Capstone Project 1: Data Ethics Audit

"An audit is not a judgment. It is a mirror." — Adapted from quality management principles


Overview

In this capstone project, you will conduct a comprehensive ethical audit of a real data system — applying the frameworks, methods, and analytical tools you've developed across this textbook. The goal is not to produce a perfect assessment but to practice the integration of technical understanding, ethical reasoning, stakeholder analysis, and governance evaluation that responsible data governance requires.

Estimated Time: 30-50 hours over 4-6 weeks Deliverable: Written audit report (8,000-12,000 words) with executive summary Assessment Criteria: Thoroughness, analytical rigor, stakeholder awareness, actionable recommendations


Phase 1: System Selection (Week 1)

Choose a data system to audit. It should be: - Accessible enough to study (publicly documented, or an organization where you have access) - Complex enough to be interesting (multiple data types, stakeholders, and decision points) - Consequential enough to matter (affects real people in meaningful ways)

Suggested Systems: - Your university's learning management system (LMS) and its data practices - A ride-sharing or delivery platform's data collection and algorithmic management - A municipal surveillance system (cameras, sensors, license plate readers) - A health app's data practices (fitness tracker, menstrual tracking, mental health app) - A hiring platform's algorithmic screening process - Your employer's workplace monitoring system - A social media platform's content recommendation algorithm - A financial institution's credit scoring or fraud detection system

Deliverable: One-page system description including: what the system does, who it affects, what data it collects, and why you chose it.


Phase 2: Data Mapping and Lifecycle Analysis (Week 2)

Using the frameworks from Chapter 1 (data lifecycle) and Chapter 22 (data governance):

  1. Map the data flows. What data is collected? From whom? How is it stored, processed, analyzed, shared, retained, and (eventually) deleted?
  2. Classify the data. What types of data are involved (personal, sensitive, metadata, behavioral, inferred)? How should each type be governed?
  3. Identify the data lifecycle risks. At each stage, what could go wrong? What governance mechanisms exist (or should exist)?

Deliverable: Data flow diagram and lifecycle risk assessment table.


Phase 3: Stakeholder Analysis (Week 2-3)

Using the frameworks from Chapters 3 (ownership), 5 (power), and 6 (ethics):

  1. Map all stakeholders. Who is affected by this system? Who benefits? Who bears the risks?
  2. Analyze power dynamics. Who has the most information? The least? Who has decision-making authority? Who is subject to decisions without participation?
  3. Apply the four themes: - Power Asymmetry: Where are the asymmetries in this system? - Consent Fiction: Is consent meaningful or theatrical? - Accountability Gap: If the system causes harm, who is responsible?

Deliverable: Stakeholder map with power analysis.


Phase 4: Ethical Analysis (Week 3-4)

Using the five-framework analysis from Chapter 6:

  1. Identify the key ethical tensions in the system (at least 3).
  2. For each tension, apply all five frameworks: - Utilitarian: Who benefits, who is harmed, and by how much? - Deontological: Are any rights violated? Is anyone treated merely as a means? - Virtue ethics: What character traits does the system's design reflect? - Care ethics: What relationships and vulnerabilities are at stake? - Justice theory: Behind the veil of ignorance, would you accept this system?
  3. Identify convergences and divergences between frameworks.

Deliverable: Multi-framework ethical analysis of each tension.


Phase 5: Governance and Compliance Assessment (Week 4-5)

Using the frameworks from Part 4 (Chapters 20-25):

  1. Identify applicable regulations (GDPR, CCPA, HIPAA, sector-specific rules, etc.)
  2. Assess compliance — is the system in compliance with applicable law?
  3. Assess the gap between compliance and ethics — where does the law fall short of ethical requirements?
  4. Evaluate existing governance mechanisms — does the organization have an ethics program, impact assessments, audit processes?

Deliverable: Compliance assessment and governance gap analysis.


Phase 6: Bias and Fairness Audit (if applicable) (Week 4-5)

If the system involves algorithmic decision-making, using Chapters 14-17:

  1. Assess potential sources of bias in the data and the model
  2. Apply fairness metrics (if data is available): demographic parity, equalized odds, calibration
  3. Evaluate transparency and explainability — can the system explain its decisions?
  4. Assess accountability mechanisms — who is responsible when the system errs?

Deliverable: Bias and fairness assessment with metrics (where available).


Phase 7: Recommendations (Week 5-6)

Based on your analysis:

  1. Prioritize findings — which issues are most urgent? Most impactful?
  2. Develop actionable recommendations — specific, feasible changes the organization could implement
  3. Categorize recommendations by timeline: - Immediate (0-3 months): quick fixes, policy changes - Medium-term (3-12 months): system redesign, governance reform - Long-term (1-3 years): structural changes, new institutions
  4. Anticipate resistance — what objections will your recommendations face? How would you respond?

Deliverable: Prioritized recommendations with implementation roadmap.


Phase 8: Report Writing and Presentation (Week 6)

Compile your work into a professional audit report:

Executive Summary (1 page): Key findings and top 3 recommendations Introduction (1-2 pages): System description, audit scope, methodology Data Mapping (2-3 pages): Data flows, lifecycle, classification Stakeholder Analysis (2-3 pages): Stakeholder map, power analysis, theme application Ethical Analysis (3-4 pages): Multi-framework analysis of key tensions Governance Assessment (2-3 pages): Compliance and gap analysis Bias and Fairness Audit (1-2 pages, if applicable) Recommendations (2-3 pages): Prioritized with implementation roadmap Appendices: Data flow diagrams, stakeholder maps, raw analysis


Assessment Rubric

Criterion Excellent (A) Good (B) Adequate (C) Needs Improvement
Thoroughness All phases completed with depth Most phases completed thoroughly Key phases completed Significant gaps
Analytical Rigor Multiple frameworks applied insightfully Frameworks applied correctly Basic analysis present Superficial analysis
Stakeholder Awareness Comprehensive, including marginalized voices Major stakeholders identified Some stakeholders identified Limited perspective
Recommendations Specific, feasible, prioritized, anticipates resistance Specific and feasible General recommendations Vague or impractical
Writing Quality Clear, professional, well-organized Clear and organized Readable Disorganized or unclear

Tips for Success

  • Start early. The audit benefits from iteration — your understanding of the system deepens as you work.
  • Talk to people. If possible, interview users, administrators, or affected community members. First-person perspectives will strengthen your analysis immeasurably.
  • Be honest about limitations. Every audit has constraints — access limitations, missing data, incomplete information. Acknowledge these transparently.
  • Prioritize ruthlessly. You cannot fix everything. Focus on the most consequential issues.
  • Remember: an audit is a tool for improvement, not a weapon for condemnation. The goal is to help the system work better for everyone.