Secure your place for the October 2026 intake.



EC01 - Privacy and Data Protection

Protecting personal data through law, technology, and responsible digital governance.

Credits

7.5 ECTS

Semester

1 Semester

Delivery

Online

Duration

13 weeks

Language

English

About This Course

This is a firts-semester course in the MBA in Advanced Cybersecurity Technologies &
Governance
Privacy and Data Protection explores how personal data is governed and protected in modern digital environments. With a strong focus on the GDPR, the course combines legal, organisational and technical perspectives to address privacy governance, risk assessment, privacy by design, and emerging challenges such as artificial intelligence and digital advertising. Students develop practical skills to assess privacy risks, ensure regulatory compliance, and balance legal, ethical and business considerations in real-world contexts.

What You Will Learn


GDPR & Global Privacy Frameworks

  • Core principles of GDPR and international data protection regimes
  • Roles, responsibilities, and governance models in privacy management
  • Legal obligations for data processing and cross-border transfers


Privacy Engineering & Risk Management

  • Privacy-by-design and data protection impact assessments (DPIAs)
  • Privacy-enhancing technologies (PETs) and secure data handling
  • Risk identification and mitigation in data ecosystems


Ethical AI & Digital Privacy Challenges

  • Privacy implications of AI, profiling, and digital advertising

  • Transparency, consent, and user rights in digital systems

  • Building privacy-aware organisational cultures

Your 13-Week Journey

Here’s how your learning unfolds

Week 1 – Introduction to Privacy and GDPR Principles 

Week introduces privacy and GDPR basics, key terms and principles, helping learners recognise violations and describe good data protection practice.

Week 2 – Legal and Regulatory Framework 

Lecture traces European data protection history to GDPR and situates it within today’s wider EU digital and data regulatory framework.

Week 3 – Privacy Governance Model 

Course introduces governance, privacy standards and ISO/IEC 27701, explaining PIMS concepts, scope, and high-level controller and processor responsibilities.

Week 4 – GDPR Compliance Requirements 

Topic covers practical GDPR compliance duties, translating principles into processes, evidence, and accountability across core operational obligations.

Week 5 – Privacy Policies 

This week explores GDPR transparency, showing how clear, accessible privacy notices build trust, support fair processing, and enable meaningful data subject rights.

Week 6 – Risk Assessment and Management 

Introduction to cybersecurity risk management, focusing on identifying, assessing, and mitigating threats using frameworks like COSO and ERM.

Week 7 – Data Protection Impact Assessment  

This week introduces DPIAs, explaining how risk-based assessment, governance, and data protection by design support accountability for high-risk processing.

Week 8 – Privacy by Design and by Default 

This week introduces privacy by design and default, and shows how ISO/IEC 27701 aligns with key privacy standards and GDPR requirements.

Week 9 – AI and Personal Data  

This week explores AI and data protection, examining GDPR and the EU AI Act and how privacy by design supports trustworthy AI systems.

Week 10 – Privacy Enhancing Technologies (PETs) 

This week introduces Privacy Enhancing Technologies, showing how PETs reduce risk, balance trade-offs, and support compliant data use across the lifecycle.

Week 11 – Privacy Awareness  

This week focuses on building effective data protection training programmes, covering design, delivery, and evaluation within organisational privacy governance.

Week 12 – Cyber Insurance and Personal Data  

This week explores personal data cyber risks, GDPR exposure, and how cyber insurance supports incident response and broader risk management.

Week 13 – Online Marketing and Advertising, Cookies and Trackers 

This week unpacks AdTech practices, real-time bidding, and consent challenges, examining whether post-cookie models can reconcile targeting with privacy rights.


Empty space, drag to resize

Skills You Will Gain

Privacy Compliance & Governance

  • Conducting DPIAs and implementing GDPR-compliant processes
  • Designing consent, notification, and data governance workflows
  • Managing international data transfer mechanisms

Privacy Engineering & Risk Mitigation

  • Applying PETs such as anonymisation and encryption
  • Identifying and mitigating privacy risks in digital systems
  • Embedding privacy-by-design across system lifecycles

Strategic Privacy Leadership

  • Leading organisational privacy programmes
  • Communicating risks to legal, technical, and executive stakeholders
  • Evaluating emerging technologies from a privacy perspective