Abstract
Service frontline encounters between customers and service providers have been subject to fundamental changes in recent years. As two major change agents, technology infusion and data privacy regulations are inextricably linked and constitute a critical ethical and societal issue. Specifically, service frontlines—as represented by human or technological agents, or some hybrid form—rely on customer data for service provision, which subjects them to privacy regulations governing the collection, submission, access, and use of any customer data thus captured. However, scant research outlines the significant implications of evolving data privacy regulations for service frontline encounters. To advance knowledge in this domain, this research distills six key dimensions of global data privacy regulations (fairness, data limits, transparency, control, consent, and recourse). Employing an intelligences theoretical lens, the authors theorize how these dimensions might become differentially manifest across three service frontline interface types (human-based, technology-based, and hybrid). Carefully intersecting the need for varying intelligences across data privacy regulatory dimensions with the abilities of service frontline interfaces to harness each intelligence type, this study offers a novel conceptual framework that advances research and practice. Theoretical, managerial, and policy implications unfold from the proposed framework, which also can inform a future research agenda.
Keywords
The service frontline—as the point of contact between service providers and customers (Bitner, Booms, and Tetreault 1990; Czepiel, Solomon, and Surprenant 1985; Singh et al. 2017)—has experienced substantive changes in recent years. The profound effect of technology on service frontlines cannot be overstated. Even as services and marketing literature have outlined its dramatic effects as a change agent (e.g., Huang and Rust 2018, 2021a, 2021b; Marinova et al. 2017; Steinhoff et al. 2019), it remains a crucial research imperative (Huang et al. 2021; Ostrom et al. 2021). The parameters of expansive, global privacy directives also have significant implications for service frontlines. Encounters at the service frontline both produce and are powered by the use of customer data, and those outcomes are especially dependent on the support of technological advancements. Therefore, service frontlines are closely intertwined with considerations raised by new data privacy regulations, which create rules governing the collection, submission, access, and use of customer data generated through customer–service provider encounters (Milberg, Smith, and Burke 2000). For example, the U.K.-based customer service outsourcing provider Frontline warned its business customers of the General Data Protection Regulation’s (GDPR) far-reaching effects on its customer service operations, citing call centers as especially vulnerable areas, because “If your [call center services fail] to gather information on customers in the way mandated by the new law, then it will be a very obvious act of non-compliance” (wearefrontline.co.uk 2021).
Yet service frontlines and data privacy regulations mostly have been studied in isolation. As customer data privacy studies evolve in services and marketing research, the implications and manifestations of regulatory and policy changes at the service frontline have remained largely unexplored (for a review, see Martin and Murphy 2017). But actors at service frontlines need insights to navigate evolving data privacy regulations. This notable gap between scholarly understanding and business practice leaves many service providers alone to grapple with their large-scale data privacy regulatory compliance (Holleran 2021), a situation that often assigns yet another set of responsibilities to already overburdened frontline employees (Critchley 2020). As regulatory insights gradually infiltrate service frontlines, this dearth in knowledge threatens compliance too, putting firms at risk of punitive measures, sanctions, and negative customer responses such as negative word of mouth or switching behaviors.
To help fill the void in services research pertaining to how data privacy regulations affect and can be managed at the service frontline, we undertake a conceptual examination of three service frontline interface configurations that reflect a spectrum of technological integration, then describe how six focal dimensions of global data privacy regulations materialize across these service frontline interfaces. Using an intelligences theoretical lens (Huang and Rust 2018, 2021a, 2021b), we examine their intersection to develop a novel theoretical framework and advance key research propositions. In encounters with customers, it is challenging for service providers to effectively and efficiently implement various data privacy regulatory dimensions across different service frontlines. Customers also attribute varying competencies to different frontline interfaces (human, technology, and hybrid), reflecting the interfaces’ differential intelligence-based capabilities. With these assessments, we can define optimal configurations of intelligences, as they are best harnessed by various service frontline interfaces. Our investigation answers calls to study the regulatory and policy effects of technological advances at service frontlines, inspired by Ostrom et al.’s (2021, p. 348) realization that “the continued acceleration of technology … will require a renewed look at existing labor, worker safety, and (consumer and employee) privacy laws.”
Our novel conceptual framework makes relevant contributions to the academic inquiry of service frontlines. Relying on Huang and Rust’s (2018, 2021a) theoretical explication of intelligences in service provision, this proposed framework delineates (1) how humans and technology exhibit different capabilities with regard to three key intelligences; (2) how implementing and safeguarding six data privacy regulatory dimensions (fairness, data limits, transparency, control, consent, and recourse) requires different intelligences; and (3) how service providers can strategically deploy service frontline interfaces (human-based, technology-based, and hybrid) to exploit the benefits of different intelligences in ways that purposefully establish and enforce each data privacy dimension for customers.
The article is structured as follows: First, we examine the role of technology as a change agent in service frontlines, through which we identify three predominant types of interfaces of how technology manifests across service frontlines. We refer to them as human-based, technology-based, and hybrid service frontline interfaces. Second, we analyze global privacy regulatory frameworks and identify six key dimensions (fairness, data limits, transparency, control, consent, and recourse) that emerge across them, regardless of their origin. Third, we investigate the intersection of the service frontline interface typology and privacy regulatory dimensions through an intelligences theoretical lens to establish three high-level research propositions. Fourth, this framework enables us to offer theoretical, managerial, and policy implications, which we leverage to suggest further research directions too.
Technology Infusion at the Service Frontline
Academic research on the service frontline acknowledges the infusion of technology, such that technology complements or substitutes human frontline employees (Marinova et al. 2017), into service frontline encounters between customers and service providers as a key change agent (Bitner, Brown, and Meuter 2000; Giebelhausen et al. 2014; Singh et al. 2017). Specifically, service providers employ different interfaces that “serve as the medium for the contact between the customer and the organization” (Singh et al. 2017, p. 4). Several conceptualizations of service frontline interfaces have been put forth (De Keyser et al. 2019; Larivière et al. 2017; Marinova et al. 2017), often featuring a continuum from solely human-based to solely technology-based interfaces. Service providers have choices in how to configure their frontline interfaces, such that they can employ human service representatives only, technology only (i.e., firm-controlled software accessed through firm-controlled or customer-controlled devices), or some blend of both. These configurations, as we delineate herein, have distinct implications for how customers, as counterparts at the service frontline and—as “natural persons” (Art. 1 GDPR)—reference objects for data privacy regulations, attribute manifestations of data privacy regulatory dimensions to the focal service provider.
