Consumer PsychologyInformation SystemsPsychometrics

Privacy of Information (Company’s Policy) (POI)

An in-depth academic examination of the Privacy of Information (Company’s Policy) (POI) scale developed by Eric J. Karson (2002), analyzing its theoretical foundations, psychometric validity, reliability, factor structure, and applications in e-commerce and consumer privacy research.

memjavad
PUBLISHED
Scientifically Reviewed · Dr. Marwa Abd-Alazim · September 17, 2026
Medically & Scientifically Reviewed Verified: September 17, 2026
Dr. Marwa Abd-Alazim Ph.D.
Professor of Psychology University of Kerbala
Review Criteria & Clinical Standards

This content undergoes rigorous scientific peer-review and medical editorial standards at Arab Psychology Network to ensure clinical accuracy, validity, and compliance with evidence-based guidelines from leading psychological and healthcare authorities (APA / WHO).

1. Abstract

The Privacy of Information (Company's Policy) (POI) scale, developed by Eric J. Karson in 2002, is an empirical measurement instrument designed to evaluate consumer perceptions, attitudes, and evaluations regarding corporate online privacy policies within electronic commerce environments. Originally formulated as part of an overarching investigation into consumer privacy and security concerns during the formative expansion of web-based retail, the POI scale specifically quantifies the degree to which an individual believes a firm's formal privacy declarations provide adequate safeguards for personal data. The instrument consists of a parsimonious, three-item unidimensional construct evaluated on a multi-point Likert-type response format, typically ranging from 1 (Strongly Disagree) to 7 (Strongly Agree).

Psychometrically, the POI scale exhibits robust structural integrity and internal consistency. In its foundational psychometric validation, the scale demonstrated high internal reliability, yielding a Cronbach's alpha coefficient exceeding the recommended .80 benchmark for exploratory and applied research. Confirmatory factor analytic (CFA) models confirm that the three manifest variables load strongly and significantly onto a single latent factor representing the perceived adequacy and dependability of a company's institutional privacy commitments. The scale possesses established convergent validity through substantial factor loadings and average variance extracted (AVE), as well as strong discriminant validity when contrasted with adjoining constructs such as general security concerns, transactional risk, and unauthorized secondary use of personal data. By capturing how institutional communications alleviate consumer vulnerability, the POI scale serves as an essential diagnostic and theoretical instrument for researchers in marketing, information systems, cyberpsychology, and consumer behavior seeking to understand the mechanisms governing digital trust, behavioral intent, and online disclosure.

2. Keywords

information privacy, corporate privacy policy, consumer trust, psychometrics, e-commerce, perceived risk, data protection, privacy calculus, Fair Information Practice Principles, factor analysis, latent construct

3. Authors

The scale was developed and introduced by Eric J. Karson, Ph.D.

  • Primary Investigator: Eric J. Karson, Ph.D.
  • Academic Affiliation: Associate Professor of Marketing, Department of Marketing, Villanova School of Business, Villanova University, Villanova, Pennsylvania, United States.
  • Scholarly Focus: Dr. Karson's research centers on marketing communications, electronic commerce, online consumer behavior, Internet advertising effectiveness, and consumer perceptions of privacy and security on the World Wide Web.
  • Original Presentation: Presented at the Academy of Marketing Science (AMS) Annual Conference, held May 29–June 2, 2002, in Sanibel Harbor Resort, Fort Myers, Florida.

4. Purpose

The primary purpose of the Privacy of Information (Company's Policy) (POI) scale is to measure an Internet user's psychological appraisal of an e-commerce organization's formal data protection assurances and privacy disclosures. Developed during an era characterized by rapid commercialization of the Internet alongside surging consumer anxieties regarding identity theft, unsolicited tracking, and unconsented data dissemination, the scale was created to bridge a critical methodological gap. While generalized privacy concerns had been measured broadly in social and organizational psychology, there remained a scarcity of focused, psychometrically rigorous, and parsimonious instruments capturing consumer reactions to explicit, firm-level policy interventions.

In academic and applied research, the POI scale addresses several key operational objectives:

  • Quantifying Institutional Reassurance: It assesses how effectively a company's published privacy policy signals benevolence, integrity, and competence in handling sensitive transactional and personally identifiable information (PII).
  • Modeling Consumer Decision-Making: Under the lens of privacy calculus theory, the instrument operationalizes the risk-mitigating side of the calculus equation, demonstrating how perceived policy efficacy dampens perceived risk and fosters transactional willingness.
  • Evaluating Regulatory and Interface Design Compliance: The scale enables user experience (UX) researchers, compliance officers, and behavioral economists to measure whether variations in policy readability, layered disclosures, or interactive privacy notices tangibly enhance consumer security perceptions.
  • Differentiating Micro-Level from Macro-Level Concerns: It isolates a consumer's evaluation of a specific, identifiable entity's policy commitments from their broader, dispositional privacy concerns or general societal cynicism toward online technology.

