the privacy risk and information disclosure benefits rationally and thoroughly. As a result, lack of awareness is viewed as a root cause of information security incidents (Safa et al. <xref ref-type="bibr" rid="CIT0042">2018</xref>). Grimes and Marquardson (<xref ref-type="bibr" rid="CIT0022">2019</xref>) found that if a user does not perceive any threats arising as a result of a particular action or behaviour, no protective measures will be taken. Therefore, in order to promote more secure online behaviour, as mentioned, users first need to be made aware of both the threats associated with the disclosure of personal information and the tools available to protect against those threats (e.g. privacy settings).</p>
<p>In industry, awareness programmes have been implemented to improve users&#x2019; compliance and promote secure user behaviour. Bauer et al. (<xref ref-type="bibr" rid="CIT0007">2017</xref>) indicate that a user&#x2019;s level of policy knowledge affects their intentions to comply with such policies. Businesses like Facebook have also begun relying on privacy policies as a self-regulatory mechanism in an attempt to reassure users that their personal information is secure (Benson, Saridakis &#x0026; Tennakoon <xref ref-type="bibr" rid="CIT0008">2015</xref>).</p>
<p>Conversely, in a study by Govani and Pashley (<xref ref-type="bibr" rid="CIT0021">2014</xref>), it was found that even though 84&#x0025; of participants were aware that they could change their privacy settings, only 48&#x0025; actually used these settings. Additionally, respondents did not change their privacy settings even after being educated on how to do so. Users therefore seemingly accept that their personal information will be misused, regardless of whether they enact protective behaviour (i.e. Facebook privacy settings). Respondents&#x2019; awareness and the consequent privacy concerns only resulted in the adoption of protective behaviour if they have had a negative experience in this regard. As such, knowledge, awareness and especially experience are seen to directly influence the intention to adopt protective behaviour such as Facebook privacy settings. The authors of this article therefore argue that:</p>
<disp-quote>
<p><bold>Proposition 2 (P2):</bold> Information security awareness will influence an individual&#x2019;s intention to use Facebook privacy settings.</p>
</disp-quote>
</sec>
<sec id="s20010">
<title>The behavioural influence of threat appraisal</title>
<p>The authors also argue that that the adoption of protective behaviour goes beyond merely making users aware. They posit that the acquired knowledge (via awareness) has to be personally relevant if individuals are to respond appropriately (Marett et al. <xref ref-type="bibr" rid="CIT0033">2019</xref>). Additionally, the individual should be willing and able to respond effectively.</p>
<p>Because PMT is concerned with how and why individuals decide to adopt protective behaviour (e.g. adopting privacy settings), the authors argue that it will also influence the extent to which such protective behaviour is enacted. This stems from the fact that an individual&#x2019;s threat appraisal involves the measurement of the perceived vulnerability and the severity of the threat. Therefore, if an individual does not perceive a threat to be particularly severe (because of their level of knowledge and awareness), they may forgo using privacy settings. Previous research has found user perceptions to be particularly important when facing decisions relating to protective behaviour &#x2013; especially within the context of fear appeals (Johnston et al. <xref ref-type="bibr" rid="CIT0028">2016</xref>). It is believed that should threat appraisal produce a sufficient amount of fear, the individual will be more likely to enact protective behaviour. This means that their level of fear &#x2013; as a result of threat appraisal &#x2013; may influence their intention to use privacy settings.</p>
<p>Similar to Hanus and Wu (<xref ref-type="bibr" rid="CIT0024">2016</xref>), this study focuses on both awareness and threat appraisal as antecedents to the intended use of Facebook privacy settings. Hanus and Wu&#x2019;s (<xref ref-type="bibr" rid="CIT0024">2016</xref>) study also demonstrates that it is not enough for users to be aware of the threats associated with a particular behaviour. Users are also influenced by their perceptions of how vulnerable they may be in this regard. The same applies to the countermeasures used to address the perceived threats. As such, awareness alone does not help promote secure behaviour, which is why the model proposed in this article also theorises the behavioural influence of threat appraisal.</p>
<p>Several recent studies have found evidence that attests to the behavioural influence of threat appraisal. For example, Strycharz et al. (<xref ref-type="bibr" rid="CIT0045">2019</xref>) found that threat appraisal (specifically perceived severity) significantly influenced respondents&#x2019; intentions to turn off personalisation in terms of the ads they are exposed to. Similarly, Feng and Xie (<xref ref-type="bibr" rid="CIT0018">2019</xref>) found that respondents&#x2019; control over privacy settings significantly influenced their intention to use virtual try-on (i.e. of clothing) apps. The additional controls enabled respondents to perceive themselves to be less vulnerable to threats. Vishwanath, Xu and Ngoh (<xref ref-type="bibr" rid="CIT0050">2018</xref>) found that perceived threat severity significantly influences both expressive privacy and information privacy. Additionally, perceived vulnerability was found to influence accessibility privacy. Ernst, Pfeiffer and Rothlauf (<xref ref-type="bibr" rid="CIT0016">2015</xref>) also found threat appraisal to exert a significant and positive influence on the intention to use the privacy settings, specifically in terms of selectivity in connections, refusal and setting strictness. Whilst a heightened threat appraisal is associated with fear (Grimes &#x0026; Marquardson <xref ref-type="bibr" rid="CIT0022">2019</xref>), a user can only evaluate a risky situation if they are aware of the risks. The authors of this article therefore propose:</p>
<disp-quote>
<p><bold>Proposition 3 (P3):</bold> The process of threat appraisal will influence a Facebook user&#x2019;s intention to use privacy settings.</p>
</disp-quote>
</sec>
<sec id="s20011">
