Overview
This project-based course applies privacy engineering principles to the design, development, evaluation, and documentation of real or simulated information systems. Students examine the collection, storage, processing, sharing, retention, and deletion of personal, sensitive, and behavioural data across the system lifecycle.
The course covers privacy principles and regulations, privacy by design, data minimisation, purpose limitation, consent and user control, identity and access management, anonymisation and pseudonymisation, encryption, privacy threat modelling, re-identification risks, data-flow mapping, privacy impact assessments, retention policies, third-party and cloud-service risks, transparency, surveillance, bias, fairness, and the protection of vulnerable populations.
Students define project scope and stakeholders, elicit functional and privacy requirements, construct system and data models, analyse threats and harms, prioritise mitigations, and produce a defensible privacy-focused architecture. Project work includes a proposal, requirements and data-flow documentation, threat model, risk assessment, prototype or design artefact, evaluation results, mitigation rationale, user-facing documentation, and final presentation. Professional collaboration, version control, peer review, project management, and technical communication are integrated throughout.
Learning Outcomes
- Analyse complex information systems to identify privacy risks, data flows, attack surfaces, and potential individual or societal harms.
- Translate legal, ethical, regulatory, and organisational expectations into precise technical and operational privacy requirements.
- Construct privacy threat models, data inventories, privacy impact assessments, and risk assessments for proposed systems.
- Evaluate and justify privacy-enhancing and security controls, including data minimisation, access management, encryption, anonymisation, pseudonymisation, retention, and deletion mechanisms.
- Design and defend a privacy-focused system architecture while balancing privacy with usability, functionality, performance, cost, and operational requirements.
- Assess residual privacy risk, control effectiveness, re-identification exposure, and the limitations of proposed mitigations through structured testing or evaluation.
- Synthesize technical findings and project evidence into clear specialist and non-specialist documentation, presentations, and user-facing transparency materials.
- Collaborate using professional project-management, version-control, review, documentation, and change-management practices.
Timetable
| Type | Length | Frequency | Period |
|---|---|---|---|
| Lecture | 2 hours | Weekly | All semester |
| Workshop | 2 hours | Weekly | All semester |
| Practicum | 2 hours | Weekly | All semester |
| Seminar | 1 hour | Fortnightly | All semester |
Assessment Schedule
| Type | Description | Weighting |
|---|---|---|
| Assignment | Project proposal and scope definition | 10.00% |
| Deliverable | Requirements, stakeholder, and data-flow documentation | 15.00% |
| Assignment | Privacy threat model and risk assessment | 20.00% |
| Deliverable | Prototype or design artifact with evaluation report | 25.00% |
| Capstone | Final project presentation | 10.00% |
| Capstone | Final project report and user-facing documentation | 20.00% |
Teaching Staff & Programs
This course is delivered jointly by faculty from the participating programs listed below. In line with the Douchewater Way, the University of Sexology tailors core instruction directly to each cohort's specific discipline — adapting curriculum to program needs rather than forcing students into a one-size-fits-all model. Learn more about our approach at The Douchewater Way.
