Effect of Types of Access Control Systems on Data Protec-tion Compliance and Security in Star-Rated Hotels in Nairobi
DOI:
https://doi.org/10.53819/81018102t3184Abstract
Star-rated hotels in Nairobi manage extensive sensitive guest data, making them prime targets for cyberattacks. This study examined the relationship between types of access control systems and data protection compliance in star‑rated hotels in Nairobi, Kenya. Guided by the Deterrence Theory of Information Security, the study adopted a mixed‑methods embedded design. A census of all 60 star‑rated hotels was conducted. Four respondents per hotel were targeted (one Hotel Manager, one IT professional, one front desk staff member, and one Security Officer), yielding a target population of 240 respondents. A total of 215 (89.6%) completed and returned the questionnaire. Data were collected via structured questionnaires and interviews. Regression analysis was conducted at a 0.05 significance level using SPSS. Results showed that types of access control systems had a significant positive effect on compliance (R = 0.452, R² = 0.204, p < 0.05), leading to rejection of the null hypothesis. The study concludes that the types of access control systems implemented have a statistically significant positive effect on data protection compliance. The Office of the Data Protection Commissioner should develop sector-specific guidelines for hospitality establishments that translate the Kenya Data Protection Act (2019) into actionable access control standards.
Keywords: Access Control Systems, Data Protection Compliance, Star-Rated Hotels, Nairobi
References
Akmese, H., & Gundogan, R. (2020). The role of internal control systems in the hotel busi-ness: A case of five star hotels in Alanya. Journal of Business Research – Turk, 12(1), 123–135.
Ashqar, R. I., Ashqar, H. I., & Ramos, C. M. Q. (2023). Identity and access management in tourism and hospitality. In Conference on Management, Tourism and Technolo-gy (pp. 445–460). Springer. https://doi.org/10.1007/978-3-031-44131-8_32
Beccaria, C. (1764). On crimes and punishments. (Original work published 1764)
Braun, V., & Clarke, V. (2006). Using thematic analysis in psychology. Qualitative Re-search in Psychology, 3(2), 77–101.
Bryman, A., & Bell, E. (2015). Business research methods (4th ed.). Oxford University Press.
Creswell, J. W., & Creswell, J. D. (2017). Research design: Qualitative, quantitative, and mixed methods approaches (5th ed.). Sage Publications.
Cylance Research Team. (2015). Critical flaw in Wi-Fi routers puts hotels and millions of guests at risk. Help Net Securi-ty.
Dijmărescu, I., Iatagan, M., Hurloiu, I., Geamănu, M., & Dijmărescu, S. (2022). Neuroman-agement decision making in facial recognition biometric authentication as a mobile payment technology in retail, restaurant, and hotel business models. Oeconomia Copernicana, 13(2), 509–540. https://doi.org/10.24136/oc.2022.019
Esiefarienrhe, B. M., & Ekka, A. H. (2018). Modified role based access control model for data security. International Journal of Scientific & Technology Research, 7(11), 182–186.
Ghaderi, Z., Beal, L., & Houanti, L. H. (2024). Cybersecurity threats in tourism and hospital-ity: Perspectives from tourists engaging with sharing economy services. Current Is-sues in Tourism, 1–22. https://doi.org/10.1080/13683500.2024.2353327
Gordon, L. A., & Loeb, M. P. (2002). The economics of information security invest-ment. ACM Transactions on Information and System Security, 5(4), 438–457.
Government of Kenya. (2019). Data Protection Act, No. 24 of 2019. Kenya Gazette Supple-ment.
Gwebu, K., & Barrows, C. W. (2020). Data breaches in hospitality: Is the industry differ-ent? Journal of Hospitality and Tourism Technology, 11(3), 511–527. https://doi.org/10.1108/JHTT-04-2019-0053
Hair, J. F., Black, W. C., Babin, B. J., & Anderson, R. E. (2021). Multivariate data analy-sis (8th ed.). Cengage.
IBM X Force Red. (2019a). Data leaks, default passwords exposed in visitor management systems. ZDNet. https://www.zdnet.com/article/data-leaks-default-passwords-exposed-in-visitor-management-systems/
Joseph Ng, P. S. (2024). Hotel room access control: An NFC approach to ecotourism frame-work. Journal of Science and Technology Policy Management, 15(3), 530–548. https://doi.org/10.1108/JSTPM-06-2023-0095
Kimingi, A. M., Mwenda, L. K. M., & Chege, P. W. (2024). Effect of digital security systems on market performance in 3–5 star rated hotels in Nakuru County, Kenya. Dedan Kimathi University of Technology Repository.
Kothari, C. R. (2004). Research methodology: Methods and techniques (2nd ed.). New Age International.
Kundu, A., & Bej, T. (2021). Experiencing e assessment during COVID 19: An analysis of Indian students' perception. Higher Education Evaluation and Development, 15(2), 114–134.
Maalem Lahcen, R. A., Caulkins, B., Mohapatra, R., & Kumar, M. (2020). Review and in-sight into the behavioural aspects of cybersecurity. Cybersecurity, 3(1), 1–18.
