Abstract
The Customer Data Vulnerability Scale (CDVS) is a psychometric instrument designed to measure a customer’s subjective perception of susceptibility to harm resulting from a commercial entity’s acquisition, storage, and utilization of their personal data. Originally developed and validated by Martin, Borah, and Palmatier (2017) in the Journal of Marketing, the scale operationalizes data access vulnerability—the baseline tier in a theoretical continuum that progresses from benign data custody to data breach, spillover, and manifest harm. Comprising six unidimensional items scored on a 7-point Likert scale, the CDVS assesses psychological exposure, perceived powerlessness, perceived safety deficits, and the latent potential for exploitation that consumers experience when interacting with data-intensive corporate systems. Across extensive empirical testing in both experimental and field settings, the CDVS demonstrates robust psychometric properties, including high internal consistency reliability (Cronbach's α typically exceeding .94; Composite Reliability > .94), strong factor loadings ranging from .82 to .94, and clear discriminant validity relative to related constructs such as generalized privacy concern, customer trust, and transactional risk perception. The CDVS serves as a vital diagnostic mechanism for behavioral researchers, enterprise privacy officers, and organizational psychologists aiming to evaluate the psychological costs of consumer data acquisition and implement effective privacy governance frameworks.
Keywords
Customer Data Vulnerability, Data Privacy, Information Asymmetry, Perceived Vulnerability, Power-Dependence Theory, Marketing Ethics, Psychometrics, Privacy Calculus, Consumer Behavior, Structural Equation Modeling
Authors
The Customer Data Vulnerability Scale was conceptualized, developed, and empirically validated by a team of leading scholars in marketing strategy, relationship marketing, and consumer psychology:
- Kelly D. Martin, Ph.D. — Professor of Marketing and University Impact Fellow at the College of Business, Colorado State University. Her research focuses on marketing ethics, consumer privacy, data stewardship, and corporate social responsibility.
- Abhishek Borah, Ph.D. — Associate Professor of Marketing at INSEAD (previously on the faculty at the Foster School of Business, University of Washington). His expertise spans quantitative marketing, social media analytics, word-of-mouth dynamics, and the commercial impacts of corporate crises and privacy events.
- Robert W. Palmatier, Ph.D. — Professor of Marketing and John C. Narver Chair in Business Administration at the Michael G. Foster School of Business, University of Washington. He is a prominent scholar in relationship marketing, customer relationship management (CRM) strategy, and marketing theory.
Purpose
The primary purpose of the Customer Data Vulnerability Scale is to measure the extent to which consumers perceive themselves to be exposed, defenseless, or vulnerable to harm strictly because a commercial enterprise holds their personal, behavioral, or financial information. Unlike traditional instruments that capture broad philosophical objections to surveillance or speculative societal concerns regarding data collection, the CDVS targets the affective and cognitive state of felt vulnerability that arises within an ongoing or prospective relationship between an individual consumer and a specific commercial entity.
In contemporary digital economies, firms routinely gather expansive volumes of customer data, often through non-transparent tracking technologies, location sensors, algorithmic profiling, and secondary data brokers. While modern corporate architectures treat consumer data as a strategic asset to drive personalization and predictive targeting, consumers frequently experience psychological friction upon realizing that their personal boundaries have been penetrated. The CDVS was developed to resolve a critical gap in organizational behavior and marketing literature: standard metrics of privacy concern often fail to explain customer behavioral backlashes, boycott movements, or relationship dissolution because they do not capture the asymmetric power differential inherent in corporate data possession.
Research applications of the CDVS span multiple paradigms:
- Evaluating Governance Mechanisms: Researchers utilize the scale to determine whether offering customers transparency (e.g., explicit privacy notices) and control (e.g., opt-in/opt-out permissions) mitigates felt vulnerability or paradoxically exacerbates it by heightening cognitive salience of data risks.
- Investigating Algorithmic Intrusiveness: The scale enables scholars to assess how aggressive real-time targeting, biometric identification, and artificial intelligence profiling elevate psychological exposure.
- Customer Relationship Management (CRM): Applied practitioners employ the scale as a diagnostic benchmark to quantify the downstream behavioral consequences of data harvesting on customer lifetime value, repurchase intentions, and brand advocacy.