<title>Ethical consideration</title>
<p>This article followed all ethical standards for a research without direct contact with human or animal subjects.</p>
</sec>
</sec>
<sec id="s0012">
<title>Discussion</title>
<p>The proposed research model is an adapted version of both the TPB and PMT (see <xref ref-type="fig" rid="F0003">Figure 3</xref>). In this model, the construct PBC is replaced by <italic>information security awareness</italic>. Both <italic>subjective norms</italic> and <italic>threat appraisal</italic> are modelled as having a direct influence on the construct <italic>intention to use privacy settings</italic>. Note that the authors do not directly argue the behavioural influence of the dotted lines in the proposed research model. This also applies to the sub-components of the construct <italic>threat appraisal</italic> (i.e. vulnerability and severity) and demographic aspects, including negative privacy experiences. The influence of information security awareness on the actual use of privacy settings is also outside the scope of this article.</p>
<p>The use of this research model allows researchers to understand how both threat appraisal (P3) and information security awareness (P2) influence the use of Facebook privacy settings. The model also allows for the evaluation of the influence exerted by subjective norms (P1). The authors argue that awareness alone is not enough to understand individuals&#x2019; intentions to enact protective behaviour. Instead, the authors posit that even though individuals are aware of information misuse, they may still avoid the use of privacy settings because they do not perceive the threat to be severe. Therefore, the personal information they disclose is not perceived as sufficiently important to misuse, and even if it is misused, not much harm can be done. The authors argue that this is not necessarily the case, especially if one considers that the influence exerted may have far-reaching implications beyond just the use of Facebook and personal information. Consider the use of cleverly designed posts that appear only to individuals deemed susceptible. Here, even just sharing one&#x2019;s gender can be used to display messages that may invoke sympathy or higher than usual levels of fear. Abnormal levels of fear, resulting from raised levels of awareness, could be used to manipulate users. Recent evidence in the form of voter profiling is but one example. Additionally, it is known that women are more sympathetic and generally more concerned about what their peers think of their behaviour and are thus influenceable (Tifferet <xref ref-type="bibr" rid="CIT0047">2019</xref>). By using the proposed research model, researchers will be able to get some indication of the extent to which subjective norms influence not only these individuals but also their peers. In doing so, the message is perpetuated, resulting in successful persuasion of an individual deemed persuadable, as alluded to in the &#x2018;Introduction&#x2019; section.</p>
<p>Because the proposed model does not focus on other individual differences and specific psychological aspects, it is useful in instances where even a minimal amount of information is not adequately protected by the privacy settings. This makes it particularly useful in providing researchers with an initial description as to what to focus on going forward. Further statistical evaluation of this model may indicate that fear appeals, as evoked during the process of threat appraisal, do not exert a significant influence on the intended use of privacy settings.</p>
<p>The thematic analysis further suggests that subjective norms will exert a significant influence on the intention to use privacy settings. Given the social nature of Facebook, this is not only expected but is also important to model &#x2013; especially in relation to demographic aspects. The results could be used to make Facebook users aware of the extent that even minimal amounts of personal information could be used to manipulate their behaviour, which inadvertently also influences their peers. Results may indicate that this is more pronounced for women. Thus, models like the one the authors propose here could be useful to social media platforms in that it is their responsibility to educate and make users aware of their level of susceptibility. This is exactly what Mark Zuckerberg (chief executive officer of Facebook) alluded to in his senate hearing (Timberg, Romm &#x0026; Dwoskin <xref ref-type="bibr" rid="CIT0048">2018</xref>), where he essentially stated that the company did not do enough to prevent the misuse of its users&#x2019; personal information. The use of similar models may thus assist in this regard.</p>
</sec>
<sec id="s0013">
<title>Limitations</title>
<p>Because this study developed a research model from thematic interpretations, the resultant arguments are influenced by the authors&#x2019; ideological frame of reference. It stands to reason that future work may develop similar models using different arguments. Additionally, although this study conducted a scoping review, as opposed to a more rigid structured review, only a limited number of secondary sources formed part of the thematic analysis. Moreover, arguments supporting the other theoretical relationships (indicated by the dotted lines in <xref ref-type="fig" rid="F0003">Figure 3</xref>) were omitted because of space limitations. Lastly, no statistical measures were developed and aligned with the constructs of the research model in this article.</p>
</sec>
<sec id="s0014">
<title>Conclusion and future research</title>
<p>In this article, the authors used a thematic approach to inductively analyse a set of secondary data sources. This in turn resulted in the identification of three themes and associated thematic maps (see <xref ref-type="fig" rid="F0002">Figure 2</xref>). Using these thematic maps, three corresponding propositions were developed and integrated into an adapted research model consisting of components of both the TPB and PMT. To deductively evaluate the adapted research model, future research could conduct appropriate statistical analyses. For example, a covariance approach to structural equation modelling (CB-SEM) could be used to evaluate the predictive power (<italic>R</italic><sup>2</sup>) of the resultant structural model. The use of a CB-SEM approach is particularly important, because the proposed model is recursive in nature, as opposed to a non-recursive version (i.e. without the bidirectional relationships), which could also be evaluated using a partial least squares path modelling.</p>