In our conceptualization, service frontline interfaces, as configured by service providers, can be grouped into three broad categories: human-based, technology-based, and hybrid. For conceptual parsimony in this nascent research domain related to the service frontline interface–data privacy regulation intersection, for technology-based interfaces, we focus on a subset of all conceivable configurations that meets two selection criteria. First, we focus on technology-based interfaces with which the (human) customer directly and actively interacts in the encounter and is thus visibly confronted with how data privacy regulations are put into practice at the service frontline. Hence, we omit machine-to-machine interfaces in which customers assume a more passive role and are often even unaware of the data exchanges between the machines (e.g., in IoT). Second, we limit our analysis to the service provider–customer dyad, excluding encounters involving third-party–controlled software applications that mediate the contact between the customer and the service provider (e.g., third-party–provided virtual assistants such as Google Duplex). Third-party–controlled technology may act as a data privacy intermediary that blurs customer attributions of who (i.e., focal service provider or third-party provider) is responsible for establishing data privacy. Next, we review service literature pertaining to each interface type, starting with solely human and solely technological frontline interfaces, then considering hybrid blends of human employees and technology at the service frontline (see Web Appendix A for a synthesis of extant literature).
Human-Based Service Frontline Interfaces
Traditionally, points of contact between customers and service providers at the service frontline have been conceptualized as “high-touch, low-tech” (Bitner, Brown, and Meuter 2000, p. 138; Giebelhausen et al. 2014, p. 113). In this view, service provision and co-creation take place through a human-based service frontline interface, such that a human frontline employee represents the service provider in service encounters with customers (Solomon et al. 1985). Such technology-free service frontlines are still prevalent in many service encounters, such as tourism and hospitality (e.g., flight attendants, restaurant servers), healthcare and wellness (e.g., physical therapy, hairdressing), or cultural activities (e.g., theater, guided tours).
Extant research outlines the effects of various characteristics and behaviors of human frontline employees. For example, customer emotions (Hennig-Thurau et al. 2006), trust (Sirdeshmukh, Singh, and Sabol 2002), and satisfaction (Bitner, Booms, and Tetreault 1990) represent important potential responses to service encounters, which determine customer–employee rapport and customers’ overall relationship with the service provider (Gwinner, Gremler, and Bitner 1998; Palmatier et al. 2006). A key skill of human frontline employees that technology-based actors cannot yet reproduce is a capacity to engage in emotional labor, such as through a self-regulated display of expected emotions (Hochschild 1983). When service employees exert high levels of authenticity in their emotional labor display, the contagious effects can increase positive affect among customers (Hennig-Thurau et al. 2006). Beyond emotions, frontline employees’ ability to provide core services represents fundamental customer expectations. Thus, customers judge the trustworthiness of service employees, along with their competency, benevolence, and problem-solving orientation, during frontline encounters (Sirdeshmukh, Singh, and Sabol 2002). With a meta-analysis, Palmatier et al. (2006) establish that frontline employees’ expertise and communication capabilities are the most relevant antecedents for building relational assets.
Frontline employees’ behaviors during service encounters can be classified as in-role (i.e., expected behaviors to serve customers) and extra-role (i.e., discretionary behaviors beyond expectations that favor the customer) (Schepers et al. 2012; Schepers and van der Borgh 2020). In-role behaviors have a stronger impact on performance evaluations (Schepers and van der Borgh 2020), but extra-role actions can create highly satisfactory critical incidents for customers (Bitner, Booms, and Tetreault 1990).
Technology-Based Service Frontline Interfaces
An increasing number of customers’ encounters with service providers at the service frontline take place without any intervention of a human service representative, in purely technology-based service frontline interfaces. Consumers use technology tools to access and complete service tasks (Meuter et al. 2000), such as ATMs, online banking applications, and self-check-in kiosks, which have largely replaced human-to-human encounters with bank clerks or airline ground personnel. The service frontlines for ecommerce firms have always relied on technology-based interfaces (e.g., shopping websites and apps), accessed by customers through their own hardware devices (e.g., computers, tablets, and smartphones), such that most customers never interact with a human service employee (Bleier, Harmeling, and Palmatier 2019). Technological advances also continue to produce new types of nonhuman frontline interfaces, capable of increasingly complex service tasks, such as autonomous taxis, humanoid service robots, or virtual voice assistants (Huang and Rust 2018, 2021a).
When customers make use of these self-service technologies, their satisfaction or dissatisfaction likely stems from several sources (Meuter et al. 2000). Satisfying service experiences arise if the self-service technology solves some intensified need, performs better than alternatives, or simply does its job effectively. Dissatisfying incidents are typically due to technology or process failures, poor design, or customer error. Bleier, Harmeling, and Palmatier (2019) identify picture size and customer star ratings as universally powerful web page design elements for stimulating favorable online customer experiences, but various design elements are available to ecommerce firms to create informative, entertaining, social, or sensory experiences.
Similar to service encounters with human employees, satisfying and dissatisfying service experiences (i.e., service failures) with technology interfaces at the service frontline raise questions about customers’ attributions of responsibility. Autonomous technology decreases customers’ perceived behavioral control, which in turn lowers their perceptions of their own responsibility for positive outcomes but not for negative outcomes (Jörling, Böhm, and Paluch 2019), seemingly due to perceptions of ownership of the service robot, irrespective of perceived behavioral control. Customer responses to these service failures and recovery efforts also depend on the robot’s appearance (humanoid vs. nonhumanoid) (Choi, Mattila, and Bolton 2021). Specifically, customers express more dissatisfaction following a process failure caused by a humanoid service robot, due to the lack of warmth it shows. Yet humanoids also can recover a service failure by themselves with a sincere apology that restores perceptions of warmth. Compared with service encounters with human frontline employees, service encounters with humanoid service robots elicit compensatory responses among customers (Mende et al. 2019); driven by feelings of discomfort (e.g., eeriness, threat to human identity), they purchase more status goods, seek social affiliation, and order and eat more food.
Hybrid Service Frontline Interfaces
On many service frontlines, service employees rely on technology to provide services. In these hybrid service frontline interfaces, service providers seek to facilitate service provision at the service frontline by using combinations of human employees and technology (De Keyser et al. 2019; Marinova et al. 2017). The technologies vary widely in their autonomy, ranging from fixed or mobile devices equipped with supporting software applications (e.g., for taking orders, checking-in customers) to autonomously moving service robots that assist frontline employees (e.g., carrying patient files and medical instruments for physicians during ward rounds in a hospital) (De Keyser et al. 2019).
