Overview

This advanced course examines the frameworks, roles, policies, processes, and technologies used to govern data responsibly across organizational and societal contexts. Topics include data stewardship, ownership, accountability, classification, inventories, lifecycle controls, access management, security principles, records management, vendor risk, and third-party oversight.

Students analyze privacy concepts and regulatory approaches concerning personally identifiable and sensitive information, consent, purpose limitation, minimization, retention, deletion, de-identification, re-identification risk, anonymization, pseudonymization, and introductory differential privacy. The course also addresses privacy-enhancing technologies, breach response, algorithmic accountability, fairness, bias, Indigenous and community data sovereignty, research ethics, and intellectual property.

Through applied exercises and case studies, students map data flows, identify governance and privacy risks, conduct impact assessments, evaluate policies, design access and retention controls, compare privacy-preserving strategies, and communicate recommendations to technical and nontechnical stakeholders. Emphasis is placed on balanced decisions that account for utility, equity, legality, security, and public trust.

Learning Outcomes

  • Evaluate data governance frameworks, stewardship structures, ownership arrangements, and accountability mechanisms across organizational contexts.
  • Classify data and design inventories, lifecycle controls, access policies, retention schedules, and deletion procedures appropriate to identified risks and obligations.
  • Map data flows and diagnose governance, privacy, security, vendor, and third-party risks using structured assessment methods.
  • Conduct privacy and data protection impact assessments addressing consent, purpose limitation, minimization, sensitive information, and re-identification risk.
  • Compare anonymization, pseudonymization, differential privacy, and other privacy-enhancing strategies in relation to utility, security, and residual risk.
  • Design proportionate responses to data breaches, records-management issues, algorithmic harms, and policy noncompliance.
  • Evaluate regulatory, ethical, intellectual-property, research, Indigenous, and community data sovereignty considerations in data-use decisions.
  • Synthesize governance recommendations and communicate them clearly to technical and nontechnical stakeholders.

Timetable

TypeLengthFrequencyPeriod
Lecture2 hoursWeeklyAll semester
Lab2 hoursWeeklyAll semester
Tutorial1 hourWeeklyAll semester

Assessment Schedule

TypeDescriptionWeighting
AssignmentGovernance policy analysis and writing15.00%
DeliverableData risk register and control recommendations15.00%
QuizQuizzes (4 × 2.5%)10.00%
TestPractical data-flow mapping and impact assessment20.00%
ExamComprehensive final examination40.00%

Prerequisites

Teaching Staff & Programs

This course is delivered jointly by faculty from the participating programs listed below. In line with the Douchewater Way, the University of Sexology tailors core instruction directly to each cohort's specific discipline — adapting curriculum to program needs rather than forcing students into a one-size-fits-all model. Learn more about our approach at The Douchewater Way.