Tutorial 2: Compliance, Privacy, and Ethics

Unit 8 ยท Governance, risk, and capstone

Objectives

Compliance requirements establish obligations, but passing an audit does not prove a system is secure. Privacy asks how personal information is collected, used, shared, retained, protected, and deleted. Purpose limitation and minimization reduce unnecessary exposure and improve trust.

purpose -> minimum data -> access + retention -> transparency
risk review -> control evidence -> correction and accountability

Ethical security practice considers vulnerable users, unequal impact, surveillance, consent, accessibility, and power. Document assumptions, data flows, processors, retention, access, incident response, and user rights where applicable. Seek legal and privacy expertise for jurisdiction-specific decisions.

Exercises

  1. Map personal data through an analytics system.
  2. Identify unnecessary collection and retention.
  3. Compare compliance evidence with actual security outcomes.

Self-check

  1. What is data minimization?
  2. Does compliance guarantee security?
  3. Why consider vulnerable users?

Self-Check Quiz

1. What is purpose limitation?

AnswerCollecting and using data for specified legitimate purposes rather than unlimited future use.

2. Why minimize retained data?

AnswerIt reduces exposure, incident impact, misuse opportunities, and unnecessary obligations.

Homework

  1. Produce a privacy and ethics review for an employee-monitoring feature.
  2. Define collection, purpose, access, retention, and deletion.
  3. Identify one potential unequal impact.
Sample answerCollect only data needed for a defined purpose, disclose it clearly, restrict access, set retention and deletion, protect it in transit and at rest, and provide review or appeal where appropriate. Examine whether monitoring disproportionately harms a group or creates chilling effects.