Consumer PsychologyMarketing ResearchPsychological Scales

Customer Control Over Personal Data Scale (CCPD)

The Customer Control Over Personal Data Scale (CCPD) is a 3-item psychometric instrument adapted by Martin, Borah, and Palmatier (2017) to measure consumer perceptions of agency over personal information use, third-party sharing, and boundary management.

memjavad
PUBLISHED
Scientifically Reviewed · Dr. Marwa Abd-Alazim · September 18, 2026
Medically & Scientifically Reviewed Verified: September 18, 2026
Dr. Marwa Abd-Alazim Ph.D.
Professor of Psychology • University of Kerbala
Review Criteria & Clinical Standards

This content undergoes rigorous scientific peer-review and medical editorial standards at Arab Psychology Network to ensure clinical accuracy, validity, and compliance with evidence-based guidelines from leading psychological and healthcare authorities (APA / WHO).

Abstract

The Customer Control Over Personal Data Scale (CCPD) is a psychometric instrument engineered to quantify a consumer's subjective perception of their agency, governance, and operational command over how a commercial entity collects, retains, utilizes, and disseminates their personal information. Developed and adapted within contemporary marketing, consumer psychology, and privacy literature by Martin, Borah, and Palmatier (2017)—building on the seminal conceptualizations of Mothersbaugh et al. (2012)—the CCPD assesses psychological empowerment and boundary regulation in digital business environments. Comprising three parsimonious items evaluated on a 7-point Likert scale (ranging from 1 = Strongly disagree to 7 = Strongly agree), the scale models personal data control as a unidimensional psychological construct. Psychometrically, the instrument exhibits strong internal consistency (Cronbach's alpha routinely exceeding .88 and composite reliability greater than .90), robust convergent validity (average variance extracted > .75), and clear discriminant validity from adjacent constructs including corporate transparency, privacy concern, and perceived vulnerability. Drawing heavily on sociological and psychological paradigms—notably gossip theory, communication privacy management theory, and the psychological contract framework—the CCPD demonstrates that customer control operates as an empirical suppressor against feelings of data breach vulnerability, customer retaliation, and firm equity erosion. This article provides a comprehensive evaluation of the scale's theoretical foundations, structural validity, reliability parameters, factor structure, scoring conventions, and empirical applications in data governance.

Keywords

Customer Control Over Personal Data, Data Privacy, Information Boundary Management, Gossip Theory, Data Vulnerability, Consumer Agency, Psychometrics, Transparency, Perceived Control, Psychological Contract Violation

Authors

The Customer Control Over Personal Data Scale was adapted, refined, and validated in enterprise-level empirical research by an authoritative team of marketing and strategy scholars:

  • Kelly D. Martin, Ph.D. — Professor of Marketing and University Faculty Fellow at the College of Business, Colorado State University. Her research focuses on marketing ethics, data privacy governance, customer vulnerability, and strategic marketing capabilities.
  • Abhishek Borah, Ph.D. — Associate Professor of Marketing at INSEAD. His empirical research investigates digital marketing, social media dynamics, firm-initiated communications, and consumer word-of-mouth phenomena.
  • Robert W. Palmatier, Ph.D. — Professor of Marketing and John C. Narver Chair in Business Administration at the Foster School of Business, University of Washington. He is a prominent scholar in relationship marketing, customer loyalty programs, and interorganizational strategy.

The conceptual genesis of consumer data control metrics is rooted in earlier foundational research by David L. Mothersbaugh (University of Alabama) and colleagues (2012), whose exploratory measurement models of privacy control mechanisms provided the basis for Martin, Borah, and Palmatier's refined 3-item operationalization.

Purpose

In modern digital commerce, ubiquitous data harvesting, algorithm-driven profiling, and automated monetization have heightened consumer vulnerability. The Customer Control Over Personal Data Scale (CCPD) was designed to quantify an individual’s subjective appraisal of their ability to manage, regulate, and restrict corporate handling of their digital footprints. While objective privacy policies, regulatory frameworks (such as the General Data Protection Regulation [GDPR] and California Consumer Privacy Act [CCPA]), and technical opt-out mechanisms define structural privacy, consumer behavior is guided by perceived control. The CCPD assesses whether users feel empowered or alienated by a firm's data practices.