The effects of frontline employees’ thoroughness, knowledgeableness, and preparedness in driving customer satisfaction are consistent and do not differ across communication channels marked by varying levels of richness (e.g., telephone, email, and text chat) (Froehle 2006). However, if exploited effectively by frontline employees, technologies can enhance service encounters. For example, their uses of salesforce automation or customer relationship management software have positive implications for customer service, employee knowledge, and adaptability (Ahearne et al. 2008). Augmenting frontline employees’ capabilities with emotion recognition software can enhance their ability to regulate or manage customers’ emotions (Henkel et al. 2020). Technology used in face-to-face encounters (e.g., self-service check-in kiosks in a hotel lobby) can create interpersonal barriers, with mixed effects on customers’ evaluations (Giebelhausen et al. 2014). If the frontline employee engages in rapport building, customers’ use of technology might distract them from responding in kind, but if the frontline employee does not display such behaviors, technology usage may represent a welcome escape from an uncomfortable social interaction, which can enhance customers’ evaluations.
Although hybrid service frontline interfaces typically are imagined to involve human frontline employees aided by technology, technology also might take the lead, especially as it grows more autonomous and independent of human control (Shanks et al. 2021). Initial evidence obtained from cobotic teams in healthcare suggests that customers are not ready for technology to lead or dominate human influence though; they express lower behavioral intentions toward a robot-led versus a human-led medical team.
Data Privacy Regulation at the Service Frontline
As service technologies have flourished, so have the corresponding recommendations to regulate the stream of customer data they generate. Global data privacy regulations have important business ramifications (Martin et al. 2020), with direct, profound effects for service frontlines. These regulations, pending or enacted in most countries worldwide, have imposed significant changes on organizations’ data privacy processes and practices. Currently, 71% of nations globally adhere to some form of privacy legislation, with another 9% currently drafting protections (United Nations Conference on Trade and Development 2022). We reviewed these frameworks to understand which core principles appear most focal and are most critical to understand in frontline services research and practice.
By reviewing global data privacy regulatory frameworks, we can distill a consistent set of the dimensions and principles used to keep customers’ personal information safe. In defining these dimensions, we recognize that the regulatory stipulations tend to be technology-neutral; they apply to an organization’s treatment of raw data rather than applications on specific technological platforms, functions, or idiosyncrasies that might complicate regulatory oversight (Wong and Henderson 2019). Most data privacy regulatory dimensions also are customer-centric and stipulate how organizations should interact with people and manage their information (Milberg, Smith, and Burke 2000; Palmatier and Martin 2019). Although economic analyses show that privacy regulations can protect and restrict customers, in ways that are either favorable or harmful to their well-being (Acquisti, Taylor, and Wagman 2016), the overarching goals of most frameworks are guided by fairness to the customer. Overall fairness is then operationalized through data limits, which mandate organizational restrictions on data quantity and purpose (Biega and Finck 2021). Beyond, privacy regulations institute transparency and control, sometimes referred to as notice and choice (Culnan 2000; Ohlhausen 2014; Solove and Hartzog 2014). In addition, customers’ ability to enter into a data exchange depends on their consent; termination of the exchange or privacy failure requires some form of recourse (Romanosky, Hoffman, and Acquisti 2014). We examine these six dimensions in the following sections (see Web Appendix B for relevant literature).
Fairness
According to most privacy regulations, fairness, as it pertains to an organization’s data collection, submission, access, use, and other practices, must be demonstrated at top management levels. Yet service frontlines typically facilitate the personal data exchange, so they must follow the practices and approaches to promote fairness principles, as established by the organization. In this sense, fairness—composed of distributive, procedural, and interactional justice (Tax, Brown, and Chandrashekaran 1998)—is largely manifest at the service frontline. Specifically, distributive justice may be determined mainly at the organization level, but the service frontline substantially affects customers’ perceptions of procedural and interactional justice. Fairness goes beyond the regulatory stipulation that any uses of customer data must be legally compliant; it implies an element of ethical practice, exceeding basic legal frames, that determines whether the organization should obtain customer data for the purposes conveyed (Clayton and Sibbald, 2020; Johnson et al., 2020). Fairness, as an overarching approach to a service providers’ data privacy practices, helps shape the ways in which all other privacy regulatory dimensions (data limits, transparency, control, consent, and recourse) are designed and implemented.
Data Limits
Data limits serve as a second guiding principle of privacy regulatory frameworks and are in many ways an operationalization of data privacy fairness. Data limits restrict the quantity (data minimization) and purpose (purpose limitation) of data collected by the organization (Jia, Jin, and Wagman 2021). By requiring (and enforcing) data limits, regulatory frameworks restrict the amount and use of data available to deliver a service to the absolute minimum (Biega et al. 2020; Pfitzmann and Hansen 2010). Organizations can collect only adequate, relevant, and necessary data points, and must commit not to access or collect data unrelated to the core service provision (Palmatier and Martin 2019). Data privacy regulations also require organizations to demonstrate their intent or purpose for using each customer data point they collect; that the data collection is valid and appropriate, given known risks to the customer; and that the collected data are necessary to complete some specific transaction or fulfill a specific contract (Biega and Finck 2021). The purpose for which data are collected must be clearly specified, communicated explicitly, and legitimate, and purpose-specific data may not be processed further for additional uses incompatible with the original purpose.
Transparency
Transparency is a cornerstone of most data privacy regulatory frameworks. If they are transparent, organizations clearly explain the intent and purpose of their data access and collection efforts (Altman et al. 2020). This openness implies full information provision to customers interested in how their personal data are being accessed and used by the firm (Bauer et al. 2021; Walker 2016). Whether achieved or not, most regulatory frameworks call for organizations to ensure their data collection and use policies are clearly conveyed, such that they can be readily understood by customers. The United Nations Privacy Principles, for example, advocate for full transparency of all organizational data processes, including “how to request access, verification, deactivation, and/or deletion of that personal data” (United Nations High-Level Committee on Management 2018, Principle 8). Providing transparency also is a key role for service frontlines (Miller and Tucker 2018), which serve as important information conduits for explaining data privacy practices and processes in ways that are accessible and understandable to customers.
Control
Providing customers with greater agency in information exchanges—such as over the accuracy, scope, parties involved, protection, and termination of those exchanges—tends to be captured in regulatory frameworks as the control dimension, which takes both restrictive and corrective forms. Global regulatory frameworks mandate customer control through a variety of means (Xu et al. 2012). A notable mechanism involves customers’ ability to exercise restrictive controls or opt-out of (or opt-in to) certain data practices (Aridor et al., 2021; Johnson, Shriver et al., 2020). The Federal Trade Commission (FTC) has long embraced a notice and choice model for personal information protection (Ohlhausen 2014), which includes both transparency (notice) and control (choice) as features of the restrictive dimension of control (Cranor 2012). Customers can exercise control to varying degrees, as is apparent in the privacy notices required of financial service providers by the Gramm-Leach-Bliley Act of 1999, which mandates that U.S. customers receive documentation about the personal information those providers have and which uses they can, or cannot, control. Global privacy frameworks also emphasize corrective control, as it relates to customers’ personal information accuracy and ability to remedy errors or discrepancies. Service frontlines are often the interface through which customers exercise control, including opt-in/opt-out preferences and decisions about data access and use. Service frontlines also can enable corrective control processes by allowing customers to revise their personal information or check its accuracy.
