Very few courses put the word misuse in their name. When one does, it is telling you something about how it will be assessed. A course called Data Analytics tests whether you can extract a finding.
Very few courses put the word misuse in their name. When one does, it is telling you something about how it will be assessed. A course called Data Analytics tests whether you can extract a finding. A course called Data Use and Misuse tests whether you can tell the difference between a finding you are entitled to act on and one you are not, which is a judgment problem wearing a technical costume. Students who arrive from the analytics side of a business degree usually spend the first few weeks answering the wrong question well.
Author: MAAS Editorial Team · Reviewed by a MAAS subject mentor
Last updated: 2026-08-18
Category: writing-tips
The course, verified
Direct answer: COMM3050 Data Use and Misuse is a 6 unit of credit third-year course in the UNSW Business School, taught by the School of Management and Governance. It has a prerequisite, it runs in Term 1 and Term 3, and it is offered in three delivery modes.
Evidence: The UNSW handbook entry for 2026 carries the course at 6 units of credit, records the enrolment rule as Prerequisite: COMM2501 or INFS3603, lists the offering terms as Term 1 and Term 3, and publishes three delivery variations at three contact hours each: in-person, multimodal, and fully online. The UNSW timetable records the owning school as the School of Management and Governance within the UNSW Business School.
The renumbering has an enrolment consequence, not just a study-notes one: the handbook states that this course was previously identified as COMM2050, and that students who have completed COMM2050 cannot enrol in COMM3050. So if you find study notes under the old number, the content will be related, but the assessment structure almost certainly is not, and more importantly you should check your own transcript before enrolling. Course outlines are published per term for a reason. Use the one for your own term and treat everything else as background.
A distinction worth making early: if you have already taken COMM1190 Data Insights and Decisions, you may expect this to be a continuation. It is not the same kind of course. The first-year course asks how you draw a defensible conclusion from data. This one asks whether you should have collected the data, whether you may act on the conclusion, and who carries the cost if you are wrong.
Who the course is written for
Direct answer: Business leaders and managers rather than technical specialists, which sets the standard for every answer you write.
The course description makes the audience explicit: big data and artificial intelligence have changed business, and it is managers and not only technical specialists who need to understand the opportunities and risks in collecting, analysing, sharing and using data, including what is legally permissible.
That framing creates the room you are marked in, and the prerequisite tells you who is in the room. Everyone has cleared COMM2501 or INFS3603, so nobody is starting from zero, but the range above that floor is wide, and the assessment cannot reward technical depth that half the cohort could not produce. What it can reward is reasoning that a technically capable person and a non-technical executive would both find sound. If your answer requires the reader to already understand the method, it has failed a criterion the course exists to teach.
| What an analytics course rewards | What this course rewards |
|---|---|
| Can you build the model | Should this model be built at all |
| Is the result statistically significant | Is the result actionable, and for whom |
| How accurate is the prediction | Who is harmed when it is wrong |
| Is the data available | Is the data legitimately usable here |
| Explaining the method | Explaining the decision to someone who will not read the method |
Why "legally permissible" is not the whole answer
Direct answer: Legality is a floor the course asks you to identify and then reason above, and answers that stop at compliance leave most of the marks on the table.
The description names what is legally permissible as part of the content, so the legal layer is examinable and you cannot skip it. But a course that also names social and ethical considerations, and asks you to balance them against organisational goals, is signalling that permitted and defensible are two different tests. Plenty of data practices that no regulator prohibits would still damage an organisation that adopted them.
Evidence: Nissenbaum (2004) supplies the concept that does the most work in this space. She argues that privacy is not secrecy but contextual integrity, meaning information flows carry norms attached to the context in which they were generated, and a violation occurs when data moves into a context with different norms even if nothing was concealed. That framing explains cases students otherwise find slippery, such as why combining two individually harmless datasets can produce something people experience as a breach.
Evidence: Solove (2006) is worth reading alongside it, because he breaks privacy harm into distinct types rather than treating it as one thing. Having that vocabulary lets you say precisely which harm a practice creates, and precision is what separates an ethical argument from a general expression of unease.
Example: Asked to assess a retailer's plan to infer customer life events from purchase patterns, a weaker answer noted that the data was collected lawfully, consent had been obtained through the terms of service, and the practice was therefore acceptable. A stronger answer accepted all of that, then argued that the inference moves purchase data into a context whose norms the customer never agreed to, identified the specific harm in Solove's terms as aggregation, the assembly of individually innocuous records into something new, rather than disclosure of anything the customer had hidden, and named the business risk that follows when customers learn what was inferred. Both landed on the same legal conclusion. Only one of them was answering the question this course asks.
The trap in questions about algorithmic decisions
Direct answer: Students tend to look for intent, and the assessable insight is that discriminatory outcomes arise from ordinary technical choices without anyone deciding to discriminate.
This is the point where a technically confident student most often writes a confidently wrong answer. Told that a hiring or lending model produced disparate outcomes, the instinct is to look for a bad actor, a biased variable, or a flawed instruction. Frequently there is none, and the course wants you to be able to explain the outcome anyway.
Evidence: Barocas and Selbst (2016) trace how disparate impact emerges through routine steps: how the target variable is defined, how training data was labelled, which features were selected, and how historical patterns get encoded as apparently neutral proxies. Their analysis is the reason a good answer can identify a mechanism rather than an offender.