</sec>
</body>
<back>
<ack>
<title>Acknowledgements</title>
<sec id="s20015" sec-type="COI-statement">
<title>Competing interests</title>
<p>The authors have declared that no competing interest exists.</p>
</sec>
<sec id="s20016">
<title>Authors&#x2019; contributions</title>
<p>All authors contributed equally to this work.</p>
</sec>
<sec id="s20017">
<title>Funding information</title>
<p>This research received no specific grant from any funding agency in the public, commercial or not-for-profit sectors.</p>
</sec>
<sec id="s20018">
<title>Data availability statement</title>
<p>Data sharing is not applicable to this article as no new data were created or analysed in this study.</p>
</sec>
<sec id="s20019">
<title>Disclaimer</title>
<p>The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official policy or position of any affiliated agency of the authors.</p>
</sec>
</ack>
<ref-list id="references">
<title>References</title>
<ref id="CIT0001"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Abed</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Weistroffer</surname>, <given-names>H.R</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Understanding deterrence theory in security compliance behavior: A quantitative meta-analysis approach</article-title>&#x2019;, in <conf-name>Proceedings of the Southern Association for Information Systems Conference, SAIS</conf-name>, pp. <fpage>1</fpage>&#x2013;<lpage>7</lpage>, <conf-loc>St. Augustine, FL</conf-loc>.</mixed-citation></ref>
<ref id="CIT0002"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Acquisti</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Gross</surname>, <given-names>R</given-names></string-name></person-group>., <year>2006</year>, &#x2018;<article-title>Imagined communities: Awareness, information sharing, and privacy on the Facebook</article-title>&#x2019;, <source><italic>Privacy Enhancing Technologies</italic></source> <volume>4258</volume>, <fpage>36</fpage>&#x2013;<lpage>58</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/11957454_3">https://doi.org/10.1007/11957454_3</ext-link></comment></mixed-citation></ref>
<ref id="CIT0003"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Ahluwalia</surname>, <given-names>P</given-names></string-name>. &#x0026; <string-name><surname>Merhi</surname>, <given-names>M.I</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Moral and subjective norms: How do they effect information security compliance?</article-title>&#x2019;, in <conf-name>Proceedings of the 24th Americas Conference on Information Systems, AMCIS</conf-name>, pp. <fpage>1</fpage>&#x2013;<lpage>10</lpage>, <conf-loc>New Orleans, LA</conf-loc>.</mixed-citation></ref>
<ref id="CIT0004"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Ajzen</surname>, <given-names>I</given-names></string-name></person-group>., <year>1985</year>, &#x2018;<chapter-title>From intentions to actions: A theory of planned behavior</chapter-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>J.</given-names> <surname>Kuhl</surname></string-name> &#x0026; <string-name><given-names>J.</given-names> <surname>Beckmann</surname></string-name> (eds.)</person-group> <source><italic>Action control: From cognition to behavior</italic></source>, pp. <fpage>11</fpage>&#x2013;<lpage>39</lpage>, <publisher-name>Springer</publisher-name>, <publisher-loc>Berlin</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0005"><mixed-citation publication-type="web"><person-group person-group-type="author"><string-name><surname>Amer</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Noujaim</surname>, <given-names>J</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>The great hack</article-title>&#x2019;, <source><italic>Netflix</italic></source>, <comment>viewed n.d., from <ext-link ext-link-type="uri" xlink:href="https://www.netflix.com/za/title/80117542">https://www.netflix.com/za/title/80117542</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0006"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Baek</surname>, <given-names>Y.M</given-names></string-name>., <string-name><surname>Kim</surname>, <given-names>E.M</given-names></string-name>. &#x0026; <string-name><surname>Bae</surname>, <given-names>Y</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>My privacy is okay, but theirs is endangered: Why comparative optimism matters in online privacy concerns</article-title>&#x2019;, <source><italic>Computers in Human Behavior</italic></source> <volume>31</volume>, <fpage>2414</fpage>&#x2013;<lpage>2419</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.chb.2013.10.010">https://doi.org/10.1016/j.chb.2013.10.010</ext-link></comment></mixed-citation></ref>
<ref id="CIT0007"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bauer</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Bernroider</surname>, <given-names>E.W.N</given-names></string-name>. &#x0026; <string-name><surname>Chudzikowski</surname>, <given-names>K</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Prevention is better than cure! Designing information security awareness programs to overcome users&#x2019; non-compliance with information security policies in banks</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>68</volume>, <fpage>145</fpage>&#x2013;<lpage>159</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2017.04.009">https://doi.org/10.1016/j.cose.2017.04.009</ext-link></comment></mixed-citation></ref>
<ref id="CIT0008"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Benson</surname>, <given-names>V</given-names></string-name>., <string-name><surname>Saridakis</surname>, <given-names>G</given-names></string-name>. &#x0026; <string-name><surname>Tennakoon</surname>, <given-names>H</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Information disclosure of social media users: Does control over personal information, user awareness and security notices matter?</article-title>&#x2019;, <source><italic>Information Technology and People</italic></source> <volume>28</volume>(<issue>3</issue>), <fpage>426</fpage>&#x2013;<lpage>441</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ITP-10-2014-0232">https://doi.org/10.1108/ITP-10-2014-0232</ext-link></comment></mixed-citation></ref>