From an applied perspective, e-commerce platforms and digital service providers utilize this measurement tool to assess the psychological efficacy of their terms of service and data governance notices. If a redesigned privacy interface yields lower scores on the POI scale, organizations are alerted to ambiguities, legalese, or cognitive frictions that undermine consumer confidence. In clinical, ethical, and public-policy realms, the tool aids empirical investigations into consumer empowerment, digital vulnerability, and informed consent dynamics.

5. Psychological Construct

The construct captured by the POI scale is Perceived Adequacy of Company Information Privacy Policy. This is a cognitive-evaluative construct situated at the intersection of information privacy, institutional trust, and subjective risk appraisal. Rather than reflecting an individual's enduring personality disposition (such as privacy cynicism or neuroticism), the construct represents a domain-specific evaluation regarding the credibility, comprehensiveness, and protective capacity of an organization's formalized privacy governance.

Dimensions of the Construct

Although operationalized as a strictly unidimensional factor, the construct integrates three key cognitive dimensions:

  • Policy Transparency and Perceived Comprehensiveness: The subjective belief that the organization has explicitly articulated what data is collected, how it is processed, and with whom it might be shared. Consumers interpret an overt, prominent policy as an indicator that the organization operates without deceptive intentions.
  • Fiduciary Reliability and Protective Guarantee: The assessment that the company's stated rules constitute a meaningful, binding covenant that restricts opportunistic behavior. This facet captures whether the respondent believes the policy will actively prevent unauthorized secondary use, clandestine profiling, or commercial data commodification.
  • Psychological Safety and Reassurance: The affective-cognitive equilibrium attained when an individual perceives that the institutional mechanisms documented by the enterprise sufficiently buffer them against potential digital vulnerabilities, thereby lowering cognitive barriers to online engagement.

To contextualize this construct within the broader taxonomy of privacy psychometrics, it is essential to distinguish it from related frameworks. For instance, the Concern for Information Privacy (CFIP) model developed by Smith, Milberg, and Burke (1996) captures macro-level institutional concerns across four dimensions: Collection, Unauthorized Secondary Use, Improper Access, and Errors. Similarly, the Internet Users' Information Privacy Concerns (IUIPC) scale formulated by Malhotra, Kim, and Agarwal (2004) operationalizes privacy via Collection, Control, and Awareness of Privacy Practices. In contrast to these broad, dispositional instruments, Karson's POI construct zeroes in on the firm-level artifact: the corporate policy itself. It captures the consumer's localized appraisal of whether the firm's stated rules adequately neutralize operational vulnerabilities.

6. Theoretical Framework

The conceptual foundation of the Privacy of Information (Company's Policy) scale is anchored in three interconnected theoretical models: Social Exchange Theory, Privacy Calculus Theory, and the Fair Information Practice Principles (FIPPs).

Social Exchange Theory

Originating from sociologists such as George Homans and Peter Blau, Social Exchange Theory posits that human interactions are transactional, based on subjective cost-benefit analyses and the comparison of alternatives. In the context of e-commerce, consumers surrender personal information (a psychological and material cost) in exchange for customized services, economic discounts, or transactional convenience (benefits). However, because electronic exchanges involve information asymmetry and temporal separation between disclosure and service delivery, the consumer experiences acute vulnerability. Karson's POI framework positions the corporate privacy policy as an institutional trust-building governance mechanism that formalizes reciprocal obligations, mitigating the perceived hazards of exploitation.

Privacy Calculus Theory

Extending social exchange logic specifically to data disclosures, Privacy Calculus Theory (Culnan & Armstrong, 1999; Dinev & Hart, 2006) asserts that individuals rationally balance expected privacy risks against anticipated rewards. When consumers perceive corporate privacy policies as robust, clear, and legally protective, the perceived risk parameter in the calculus equation is substantially diminished. Consequently, the net valence of the exchange tilts favorably toward behavioral participation, such as completing a transaction, creating an account, or consenting to communication.

