Privacy and Data Protection Law - LW921

Location Term Level Credits (ECTS) Current Convenor 2019-20
(version 2)
7 20 (10) DR P White







The module will explore emerging privacy and data protection issues, including Big Data, CCTV surveillance, Internet and cyber surveillance, and cross-border information flows, legal structures and privacy protection measures. Students will be challenged to critically examine how personal, financial, health and transactional data are managed and who has access to this information. It will require students to assess emerging legal, regulatory, data protection and personal privacy issues raised by widespread access to personal information, including genetic data. The module will focus on the legal data protection, human rights, consent, confidentiality, and IT data security questions that arise when personal information is accessed by the state, law enforcement agencies, corporations and business, employers, health clinicians and researchers.

The essential aims and objectives of the proposed LLM module are to equip students to undertake a sustained analysis of privacy and data protection law. Students will be asked to critically examine whether privacy protection, consent and confidentiality measures are proportionate to the legal requirements to protect personal information while balancing the requirements of economic commerce, the state and public administrations to collect, use and share personal information.


Contact hours

Total study hours: 200
Contact hours: 18
Private study hours: 182


Autumn Term

Method of assessment

An essay of no more than 5,000 words (100%)

Indicative reading

Learning outcomes

1. Demonstrate an advanced grounding in concepts, principles and rules of data protection, consent, and privacy.
2. Demonstrate a systematic understanding of the origins and development of EU and UK data protection laws and Corporate Binding Rules (US Safe Harbours) protection.
3. Critically analyse emerging issues in data protection: Big Data, social media, data matching, data anonymization, tracking, data access controls, state and commercial surveillance, and blurred boundaries among clinical, research and administrative uses of personal information (genetic exceptionalism, biobanks, electronic health records, client and ethnic profiling)
4. Demonstrate a critical awareness of, and the ability to evaluate legal and regulatory actions taken in response to the failure to protect data and ensure confidentiality.
5. Critically analyse and evaluate the permeability of public/private boundaries in the workplace, in public and commercial spaces, on the Internet and in cyber space.
6. Demonstrate a critical understanding of the public and private tensions involved in privacy and data protection.


Stage 1