<ref id="CIT0009"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bowen</surname>, <given-names>G.A</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>Document analysis as a qualitative research method</article-title>&#x2019;, <source><italic>Qualitative Research Journal</italic></source> <volume>9</volume>(<issue>2</issue>), <fpage>27</fpage>&#x2013;<lpage>40</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3316/QRJ0902027">https://doi.org/10.3316/QRJ0902027</ext-link></comment></mixed-citation></ref>
<ref id="CIT0010"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Boyd</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Hargittai</surname>, <given-names>E</given-names></string-name></person-group>., <year>2010</year>, &#x2018;<article-title>Facebook privacy settings: Who cares?</article-title>&#x2019;, <source><italic>First Monday: Peer-Reviewed Journal on the Internet</italic></source> <volume>15</volume>(<issue>8</issue>). <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.5210/fm.v15i8.3086">https://doi.org/10.5210/fm.v15i8.3086</ext-link></comment></mixed-citation></ref>
<ref id="CIT0011"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Braun</surname>, <given-names>V</given-names></string-name>. &#x0026; <string-name><surname>Clarke</surname>, <given-names>V</given-names></string-name></person-group>., <year>2006</year>, &#x2018;<article-title>Using thematic analysis in psychology</article-title>&#x2019;, <source><italic>Qualitative Research in Psychology</italic></source> <volume>3</volume>(<issue>2</issue>), <fpage>77</fpage>&#x2013;<lpage>101</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1191/1478088706qp063oa">https://doi.org/10.1191/1478088706qp063oa</ext-link></comment></mixed-citation></ref>
<ref id="CIT0012"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chalub</surname>, <given-names>F.A.C.C</given-names></string-name>., <string-name><surname>Santos</surname>, <given-names>F.C</given-names></string-name>. &#x0026; <string-name><surname>Pacheco</surname>, <given-names>J.M</given-names></string-name></person-group>., <year>2006</year>, &#x2018;<article-title>The evolution of norms</article-title>&#x2019;, <source><italic>Journal of Theoretical Biology</italic></source> <volume>241</volume>(<issue>2</issue>), <fpage>233</fpage>&#x2013;<lpage>240</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.jtbi.2005.11.028">https://doi.org/10.1016/j.jtbi.2005.11.028</ext-link></comment></mixed-citation></ref>
<ref id="CIT0013"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chung</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Rimal</surname>, <given-names>R.N</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Social norms: A review</article-title>&#x2019;, <source><italic>Review of Communication Research</italic></source> <volume>4</volume>, <fpage>1</fpage>&#x2013;<lpage>28</lpage>.</mixed-citation></ref>
<ref id="CIT0014"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Debatin</surname>, <given-names>B</given-names></string-name>., <string-name><surname>Lovejoy</surname>, <given-names>J.P</given-names></string-name>., <string-name><surname>Horn</surname>, <given-names>A.-K</given-names></string-name>. &#x0026; <string-name><surname>Hughes</surname>, <given-names>B.N</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>Facebook and online privacy: Attitudes, behaviors, and unintended consequences</article-title>&#x2019;, <source><italic>Journal of Computer-Mediated Communication</italic></source> <volume>15</volume>(<issue>1</issue>), <fpage>83</fpage>&#x2013;<lpage>108</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1111/j.1083-6101.2009.01494.x">https://doi.org/10.1111/j.1083-6101.2009.01494.x</ext-link></comment></mixed-citation></ref>
<ref id="CIT0015"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Dickinson</surname>, <given-names>S.J</given-names></string-name>. &#x0026; <string-name><surname>Holmes</surname>, <given-names>M</given-names></string-name></person-group>., <year>2008</year>, &#x2018;<article-title>Understanding the emotional and coping responses of adolescent individuals exposed to threat appeals</article-title>&#x2019;, <source><italic>International Journal of Advertising</italic></source> <volume>27</volume>(<issue>2</issue>), <fpage>251</fpage>&#x2013;<lpage>278</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/02650487.2008.11073054">https://doi.org/10.1080/02650487.2008.11073054</ext-link></comment></mixed-citation></ref>
<ref id="CIT0016"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Ernst</surname>, <given-names>H</given-names></string-name>., <string-name><surname>Pfeiffer</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Rothlauf</surname>, <given-names>F</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<chapter-title>Privacy protecting behavior in social network sites</chapter-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>C-P.H.</given-names> <surname>Ernst</surname></string-name> (ed.)</person-group>, <source><italic>Factors driving social network site usage</italic></source>, pp. <fpage>1</fpage>&#x2013;<lpage>9</lpage>, <publisher-name>Springer</publisher-name>, <publisher-loc>Wiesbaden</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0017"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>Facebook</collab></person-group>, <year>2019</year>, <source><italic>What is public information on Facebook?</italic></source>, <comment>viewed 01 April 2020, from <ext-link ext-link-type="uri" xlink:href="https://www.facebook.com/help/203805466323736">https://www.facebook.com/help/203805466323736</ext-link></comment></mixed-citation></ref>
<ref id="CIT0018"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Feng</surname>, <given-names>Y</given-names></string-name>. &#x0026; <string-name><surname>Xie</surname>, <given-names>Q</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Privacy concerns, perceived intrusiveness, and privacy controls: An analysis of virtual try-on apps</article-title>&#x2019;, <source><italic>Journal of Interactive Advertising</italic></source> <volume>19</volume>(<issue>1</issue>), <fpage>43</fpage>&#x2013;<lpage>57</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/15252019.2018.1521317">https://doi.org/10.1080/15252019.2018.1521317</ext-link></comment></mixed-citation></ref>