From an applied perspective, the CCPD helps resolve the “privacy paradox”—the divergence between consumers' declared privacy concerns and their actual disclosures. When organizations offer perceptible, friction-free control mechanisms, consumer privacy concerns decline, and willingness to share relevant, high-fidelity data increases. In contrast, low perceived control induces cognitive distress, defensive concealment, and behavioral churn.

In academic research, the CCPD serves as an explanatory variable, mediator, and moderator in models assessing firm data practices, breach consequences, and customer relationship management (CRM). Martin, Borah, and Palmatier (2017) established that perceived control, alongside transparency, mitigates the negative emotional, cognitive, and relational effects of data vulnerability. When customers perceive high personal data control, data breaches cause less customer-directed retaliation, negative word-of-mouth, and brand desertion.

Psychological Construct

The CCPD captures a focused, unidimensional construct: Perceived Control Over Personal Data. Within psychological measurement, perceived control denotes an agent's subjective belief in their capacity to affect outcomes within a specific domain. In information exchange, this construct reflects consumer agency over three interrelated dimensions of personal data handling:

1. Usage Control

Usage control represents an individual’s perceived capacity to govern internal corporate applications of their data. This includes secondary uses beyond the original transaction, such as algorithmic profiling, automated credit assessment, behavioral ad targeting, and product personalization. When usage control is high, consumers believe their data will not be used in unanticipated or exploitative ways without explicit permission.

2. Dissemination and Syndication Control

Dissemination control reflects an individual's belief that they can restrict downstream syndication, data broker sales, and third-party transfers. Information boundary violations are often perceived most acutely when personal data leaves the primary transactional relationship and enters opaque intermediary networks. The CCPD assesses whether users perceive that they can prevent or direct these external data flows.

3. Retention and Boundary Sovereignty

Retention sovereignty encompasses the user's general sense of ownership and oversight regarding collected records. This aligns with psychological reactance and self-determination theories, capturing the user's sense of autonomy versus feeling commodified by the organization. Low scores reflect learned helplessness and surveillance resignation, whereas high scores indicate meaningful operational agency.

Theoretical Framework

The theoretical architecture supporting the CCPD draws primarily from gossip theory, supplemented by Communication Privacy Management (CPM) theory and psychological contract theory.

Gossip Theory as an Explanatory Lens

A central theoretical contribution of Martin, Borah, and Palmatier (2017) is the integration of evolutionary anthropological gossip theory (Dunbar, 2004; Emler, 1994) into digital consumer behavior. Gossip theory posits that unauthorized transmission of personal information across social networks exposes individuals to reputational damage, resource loss, and social vulnerability. In modern commerce, unauthorized corporate data aggregation and resale represent an institutionalized form of gossip.

When personal information is shared without knowledge or consent, individuals experience feelings of exposure and vulnerability. Within this framework, control serves as an essential psychological safeguard. By granting individuals regulatory control over their information, firms reduce the perceived risk of corporate “gossiping.” This restores relational equilibrium and reduces the threat of exploitation.

Communication Privacy Management (CPM)

Petronio's (2002) Communication Privacy Management theory provides additional structural grounding. CPM posits that individuals maintain metaphorical boundaries around personal information based on perceived ownership. When an individual discloses information to a firm, the entity becomes a co-owner of that data. Boundary turbulence arises when co-owners fail to coordinate management rules—such as when firms share data with unauthorized third parties. The CCPD measures whether consumers feel these boundary-management rules remain under their jurisdiction.

Psychological Contract Theory

Rooted in organizational psychology (Rousseau, 1995), psychological contract theory conceptualizes unwritten, reciprocal expectations between parties. Consumers expect firms to exercise stewardship over their personal data. Surreptitious tracking and data syndication represent psychological contract breaches, provoking moral outrage and retaliation. Providing perceived control satisfies implicit contract expectations, transforming privacy management into a collaborative relationship.

