Data has become a core enterprise asset, but collecting and using personal information also creates substantial legal, operational, strategic, cybersecurity, and reputational obligations. Modern companies routinely process information about customers, employees, website visitors, patients, suppliers, applicants, business partners, and users across cloud platforms, artificial-intelligence systems, mobile applications, advertising technologies, analytics environments, and international data networks. Executives therefore need to understand not merely whether data can be collected or analyzed, but why it is being collected, what authority supports its use, how long it should be retained, who can receive it, what rights individuals possess, how third parties are governed, and what happens when the organization’s original purpose for collecting the information changes.
Privacy & Data Protection is an advanced Junior MBA course designed to develop privacy as an enterprise governance and strategic management capability, rather than provide another introductory survey of privacy terminology. Students examine data inventories, processing purposes, lawful-use frameworks, consent, individual rights, sensitive information, privacy-by-design, vendor governance, behavioral advertising, artificial intelligence, employee monitoring, health information, financial information, international transfers, cybersecurity incidents, mergers and acquisitions, regulatory investigations, and board oversight.
The course reflects the increasingly fragmented regulatory environment confronting multinational companies. The EU GDPR establishes principles including lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, security, and accountability. California’s current CCPA regulatory framework includes regulations effective January 1, 2026 addressing subjects including risk assessments, cybersecurity audits, and automated decision-making technology. Meanwhile, U.S. federal privacy obligations remain sector-specific in important areas: for example, HIPAA protects certain health information handled by covered entities and their business associates, while the FTC plays a significant role in privacy and data-security enforcement affecting businesses more broadly.
The managerial challenge is therefore not simply to memorize multiple laws. Executives must build organizational systems capable of translating legal requirements into product design, marketing strategy, technology architecture, procurement, artificial-intelligence governance, cybersecurity, human resources, acquisitions, international operations, and day-to-day decision-making.
The central questions throughout the course are: What personal information do we actually hold? Why do we need it? Who controls its use? What rights attach to it? Which third parties receive it? What happens when we combine datasets? Should we build this feature simply because technically we can? What could go wrong if the data were exposed, misunderstood, repurposed, or used by an algorithm? And how do we create commercial value from data without creating unnecessary enterprise risk?
Course Objectives
By the end of this course, students will be able to:
• Analyze privacy and data protection as strategic enterprise-management responsibilities.
• Map personal-data flows across complex organizations.
• Distinguish personal data, sensitive data, anonymized data, pseudonymized data, and other important data categories.
• Apply purpose limitation and data-minimization thinking to business decisions.
• Evaluate privacy risks before launching products, technologies, or new data uses.
• Understand controller, processor, joint-controller, vendor, and service-provider relationships.
• Evaluate consent and other legal-use frameworks from a managerial perspective.
• Design practical systems for responding to individual privacy rights.
• Develop privacy governance for employee and workforce information.
• Evaluate digital advertising, tracking, profiling, and personalization strategies.
• Assess privacy risks associated with artificial intelligence and automated decision systems.
• Integrate privacy into product development and software design.
• Govern sensitive information including health, financial, biometric, children’s, and location data.
• Evaluate vendor and cloud-provider privacy risk.
• Understand privacy implications of mergers, acquisitions, partnerships, and data transactions.
• Evaluate international data-transfer risks.
• Develop enterprise retention and deletion strategies.
• Integrate privacy and cybersecurity incident management.
• Measure privacy-program effectiveness using meaningful executive indicators.
• Communicate privacy risk effectively to executive leadership and boards.
• Apply executive judgment when legal permissibility, customer expectations, technology capability, and business objectives conflict.