<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>دانشگاه قم</PublisherName>
				<JournalTitle>علوم و فنون مدیریت اطلاعات</JournalTitle>
				<Issn>2476-6658</Issn>
				<Volume>12</Volume>
				<Issue>1</Issue>
				<PubDate PubStatus="epublish">
					<Year>2026</Year>
					<Month>03</Month>
					<Day>21</Day>
				</PubDate>
			</Journal>
<ArticleTitle>Proposed Model for Data Governance Implementation with an Emphasis on Privacy</ArticleTitle>
<VernacularTitle>مدل پیشنهادی برای استقرار حکمرانی داده‌ها با تأکید بر حریم خصوصی</VernacularTitle>
			<FirstPage>111</FirstPage>
			<LastPage>123</LastPage>
			<ELocationID EIdType="pii">3464</ELocationID>
			
<ELocationID EIdType="doi">10.22091/stim.2025.12492.2221</ELocationID>
			
			<Language>FA</Language>
<AuthorList>
<Author>
					<FirstName>مرتضی</FirstName>
					<LastName>محمودی پرچینی</LastName>
<Affiliation>گروه مدیریت فن آوری اطلاعات ، واحد بین المللی کیش، دانشگاه آزاد اسلامی، کیش، ایران</Affiliation>
<Identifier Source="ORCID">0009-0007-7781-2583</Identifier>

</Author>
<Author>
					<FirstName>لادن</FirstName>
					<LastName>ریاضی</LastName>
<Affiliation>گروه مدیریت فناوری اطلاعات، دانشکده مدیریت و اقتصاد، واحد علوم و تحقیقات، دانشگاه آزاد اسلامی، تهران، ایران</Affiliation>
<Identifier Source="ORCID">0009-0000-6813-0854</Identifier>

</Author>
<Author>
					<FirstName>علیرضا</FirstName>
					<LastName>پور ابراهیمی</LastName>
<Affiliation>گروه مدیریت صنعتی، دانشکده مدیریت، دانشگاه آزاد اسلامی، واحد کرج، دانشگاه آزاد اسلامی، واحد کرج، ایران</Affiliation>
<Identifier Source="ORCID">0000-0001-5741-0260</Identifier>