Psychological Construct
The construct captured by the CDVS is perceived customer data vulnerability. Martin, Borah, and Palmatier (2017) conceptualize this construct as a consumer's mental representation of their susceptibility to being harmed, exploited, or compromised as a direct consequence of a firm's access to, custody of, or authority over their personal information. The construct is grounded in the subjective feeling of exposure and powerlessness, independent of whether an objective data breach or material harm has taken place.
Perceived customer data vulnerability is theoretically demarcated across four progressive stages along a continuum of vulnerability:
- Data Access Vulnerability: The baseline, pervasive state characterized by simple organizational possession of consumer data. The consumer recognizes that the firm possesses their identity, preferences, financial details, or lifestyle traces. This benign access stage is precisely what the CDVS operationalizes.
- Data Breach Vulnerability: The heightened vulnerability state occurring when firm security safeguards are compromised, resulting in unauthorized access or accidental exposure to outside entities.
- Data Spillover Vulnerability: The psychological and relational fallout when a data compromise involving one firm induces feelings of vulnerability toward unrelated partner firms or across the industry ecosystem.
- Manifest Vulnerability: The realization of actual, concrete damage, such as financial identity theft, reputational harm, digital extortion, or aggressive differential pricing.
The psychological construct represents a multidimensional psychological experience captured within a unidimensional psychometric structure. It is characterized by three experiential facets:
- Felt Insecurity and Lack of Protection: The subjective sensation that one's personal boundary has been dismantled, leaving the individual defenseless against potential organizational malfeasance or systemic data leakages.
- Power Asymmetry: The awareness that the firm holds asymmetric informational leverage. As the firm accumulates granular records of consumer behavior, it gains an unreciprocated capacity to predict, manipulate, or restrict the consumer's options.
- Latent Threat Expectation: The continuous, low-grade cognitive appraisal that possessed data can be weaponized, sold, or mishandled at any point in the future without the subject's consent or forewarning.
Theoretical Framework
The conceptual infrastructure of the Customer Data Vulnerability Scale is built at the intersection of several foundational social scientific and organizational theories:
Power-Dependence Theory
The scale draws heavily upon Power-Dependence Theory, originally formulated by Richard M. Emerson (1962). Emerson posited that the power of actor A over actor B is a function of actor B's dependence on actor A for critical resources, inversely related to actor B's ability to control the exchange. In modern digital commerce, when a consumer provides personal data to a firm to secure goods or services, an asymmetric power dependency is institutionalized. The firm possesses proprietary algorithms, permanent archives of personal information, and the capacity to monetize those assets. Conversely, the individual consumer rarely possesses insight into how that data is stored, shared, or leveraged. Consequently, data vulnerability emerges directly from this structural dependency and power disparity.
Social Exchange Theory and Psychological Contracts
Social Exchange Theory (Blau, 1964) asserts that enduring interpersonal and commercial relationships rely on subjective cost-benefit analyses, reciprocity, and mutual trust. When consumers transact with an organization, they enter into an implicit psychological contract (Rousseau, 1995) stipulating that personal information surrendered in exchange for utility will be managed with benevolence and confidentiality. When consumers suspect that an enterprise collects excessive information or might deploy it opportunistically, the psychological contract is fractured. This perceived breach manifests as acute vulnerability, undermining the social exchange baseline and converting collaborative relational dynamics into defensive, self-protective posturing.
Communication Privacy Management Theory
Sandra Petronio's (2002) Communication Privacy Management (CPM) theory serves as an additional theoretical pillar. CPM posits that individuals believe they own their personal private information and erect symbolic privacy boundaries to control its flow. When individuals disclose data, they convert recipients into authorized co-owners of that information, with the clear expectation that co-owners will observe reciprocal boundary coordination rules. When commercial firms leverage big data analytics to unilaterally alter, extend, or dissolve these boundary agreements without customer negotiation, boundary turbulence ensues. Perceived vulnerability represents the psychological manifestation of this boundary turbulence.
Validity
The empirical foundation of the Customer Data Vulnerability Scale was established through a series of rigorous psychometric, laboratory, and field studies documented by Martin, Borah, and Palmatier (2017). The scale has undergone extensive validation across diverse customer cohorts and experimental contexts.
