Quantifying Routine Activity Theory Factors in Personal Data Protection for Financial Institutions
DOI:
https://doi.org/10.26877/asset.v8i4.2682Keywords:
Routine Activity Theory (RAT), personal data protection, financial institutions, Information SecurityAbstract
Personal data protection has become a crucial issue in the financial sector as banking, fintech, and insurance services become increasingly digitized. This study aims to analyze the role of Routine Activity Theory (RAT) through three factors: motivated offender, suitable target, and capable guardianship, in improving the effectiveness of personal data protection. A quantitative method was used with a population of employees directly involved in personal data management, and 233 respondents were obtained through purposive sampling. Multiple regression analysis using SPSS showed that the three RAT constructs had a significant effect, with the capable guardianship factor having the strongest coefficient. The findings emphasize the importance of monitoring, access control, and risk mitigation against data leaks. The implication for financial institutions is the need to develop information security management strategies based on actor behavior, target vulnerability, and supervision mechanisms to increase public trust and digital resilience in the era of digital financial transformation.
References
[1] Barroso M, Laborda J. Digital transformation and the emergence of the Fintech sector: Systematic literature review. Digital Business 2022;2:100028. https://doi.org/10.1016/j.digbus.2022.100028.
[2] Aldboush HHH, Ferdous M. Building trust in fintech: an analysis of ethical and privacy considerations in the intersection of big data, AI, and customer trust. International Journal of Financial Studies 2023;11:90. https://doi.org/10.3390/ijfs11030090.
[3] Cremer F, Sheehan B, Fortmann M, Kia AN, Mullins M, Murphy F, et al. Cyber risk and cybersecurity: a systematic review of data availability. Geneva Pap Risk Insur Issues Pract 2022;47:698. https://doi.org/10.1057/s41288-022-00266-6.
[4] Zostant M, Chataut R. Privacy in computer ethics: Navigating the digital age. Computer Science and Information Technologies 2023;4:183–90. https://doi.org/10.11591/csit.v4i2.pp183-190.
[5] Wibowo A, Alawiyah W, Azriadi. The importance of personal data protection in Indonesia’s economic development. Cogent Soc Sci 2024;10:2306751. https://doi.org/10.1080/23311886.2024.2306751.
[6] Stadnicki I, Corsini M, Szulkin M. Application of criminology in urban ecology and evolution: Routine Activity Theory and field equipment disappearance dynamics. Ecol Indic 2024;165:112095. https://doi.org/10.1016/j.ecolind.2024.112095.
[7] Madarie R, Weulen Kranenbarg M, de Poot C. Cybersecurity expert perspectives on data thieves’ actions in digital environments: Potential refinements for routine activity theory. Deviant Behav 2026;47:544–62. https://doi.org/10.1080/01639625.2025.2453440.
[8] Kamil S, Al-Turfi M, Almukhtar R. Advancements in chemical materials: Exploring smart storage equipment and protection systems. Journal of Applied Engineering and Technological Science (JAETS) 2024;5:1086–101. https://doi.org/10.37385/jaets.v5i2.4096.
[9] Bello M, Griffiths M. Routine activity theory and cybercrime investigation in Nigeria: how capable are law enforcement agencies? Rethinking Cybercrime: Critical Debates, Springer; 2020, p. 213–35. https://doi.org/10.1007/978-3-030-55841-3_11.
[10] Lee YY, Gan CL, Liew TW. Phishing victimization among Malaysian young adults: cyber routine activities theory and attitude in information sharing online. The Journal of Adult Protection 2022;24:179–94. https://doi.org/10.1108/JAP-06-2022-0011.
[11] Ahmad R, Thurasamy R. A systematic literature review of routine activity theory’s applicability in cybercrimes. Journal of Cyber Security and Mobility 2022;11:405–32. https://doi.org/10.13052/jcsm2245-1439.1133.
[12] Özaşçılar M, Çalıcı C, Vakhitova Z. Examining cybercrime victimisation among Turkish women using routine activity theory. Crime Prevention and Community Safety 2024;26:112–28. https://doi.org/10.1057/s41300-024-00201-y.
[13] Bekele WB, Ago FY. Sample size for interview in qualitative research in social sciences: A guide to novice researchers. Research in Educational Policy and Management 2022;4:42–50. https://doi.org/10.46303/repam.2022.3.
[14] Demir S. Comparison of normality tests in terms of sample sizes under different skewness and kurtosis coefficients. International Journal of Assessment Tools in Education 2022;9:397–409. https://doi.org/10.21449/ijate.1101295.