Mandarin Oriental Hotel Group. (2015, July 10). Press release and notice regarding Manda-rin Oriental credit card breach. https://photos.mandarinoriental.com/is/content/MandarinOriental/corporate-global-pdf-mohg-malware-notice-july-10-2015
Marriott International Inc. (2020). Probing Marriott's mega breach: 9 cybersecurity takea-ways. BankInfoSecurity. https://www.bankinfosecurity.net/probing-marriotts-mega-breach-9-cybersecurity-takeaways-a-15338
Marriott. (2018, November 30). Marriott announces Starwood guest reservation database security incident. https://news.marriott.com/news/2018/11/30/marriott-announces-starwood-guest-reservation-database-security-incident
Masaire, T. M., Tsokota, T., & Chipfumbu, C. T. (2024). Information security in the Zimba-bwean hotel sector. In Tourism and hospitality for sustainable development (pp. 87–108). Springer. https://doi.org/10.1007/978-3-031-63073-6_6
Medugu, J. D., Binuyo, B. A., Efunwole, A. A., & Oyebisi, S. O. (2023). Security control systems in the hospitality industry in Lagos Metropolis, Nigeria. Journal of Hospi-tality and Tourism Insights, 6(3), 1122–1140.
Mubarak, R., Alsboui, T., Alshaikh, O., Inuwa Dutse, I., Khan, S., & Parkinson, S. (2023). A survey on the detection and impacts of deepfakes in visual, audio, and textual for-mats. IEEE Access, 11, 144497–144529. https://doi.org/10.1109/ACCESS.2023.3344653
Mugenda, O. M., & Mugenda, A. G. (2003). Research methods: Quantitative and qualitative approaches. African Centre for Technology Studies.
National Cybersecurity Centre of Excellence. (2021). Securing property management sys-tems (NIST SP 1800-27). National Institute of Standards and Technolo-gy. https://www.tripwire.com/state-of-security/nist-sp-1800-27-securing-property-management-systems
Nayak, M. S. D. P., & Narayan, K. A. (2019). Strengths and weaknesses of online sur-veys. Technology, 6(7), 0837–2405053138.
Njoroge, J. (2023, October 10). Data protection is vital in the hospitality sector. The Star (Kenya). https://www.the-star.co.ke/sports/football/2023-10-10-njoroge-data-protection-vital-in-hospitality-sector
Office of the Data Protection Commissioner. (2024). Data Protection Compliance Direc-torate. Government of Kenya. https://www.odpc.go.ke/data-protection-compliance/
Pillay, L. (2018). POPI: Changing the way SA tour operators do business. Tourism Up-date. https://www.tourismupdate.com/article/popi-changing-the-way-sa-tour-operators-do-business
Prow & Company Advocates. (2021). Radisson Blu Hotel data breach complaint (Complaint No. ODPC/COMP/2021/042). Office of the Data Protection Commission-er. https://caselawlibrary.cipit.org/complaints/detail/radisson-blu-data-breach
Shanmugam, M., Rana, N. P., & Kong, X. (2024). Technological advancements and smart tourism strategies in Malaysia's post pandemic tourism industry. Journal of Smart Tourism, 5(1), 33–50.
Shred it. (2019). 2019 data protection report: Hospitality find-ings. https://www.shredit.com/en-ca/blog/protect-hotel-guests-confidential-information
Simon, M. K., & Goes, J. (2012). Dissertation and scholarly research: Recipes for suc-cess (2nd ed.). CreateSpace Independent Publishing Platform.
Solomon, G., & Brown, I. (2021). The influence of organisational culture and information security culture on employee compliance behaviour. Journal of Enterprise Infor-mation Management, 35(4/5), 1024–1047. https://doi.org/10.1108/JEIM-08-2019-0217
Straub, D. W. (1990). Effective IS security: An empirical study. Information Systems Re-search, 1(3), 255–276.
Straub, D. W., & Welke, R. J. (1998). Coping with systems risk: Security planning models for management decision-making. MIS Quarterly, 22(4), 441–469.
Tourism Regulatory Authority. (2023). Register of classified establishments for the period 2015–2023 in Kenya by TRA classification regions. https://tra.go.ke/classification-and-grading/
Wang, J., Shan, Z., Gupta, M., & Rao, H. R. (2019). A longitudinal study of unauthorised access attempts on information systems: The role of opportunity contexts. MIS Quarterly, 43(2), 601–622.
Wang, T. (2025). Has your information been leaked? The impact of cybersecurity risks on the performance of tourism enterprises. Current Issues in Tourism, 1–20. https://doi.org/10.1080/13683500.2025.2501678
World Travel & Tourism Council. (2021). Kenya's tourism numbers up by 40%. Tourism Update. https://www.tourismupdate.com/article/kenyas-tourism-numbers-up-by-40
Yang, S., & Berdine, G. (2021). Normality tests. The Southwest Respiratory and Critical Care Chronicles, 9(41), 50–52. https://doi.org/10.12746/swrccc2021.0901.222