Overview

This project-based course applies privacy engineering principles to the design, development, evaluation, and documentation of real or simulated information systems. Students examine the collection, storage, processing, sharing, retention, and deletion of personal, sensitive, and behavioural data across the system lifecycle.

The course covers privacy principles and regulations, privacy by design, data minimisation, purpose limitation, consent and user control, identity and access management, anonymisation and pseudonymisation, encryption, privacy threat modelling, re-identification risks, data-flow mapping, privacy impact assessments, retention policies, third-party and cloud-service risks, transparency, surveillance, bias, fairness, and the protection of vulnerable populations.

Students define project scope and stakeholders, elicit functional and privacy requirements, construct system and data models, analyse threats and harms, prioritise mitigations, and produce a defensible privacy-focused architecture. Project work includes a proposal, requirements and data-flow documentation, threat model, risk assessment, prototype or design artefact, evaluation results, mitigation rationale, user-facing documentation, and final presentation. Professional collaboration, version control, peer review, project management, and technical communication are integrated throughout.

Learning Outcomes

  • Analyse complex information systems to identify privacy risks, data flows, attack surfaces, and potential individual or societal harms.
  • Translate legal, ethical, regulatory, and organisational expectations into precise technical and operational privacy requirements.
  • Construct privacy threat models, data inventories, privacy impact assessments, and risk assessments for proposed systems.
  • Evaluate and justify privacy-enhancing and security controls, including data minimisation, access management, encryption, anonymisation, pseudonymisation, retention, and deletion mechanisms.
  • Design and defend a privacy-focused system architecture while balancing privacy with usability, functionality, performance, cost, and operational requirements.
  • Assess residual privacy risk, control effectiveness, re-identification exposure, and the limitations of proposed mitigations through structured testing or evaluation.
  • Synthesize technical findings and project evidence into clear specialist and non-specialist documentation, presentations, and user-facing transparency materials.
  • Collaborate using professional project-management, version-control, review, documentation, and change-management practices.

Timetable

TypeLengthFrequencyPeriod
Lecture2 hoursWeeklyAll semester
Workshop2 hoursWeeklyAll semester
Practicum2 hoursWeeklyAll semester
Seminar1 hourFortnightlyAll semester

Assessment Schedule

TypeDescriptionWeighting
AssignmentProject proposal and scope definition10.00%
DeliverableRequirements, stakeholder, and data-flow documentation15.00%
AssignmentPrivacy threat model and risk assessment20.00%
DeliverablePrototype or design artifact with evaluation report25.00%
CapstoneFinal project presentation10.00%
CapstoneFinal project report and user-facing documentation20.00%

Teaching Staff & Programs

This course is delivered jointly by faculty from the participating programs listed below. In line with the Douchewater Way, the University of Sexology tailors core instruction directly to each cohort's specific discipline — adapting curriculum to program needs rather than forcing students into a one-size-fits-all model. Learn more about our approach at The Douchewater Way.