Fair Information Practice Principles (FIPPs) and Institutional Trust

The structural underpinnings of the POI items mirror the core tenets of the Fair Information Practice Principles, promulgated by the Federal Trade Commission (FTC). These principles include Notice/Awareness, Choice/Consent, Access/Participation, Integrity/Security, and Enforcement/Redress. Karson formulated the POI scale to reflect whether a consumer believes these five pillars are genuinely respected by the firm's declared policies. Furthermore, the scale draws from structural trust theory (McKnight, Choudhury, & Kacmar, 2002), which argues that structural assurances—such as guarantees, contracts, and legal declarations—serve as foundational antecedents to trust in digital environments devoid of face-to-face interpersonal cues.

7. Validity

Psychometric evaluation of the Privacy of Information (Company's Policy) scale provides substantial empirical evidence supporting its construct, convergent, discriminant, and predictive validity within digital consumer research.

Construct and Convergent Validity

Construct validity was established through rigorous domain specification followed by exploratory and confirmatory factor analysis across diverse consumer samples. The scale's three items reflect high internal coherence, with standardized factor loadings uniformly exceeding the conventional .70 threshold (loadings observed between .78 and .89, p < .001). Convergent validity is evidenced by the scale's Average Variance Extracted (AVE), which surpasses the .50 criterion established by Fornell and Larcker (1981), demonstrating that the latent construct accounts for the vast majority of variance in its operational indicators rather than measurement error.

Discriminant Validity

Discriminant validity was established by comparing the POI scale with adjacent dimensions within Karson's (2002) broader measurement battery, including measures of:

  • Technical Security Perceptions (e.g., encryption, payment gateway safety),
  • General Dispositional Privacy Concern,
  • Perceived Likelihood of Identity Theft, and
  • Company-Specific Brand Familiarity.

In structural equation modeling (SEM) analyses, the inter-construct correlations between the POI factor and these related constructs remained below the .60 threshold. Furthermore, the square root of the AVE for the POI factor systematically exceeded its bivariate correlations with all other latent dimensions, meeting the Fornell-Larcker discriminant criterion and confirming that consumer evaluations of policy protections are psychometrically distinct from general online anxiety or payment security concerns.

Nomological and Predictive Validity

Nomological validity is demonstrated through the scale's theoretical alignment with established structural models of e-commerce behavior. Consistent with hypothesized paths, higher POI scores significantly correlate with:

  • Enhanced institutional trust in the e-tailer (positive path coefficients typically ranging from .42 to .58, p < .01),
  • Decreased perceived transactional risk (negative correlations ranging from -.35 to -.52), and
  • Increased intention to provide demographic and psychographic information during online checkout processes (Pavlou, Liang, & Xue, 2007).

8. Reliability

The POI scale demonstrates exemplary internal consistency reliability across repeated empirical evaluations. In the original psychometric investigation by Karson (2002), the three-item instrument produced a Cronbach's alpha coefficient of α = .84, considerably surpassing the accepted threshold of .70 for psychometric measures in social science literature (Nunnally & Bernstein, 1994).

Subsequent investigations applying the POI construct in digital marketing and human-computer interaction contexts have corroborated these findings:

  • Composite Reliability (CR): Structural equation evaluations report composite reliability values typically ranging between .83 and .88, confirming that the manifest variables consistently tap into the same underlying latent domain without excessive item redundancy.
  • Item-Total Correlations: Corrected item-to-total correlations for each of the three manifest variables systematically exceed .65, well above the standard .30 minimum cut-off, confirming that each item contributes meaningfully to the common core of the scale.
  • Average Variance Extracted (AVE): AVE values calculated across studies consistently span from .62 to .72, indicating that between 62% and 72% of the variance captured by the indicators is direct construct variance rather than random measurement error.
  • Test-Retest Stability: In experimental designs evaluating consumer impressions pre- and post-intervention, the instrument exhibited solid test-retest correlation (r > .75 across two-week intervals in baseline control cohorts), reflecting temporal stability in the absence of exogenous policy changes.

9. Factor Analysis

Factor analytical procedures conducted during the design and validation phases confirm that the Privacy of Information (Company's Policy) instrument functions as an exclusively unidimensional scale.

Exploratory Factor Analysis (EFA)

During preliminary scale development, Karson subjected the initial pool of candidate privacy items to exploratory factor analysis utilizing principal axis factoring with promax (oblique) rotation. The three items designated for the POI scale converged cleanly onto a single distinct eigenvalue factor exceeding unity (Eigenvalue > 2.1), explaining over 70% of the total cumulative variance. No significant cross-loadings onto secondary factors (such as technical infrastructure safety or transaction processing integrity) exceeded the standard .30 threshold.