<ref id="CIT0019"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Foltz</surname>, <given-names>B.B</given-names></string-name>., <string-name><surname>Newkirk</surname>, <given-names>H.E</given-names></string-name>. &#x0026; <string-name><surname>Schwager</surname>, <given-names>P.H</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>An empirical investigation of factors that influence individual behavior toward changing social networking security settings</article-title>&#x2019;, <source><italic>Journal of Theoretical and Applied Electronic Commerce Research</italic></source> <volume>11</volume>(<issue>2</issue>), <fpage>1</fpage>&#x2013;<lpage>15</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4067/S0718-18762016000200002">https://doi.org/10.4067/S0718-18762016000200002</ext-link></comment></mixed-citation></ref>
<ref id="CIT0020"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Golbeck</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Mauriello</surname>, <given-names>M</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>User perception of Facebook app data access: A comparison of methods and privacy concerns</article-title>&#x2019;, <source><italic>Future Internet</italic></source> <volume>8</volume>(<issue>2</issue>), <fpage>9</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/fi8020009">https://doi.org/10.3390/fi8020009</ext-link></comment></mixed-citation></ref>
<ref id="CIT0021"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Govani</surname>, <given-names>T</given-names></string-name>. &#x0026; <string-name><surname>Pashley</surname>, <given-names>H</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>Student awareness of the privacy implications when using Facebook</article-title>&#x2019;, <source><italic>Cyberpsychology</italic></source> <volume>8</volume>(<issue>2</issue>), <fpage>1</fpage>&#x2013;<lpage>17</lpage>.</mixed-citation></ref>
<ref id="CIT0022"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Grimes</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Marquardson</surname>, <given-names>J</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Quality matters: Evoking subjective norms and coping appraisals by system design to increase security intentions</article-title>&#x2019;, <source><italic>Decision Support Systems</italic></source> <volume>119</volume>, <fpage>23</fpage>&#x2013;<lpage>34</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.dss.2019.02.010">https://doi.org/10.1016/j.dss.2019.02.010</ext-link></comment></mixed-citation></ref>
<ref id="CIT0023"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ham</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Jeger</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Ivkovi&#x0107;</surname>, <given-names>A.F</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>The role of subjective norms in forming the intention to purchase green food</article-title>&#x2019;, <source><italic>Economic Research-Ekonomska Istrazivanja</italic></source> <volume>28</volume>(<issue>1</issue>), <fpage>738</fpage>&#x2013;<lpage>748</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/1331677X.2015.1083875">https://doi.org/10.1080/1331677X.2015.1083875</ext-link></comment></mixed-citation></ref>
<ref id="CIT0024"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hanus</surname>, <given-names>B</given-names></string-name>. &#x0026; <string-name><surname>Wu</surname>, <given-names>Y</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Impact of users&#x2019; security awareness on desktop security behavior: A protection motivation theory perspective</article-title>&#x2019;, <source><italic>Information Systems Management</italic></source> <volume>33</volume>(<issue>1</issue>), <fpage>2</fpage>&#x2013;<lpage>16</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/10580530.2015.1117842">https://doi.org/10.1080/10580530.2015.1117842</ext-link></comment></mixed-citation></ref>
<ref id="CIT0025"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Haynes</surname>, <given-names>D</given-names></string-name>., <string-name><surname>Bawden</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Robinson</surname>, <given-names>L</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>A regulatory model for personal data on social networking services in the UK</article-title>&#x2019;, <source><italic>International Journal of Information Management</italic></source> <volume>36</volume>(<issue>6</issue>), <fpage>872</fpage>&#x2013;<lpage>882</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ijinfomgt.2016.05.012">https://doi.org/10.1016/j.ijinfomgt.2016.05.012</ext-link></comment></mixed-citation></ref>
<ref id="CIT0026"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ifinedo</surname>, <given-names>P</given-names></string-name></person-group>., <year>2012</year>, &#x2018;<article-title>Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>31</volume>(<issue>1</issue>), <fpage>83</fpage>&#x2013;<lpage>95</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2011.10.007">https://doi.org/10.1016/j.cose.2011.10.007</ext-link></comment></mixed-citation></ref>
<ref id="CIT0027"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Joffe</surname>, <given-names>H</given-names></string-name></person-group>., <year>2012</year>, <source><italic>Qualitative research methods in mental health and psychotherapy: A guide for students and practitioners</italic></source>, pp. <fpage>209</fpage>&#x2013;<lpage>223</lpage>, <publisher-name>Wiley-Blackwell</publisher-name>, <publisher-loc>New York, NY</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0028"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Johnston</surname>, <given-names>A.C</given-names></string-name>., <string-name><surname>Warkentin</surname>, <given-names>M</given-names></string-name>., <string-name><surname>McBride</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Carter</surname>, <given-names>L</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Dispositional and situational factors: Influences on information security policy violations</article-title>&#x2019;, <source><italic>European Journal of Information Systems</italic></source> <volume>25</volume>(<issue>3</issue>), <fpage>231</fpage>&#x2013;<lpage>251</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1057/ejis.2015.15">https://doi.org/10.1057/ejis.2015.15</ext-link></comment></mixed-citation></ref>