Consent
As it relates to regulatory frameworks, the consent dimension means customers may choose freely whether to allow their personal data to be collected in an exchange with an organization (Schmitt, Miller, and Skiera 2020). The decision to provide (or revoke) consent typically happens at service frontlines, which in turn are responsible for ensuring that the service provider is in compliance with customers’ consent choices. Under Australian, Canadian, European, and other global frameworks, people may freely give and revoke consent as they choose (Godinho de Matos and Adjerid 2021; Goldberg, Johnson, and Shriver 2021). Requiring customer consent encourages organizations to be good stewards of personal data and stipulates that data exchanges may occur only if customers explicitly agree (Adjerid et al. 2016). Ideally, customers have adequate knowledge of how the firm intends to use, transmit, protect, and dispose of their data, so they can make informed, free choices about the acceptability of the data exchange and whether they consent to it. Legal and regulatory definitions and operationalizations of consent include fairness, data limits, transparency, and control considerations, so in a sense, this dimension is a culmination of the preceding principles.
Recourse
The final data privacy regulatory dimension we consider involves recourse, as it relates to customer remedies involving data shelf-life, data protection, customer-initiated termination, and voluntary organization-side expunging requirements. According to privacy laws in several U.S. states, data longevity must be monitored, so data can be removed at some point in time, agreed to by the organization and regulators. If organizations violate these terms, customers have legal recourses, so this feature helps ensure organizational accountability. Recourse also gives customers additional sources of control and minimizes their (time, effort, and financial) costs. For example, beyond viable paths to legal recompense or justice, provisions for data portability can minimize customer switching costs (Krämer and Stüdlein 2019); as explicitly stipulated in the GDPR, these provisions allow customers to transfer their personal information from one organization to another more seamlessly than they could before its implementation (Kuebler-Wachendorff et al. 2021).
Another salient form of data privacy recourse involves privacy failures, such as data breaches, and their recovery. With regard to customer options, abilities, and outcomes, prior research has conceptualized data breaches as service failures by the organization (e.g., Malhotra and Malhotra 2011). They offer a relevant context for gaining a better understanding of service failure recovery (Rasoulian et al. 2017). With regard to recourse, the service frontline generally is not responsible for providing or managing the legal response to a data privacy failure, though customers may bring their initial inquiries about these events to service frontlines. The value of service frontlines likely stems from their ability to recover, such that they can provide comfort, empathy, or remedy beyond standard provisions stipulated in regulations or legal mandates.
Integrating Technology Infusion and Data Privacy Regulation at the Service Frontline: An Intelligences-Based Conceptual Framework
Developments in both technology and data privacy regulation converge at the service frontline. In encounters with customers, through different types of service frontline interfaces, service providers face the challenge of effectively and efficiently implementing various data privacy regulation dimensions. Relying on Huang and Rust’s (2018, 2021a) theoretical framework of intelligences in service provision, in our proposed conceptual framework we delineate (1) how humans and technology exhibit different capabilities with regard to three key intelligences, (2) how the six data privacy regulation dimensions (fairness, data limits, transparency, control, consent, and recourse) demand exhibitions of different intelligences, and (3) how service providers can design service frontline interfaces (human-based, technology-based, and hybrid) strategically to gain benefits from different intelligences by purposefully establishing each data privacy dimension for customers.
Technology Infusion at the Service Frontline: Different Intelligences for Service Provision
Intelligence Capabilities of Human and Artificial Intelligences.
Mechanical intelligence involves minimal learning and adaptation. It entails automatically and repeatedly executing routine tasks that demand little or no creativity or careful thought (Huang and Rust 2018; Sternberg 1997). In this sense, mechanical intelligence facilitates standardization (Huang and Rust 2021b). If service tasks require more mechanical intelligence, technology gains relative advantages over humans. Even if humans can execute repetitive tasks without much consideration, as those repetitions increase, they tend to exhibit less consistency and accuracy and become more error-prone. But technology does not suffer fatigue, so it can reliably fulfill mechanical tasks in an automated, error-free (assuming the underlying rule is programmed properly) fashion.
Thinking intelligence comprises both analytical and intuitive intelligence, such that learning and adaptation are based on data (Huang and Rust 2018, 2021a, 2021b). Analytical intelligence supports data mining and the identification of patterns in data. Intuitive intelligence is more advanced and capable of interpreting data and thus deriving implications from them. Combining analytical and intuitive skills, thinking intelligence facilitates personalization (Huang and Rust 2021a, 2021b). It also creates differentiated relative advantages for humans versus technology (Huang and Rust 2018). On the one hand, thinking tasks that require analytical skills favor artificial intelligence-based technology. Fueled by ever-growing computing power and memory capacities for information processing and storage, artificial intelligence can easily and instantly handle large data quantities, whereas humans are vastly limited in their memory capacities and speed of data analysis. On the other hand, when it comes to interpreting the results of data analyses, which demands intuitive intelligence, humans are superior. Due to their innate capabilities for understanding and creative thinking, humans remain relatively better equipped to draw conclusions and derive implications from data than machines are.
As the highest level, feeling intelligence relies on learning from and adapting to experience. Analyzing and acting on experiences demands the ability to make sense of contextual and individual-specific data. To perform service tasks that require feeling intelligence, actors need empathy and understanding of emotional, social, and relational cues (Huang and Rust 2018, 2021a, 2021b). Such interpersonal capabilities can facilitate relationalization (Huang and Rust 2021a, 2021b). Feeling intelligence, to date, represents the most substantial advantage of humans over technology. Artificial intelligence applications continue to make gains in feeling intelligence capabilities, but human empathy remains superior in terms of reading interpersonal signals and relating to interactional counterparts. Building and maintaining relationships also requires trust based on mutual understanding and appropriate responses based on socio-emotional cues, which puts humans at a relative advantage.
Data Privacy Regulation at the Service Frontline: Different Intelligence Requirements
Intelligence Requirements for Establishing Data Privacy Regulation Dimensions.