Construct and Convergent Validity
Convergent validity of the CDVS was established using Confirmatory Factor Analysis (CFA). All six standardized factor loadings exceed the conventional .70 threshold, ranging from .82 to .94 (all p < .001). The Average Variance Extracted (AVE) for the CDVS consistently exceeds .75 across empirical samples, demonstrating that the latent construct accounts for the vast majority of variance in its observed measurement items.
Discriminant Validity
Discriminant validity was verified through multiple statistical approaches:
- Fornell-Larcker Criterion: The square root of the AVE for the CDVS is significantly greater than the inter-construct correlations between data vulnerability and related relational constructs, including customer trust, perceived privacy risk, perceived control, and opportunistic behavior.
- Chi-Square Difference Testing: Nested model comparisons restricting the correlation between the CDVS and general privacy concern to unity (Φ = 1.0) yielded a statistically significant deterioration in overall model fit (Δχ²(1) > 120.0, p < .001), corroborating that customer data vulnerability represents an empirically distinct psychological construct rather than redundant privacy apprehension.
- Heterotrait-Monotrait Ratio (HTMT): In subsequent replications, HTMT ratios with adjoining marketing constructs (e.g., brand betrayal, transaction risk) consistently fell below the conservative .85 cutoff.
Predictive and Nomological Validity
Nomological validity was verified by integrating the CDVS into extensive structural equation models predicting customer behavior and firm financial outcomes. Findings demonstrate that elevated scores on the CDVS:
- Directly and significantly decrease customer trust (β ≈ -.42, p < .001) and commitment.
- Directly increase customer avoidance behaviors, regulatory complaints, and active anti-firm behaviors (e.g., negative word-of-mouth, data falsification).
- Significantly suppress customer purchase intentions and actual share of wallet.
- Mediate the destructive influence of unauthorized corporate data practices and third-party data spillovers on firm abnormal stock returns and long-term equity valuation.
Reliability
The Customer Data Vulnerability Scale exhibits high internal consistency reliability across varied empirical samples:
- Cronbach's Alpha (α): Across the developmental calibration and validation studies reported by Martin et al. (2017), Cronbach's alpha coefficients for the 6-item instrument ranged from .94 to .96, indicating strong item homogeneity and low measurement error.
- Composite Reliability (CR): Structural equation estimates yielded Composite Reliability values exceeding .95, substantially exceeding the recommended threshold of .70 (Bagozzi & Yi, 1988).
- Average Variance Extracted (AVE): The construct AVE values across cross-sectional customer cohorts consistently achieved .78 to .82, verifying that random measurement noise accounts for less than 22% of item variance.
- Test-Retest Stability: In longitudinal assessments spanning two- to four-week intervals without intervene organizational privacy incidents, the CDVS displayed high temporal stability (intraclass correlation coefficients r > .80), indicating that baseline perceived vulnerability represents a stable evaluative attitude toward a specific corporate entity.
Factor Analysis
The dimensionality of the CDVS was evaluated using Exploratory Factor Analysis (EFA) followed by Confirmatory Factor Analysis (CFA) within a structural equation modeling environment.
Exploratory Factor Analysis (EFA)
Initial principal axis factoring with promax rotation performed on scale development items demonstrated a clean, single-factor solution. A single dominant eigenvalue exceeding 4.6 was extracted, explaining over 76% of the total variance among the items. Scree plot inspections exhibited an unmistakable inflection point after the first factor, with no secondary factors demonstrating eigenvalues above 0.65. All six items loaded substantially on this single dimension, with factor loadings between .84 and .93, confirming unidimensionality.