<ref id="CIT0029"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kautonen</surname>, <given-names>T</given-names></string-name>., <string-name><surname>Van Gelderen</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Fink</surname>, <given-names>M</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Robustness of the theory of planned behavior in predicting entrepreneurial intentions and actions</article-title>&#x2019;, <source><italic>Entrepreneurship Theory and Practice</italic></source> <volume>39</volume>(<issue>3</issue>), <fpage>655</fpage>&#x2013;<lpage>674</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1111/etap.12056">https://doi.org/10.1111/etap.12056</ext-link></comment></mixed-citation></ref>
<ref id="CIT0030"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kusyanti</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Puspitasari</surname>, <given-names>D.R</given-names></string-name>., <string-name><surname>Catherina</surname>, <given-names>H.P.A</given-names></string-name>. &#x0026; <string-name><surname>Sari</surname>, <given-names>Y.A.L</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Information privacy concerns on teens as Facebook users in Indonesia</article-title>&#x2019;, <source><italic>Procedia Computer Science</italic></source> <volume>124</volume>, <fpage>632</fpage>&#x2013;<lpage>638</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.procs.2017.12.199">https://doi.org/10.1016/j.procs.2017.12.199</ext-link></comment></mixed-citation></ref>
<ref id="CIT0031"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lapinski</surname>, <given-names>M.K</given-names></string-name>. &#x0026; <string-name><surname>Rimal</surname>, <given-names>R.N</given-names></string-name></person-group>., <year>2005</year>, &#x2018;<article-title>An explication of social norms</article-title>&#x2019;, <source><italic>Communication Theory</italic></source> <volume>15</volume>(<issue>2</issue>), <fpage>127</fpage>&#x2013;<lpage>147</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1111/j.1468-2885.2005.tb00329.x">https://doi.org/10.1111/j.1468-2885.2005.tb00329.x</ext-link></comment></mixed-citation></ref>
<ref id="CIT0032"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lewis</surname>, <given-names>K</given-names></string-name>., <string-name><surname>Kaufman</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Christakis</surname>, <given-names>N</given-names></string-name></person-group>., <year>2008</year>, &#x2018;<article-title>The taste for privacy: An analysis of college student privacy settings in an online social network</article-title>&#x2019;, <source><italic>Journal of Computer-Mediated Communication</italic></source> <volume>14</volume>(<issue>1</issue>), <fpage>79</fpage>&#x2013;<lpage>100</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1111/j.1083-6101.2008.01432.x">https://doi.org/10.1111/j.1083-6101.2008.01432.x</ext-link></comment></mixed-citation></ref>
<ref id="CIT0033"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Marett</surname>, <given-names>K</given-names></string-name>., <string-name><surname>Vedadi</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Durcikova</surname>, <given-names>A</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>A quantitative textual analysis of three types of threat communication and subsequent maladaptive responses</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>80</volume>, <fpage>25</fpage>&#x2013;<lpage>35</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2018.09.004">https://doi.org/10.1016/j.cose.2018.09.004</ext-link></comment></mixed-citation></ref>
<ref id="CIT0034"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Marino</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Vieno</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Pastore</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Albery</surname>, <given-names>I.P</given-names></string-name>., <string-name><surname>Frings</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Spada</surname>, <given-names>M.M</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Modeling the contribution of personality, social identity and social norms to problematic Facebook use in adolescents</article-title>&#x2019;, <source><italic>Addictive Behaviors</italic></source> <volume>63</volume>, <fpage>51</fpage>&#x2013;<lpage>56</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.addbeh.2016.07.001">https://doi.org/10.1016/j.addbeh.2016.07.001</ext-link></comment></mixed-citation></ref>
<ref id="CIT0035"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Min</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Kim</surname>, <given-names>B</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>How are people enticed to disclose personal information despite privacy concerns in social network sites? The calculus between benefit and cost</article-title>&#x2019;, <source><italic>Journal of the Association for Information Science and Technology</italic></source> <volume>66</volume>(<issue>4</issue>), <fpage>839</fpage>&#x2013;<lpage>857</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1002/asi.23206">https://doi.org/10.1002/asi.23206</ext-link></comment></mixed-citation></ref>
<ref id="CIT0036"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Munn</surname>, <given-names>Z</given-names></string-name>., <string-name><surname>Peters</surname>, <given-names>M.D.J</given-names></string-name>., <string-name><surname>Stern</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Tufanaru</surname>, <given-names>C</given-names></string-name>., <string-name><surname>McArthur</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Aromataris</surname>, <given-names>E</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Systematic review or scoping review? Guidance for authors when choosing between a systematic or scoping review approach</article-title>&#x2019;, <source><italic>BMC Medical Research Methodology</italic></source> <volume>18</volume>(<issue>143</issue>), <fpage>1</fpage>&#x2013;<lpage>7</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1186/s12874-018-0611-x">https://doi.org/10.1186/s12874-018-0611-x</ext-link></comment></mixed-citation></ref>