[15] Janna N, Herianto H. Konsep uji validitas dan reliabilitas dengan menggunakan SPSS 2021. https://doi.org/10.31219/osf.io/v9j52.
[16] Gonçalves MC, Silva R. The effect of statistical hypothesis testing on machine learning model selection. Brazilian conference on intelligent systems, Springer; 2023, p. 415–27. https://doi.org/10.1007/978-3-031-45389-2_28.
[17] De Kimpe L, Walrave M, Verdegem P, Ponnet K. What we think we know about cybersecurity: an investigation of the relationship between perceived knowledge, internet trust, and protection motivation in a cybercrime context. Behaviour & Information Technology 2022;41:1796–808. https://doi.org/10.1080/0144929X.2021.1905066.
[18] Mazarr MJ, Rhoades AL, Beauchamp-Mustafaga N, Blanc AA, Eaton D, Feistel K, et al. Disrupting deterrence: Examining the effects of technologies on strategic deterrence in the 21st century 2022.
[19] Wijaya ID, Salam R, Ghozi S, Mubarok FU, Subkhan MF. Perceived security and trust as mechanisms of P2P adoption technology: Evidence from pre-adopters using PLS-SEM approach. International Journal of Environment, Engineering and Education 2026;8:19–34. https://doi.org/10.55151/ijeedu.v8i1.373.
[20] Ireland L. Predicting online target hardening behaviors: An extension of routine activity theory for privacy-enhancing technologies and techniques. Deviant Behav 2021;42:1532–48. https://doi.org/10.1080/01639625.2020.1760418.
[21] Hughes-Lartey K, Li M, Botchey FE, Qin Z. Human factor, a critical weak point in the information security of an organization’s Internet of things. Heliyon 2021;7. https://doi.org/10.1016/j.heliyon.2021.e06522.
[22] Fontes C, Hohma E, Corrigan CC, Lütge C. AI-powered public surveillance systems: why we (might) need them and how we want them. Technol Soc 2022;71:102137. https://doi.org/10.1016/j.techsoc.2022.102137.
[23] Chen S, Hao M, Ding F, Jiang D, Dong J, Zhang S, et al. Exploring the global geography of cybercrime and its driving forces. Humanit Soc Sci Commun 2023;10:71. https://doi.org/10.1057/s41599-023-01560-x.
[24] Al-Harrasi A, Shaikh AK, Al-Badi A. Towards protecting organisations’ data by preventing data theft by malicious insiders. International Journal of Organizational Analysis 2023;31:875–88. https://doi.org/10.1108/IJOA-01-2021-2598.
[25] Aslan Ö, Aktuğ SS, Ozkan-Okay M, Yilmaz AA, Akin E. A comprehensive review of cyber security vulnerabilities, threats, attacks, and solutions. Electronics (Basel) 2023;12:1333. https://doi.org/10.3390/electronics12061333.
[26] Lehto M. Cyber-attacks against critical infrastructure. Cyber security: Critical infrastructure protection, Springer; 2022, p. 3–42. https://doi.org/10.1007/978-3-030-91293-2_1.
[27] Sargiotis D. Data security and privacy: Protecting sensitive information. Data governance: a guide, Springer; 2024, p. 217–45. https://doi.org/10.1007/978-3-031-67268-2_6.
[28] Brown H, Lee K, Mireshghallah F, Shokri R, Tramèr F. What does it mean for a language model to preserve privacy? Proceedings of the 2022 ACM conference on fairness, accountability, and transparency, 2022, p. 2280–92. https://doi.org/10.1145/3531146.3534642.
[29] Jamal H, Algeelani NA, Al-Sammarraie N. Safeguarding data privacy: strategies to counteract internal and external hacking threats. Computer Science and Information Technologies 2024;5:46–54. https://doi.org/10.11591/csit.v5i1.pp46-54.
[30] Bouraffa T, Hui K-L. Regulating information and network security: Review and challenges. ACM Comput Surv 2025;57:1–38. https://doi.org/10.1145/3711124.
[31] Delso-Vicente A-T, Diaz-Marcos L, Aguado-Tevar O, de Blanes-Sebastián MG. Factors influencing employee compliance with information security policies: a systematic literature review of behavioral and technological aspects in cybersecurity. Future Business Journal 2025;11:28. https://doi.org/10.1186/s43093-025-00452-7.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Advance Sustainable Science Engineering and Technology

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.