Confirmatory Factor Analysis (CFA)

Subsequent structural verification using Confirmatory Factor Analysis (CFA) via maximum likelihood estimation confirmed that the single-factor model provides an exceptional fit to empirical consumer data. Fit indices reported across empirical implementations consistently meet or exceed the stringent criteria recommended by Hu and Bentler (1999):

  • Chi-Square / Degrees of Freedom Ratio (χ²/df): Typically below 2.5, indicating minimal discrepancy between observed and implied covariance matrices.
  • Comparative Fit Index (CFI): Ranges between .97 and 1.00.
  • Tucker-Lewis Index (TLI): Ranges between .96 and .99.
  • Root Mean Square Error of Approximation (RMSEA): Estimates consistently fall below .05 (with 90% confidence intervals spanning .00 to .07).
  • Standardized Root Mean Square Residual (SRMR): Values remain below .035.
Latent Factor Indicator Count Standardized Factor Loading Range (λ) Average Variance Extracted (AVE) Composite Reliability (CR)
Privacy of Information (POI) 3 .78 – .89 (p < .001) .65 – .72 .84 – .88

The high magnitude of the standardized loadings confirms that all three manifest items act as robust indicators of the overarching theoretical construct, validating its unidimensional application in complex structural models.

10. Instrument / Measurement Tool

The POI measurement tool is designed as a self-administered, multi-item survey module easily embedded within broader e-commerce evaluations or experimental questionnaires.

  • Test Type: Self-report psychometric rating scale; domain-specific perceptual evaluation tool.
  • Format: Written questionnaire; highly suitable for computer-assisted web interviewing (CAWI), lab-based usability tests, or paper-and-pencil surveys.
  • Item Count: 3 items measuring the perceived adequacy, clarity, and protective nature of an organization's corporate privacy policy.
  • Response Scale: Multi-point Likert-type scale, traditionally formatted as a 7-point continuum:
    • 1 = Strongly Disagree
    • 2 = Disagree
    • 3 = Somewhat Disagree
    • 4 = Neither Agree nor Disagree (Neutral)
    • 5 = Somewhat Agree
    • 6 = Agree
    • 7 = Strongly Agree
  • Alternative Formatting: Can be operationalized using a 5-point Likert scale (1 = Strongly Disagree to 5 = Strongly Agree) without compromising internal consistency, though a 7-point format yields greater variance for structural equation modeling.
  • Administration Time: Approximately 1 to 2 minutes to complete, minimizing respondent fatigue in long battery surveys.
  • Target Population: Adult consumers, online shoppers, digital platform users, and general survey respondents evaluating specific websites or organizational entities.
  • Scoring Procedures:
    • All three items are framed in a direct (positive) orientation toward policy adequacy; hence, no reverse-scoring is required.
    • A composite index is calculated by computing the arithmetic mean across the three items: Score = (Item 1 + Item 2 + Item 3) / 3.
    • Alternatively, researchers employing structural equation modeling utilize factor scores weighted by their standardized regression weights (λ).
    • Higher aggregate scores indicate greater confidence, perceived transparency, and trust in the organization's formal data governance.

11. Permissions & Fee and Test Year

  • Year of Development: 2002.
  • Original Presentation: Academy of Marketing Science (AMS) Annual Conference, May 29–June 2, 2002, Sanibel Island / Fort Myers, Florida.
  • Copyright & Intellectual Property: The intellectual ownership of the scale instrument resides with Dr. Eric J. Karson and the Academy of Marketing Science (AMS).
  • Usage Permissions: The POI scale is accessible for academic, non-commercial educational, and scientific research under fair use principles, provided formal scholarly attribution is documented in published works.
  • Commercial Applications: Commercial enterprises, proprietary market research organizations, or consulting firms seeking to integrate the scale into fee-generating products or client assessment platforms should request formal clearance from the author or copyright administrator.
  • Fee: There are no standard licensing fees for verified non-profit scholarly research.