Establishing data privacy-related fairness requires high levels of feeling intelligence. An overarching approach to fairness involves service providers’ ethical management of customer data generally (Martin and Murphy 2017) and shapes all other data privacy regulatory dimensions as discussed. Service providers’ data limits, control, transparency, consent, and recourse all should be determined using principles of fairness, as stressed in global regulations. Ethical behavior and practices, to include fairness, are consistent with Huang and Rust’s (2018) explication of empathetic intelligence, embodying skills such as advocating, negotiating, taking leadership positions, and drawing from experience. Establishing ethical principles to manage the fairness of a service provider’s data privacy practices also involves a strong focus on relationships, consistent with Huang and Rust’s (2021a) conceptualization of feeling intelligence. In fostering empathetic, emotional relationships with customers, service frontline employees help create mutually beneficial, fair outcomes for both the firm and its customers. In particular, service frontline encounters strongly shape customers’ perceptions of procedural and interactional justice (Tax, Brown, and Chandrashekaran 1998), moving beyond the distributive justice determined by the overall service organization. Beneficial data privacy outcomes for customers involve minimal collection and use of data and careful assurance that the various ways in which the firm uses customer data both are just and provide customers with commensurate value in exchange. Preserving fairness in data privacy practices thus evokes a strong need for feeling intelligence, but given the underlying requirement to sense, perceive, and respond on emotional levels, the needs for mechanical and thinking intelligences are comparably low.
Data limits are one way service providers can operationalize fairness by ensuring minimal collection and use. Once data quantities and purposes are determined to be fair and are agreed upon by the service provider and regulators, these data limits can be enforced with mechanical intelligence (Biega and Finck 2021). Complex conceptual thinking based on intuitive intelligence is required to initially identify the set of relevant data quantity and collection purposes of a given service provider (Jia, Jin, and Wagman 2021). In addition, for each purpose, the service provider needs to specify the data quantity requirements and ensure the relevant data points—not more, but also not less—get collected during the frontline encounter. However, once data limits are fairly defined, enacting such limits can be effectively done using mechanical intelligence (Aledhari et al. 2021; Altman et al. 2020). Accurately collecting and storing the minimum amount of appropriate use data points mostly requires automated and standardized processes which facilitate compliance with approved data limits. Analytical skills might help to assess data accuracy from time to time and quickly identify potential data surplus or purpose deviation requiring remedy. In turn, relationalization through feeling intelligence between customer and service provider might even be disadvantageous for safeguarding data limits due to additional information captured in more relational conversations.
Establishing transparency and ensuring customer understanding of data privacy information requires high levels of both thinking and feeling intelligence. Providing appropriate information that customers comprehend requires thinking intelligence; service providers must analyze and then distill what is likely a broad, complex set of data privacy practices into condensed, simplified, and accessible forms. Thinking intelligence also is required to determine whether customers understand the information they have been provided sufficiently so that it creates transparency (Huang and Rust 2018). Transparency demands emotional perception, sensing, and relationalization too (Huang and Rust 2021a), to discover if the information supplied appears sufficient to establish understanding, or if additional efforts are needed to fill gaps (e.g., Bauer et al. 2021). Detecting areas of customer confusion and error-proneness may require greater firm openness about data privacy practices, which might be accomplished best through a blend of analytical interpretation, as is characteristic of thinking intelligence, and emotional sensing, characteristic of feeling intelligence. To establish and preserve transparency for customers in frontline service encounters, mechanical intelligence proves less useful than the higher-order intelligences.
Control, in contrast, benefits from high levels of mechanical intelligence. Restrictive control can be more effectively established and preserved with standardized practices (Huang and Rust 2021a) that ensure adequate opt-in/opt-out choices for customers (Johnson, Shriver, and Du 2020) and also guarantee that those choices are honored and implemented by the service provider (Ohlhausen 2014). Beyond the routinization and standardization characteristic of mechanical intelligence, establishing and ensuring customer control requires thinking intelligence to endow customers with corrective controls. With the help of service providers, customers sometimes must modify data privacy practices or situations to achieve the outcomes they seek (e.g., Tucker 2014). Thinking intelligence can allow the service provider to analyze the situation and interpret solutions in partnership with the customer, which approaches but does not require feeling intelligence. That is, restrictive control can be established and protected with standardization and mechanical intelligence; corrective control requires additional analyses and interpretation, characteristic of thinking intelligence. This description implies escalating intelligence needs as customers exercise data privacy control in different ways, but establishing and protecting customer control currently requires rather low levels of feeling intelligence.
Implementing consent at the service frontline is mainly a mechanical task. Because consent is focal to so many global privacy regulatory frameworks (e.g., Schmitt, Miller, and Skiera 2020), service providers must be especially careful and consistent with its establishment and implementation. High levels of mechanical intelligence are both necessary and beneficial; the more routine and standardized consent processes become, the more likely service providers can ensure they are in regulatory compliance, and the more likely customers are to agree with less effortful processes and surrender their data, which benefits the firm (Goldberg, Johnson, and Shriver 2021). If customers choose to revoke consent, this choice also should be enabled through routinized processes that make doing so as hassle-free as possible, for both the customer and service provider. To ensure convenient, compliant consent procedures, service providers should maximize standardization and routinization using mechanical intelligence (Huang and Rust 2021a); thinking and feeling intelligences are less relevant.
Finally, when dealing with recourse concerns at the service frontline, thinking intelligence is helpful, in both analytical and intuitive forms (Huang and Rust 2018). Analytical intelligence might be required to identify that the customer has incurred a data privacy-related harm, because the service provider needs to review a single customer’s privacy violation or manage the recourses required following a large-scale data breach. In turn, the service provider needs intuitive intelligence to determine the appropriate compensation. Legal frameworks and professions often are responsible for enacting the recourse dimension, and Huang and Rust (2018) highlight the legal profession as specifically aligned with thinking intelligences (namely, intuitive intelligence). In addition to establishing the legal determination of harm and appropriate recourse, this dimension requires soft skills and emotional capabilities to manage customers’ negative reactions. We therefore propose that feeling intelligence is required to mitigate customers’ potential grievances. The more relationalization that occurs in response to negative data privacy events, the less likely customers are to react adversely, defect, or switch to a rival (e.g., Martin, Borah, and Palmatier 2017).
Integrating Technology Infusion and Data Privacy Regulation at the Service Frontline: Exploiting Different Intelligence Capabilities
Establishing Data Privacy Regulation Dimensions Through Service Frontline Interfaces.
Due to their unique abilities to show empathy and engage in socio-emotional interactions, human-based service frontline interfaces are particularly well-suited to contexts that demand high levels of feeling intelligence (Huang and Rust 2018). They also align with data privacy dimension requirements that involve intuitive thinking intelligence. These human strengths surface specifically when it comes to establishing the fairness of data exchanges, including initially determining data quantity and use specifications, setting parameters around customer control, and carefully considering the transparency, consent, and recourse or remedial measures of their summative privacy practices.