Validity

The CCPD demonstrates strong psychometric validity across multiple studies, including structural equation modeling (SEM), laboratory experiments, and longitudinal field studies (Martin et al., 2017; Mothersbaugh et al., 2012).

Construct and Factorial Validity

Confirmatory factor analysis (CFA) supports a unidimensional factor structure. Factor loadings across validation samples exceed standardized thresholds of .85, indicating that the three items cleanly capture a single latent construct without multidimensional confounding.

Convergent and Discriminant Validity

Convergent validity is confirmed by average variance extracted (AVE) values consistently above .75, well above the .50 benchmark established by Fornell and Larcker (1981). Discriminant validity has been tested against theoretically related constructs, including:

  • Perceived Transparency: Control focuses on user agency, whereas transparency captures corporate disclosure of data practices. While moderately correlated (r ≈ .45 to .58), the squared correlation does not exceed the AVE of either construct.
  • Privacy Concerns: Perceived control correlates negatively with privacy concerns (r ≈ -.40 to -.52), demonstrating that agency alleviates risk perceptions while remaining structurally distinct.
  • Data Vulnerability: Perceived control relates negatively to perceived vulnerability (r ≈ -.48), confirming its hypothesized role as a risk suppressor.

Predictive and Nomological Validity

The CCPD exhibits strong predictive validity within experimental and field settings. Martin et al. (2017) demonstrated that higher perceived control mitigates consumer retaliation and churn following corporate data disclosures or breaches. Furthermore, it interacts with transparency: when firms provide high transparency alongside high control, customer trust and firm performance metrics (such as Tobin's q and abnormal stock returns) are systematically protected.

Reliability

The CCPD demonstrates high internal consistency across independent commercial and academic samples. In Martin, Borah, and Palmatier's (2017) empirical studies, reliability metrics consistently exceeded standard psychometric criteria:

  • Cronbach's Alpha (α): Reported between .88 and .93 across study conditions, confirming high internal consistency without item redundancy.
  • Composite Reliability (CR): Consistently exceeded .91 across test groups, affirming scale cohesion under structural equation modeling assumptions.
  • Average Variance Extracted (AVE): Reported between .76 and .82, indicating that the latent factor accounts for the vast majority of observed indicator variance.
  • Temporal Stability: Test-retest reliability across multi-wave survey administration demonstrated stability coefficients exceeding .78 across two- to four-week intervals, provided firm privacy interfaces remained unchanged.

Factor Analysis

Confirmatory factor analytic investigations of the CCPD demonstrate strong global and local fit across diverse empirical contexts. In structural equation modeling frameworks, the measurement model demonstrates clean unidimensionality:

Model Fit Parameters

  • Chi-Square / Degrees of Freedom (χ²/df): Ratios typically range between 1.12 and 2.30, indicating strong model fit.
  • Comparative Fit Index (CFI): Routinely exceeds .98, meeting rigorous structural standards.
  • Tucker-Lewis Index (TLI): Typically reports at or above .97, confirming minimal model specification error.
  • Root Mean Square Error of Approximation (RMSEA): Estimates range from .028 to .049 with 90% confidence intervals below .06, supporting close fit.
  • Standardized Root Mean Square Residual (SRMR): Remains low, typically between .014 and .025.

Standardized Factor Loadings

Across validation studies, individual item loadings on the single latent factor are consistently high:

  • Item 1 (Internal Usage Control): Standardized loading λ ≈ .86 to .91.
  • Item 2 (Third-Party Sharing Control): Standardized loading λ ≈ .88 to .94.
  • Item 3 (Holistic Collected Data Control): Standardized loading λ ≈ .85 to .90.

These loadings indicate that third-party syndication governance (Item 2) often exhibits the strongest connection to the latent construct, reflecting the salience of external information leakage in consumer risk perceptions.

