Capstone Project 1: Data Ethics Audit
"An audit is not a judgment. It is a mirror." — Adapted from quality management principles
Overview
In this capstone project, you will conduct a comprehensive ethical audit of a real data system — applying the frameworks, methods, and analytical tools you've developed across this textbook. The goal is not to produce a perfect assessment but to practice the integration of technical understanding, ethical reasoning, stakeholder analysis, and governance evaluation that responsible data governance requires.
Estimated Time: 30-50 hours over 4-6 weeks Deliverable: Written audit report (8,000-12,000 words) with executive summary Assessment Criteria: Thoroughness, analytical rigor, stakeholder awareness, actionable recommendations
Phase 1: System Selection (Week 1)
Choose a data system to audit. It should be: - Accessible enough to study (publicly documented, or an organization where you have access) - Complex enough to be interesting (multiple data types, stakeholders, and decision points) - Consequential enough to matter (affects real people in meaningful ways)
Suggested Systems: - Your university's learning management system (LMS) and its data practices - A ride-sharing or delivery platform's data collection and algorithmic management - A municipal surveillance system (cameras, sensors, license plate readers) - A health app's data practices (fitness tracker, menstrual tracking, mental health app) - A hiring platform's algorithmic screening process - Your employer's workplace monitoring system - A social media platform's content recommendation algorithm - A financial institution's credit scoring or fraud detection system
Deliverable: One-page system description including: what the system does, who it affects, what data it collects, and why you chose it.
Phase 2: Data Mapping and Lifecycle Analysis (Week 2)
Using the frameworks from Chapter 1 (data lifecycle) and Chapter 22 (data governance):
- Map the data flows. What data is collected? From whom? How is it stored, processed, analyzed, shared, retained, and (eventually) deleted?
- Classify the data. What types of data are involved (personal, sensitive, metadata, behavioral, inferred)? How should each type be governed?
- Identify the data lifecycle risks. At each stage, what could go wrong? What governance mechanisms exist (or should exist)?
Deliverable: Data flow diagram and lifecycle risk assessment table.
Phase 3: Stakeholder Analysis (Week 2-3)
Using the frameworks from Chapters 3 (ownership), 5 (power), and 6 (ethics):
- Map all stakeholders. Who is affected by this system? Who benefits? Who bears the risks?
- Analyze power dynamics. Who has the most information? The least? Who has decision-making authority? Who is subject to decisions without participation?
- Apply the four themes: - Power Asymmetry: Where are the asymmetries in this system? - Consent Fiction: Is consent meaningful or theatrical? - Accountability Gap: If the system causes harm, who is responsible?
Deliverable: Stakeholder map with power analysis.
Phase 4: Ethical Analysis (Week 3-4)
Using the five-framework analysis from Chapter 6:
- Identify the key ethical tensions in the system (at least 3).
- For each tension, apply all five frameworks: - Utilitarian: Who benefits, who is harmed, and by how much? - Deontological: Are any rights violated? Is anyone treated merely as a means? - Virtue ethics: What character traits does the system's design reflect? - Care ethics: What relationships and vulnerabilities are at stake? - Justice theory: Behind the veil of ignorance, would you accept this system?
- Identify convergences and divergences between frameworks.
Deliverable: Multi-framework ethical analysis of each tension.
Phase 5: Governance and Compliance Assessment (Week 4-5)
Using the frameworks from Part 4 (Chapters 20-25):
- Identify applicable regulations (GDPR, CCPA, HIPAA, sector-specific rules, etc.)
- Assess compliance — is the system in compliance with applicable law?
- Assess the gap between compliance and ethics — where does the law fall short of ethical requirements?
- Evaluate existing governance mechanisms — does the organization have an ethics program, impact assessments, audit processes?
Deliverable: Compliance assessment and governance gap analysis.
Phase 6: Bias and Fairness Audit (if applicable) (Week 4-5)
If the system involves algorithmic decision-making, using Chapters 14-17:
- Assess potential sources of bias in the data and the model
- Apply fairness metrics (if data is available): demographic parity, equalized odds, calibration
- Evaluate transparency and explainability — can the system explain its decisions?
- Assess accountability mechanisms — who is responsible when the system errs?
Deliverable: Bias and fairness assessment with metrics (where available).
Phase 7: Recommendations (Week 5-6)
Based on your analysis:
- Prioritize findings — which issues are most urgent? Most impactful?
- Develop actionable recommendations — specific, feasible changes the organization could implement
- Categorize recommendations by timeline: - Immediate (0-3 months): quick fixes, policy changes - Medium-term (3-12 months): system redesign, governance reform - Long-term (1-3 years): structural changes, new institutions
- Anticipate resistance — what objections will your recommendations face? How would you respond?
Deliverable: Prioritized recommendations with implementation roadmap.
Phase 8: Report Writing and Presentation (Week 6)
Compile your work into a professional audit report:
Executive Summary (1 page): Key findings and top 3 recommendations Introduction (1-2 pages): System description, audit scope, methodology Data Mapping (2-3 pages): Data flows, lifecycle, classification Stakeholder Analysis (2-3 pages): Stakeholder map, power analysis, theme application Ethical Analysis (3-4 pages): Multi-framework analysis of key tensions Governance Assessment (2-3 pages): Compliance and gap analysis Bias and Fairness Audit (1-2 pages, if applicable) Recommendations (2-3 pages): Prioritized with implementation roadmap Appendices: Data flow diagrams, stakeholder maps, raw analysis
Assessment Rubric
| Criterion | Excellent (A) | Good (B) | Adequate (C) | Needs Improvement |
|---|---|---|---|---|
| Thoroughness | All phases completed with depth | Most phases completed thoroughly | Key phases completed | Significant gaps |
| Analytical Rigor | Multiple frameworks applied insightfully | Frameworks applied correctly | Basic analysis present | Superficial analysis |
| Stakeholder Awareness | Comprehensive, including marginalized voices | Major stakeholders identified | Some stakeholders identified | Limited perspective |
| Recommendations | Specific, feasible, prioritized, anticipates resistance | Specific and feasible | General recommendations | Vague or impractical |
| Writing Quality | Clear, professional, well-organized | Clear and organized | Readable | Disorganized or unclear |
Tips for Success
- Start early. The audit benefits from iteration — your understanding of the system deepens as you work.
- Talk to people. If possible, interview users, administrators, or affected community members. First-person perspectives will strengthen your analysis immeasurably.
- Be honest about limitations. Every audit has constraints — access limitations, missing data, incomplete information. Acknowledge these transparently.
- Prioritize ruthlessly. You cannot fix everything. Focus on the most consequential issues.
- Remember: an audit is a tool for improvement, not a weapon for condemnation. The goal is to help the system work better for everyone.