<ref id="CIT0037"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>&#x00D6;&#x0287;&#x00FC;t&#x00E7;&#x00FC;</surname>, <given-names>G</given-names></string-name>., <string-name><surname>Testik</surname>, <given-names>&#x00D6;.M</given-names></string-name>. &#x0026; <string-name><surname>Chouseinoglou</surname>, <given-names>O</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Analysis of personal information security behavior and awareness</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>56</volume>, <fpage>83</fpage>&#x2013;<lpage>93</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2015.10.002">https://doi.org/10.1016/j.cose.2015.10.002</ext-link></comment></mixed-citation></ref>
<ref id="CIT0038"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Park</surname>, <given-names>E.H</given-names></string-name>., <string-name><surname>Kim</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Park</surname>, <given-names>Y.S</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>The role of information security learning and individual factors in disclosing patients&#x2019; health information</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>65</volume>, <fpage>64</fpage>&#x2013;<lpage>76</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2016.10.011">https://doi.org/10.1016/j.cose.2016.10.011</ext-link></comment></mixed-citation></ref>
<ref id="CIT0039"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rogers</surname>, <given-names>R.W</given-names></string-name></person-group>., <year>1975</year>, &#x2018;<article-title>A protection motivation theory of fear appeals and attitude change</article-title>&#x2019;, <source><italic>The Journal of Psychology</italic></source> <volume>91</volume>(<issue>1</issue>), <fpage>93</fpage>&#x2013;<lpage>114</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/00223980.1975.9915803">https://doi.org/10.1080/00223980.1975.9915803</ext-link></comment></mixed-citation></ref>
<ref id="CIT0040"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Saeri</surname>, <given-names>A.K</given-names></string-name>., <string-name><surname>Ogilvie</surname>, <given-names>C</given-names></string-name>., <string-name><surname>La Macchia</surname>, <given-names>S.T</given-names></string-name>., <string-name><surname>Smith</surname>, <given-names>J.R</given-names></string-name>. &#x0026; <string-name><surname>Louis</surname>, <given-names>W.R</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>Predicting Facebook users online privacy protection: Risk, trust, norm focus theory, and the theory of planned behavior</article-title>&#x2019;, <source><italic>Journal of Social Psychology</italic></source> <volume>154</volume>(<issue>4</issue>), <fpage>352</fpage>&#x2013;<lpage>369</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/00224545.2014.914881">https://doi.org/10.1080/00224545.2014.914881</ext-link></comment></mixed-citation></ref>
<ref id="CIT0041"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Safa</surname>, <given-names>N.S</given-names></string-name>. &#x0026; <string-name><surname>Von Solms</surname>, <given-names>R</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>An information security knowledge sharing model in organizations</article-title>&#x2019;, <source><italic>Computers in Human Behavior</italic></source> <volume>57</volume>, <fpage>442</fpage>&#x2013;<lpage>451</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.chb.2015.12.037">https://doi.org/10.1016/j.chb.2015.12.037</ext-link></comment></mixed-citation></ref>
<ref id="CIT0042"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Safa</surname>, <given-names>N.S</given-names></string-name>., <string-name><surname>Maple</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Watson</surname>, <given-names>T</given-names></string-name>. &#x0026; <string-name><surname>Von Solms</surname>, <given-names>R</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Motivation and opportunity based model to reduce information security insider threats in organisations</article-title>&#x2019;, <source><italic>Journal of Information Security and Applications</italic></source> <volume>40</volume>, <fpage>247</fpage>&#x2013;<lpage>257</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.jisa.2017.11.001">https://doi.org/10.1016/j.jisa.2017.11.001</ext-link></comment></mixed-citation></ref>
<ref id="CIT0043"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Stern</surname>, <given-names>T</given-names></string-name>. &#x0026; <string-name><surname>Salb</surname>, <given-names>D</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Examining online social network use and its effect on the use of privacy settings and profile disclosure</article-title>&#x2019;, <source><italic>Bulletin of Science, Technology &#x0026; Society</italic></source> <volume>35</volume>(<issue>1&#x2013;2</issue>), <fpage>25</fpage>&#x2013;<lpage>34</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1177/0270467615596890">https://doi.org/10.1177/0270467615596890</ext-link></comment></mixed-citation></ref>
<ref id="CIT0044"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Strater</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Lipford</surname>, <given-names>H</given-names></string-name></person-group>., <year>2008</year>, &#x2018;<article-title>Strategies and struggles with privacy in an online social networking community</article-title>&#x2019;, in <conf-name>Proceedings of the 22nd British HCI Group Annual Conference on People and Computers: Culture, Creativity, Interaction, BCS-HCI</conf-name>, pp. <fpage>111</fpage>&#x2013;<lpage>119</lpage>, <conf-loc>Liverpool</conf-loc>.</mixed-citation></ref>
<ref id="CIT0045"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Strycharz</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Van Noort</surname>, <given-names>G</given-names></string-name>., <string-name><surname>Smit</surname>, <given-names>E</given-names></string-name>. &#x0026; <string-name><surname>Helberger</surname>, <given-names>N</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Protective behavior against personalized ads: Motivation to turn personalization off</article-title>&#x2019;, <source><italic>Cyberpsychology</italic></source> <volume>13</volume>(<issue>2</issue>), <fpage>1</fpage>&#x2013;<lpage>22</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.5817/CP2019-2-1">https://doi.org/10.5817/CP2019-2-1</ext-link></comment></mixed-citation></ref>