</Author>
<Author>
					<FirstName>سیدعبداله امین</FirstName>
					<LastName>موسوی</LastName>
<Affiliation>گروه مدیریت فناوری اطلاعات، واحد تهران مرکزی، دانشگاه آزاد اسلامی، تهران، ایران</Affiliation>
<Identifier Source="ORCID">0009-0005-3052-5910</Identifier>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2025</Year>
					<Month>03</Month>
					<Day>10</Day>
				</PubDate>
			</History>
		<Abstract>&lt;strong&gt;Objective: &lt;/strong&gt;In the contemporary digital landscape, data governance stands as a critical challenge in both IT policy and technology law. Given the increasing volume of personal data processing and exchange, the necessity for a localized data governance framework, tailored to a country’s specific legal and technological infrastructure, is more pressing than ever. This study proposes a data governance model with a strong emphasis on privacy, addressing current challenges and providing practical solutions for improving personal data management. The primary objective is to develop a localized data governance framework for Iran, aligned with international standards such as the GDPR and the CCPA. By analyzing legal gaps, implementation challenges, and potential solutions, this study aims to establish a practical framework that not only enhances security and privacy protection but also fosters public trust in digital services.
&lt;strong&gt;Methodology&lt;/strong&gt;: This applied-developmental study utilizes a mixed-methods approach. In the qualitative phase, legal documents, regulatory policies, and existing data governance models from Iran and other countries were analyzed. Furthermore, the Delphi method was employed to collect and examine the insights of 58 experts in technology, digital law, and information security. In the quantitative phase, Confirmatory Factor Analysis (CFA) was applied to validate the proposed model. Data were gathered through semi-structured expert interviews, a review of domestic laws and policies, and comparative studies with international frameworks. Key model indicators were extracted using qualitative content analysis, and statistical tests were employed to assess the model’s validity and reliability.
&lt;strong&gt;Findings: &lt;/strong&gt;Results indicate that the primary challenges to data governance in Iran include the lack of an integrated legal framework, the absence of an independent regulatory body, and deficiencies in the enforcement of data protection policies. A comparative analysis with the European GDPR and the U.S. CCPA revealed that Iran lacks clear requirements for data processing transparency and independent oversight—two pillars of international standards. Furthermore, findings indicate high levels of privacy concern among Iranian users; 78% expressed anxiety regarding how their data is managed on domestic platforms. The proposed model comprises three dimensions (legal-policy, technical-technological, and organizational-regulatory), six components, and 24 operational indicators. Data analysis demonstrated that implementing this model could reduce privacy violations by 30.8%, increase user trust in digital services by 44.6%, and improve regulatory efficiency by 38.2%.
&lt;strong&gt;Conclusion: &lt;/strong&gt;Data governance in Iran requires a transparent and binding framework that enhances security and user data protection while improving database interoperability and the efficiency of regulatory institutions. This study underscores that drafting comprehensive data governance legislation and establishing an independent regulatory body are critical steps. Additionally, implementing robust security policies, advanced encryption, and revising laws related to data collection and processing can mitigate cybercrimes and bolster public trust. A comparative analysis shows that the proposed model possesses a high degree of adaptability to global standards, suggesting that its proper implementation could enhance data protection standards by up to 79.4%. Ultimately, this research highlights the urgent need to reform data governance policies, enact new regulations, and increase transparency in personal data management. Future studies should focus on evaluating the practical implementation of this model within both public and private sectors.</Abstract>
			<OtherAbstract Language="FA">&lt;strong&gt;هدف:&lt;/strong&gt; در دنیای دیجیتال امروز، حکمرانی داده‌ها یکی از مهمترین چالش‌های سیاست‌گذاری و حقوق فناوری اطلاعات است. با افزایش پردازش و تبادل داده‌های شخصی، نیاز به چارچوبی بومی برای حکمرانی داده‌ها که متناسب با زیرساخت‌های قانونی و فناوری کشور باشد، بیش‌ازپیش احساس می‌شود. این پژوهش، مدلی پیشنهادی برای حکمرانی داده‌ها با تأکید بر حریم خصوصی ارائه می‌دهد. مدل یادشده با بررسی چالش‌های موجود، برای بهبود مدیریت داده‌های شخصی راهکارهای اجرایی را پیشنهاد می‌کند. هدف اصلی پژوهش، ارائة الگویی بومی برای حکمرانی داده در ایران و تطبیق آن با استانداردهای بین‌المللی مانند مقررات عمومی حفاظت از داده‌ها  و قانون حفظ حریم خصوصی مصرف‌کنندگان کالیفرنیا است. این مطالعه با تحلیل شکاف‌های قانونی، مشکلات اجرایی، و راهکارهای کاربردی، چارچوبی عملیاتی برای مدیریت داده‌ها ارائه می‌کند که می‌تواند امنیت و حریم خصوصی را افزایش دهد و موجب تقویت اعتماد عمومی به خدمات دیجیتال شود.&lt;br /&gt;&lt;strong&gt;روش:&lt;/strong&gt; پژوهش حاضر از نوع کاربردی-توسعه‌ای با رویکرد ترکیبی (کمّی و کیفی) است. در بخش کیفی، اسناد حقوقی، سیاست‌های تنظیم‌گری، و مدل‌های حکمرانی داده در ایران و کشورهای دیگر تحلیل شدند. با استفاده از روش دلفی، نظرات ۵۸ متخصص در حوزه‌های فناوری، حقوق دیجیتال، و امنیت اطلاعات گردآوری و تحلیل شد. در بخش کمّی، تحلیل عاملی تأییدی برای اعتبارسنجی مدل به کار رفت. داده‌ها با مصاحبه‌های نیمه‌ساختاریافته، تحلیل قوانین داخلی، و مقایسة تطبیقی با چارچوب‌های بین‌المللی گردآوری شد.&lt;br /&gt;&lt;strong&gt;یافته‌ها:&lt;/strong&gt; یافته‌ها نشان می‌دهد که در ایران، نبود چارچوب قانونی یکپارچه، نهاد نظارتی مستقل، و ضعف در اجرای سیاست‌های حفاظت از داده، از چالش‌های اصلی حکمرانی داده هستند. مدل پیشنهادی شامل سه بُعد (حقوقی-سیاستی، فنی-فناورانه، سازمانی-نظارتی)، شش مؤلفة کلیدی، و ۲۴ شاخص اجرایی است. تحلیل داده‌ها نشان داد که اجرای مدل پیشنهادی می‌تواند میزان نقض حریم خصوصی را تا ۳۰ درصد کاهش دهد و اعتماد کاربران به خدمات دیجیتال را تا ۴۵ درصد افزایش دهد.&lt;br /&gt;&lt;strong&gt;نتیجه‌گیری:&lt;/strong&gt; برای بهبود وضعیت حکمرانی داده در ایران، تدوین قانون جامع، ایجاد نهاد نظارتی مستقل، و شفافیت در سیاست‌های جمع‌آوری داده ضروری است. مقایسة مدل پیشنهادی با استانداردهای بین‌المللی، نشان‌دهندة سازگاری بالای آن است و اجرای مؤثر آن می‌تواند استانداردهای حفاظت از داده را تا ۸۰ درصد ارتقاء دهد.</OtherAbstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">حکمرانی داده‌ها</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">حریم خصوصی</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">مدل حکمرانی داده</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">GDPR</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">سیاست‌گذاری داده</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://stim.qom.ac.ir/article_3464_12851f1783e557a604e50fffdf9fde70.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
