top of page

When Data Privacy Enters the MBA Examination, Something Is Changing

Anuuj Medirattaa
2 days ago
4 min read

I recently completed around six hours of Data Privacy sessions with first-semester MBA students. What interested me even more came afterwards — Data Privacy became part of their Mid-Term Examination.


I have been involved in privacy education for some time now — through corporate sessions, management students, courses and workshops.


But a recent teaching assignment made me think about how privacy education itself may be evolving.


I had just completed around six hours of Data Privacy lectures for first-semester MBA students at a management institute.


These were not students specializing in privacy, information security or law.


They were management students at the beginning of their MBA journey.


And then came something I found particularly encouraging.


The institute included Data Privacy in their Mid-Term Examination.


From a Lecture to an Academic Subject

At first, this may not appear particularly significant.

Students attend lectures. Institutes conduct examinations. Subjects get assessed.

But I see an important distinction here.

It is relatively easy to organize an awareness session on Data Privacy.

A guest speaker can be invited. A workshop can be conducted. Students can be introduced to the Digital Personal Data Protection framework and some basic privacy concepts.

That certainly has value.

But when the subject becomes part of a formal examination, something changes.

The institution is effectively saying that this is knowledge students are expected to understand — not merely something interesting they were exposed to.


A lecture introduces a subject. An examination gives it academic weight.


For privacy education, I think that distinction matters.


These Students Are Not Becoming Privacy Professionals

Perhaps the more important point is that most of these students will probably never become privacy professionals.

And they don't need to.

Some may eventually work in Human Resources.

Others may move into marketing, finance, operations, consulting, technology, sales or entrepreneurship.

Yet almost irrespective of the function they choose, they are likely to make decisions involving personal data.

An HR manager may decide what employee information should be collected during onboarding.

A marketing professional may decide what customer information is useful for a campaign.

Someone working in operations may select a vendor who will process customer or employee information.

A product manager may decide which information an application asks users to provide.

A business leader may eventually approve an initiative involving large amounts of personal data.


Privacy therefore isn't relevant only to the person carrying the title of DPO, CISO, Privacy Officer or Legal Counsel.


It increasingly becomes part of ordinary management decision-making.


Something I See in Privacy Assessments

This connects closely with what I encounter while working with organizations on privacy assessments.

Many privacy questions don't begin inside the privacy or information security department.

They begin with perfectly normal business decisions.

Someone decides to collect another field in a form.

A department retains a document because it has always retained it.

A spreadsheet containing personal information gets shared with another team.

A new SaaS application is introduced.

A vendor is given access to information because it needs to perform a particular activity.

A product team decides that another piece of customer information could improve the service.


None of these decisions necessarily begins as a "privacy decision."


But each can have privacy consequences.


This is why developing privacy awareness among future managers can be valuable.


Learning to Ask One More Question

I don't expect MBA students to remember every provision of a privacy law after completing a few classroom sessions.

That isn't really the objective.

What I would like them to retain is the habit of asking one more question.

Why are we collecting this information?

Do we actually need it?

Does the individual understand what we intend to do with it?

Who else will have access to it?

How long should we keep it?

What happens when we no longer need it?


If some of these questions start appearing naturally in future business discussions, privacy education has achieved something useful.


Privacy Education Before the Workplace

Traditionally, much of professional privacy education happens after people enter organizations.

An employee joins a company and receives an awareness session.

Managers attend compliance training.

Specialists undertake certifications.

Organizations introduce privacy programs after regulatory requirements create the need.

There will always be a place for such training.

But introducing privacy thinking during management education creates another possibility.

Students can encounter these ideas before their business habits become established.

They begin understanding that personal data isn't simply information available to the organization because someone has provided it.

Its collection and use involve purpose, transparency, responsibility and trust.


A Small Development, But an Encouraging One

I don't want to overstate what one examination represents.

But I do find the direction encouraging.

I went into the classroom to introduce first-semester MBA students to Data Privacy.

A few weeks later, they are being formally assessed on what they learned.

For me, that represents another small step in taking privacy beyond specialist discussions.

Privacy regulation will continue to evolve. Organizations will build compliance programs. Technology will create new questions around how personal information is collected and used.

But sustainable privacy practices will ultimately depend on people making everyday business decisions.

And some of those future decision-makers are sitting in management classrooms today.


Perhaps teaching them to think about privacy before they enter the workplace is one of the better places to start.


Privacy Field Notes is a series in which I share observations and lessons from my work across privacy assessments, implementation and education. Organizational details may be generalized where appropriate.


Anuuj MedirattaaFounder & CTO, Ace Data Devices Pvt. Ltd.

bottom of page