Confirmatory Factor Analysis (CFA)
Confirmatory Factor Analysis confirmed the single-factor measurement model, demonstrating satisfactory goodness-of-fit indices across diverse validation samples:
- Chi-Square to Degrees of Freedom: χ²/df < 2.5
- Comparative Fit Index (CFI): .985 to .994 (threshold > .95)
- Tucker-Lewis Index (TLI): .978 to .990 (threshold > .95)
- Root Mean Square Error of Approximation (RMSEA): .038 to .052 (threshold < .06, with 90% confidence intervals bounded within .021 and .068)
- Standardized Root Mean Square Residual (SRMR): .018 to .025 (threshold < .05)
All standardized factor loadings (λ) are statistically significant at p < .001. Representative parameter estimates from the baseline model include:
- Item 1 (λ ≈ .87)
- Item 2 (λ ≈ .92)
- Item 3 (λ ≈ .83)
- Item 4 (λ ≈ .89)
- Item 5 (λ ≈ .91)
- Item 6 (λ ≈ .88)
Instrument / Measurement Tool
The operational specifications of the Customer Data Vulnerability Scale are structured as follows:
- Test Type: Self-report psychometric scale; unidimensional attitudinal measure.
- Target Population: Consumers, retail patrons, digital service subscribers, and technology platform users whose personal data is managed by an enterprise.
- Item Format: 6 reflective declarative statements.
- Administration Modality: Web-based surveys, paper-and-pencil questionnaires, or in-app customer experience feedback panels.
- Completion Duration: Approximately 1 to 2 minutes.
- Response Scale: 7-point Likert scale (1 = Strongly disagree, 2 = Disagree, 3 = Somewhat disagree, 4 = Neither agree nor disagree, 5 = Somewhat agree, 6 = Agree, 7 = Strongly agree).
- Scoring Algorithm: Standard unweighted arithmetic mean calculation across all six observed items. There are no reverse-scored items in this instrument.
- Mathematical Formula:
$$\text{CDVS Composite Score} = \frac{\sum_{i=1}^{6} \text{Item}_i}{6}$$ - Score Interpretation:
- 1.00 – 2.49: Low Perceived Vulnerability (high customer psychological safety; strong perceived data security).
- 2.50 – 4.49: Moderate/Latent Vulnerability (neutrality, cautious surveillance awareness, or nascent discomfort).
- 4.50 – 7.00: Acute Perceived Vulnerability (high felt exposure, defenselessness, and severe operational risk of customer churn or brand retaliation).
Permissions & Fee and Test Year
The Customer Data Vulnerability Scale was published in 2017 in the Journal of Marketing (American Marketing Association). The instrument is widely considered accessible for non-commercial academic, scientific, and doctoral research purposes under standard academic fair-use conventions, provided proper attribution and citation are given to the original authors (Martin, Borah, & Palmatier, 2017). Commercial enterprises, proprietary market research organizations, or commercial software developers integrating the scale into proprietary customer sentiment tracking suites should obtain formal permissions or licensing through the copyright holder, the American Marketing Association (AMA), or via the Copyright Clearance Center (CCC).
References
- Bagozzi, R. P., & Yi, Y. (1988). On the evaluation of structural equation models. Journal of the Academy of Marketing Science, 16(1), 74–94. https://doi.org/10.1007/BF02723327
- Blau, P. M. (1964). Exchange and power in social life. John Wiley & Sons.
- Emerson, R. M. (1962). Power-dependence relations. American Sociological Review, 27(1), 31–41. https://doi.org/10.2307/2089716
- Fornell, C., & Larcker, D. F. (1981). Evaluating structural equation models with unobservable variables and measurement error. Journal of Marketing Research, 18(1), 39–50. https://doi.org/10.1177/002224378101800104
- Martin, K. D., Borah, A., & Palmatier, R. W. (2017). Data privacy: Effects on customer and firm performance. Journal of Marketing, 81(1), 36–58. https://doi.org/10.1509/jm.15.0497
- Petronio, S. (2002). Boundaries of privacy: Dialectics of disclosure. State University of New York Press.
- Rousseau, D. M. (1995). Psychological contracts in organizations: Understanding written and unwritten agreements. SAGE Publications. https://doi.org/10.4135/9781452231594
Items of the Scale
Response Scale: 7-point Likert scale (1 = Strongly disagree, 7 = Strongly agree)
Instructions: Please indicate your level of agreement or disagreement with each of the following statements regarding this firm possessing your personal information:
- I feel susceptible to harm due to this firm possessing my personal information.
- This firm holding my personal information makes me vulnerable to harm.
- Possessing my personal information gives this firm power over me.
- I feel that my information is exposed because this firm possesses it.
- I feel unprotected having personal information with this firm.
- This firm possessing my personal information is unsafe for me.