Securing the perceived fairness of a service provider’s data privacy practices requires service representatives who exhibit high feeling intelligence and relationalization abilities. Although broader questions of data privacy ethicality and mutually beneficial customer data exchanges with the service provider (i.e., distributive fairness of data exchanges) typically get determined at higher organizational levels, the service frontline nurtures perceptions of procedural and interactional fairness. Human service employees’ ability to use empathy when collecting customer data (Crawford et al. 2021), unlike technology-based frontlines that are programmed to gather all data specified in a preset list, may prompt them to pause or stop the collection or reframe certain questions to be more appropriate if they identify customer discomfort. Humans also can appropriately respond to and attenuate customers’ potential sense of unfairness or injustice related to data privacy concerns and thereby prevent customer defection or switching, which otherwise represent likely customer responses to experiences of unfairness in their encounters with a firm (e.g., Samaha, Palmatier, and Dant 2011).
Technology-based service frontline interfaces can be effectively and efficiently employed for the data privacy regulation dimensions that rely more on mechanical and analytical thinking intelligences. For example, data limits, control, and consent dimensions benefit from routinized tasks and standardized procedures enabled by mechanical intelligence. Ensuring limited data collection, allowing customers to exercise control options, and securing their consent are mostly mechanical tasks, though they may require some additional analytical thinking. Human-based service frontlines thus suffer a relative disadvantage, due to their unwitting attainment of additional information through customer conversations, increased error-proneness in repetitive settings, and their inability to analyze vast quantities of information.
Technology-based service frontlines, with their superior mechanical intelligence capabilities, are ideal to safeguard data limits. Indeed, computer science literature outlines ways in which artificial intelligence, deployed through technology-based frontlines, help service providers comply with data minimization and purpose limitation requirements (Aledhari et al. 2021; Altman et al. 2020; Biega and Finck 2021). Through standardized data collection procedures, service providers can ensure and signal to customers that only the minimally required data points are captured and stored, as well as used only for intended and prespecified purposes. Human service frontline employees are prone to, intentionally or unintentionally, capture additional subjective, socio-emotional information about customers, thereby potentially hurting data minimization by collecting additional, nonessential data.
A technology-based service frontline configuration instead is ideal for establishing and endowing customers with control. The more routinized (i.e., through mechanical intelligence) a service provider’s control terms are, the more seamlessly customers can exercise their opt-in and opt-out preferences through restrictive control. Technology interfaces also should facilitate corrective control, allowing customers to revise inaccuracies or shift their preferences without requiring the involvement of more expensive, error-prone human service representatives. For example, a corrective regulatory element of control stipulates that customers may move or port their personal data between service providers (Krämer and Stüdlein 2019), or else remove those data altogether, known as the right to be forgotten (Kuebler-Wachendorff et al. 2021). Both abilities, to ensure accuracy and to be forgotten, are more feasible in practice in technology-based service frontlines, because deleting data means they are gone and cannot be accessed any further by the service provider. A measure of analytical intelligence is required for corrective controls that rely on fact checking or complex data analysis. Thus, control is best (i.e., most efficiently) enabled through technology-based service frontlines (McLeay et al. 2021).
For consent, most interfaces through which service providers seek customer agreement are technological in nature, and consent has become a nearly automatic or default choice (Walker 2016). The language of consent is prespecified by regulatory stipulations and must be uniform across requests. Thereby, mechanical intelligence enacted through technology-based service frontlines facilitates regulatory compliance. If consent is standard and routine, customers also are more likely to accept the service provider’s terms without more elaborate processing or possible skepticism. Thus, greater mechanical intelligence benefits the service provider, by increasing customer acceptance, and technology-based service frontlines represent the ideal configuration.
Finally, hybrid service frontline interfaces aim to combine ideal elements of human and artificial intelligences, effectively augmenting humans’ superior capabilities in intuitive thinking and feeling intelligences with technology’s benefits in executing mechanical and analytical thinking intelligences. Fairness (human-based service frontlines), data limits, control, and consent (technology-based service frontlines) can effectively be safeguarded through either human or technology interfaces alone, but the combinative benefits appear particularly relevant for transparency and recourse dimensions, which require intuitive thinking and feeling intelligences to augment mechanical and analytical thinking intelligences. Thus, they are well-suited to a hybrid service frontline configuration that blends human and technology elements to exploit their diverse strengths and intelligences.
Because information breadth/depth and relatability is required for transparency, hybrid service frontlines may be the optimal service frontline configuration: They achieve technological depth, breadth, and accuracy of information but simultaneously provide human abilities to answer questions, provide clarification, and discuss the parameters of the data exchange. Human-based service frontlines can contribute understandable and relatable information, using their relative advantages in intuitive and feeling intelligences. Being transparent about the service provider’s data privacy practices also involves the ability to gather, distill, and interpret large volumes of complex information related to data privacy practices. Although analytical intelligence, enabled by technology, is useful for culling such information, understanding how customers are likely to act on it requires higher levels of intelligence held by human employees. Identifying customer discrepancies in understanding or risky interpretation mistakes also requires intuitive thinking and feeling intelligences, which are sharpened through human-to-human encounters. Customers can follow up, engage in dialogue, ask for clarification, or pose questions about data practices. This transparency benefit reflects the innate way humans address complex problems, by directly engaging with one another (Sok et al. 2018).
Enabling transparency also requires mechanical and analytical processing of complex information to provide sufficient depth and breadth of knowledge (Palmatier and Martin 2019), which is likely beyond human cognitive capabilities. Considering potential gaps in understanding that arise from human-based service frontlines, technology-based service frontlines may offer transparency benefits, due to their strong mechanical and analytical intelligences. Technological interfaces cannot forget or misconstrue important data exchange information or necessary disclosure elements (McLeay et al. 2021)—an important distinction because, in customer data exchanges, service providers may unintentionally violate regulatory protocols if frontline employees are not properly trained or sufficiently knowledgeable to provide customers with adequate transparency about the firm’s data practices.
A similar relationship exists with recourse. To preserve a relationship and prevent defection following a service failure, strong human empathy skills, based in feeling intelligence, are required. Human-based service frontlines can exercise both thinking and feeling intelligence to identify data privacy failures and derive appropriate compensatory courses of action in response. Although this analytical and intuitive thinking might be performed by a service provider’s legal team, with the aid of technology, service frontline employees are likely to encounter customers’ initial requests for recourse. In such contexts, they can use their feeling intelligence to express empathy and concern for customers who have experienced a data privacy failure. They also might deploy relationalization skills in immediate service recovery attempts (e.g., apology and empathy) to offset or mitigate customer grievances. If their emotional reactions can calm customers, it may temper those customers’ desire to demand higher-level recourse, seek punitive measures against the service provider, or defect (Romanosky, Hoffman, and Acquisti 2014). Human-based service frontlines are therefore required, for their ability to use intuitive thinking intelligence and feeling intelligence, in data privacy recourse situations.