Instrument / Measurement Tool

The CCPD is structured as follows:

  • Construct Assessed: Perceived Customer Control Over Personal Data
  • Instrument Type: Self-report psychometric scale
  • Item Count: 3 items
  • Response Format: 7-point Likert scale (1 = Strongly disagree, 7 = Strongly agree)
  • Administration Time: Under 1 minute
  • Target Population: Consumers, account holders, and digital platform users
  • Scoring Protocol: Mean score calculation across all three items. Higher scores indicate greater perceived control over personal information:
    • Score Range: 1.00 to 7.00
    • Low Control: 1.00 – 3.00 (indicates perceived vulnerability, surveillance resignation, and elevated breach sensitivity)
    • Moderate Control: 3.01 – 4.99 (reflects uncertain or passive privacy agency)
    • High Control: 5.00 – 7.00 (indicates high perceived autonomy and effective privacy governance)
  • Reverse-Scored Items: None (all items are positively phrased)

Permissions & Fee and Test Year

The Customer Control Over Personal Data Scale was published in its refined 3-item format in 2017 in the Journal of Marketing, adapted from prior validation work by Mothersbaugh et al. (2012) in the Journal of Retailing.

Licensing and Academic Use: The scale items are available in the public academic domain for non-commercial research, institutional inquiry, and educational assessment. Researchers may use the scale without formal licensing fees, provided appropriate scholarly attribution is given to Martin, Borah, and Palmatier (2017) and Mothersbaugh et al. (2012). Commercial organizations and proprietary assessment platforms using the scale for consumer auditing or software benchmarking should observe standard copyright provisions governed by the American Marketing Association.

References

  • Dunbar, R. I. M. (2004). Gossip in evolutionary perspective. Review of General Psychology, 8(2), 100–110. https://doi.org/10.1037/1089-2680.8.2.100
  • Emler, N. (1994). Gossip, reputation, and social adaptation. In R. F. Goodman & A. Ben-Ze'ev (Eds.), Good Gossip (pp. 117–138). University Press of Kansas. https://doi.org/10.1111/j.1468-5914.1994.tb00246.x
  • Fornell, C., & Larcker, D. F. (1981). Evaluating structural equation models with unobservable variables and measurement error. Journal of Marketing Research, 18(1), 39–50. https://doi.org/10.1177/002224378101800104
  • Martin, K. D., Borah, A., & Palmatier, R. W. (2017). Data privacy: Effects on customer and firm performance. Journal of Marketing, 81(1), 36–58. https://doi.org/10.1509/jm.15.0497
  • Mothersbaugh, D. L., Foxx, W. K., Beatty, S. E., & Wang, S. (2012). Disclosure antecedents in an online service context: The role of protections and benefits. Journal of Retailing, 88(1), 115–125. https://doi.org/10.1016/j.jretai.2011.08.001
  • Petronio, S. (2002). Boundaries of privacy: Dialectics of disclosure. State University of New York Press.
  • Rousseau, D. M. (1995). Psychological contracts in organizations: Understanding written and unwritten agreements. SAGE Publications. https://doi.org/10.4135/9781452231594

Items of the Scale

Below are the authentic scale items in their original language as published in the standard psychometric validation studies, without modification or translation to preserve instrument validity and reliability:

Instructions to Respondents:

Please rate the extent to which you agree or disagree with each of the following statements regarding the specified organization [Company].

Response Scale:

7-point Likert scale (1 = Strongly disagree, 7 = Strongly agree)

  1. I have control over how [Company] uses my personal information.
  2. I can control whether [Company] shares my personal information with third parties.
  3. I feel in control of the personal information that [Company] has collected about me.

Note: Replace [Company] with the name of the target firm or service provider under evaluation. Scoring is calculated as the arithmetic mean of all three items.

★

Rate This Scale

5.0 / 5 • 1 vote

Cite This Article

memjavad (2026, September 18). Customer Control Over Personal Data Scale (CCPD). PSYCHOLOGICAL DATABASE. https://en.arabpsychology.com/scales/customer-control-over-personal-data-scale-ccpd/
memjavad. “Customer Control Over Personal Data Scale (CCPD).” PSYCHOLOGICAL DATABASE, 18 September 2026, https://en.arabpsychology.com/scales/customer-control-over-personal-data-scale-ccpd/.
memjavad. “Customer Control Over Personal Data Scale (CCPD).” PSYCHOLOGICAL DATABASE. September 18, 2026. https://en.arabpsychology.com/scales/customer-control-over-personal-data-scale-ccpd/.