BALANCING ACCESS AND PRIVACY: REGULATORY GAPS, AUTHENTICATION, AND DATA SECURITY IN DIGITAL PRESERVATION OF INSTITUTIONAL RECORDS
Abstract
Digital preservation is often framed as a technical archival problem, yet the governance choices surrounding it carry direct consequences for information security and data privacy. This study draws on qualitative case-study data from a Ghanaian educational institution to examine how the absence of enforced legal and regulatory frameworks for digitized records shapes user authentication practices, data security, and privacy outcomes in a live school management information system. Twenty-five stakeholders, including parents, teachers, facilitators, and administrators, were interviewed about their experiences with user access, authentication, and data handling. Findings show that authentication mechanisms, including unique login credentials, QR-code verification, and digital signatures, were valued by users primarily as privacy safeguards, and that stakeholders explicitly requested encryption and non-disclosure of data to third parties, despite the absence of a specific institutional data-protection policy referencing Ghana’s regulatory framework. The findings are discussed in relation to Ghana’s Data Protection Act, 2012, and the Public Records and Archives Administration Act, 1997, alongside the growing role of artificial-intelligence-assisted compliance monitoring and cloud security posture management. The study concludes that in resource-constrained institutional settings, privacy protection is being improvised by end users and administrators in the absence of formal governance, a pattern with implications for institutions well beyond the case examined here.