But identifying a data privacy failure and its scope, reach, and remedy might best be enacted with technology and its mechanical processing and analytical thinking capabilities. In the service provider’s back office, a legal team likely works to identify and process recourse cases with the aid of technology. But at the service frontline, technology also can be meaningfully deployed to provide customers with standardized, reliable processes for filing for recourse. For example, enabling customers to leave contact information and provide details on the type of data privacy failure they experienced, by entering these data into a technology-supported form, signals to customers that the service provider takes their complaints seriously and has established processes to review and recover data privacy failure incidents.
In summary, our theoretical analysis implies that to maximize the effectiveness and efficiency of implementing data privacy fairness, data limits, transparency, control, consent, and recourse at the service frontline, organizations should capitalize on the different intelligence capabilities of three service frontline interfaces. Using the intelligences framework to establish and maintain data privacy regulatory dimensions in service frontline encounters leads us to advance our three propositions, as also explicated in Table 3.
Discussion
Implications and Research Directions.
Theoretical Implications and Research Directions
Service researchers can use and leverage the insights from our conceptual framework in four main ways. First, we establish the implementation of data privacy regulatory dimensions as an emerging and relevant area for service frontline research. To date, research on the service frontline has focused on investigating competencies for building rapport and relationships with customers (Giebelhausen et al. 2014), recovering service failures (Bitner, Booms, and Tetreault 1990), or engaging in emotional labor (Hennig-Thurau et al. 2006). Yet customer data and how service providers handle them are increasingly critical variables in customer–firm encounters at the service frontline and can easily become part of relationship building, service recovery, or emotional labor efforts. Customer perceptions of service providers’ data privacy practices likely depend heavily on what they experience during points of contact at the service frontline. Thus, even if overarching firm approaches to privacy are determined at upper organizational levels, and operational processes are implemented in the back office, the service frontline, as the “face to the customer,” must both represent and act on firm policy. At the same time, service frontlines must balance firm interests, regulatory requirements, and customer needs and preferences. Establishing an environment for customers that promotes data privacy regulatory compliance through fairness, data limits, transparency, control, consent, and recourse remains a challenging service task that requires dedicated, detailed attention from service researchers.
Second, we advance data privacy research with a fine-grained battery of six dimensions that generally characterize global data privacy regulations. Extant data privacy research typically emphasizes customer perceptions of and responses to one or a few dimensions (e.g., Brough et al. 2022; Okazaki et al. 2020); by reviewing major global data privacy regulatory frameworks, we identify a comprehensive set of data privacy elements that regulators have deemed essential to safeguard the privacy of consumers’ data. Service and data privacy researchers can use our six-dimensional battery to develop measurement instruments—similar to the recently developed privacy calculus index (Beke et al. 2022)—and assess the weight of different dimensions in driving overall data privacy perceptions and downstream consequences (e.g., willingness to share data, customer loyalty).
Third, we believe our parsimonious framework represents a valuable point of departure to understand data privacy manifestations at the service frontline, and we encourage service researchers to broaden this conceptualization even further to account for emerging developments in customer–firm encounters. In our framework, we concentrate on (human) customers directly and actively encountering the service provider’s interface and the focal service provider–customer dyad, analyzing how customers perceive the capabilities of service providers’ frontline configurations (i.e., human-based, technology-based, and hybrid) for establishing the fairness, data limits, transparency, control, consent, and recourse of the service provider’s data privacy practices. Yet in some service encounter constellations, the encounter between the service provider and the customer may be more indirect in nature, mediated by a focal service provider– or third-party–controlled software that acts on behalf of the customer (e.g., machine-to-machine interfaces, third-party virtual assistants; De Keyser et al. 2019). To uncover the implications of these rapidly growing interfaces, service researchers should look at customers’ data privacy perceptions when assigned a passive role and typically unaware of how and when a machine acts on their behalf in interaction with another machine. Additionally, to shed light on the impact of third-party intermediaries on customers’ privacy-related perceptions and attributions, researchers might investigate complex, triadic settings involving the customer, service provider, and a third party to determine whom the customer deems responsible for establishing data privacy, relative to who is legally responsible (i.e., focal service provider or third party).
Fourth, in this research, we focus on what the service provider brings to the service frontline and typically exerts relative control over when interacting with customers (e.g., firm-employed service representatives or firm-controlled software). Yet, especially when technology is involved, there are service frontline encounters in which the company is not in full control but rather shares control with customers, for example, when customers use their own device (e.g., computer, tablet, and smartphone) to access service provider-controlled software (e.g., proprietary smartphone app). When doing so, customers exert enhanced control over their device-specific privacy settings (e.g., turn on/off GPS, using Apple’s App Tracking Transparency feature) which may affect their perception of and alertness to focal service providers’ handling of customer data and data privacy regulatory compliance (e.g., when customers are made aware of an app’s data tracking activities).
Managerial Implications and Research Directions
Our conceptual framework provides theory-based suggestions for service managers regarding how to effectively and proactively implement data privacy regulatory requirements at service frontlines. We suggest four key implications emanating from our analysis. First, service providers operating globally need to account for intercultural differences as an important contingency factor in the technology infusion–data privacy regulation interplay. Despite nation- (e.g., Canada) or region- (e.g., EU) specific variations, we identify fairness, data limits, transparency, control, consent, and recourse as overarching dimensions that regulators impose to protect consumer privacy. Yet at the consumer level, intercultural differences emerge regarding perceptions of technology infusion and data privacy regulations, as two key change agents for service frontlines. Countries differ in their technological readiness (Steinhoff et al. 2022) and in the relevance they attribute to privacy in their existing laws and regulations (Martin et al. 2020). These differences in turn shape international consumers’ attitudes toward different service frontline types and data privacy. Depending on a country’s technological readiness, for example, consumers may be more or less open to human- versus technology-based interfaces, irrespective of their intelligence-based competencies for establishing data privacy dimensions. Depending on the legal role of data privacy in a country, consumers also may put more emphasis on certain regulatory dimensions. For example, German customers may insist more strongly on appropriate recourse measures because of the historic relevance of data privacy as a basic right warranted in their constitution; U.S. customers may view data exchanges as a more relaxed, give-and-get between firms and customers, given that country’s treatment of data privacy as part of commercial law (Martin et al. 2020). Chinese customers, until recently, have not experienced privacy-related regulations or protections, so they may take yet another stance on data privacy.
