Institutional Apathy and Security Fatigue in Information Privacy and Data Security Governance: A Critical Narrative Review of Psychological Limits and Organisational Design

Onyii Henry *

University of the District of Columbia, 4200 Connecticut Ave NW, Washington, DC 20008, United States of America.

Tunbosun Oyewale Oladoyinbo

University of Maryland Global Campus, 3501 University Blvd E, Adelphi, MD 20783, United States of America.

Oluseyi Peter Adeoye

University of Gloucestershire, Gloucester, UK.

Christopher Ugbong Akeke

Howard University, 2400 Sixth Street NW, Washington, DC 20059-0001, United States of America.

Oluwadayo Mafolasere Olaniyi

University of the Cumberlands, 6178 College Station Drive, Williamsburg, KY 40769, United States of America.

*Author to whom correspondence should be addressed.


Abstract

Information privacy and data security governance increasingly depend on sustained human attention: employees must interpret warnings, follow changing policies, report anomalies, manage credentials, make disclosure decisions and repeatedly consent to data practices. Yet governance arrangements commonly treat attention, motivation and self-control as effectively unlimited. This critical narrative review examines how security fatigue, privacy fatigue, habituation, burnout, cynicism, organisational silence and institutional decoupling interact to weaken protective behaviour and governance legitimacy. Literature published from 1 January 2000 to 20 May 2026 was identified through accessible scholarly indexes, bibliographic databases, disciplinary digital libraries, DOI metadata services, institutional repositories and citation chaining, with foundational earlier works retained where conceptually necessary. Evidence was appraised for design quality, behavioural measurement, temporal ordering, ecological validity, theoretical coherence and relevance to organisational governance. The synthesis indicates that fatigue is not adequately explained as individual carelessness. Repeated low-value warnings, work-impeding controls, opaque privacy choices, excessive policy demands and punitive reporting climates create cumulative cognitive and emotional costs. These costs can produce attentional habituation, rational workarounds, reduced self-efficacy, resignation and silence. At institutional level, audit-oriented programmes may become decoupled from operational risk reduction, allowing training completion, policy acknowledgement and nominal consent to substitute for observed protective outcomes. Evidence is strongest for warning habituation, compliance-cost reasoning, privacy concern–behaviour discrepancies and associations between exhaustion and silence. Confidence is lower regarding long-term causal pathways and the effectiveness of organisation-wide interventions because much of the literature is cross-sectional, self-reported and based on behavioural intention. An integrated burden–efficacy–legitimacy cycle is proposed to explain how security demands, perceived control, organisational credibility and voice climate jointly shape behaviour. Sustainable governance should reduce unnecessary security work, prioritise high-consequence actions, automate where safe, design adaptive warnings, preserve meaningful choice, support non-punitive reporting and evaluate real behaviour and risk outcomes rather than ceremonial indicators.

Keywords: Cybersecurity culture, employee compliance, human factors, organisational silence, privacy fatigue, security fatigue, usable security, institutional decoupling.


How to Cite

Henry, Onyii, Tunbosun Oyewale Oladoyinbo, Oluseyi Peter Adeoye, Christopher Ugbong Akeke, and Oluwadayo Mafolasere Olaniyi. 2026. “Institutional Apathy and Security Fatigue in Information Privacy and Data Security Governance: A Critical Narrative Review of Psychological Limits and Organisational Design”. Asian Journal of Research in Computer Science 19 (8):152-71. https://doi.org/10.9734/ajrcos/2026/v19i8898.

Downloads

Download data is not yet available.