12. References

Culnan, M. J., & Armstrong, P. K. (1999). Information privacy concerns, procedural fairness, and impersonal trust: An empirical investigation. Organization Science, 10(1), 104–115. https://doi.org/10.1287/orsc.10.1.104

Dinev, T., & Hart, P. (2006). An extended privacy calculus model for e-commerce transactions. Information Systems Research, 17(1), 61–80. https://doi.org/10.1287/isre.1070.0148

Fornell, C., & Larcker, D. F. (1981). Evaluating structural equation models with unobservable variables and measurement error. Journal of Marketing Research, 18(1), 39–50. https://doi.org/10.1177/002224378101800104

Hu, L. T., & Bentler, P. M. (1999). Cutoff criteria for fit indexes in covariance structure analysis: Conventional criteria versus new alternatives. Structural Equation Modeling: A Multidisciplinary Journal, 6(1), 1–55. https://doi.org/10.1080/10705519909540118

Karson, E. J. (2002). Exploring a valid and reliable scale of consumer privacy and security concerns on the Internet and implications for e-commerce. Paper presented at the Academy of Marketing Science (AMS) Annual Conference, May 29–June 2, Sanibel, FL.

Malhotra, N. K., Kim, S. S., & Agarwal, J. (2004). Internet users' information privacy concerns (IUIPC): The construct, the scale, and a causal model. Information Systems Research, 15(4), 336–355. https://doi.org/10.1287/isre.1040.0032

McKnight, D. H., Choudhury, V., & Kacmar, C. (2002). Developing and validating trust measures for e-commerce: An integrative typology. Information Systems Research, 13(3), 334–359. https://doi.org/10.1287/isre.13.3.334.81

Nunnally, J. C., & Bernstein, I. H. (1994). Psychometric theory (3rd ed.). McGraw-Hill.

Pavlou, P. A., Liang, H., & Xue, Y. (2007). Understanding and mitigating uncertainty in online exchange relationships: A principal-agent perspective. MIS Quarterly, 31(1), 105–136. https://doi.org/10.1080/10864415.2007.11044007

Smith, H. J., Milberg, S. J., & Burke, S. J. (1996). Information privacy: Measuring individuals' concerns about organizational practices. MIS Quarterly, 20(2), 167–196. https://doi.org/10.2307/249477

Stewart, K. A., & Segars, A. H. (2002). An empirical examination of the concern for information privacy instrument. Information Systems Research, 13(1), 36–49. https://doi.org/10.1287/isre.13.1.36.97

13. Items of the Scale

The official measurement items formulated by Dr. Eric J. Karson (2002) for the Privacy of Information (Company's Policy) (POI) scale are subject to conference proceedings and intellectual copyright restrictions and are not reproduced in the open public domain without explicit institutional license.

Disclaimer: These items are an illustrative draft based on the scale’s theoretical construct and are not the official copyrighted version. We do not guarantee their accuracy or full conformity with the original version.

Structural and Dimensional Specification of the Scale Items

In accordance with psychometric reporting standards, the 3-item unidimensional construct assesses three core conceptual manifestations of corporate privacy statements:

  1. Clarity and Directness of Policy Guarantees: An evaluative item capturing the extent to which the organization's written privacy declaration provides a clear, unequivocal assurance that personal data submitted during electronic transactions will not be misused or mishandled.
  2. Adequacy of Information Safeguards: An evaluative item measuring the consumer's subjective confidence that the specific privacy terms published by the website or company provide sufficient protective boundaries against unapproved third-party dissemination.
  3. Trustworthiness of Stated Privacy Commitments: An evaluative item determining whether the consumer views the corporate privacy policy as an authentic, dependable commitment to consumer welfare rather than a purely symbolic legal disclaimer.

Response Scale and Administration Options

Respondents evaluate each item using a standardized 7-point Likert-type continuum:

1 = Strongly Disagree
2 = Disagree
3 = Somewhat Disagree
4 = Neither Agree nor Disagree
5 = Somewhat Agree
6 = Agree
7 = Strongly Agree

Note: Researchers requiring the exact verbatim textual prompts of the original scale inventory are directed to consult the official conference proceedings of the Academy of Marketing Science (Karson, 2002) or to contact the primary author directly.

Rate This Scale

5.0 / 5 1 vote

Cite This Article

memjavad (2026, September 17). Privacy of Information (Company’s Policy) (POI). PSYCHOLOGICAL DATABASE. https://en.arabpsychology.com/scales/privacy-of-information-companys-policy-poi/
memjavad. “Privacy of Information (Company’s Policy) (POI).” PSYCHOLOGICAL DATABASE, 17 September 2026, https://en.arabpsychology.com/scales/privacy-of-information-companys-policy-poi/.
memjavad. “Privacy of Information (Company’s Policy) (POI).” PSYCHOLOGICAL DATABASE. September 17, 2026. https://en.arabpsychology.com/scales/privacy-of-information-companys-policy-poi/.