Second, our high-level propositions regarding different service frontlines’ suitability for establishing data privacy dimensions might be contingent on the type of service. From a data privacy perspective, we could distinguish services according to the different levels of data sensitivity involved when customers use the service (Huang and Rust 2021b). For example, customers perceive services requiring the provision of financial (i.e., banking) or medical (i.e., healthcare) data as more sensitive than services processing data about their online behavior (i.e., social media) or purchase habits (i.e., ecommerce) (Phelps, Nowak, and Ferrell 2000). Data sensitivity considerations in turn may interfere with service frontline types when customers evaluate data privacy dimensions. Specifically, in high data sensitivity settings, irrespective of human service employees’ superior capabilities for providing feeling intelligence, customers may prefer to interface with technology-based service frontlines, because they fear the social judgments that may result from high levels of feeling intelligence (Pitardi et al. 2021). Another, more granular contingency factor might be the type of interaction between the service provider and the customer in a given service frontline encounter. According to Singh et al. (2017), service frontline encounters encompass interactions and interfaces. Our research focuses on the interface component of the service frontline encounter. However, the very same interface used in a frontline encounter can have differential, positively and negatively valenced privacy implications depending on the specific type of interaction. For example, a GPS-based application like Google Maps can guide customers to their requested destination. At the same time, though, the same app can detect customers’ movement, thereby tracking potentially confidential information and intruding into their private sphere.
Third, we encourage service managers to conduct regular audits of their data privacy regulatory compliance (Palmatier and Martin 2019). They should survey customers on the perceived fairness, data limits, transparency, control, consent, and recourse of their data privacy practices at different service frontlines. Such data privacy-related measures could be included in typical customer satisfaction surveys following service encounters. Ideally, service providers employing different service frontline configurations would test customers’ perceptions of their varied capabilities for establishing data privacy regulatory dimensions, then reconfigure the frontlines accordingly to optimize data privacy regulatory compliance.
Fourth, when service frontline encounters between a service provider and a customer involve a third party, the service provider must evaluate the extent to which its proprietary data privacy policy is (in)compatible with the third-party provider’s policy. In such complex constellations, customers may have a hard time attributing responsibility and could perceive the focal and third-party service providers as one entity when it comes to implementing data privacy. In turn, the service provider needs to be careful when choosing third-party collaborators, to help customers access their services but avoid negative spillover effects. A growing and intriguing type of third party, relevant to data privacy considerations, among other topics, is virtual assistants that act on behalf of the consumer (e.g., Google Duplex; De Keyser et al. 2019).
Policy Implications and Research Directions
Our work also suggests several policy implications. First, we identify and articulate the fundamental dimensions that global data privacy regulations seek to establish and uphold. The six emergent dimensions of fairness, data limits, transparency, control, consent, and recourse expand prior policy conceptualizations, such as the U.S. FTC’s exclusive emphasis on notice and choice (e.g., Cranor 2012; Ohlhausen 2014). This expanded articulation offers insights into dimensions that resonate globally, as indicated by global frameworks at the heart of our study, and at a regional level, such as in the CPRA, Virginia, and Colorado laws. By recognizing six key areas that aim to protect consumers and their information, as well as offer remedies following wrongdoing, policymakers can use this template to craft and implement new data privacy regulations. Such a foundation may prove especially useful to countries that currently have no data privacy protections in place, as well as at the U.S. state level, given the current lack of appetite for a federal data privacy policy.
Second, regulation is an evolving process, and policymakers charged with overseeing ongoing regulatory implementations and effectiveness can benefit from our framework. Assessing regulatory efficacy over time can reveal both intended and unintended consequences (e.g., Brough et al., 2022; Goldfarb and Tucker 2011). For example, the costs and requirements of many large-scale global data privacy regulations had the unintended effect of disproportionately harming small- and medium-sized organizations that lacked the resources needed for smooth implementation (Campbell et al., 2015; Quach et al., 2022). Big technology firms then reaped the benefits, because they had plentiful resources to implement and monitor their compliance efforts. A closer examination of how service frontlines can, and sometimes struggle to, manage data privacy regulatory compliance should be illuminating for regulators that seek to strengthen protections over time. Our framework points regulators to some specific sources of questions, such as those related to establishing and upholding consumer recourse measures.
Third, in explaining the intersection of service frontline interfaces and data privacy regulatory dimensions with varying intelligences, our framework can inform policy further. Regulators should consider how service frontlines, depending on their specific configuration, can or cannot effectively establish and uphold privacy protections, due to their varying abilities to harness different intelligences. For example, our review reveals that obtaining consent from consumers has become a highly routinized, mechanical function performed readily at technology interfaces and needing little to no human intervention. Implementing and complying with this regulatory stipulation thus appears straightforward for service providers. But its intention—to gain informed consumer consent—likely is not achieved through such automatic, low involvement practices. Ideally, each consumer would carefully consider the benefits and risks and thoughtfully determine whether to proceed. By operationalizing consent as a quick, mechanical, low-level intelligence function, regulatory mandates seemingly have failed to implement consent as originally designed. If they examine each dimension in this way, particularly as regulations get put into practice at service frontlines, regulators can strengthen or revise their stipulations to better protect consumers.
Conclusion
Technology infusion and data privacy regulations are changing customer–service provider encounters at the service frontline, which are fundamentally fueled by customer data (e.g., Martin et al. 2020; Ostrom et al. 2021). Although closely intertwined, the domains of service frontline technology infusion and data privacy regulations typically have been studied in isolation. We put forth an integrated conceptual framework, linking three types of service frontline interfaces (human-based, technology-based, and hybrid) with six dimensions (fairness, data limits, transparency, control, consent, and recourse) of global data privacy regulatory frameworks, through the lens of a multi-intelligences framework (Huang and Rust 2021a, 2021b). To build new service theory and inform service practice as well as policymakers (Kohli and Haenlein 2021), we advance an intelligences-based framework and delineate three research propositions, theorizing about the varying capabilities of frontline interfaces to ensure compliance with data privacy regulations. Beyond offering relevant implications for researchers, practitioners, and privacy regulators, we hope to encourage additional research on the important intersection of technology infusion and data privacy regulations at the service frontline.
Supplemental Material
Supplemental Material - Putting Data Privacy Regulation into Action: The Differential Capabilities of Service Frontline Interfaces
Supplemental Material for Putting Data Privacy Regulation into Action: The Differential Capabilities of Service Frontline Interfaces by Lena Steinhoff and Kelly D. Martin in Journal of Service Research
Footnotes
Declaration of Conflicting Interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) received no financial support for the research, authorship, and/or publication of this article.
Supplemental Material
Supplemental material for this article is available online.
Author Biographies
References
Supplementary Material
Please find the following supplemental material available below.
For Open Access articles published under a Creative Commons License, all supplemental material carries the same license as the article it is associated with.
For non-Open Access articles published, all supplemental material carries a non-exclusive license, and permission requests for re-use of supplemental material or any part of supplemental material shall be sent directly to the copyright owner as specified in the copyright notice associated with the article.