<ref id="CIT0046"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Symeonidis</surname>, <given-names>I</given-names></string-name>., <string-name><surname>Bicz&#x00F3;k</surname>, <given-names>G</given-names></string-name>., <string-name><surname>Shirazi</surname>, <given-names>F</given-names></string-name>., <string-name><surname>P&#x00E9;rez-Sol&#x00E0;</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Schroers</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Preneel</surname>, <given-names>B</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Collateral damage of Facebook third-party applications: A comprehensive study</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>77</volume>, <fpage>179</fpage>&#x2013;<lpage>208</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2018.03.015">https://doi.org/10.1016/j.cose.2018.03.015</ext-link></comment></mixed-citation></ref>
<ref id="CIT0047"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tifferet</surname>, <given-names>S</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Gender differences in privacy tendencies on social network sites: A meta-analysis</article-title>&#x2019;, <source><italic>Computers in Human Behavior</italic></source> <volume>93</volume>, <fpage>1</fpage>&#x2013;<lpage>12</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.chb.2018.11.046">https://doi.org/10.1016/j.chb.2018.11.046</ext-link></comment></mixed-citation></ref>
<ref id="CIT0048"><mixed-citation publication-type="web"><person-group person-group-type="author"><string-name><surname>Timberg</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Romm</surname>, <given-names>T</given-names></string-name>. &#x0026; <string-name><surname>Dwoskin</surname>, <given-names>E</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Zuckerberg apologizes, promises reform as senators grill him over Facebook&#x2019;s failings</article-title>&#x2019;, <comment>viewed 01 April 2020, from <ext-link ext-link-type="uri" xlink:href="https://www.washingtonpost.com/business/technology/2018/04/10/b72c09e8-3d03-11e8-974f-aacd97698cef_story.html">https://www.washingtonpost.com/business/technology/2018/04/10/b72c09e8-3d03-11e8-974f-aacd97698cef_story.html</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0049"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tsai</surname>, <given-names>H.Y.S</given-names></string-name>., <string-name><surname>Jiang</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Alhabash</surname>, <given-names>S</given-names></string-name>., <string-name><surname>LaRose</surname>, <given-names>R</given-names></string-name>., <string-name><surname>Rifon</surname>, <given-names>N.J</given-names></string-name>. &#x0026; <string-name><surname>Cotten</surname>, <given-names>S.R</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Understanding online safety behaviors: A protection motivation theory perspective</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>59</volume>, <fpage>138</fpage>&#x2013;<lpage>150</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2016.02.009">https://doi.org/10.1016/j.cose.2016.02.009</ext-link></comment></mixed-citation></ref>
<ref id="CIT0050"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Vishwanath</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Xu</surname>, <given-names>W</given-names></string-name>. &#x0026; <string-name><surname>Ngoh</surname>, <given-names>Z</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>How people protect their privacy on Facebook: A cost-benefit view</article-title>&#x2019;, <source><italic>Journal of the Association for Information Science and Technology</italic></source> <volume>69</volume>(<issue>5</issue>), <fpage>700</fpage>&#x2013;<lpage>709</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1002/asi.23894">https://doi.org/10.1002/asi.23894</ext-link></comment></mixed-citation></ref>
<ref id="CIT0051"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>White</surname>, <given-names>K.M</given-names></string-name>., <string-name><surname>Smith</surname>, <given-names>J.R</given-names></string-name>., <string-name><surname>Terry</surname>, <given-names>D.J</given-names></string-name>., <string-name><surname>Greenslade</surname>, <given-names>J.H</given-names></string-name>. &#x0026; <string-name><surname>Blake</surname>, <given-names>M</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>Social influence in the theory of planned behaviour : The role of descriptive, injunctive, and ingroup norms</article-title>&#x2019;, <source><italic>Society</italic></source> <volume>48</volume>(<issue>1</issue>), <fpage>135</fpage>&#x2013;<lpage>158</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1348/014466608X295207">https://doi.org/10.1348/014466608X295207</ext-link></comment></mixed-citation></ref>
<ref id="CIT0052"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Witte</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Allen</surname>, <given-names>M</given-names></string-name></person-group>., <year>2000</year>, &#x2018;<article-title>A meta-analysis of fear appeals: Implications for effective public health campaigns</article-title>&#x2019;, <source><italic>Health Education &#x0026; Behavior</italic></source> <volume>27</volume>(<issue>5</issue>), <fpage>591</fpage>&#x2013;<lpage>615</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1177/109019810002700506">https://doi.org/10.1177/109019810002700506</ext-link></comment></mixed-citation></ref>
<ref id="CIT0053"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zlatolas</surname>, <given-names>L.N</given-names></string-name>., <string-name><surname>Welzer</surname>, <given-names>T</given-names></string-name>., <string-name><surname>Heri&#x010D;ko</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>H&#x00F6;lbl</surname>, <given-names>M</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Privacy antecedents for SNS self-disclosure: The case of Facebook</article-title>&#x2019;, <source><italic>Computers in Human Behavior</italic></source> <volume>45</volume>, <fpage>158</fpage>&#x2013;<lpage>167</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.chb.2014.12.012">https://doi.org/10.1016/j.chb.2014.12.012</ext-link></comment></mixed-citation></ref>
</ref-list>
<fn-group>
<fn><p><bold>How to cite this article:</bold> Read, K. &#x0026; Van der Schyff, K., 2020, &#x2018;Modelling the intended use of Facebook privacy settings&#x2019;, <italic>South African Journal of Information Management</italic> 22(1), a1238. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajim.v22i1.1238">https://doi.org/10.4102/sajim.v22i1.1238</ext-link></p></fn>
</fn-group>
</back>
</article>