There are some risks to confidentiality and privacy from utilizing
offshore outsourcing of various information system functions. It is an
additional layer that has access to the information versus if the
information remained within the company. The third party may have
different standards/regulations and liabilities regarding the
information. The distance prevents quick access to how the third-
party operations are set up. Meaning you wouldn’t have any idea how
the third party is securing the physical location; the software or
equipment utilized from breaches.
I think the organization has the responsibility and duty to protect the
privacy of its customers’ personal information. It should be treated in
the same matter as if it was physical property. The organization
should take every step to ensure it’s safety. In this digital age, not
securing this type of information can have an influential impact on the
health of a company.
Also, there are regulations/standards in place to ensure the
protection of personal information. For example, the GDPR or
General Data Protection Regulation in the European Union is “One of
the strictest and most far-reaching privacy regulations, imposing huge
fines for issues such as not properly obtaining consent to collect and
use personal information or not being able to document that the
organization has taken a proactive approach to protect privacy”
(Romney, Steinbart, Summers, & Wood, 2020 pg. 372).
Reference
Romney, M. B., Steinbart, P. J., Summers, S. L., & Wood, D. A. (2020).
Accounting Information Systems (15th ed.). Pearson Education (US).
https://mbsdirect.vitalsource.com/books/9780135573082