Evidence: Mittelstadt et al. (2016) map the debate into distinct concerns including inconclusive, inscrutable and misguided evidence, along with unfair outcomes and traceability. That structure is directly useful under exam conditions, because it lets you say which kind of problem a case presents instead of describing it as an ethics issue in general terms.
Evidence: boyd and Crawford (2012) is the reference for the framing error underneath many of these cases. Their argument that larger datasets are not automatically better, and that data taken out of context loses meaning, addresses the assumption that scale substitutes for validity. It is the counterweight to the reflex that more data resolves a measurement problem.
Where the marks sit: in naming the mechanism and then saying what an organisation could actually do about it. An answer that identifies proxy discrimination and stops has diagnosed. An answer that adds which stage of the pipeline the intervention belongs at, and what it costs, has advised, and advising is what a management course is training.
The communication requirement is assessed, not assumed
Direct answer: Communication is assessed directly, including an individual presentation, so how you present the argument is part of what is marked rather than a wrapper around it.
Tutorials carry real weight here. The published contact load is three hours a week, and the timetable for the in-person mode shows multiple tutorial sections against a single lecture stream, which is a structure built for discussion rather than for content delivery. Case discussion in a course about contested judgments is not revision. It is the only place you find out whether your position survives someone competent disagreeing with it, and that is precisely what the oral component assesses.
Group work in this subject area fails in a characteristic way. Teams divide the case by section, each person writes their part, and the submission arrives holding two incompatible positions on the central question because nobody ever forced the disagreement into the open. The cheap fix is to settle the position first as a group, in one or two sentences everyone can repeat, and only then divide the writing.
Preparing across the term
This material rewards a stock of real cases, and cases are cheap to gather in advance and painfully expensive to find the week something is due. Keep the record simple enough that you will actually maintain it: the organisation, what it did with data, which norm that crossed, and the point at which a manager could have chosen otherwise. The last field is the one that pays, because it converts a story into an argument. It also keeps you off the two headline scandals that half the cohort will reach for.
One more thing worth doing early. The course sits at the intersection of law, ethics and management, and students routinely prepare for only the layer they find most comfortable. If you are strong technically, the legal and normative material is where your marginal marks are. If you came from outside the analytics specialisation, the cost is different: you need enough understanding of how a model is actually built to say where in the pipeline a problem entered, because an ethical argument that cannot locate the mechanism reads as commentary.
Before you plan anything around this course, open the handbook record for your own year and read the enrolment rules yourself. There is a prerequisite, there are three excluded courses, and there is a bar on enrolling if you have already completed COMM2050. Offerings, delivery mode and assessment are all set per term, and every one of those has changed for some UNSW course between one year and the next.
The one habit worth getting a mentor to break
Students rarely fail this course on ethics. They fail it on vagueness. The instinct is usually right, the case really is troubling, and then the sentence says a practice raises significant ethical concerns, which is a sentence that could be attached to any case in the syllabus and therefore says nothing about this one.
A MAAS mentor mostly refuses to accept that sentence. Which harm, named? At which point in the pipeline did it enter, and what would have caught it there? What does your recommended fix cost, and who pays it? Then the last check, which is the one most students have never had done to them: the argument gets read back as a finance director would read it, out loud, to find out whether it survives contact with someone who will not read your method section.
The cases are yours to choose and the positions are yours to hold. A mentor only insists that you say them precisely enough to be disagreed with.
Frequently asked questions
Whose course is this?
UNSW Sydney, where COMM3050 Data Use and Misuse is a 6 unit of credit course owned by the School of Management and Governance within the UNSW Business School, taught in person at the Sydney campus.
What do I need before I can enrol?
The 2026 handbook records the enrolment rule as Prerequisite: COMM2501 or INFS3603. It also lists exclusions against TABL2712 Business Ethics and the Law, TABL3016 and TABL5916 Critical Perspectives and Ethics, so credit in any of those blocks enrolment here. Check the handbook for your own year, since these are revised.
I found notes labelled COMM2050 with the same course name. Can I use them?
Treat them as background only, and check something more important first. The handbook states this course was previously COMM2050 and that students who have completed COMM2050 cannot enrol in COMM3050. On the notes themselves, a matching course name does not mean a matching assessment structure, and assessment is set per term.
Is this the same as COMM1190 Data Insights and Decisions?
No. The first-year course concerns drawing defensible conclusions from data. This one concerns whether the data should have been collected, whether you may act on the conclusion, and who bears the cost of error.
How much law is in it?
Enough that you cannot avoid it. The description names what is legally permissible as part of the content. It is a floor rather than the whole answer, since the course also asks you to weigh social and ethical considerations against organisational goals.
When does it run, and can I take it online?
The 2026 handbook lists offering terms as Term 1 and Term 3, and publishes three delivery variations: in-person, multimodal, and fully online, each at three contact hours. Offerings and modes change between years, so confirm for your own year before planning around them.
Related reading
- COMM1190: data insights and decisions
- COMM3000: evidence based intervention
- Data and coding project support
Ask a MAAS mentor about your course
References
Barocas, S., & Selbst, A. D. (2016). Big data's disparate impact. California Law Review, 104(3), 671–732. https://doi.org/10.15779/Z38BG31
boyd, d., & Crawford, K. (2012). Critical questions for big data: Provocations for a cultural, technological, and scholarly phenomenon. Information, Communication & Society, 15(5), 662–679. https://doi.org/10.1080/1369118X.2012.678878
Mittelstadt, B. D., Allo, P., Taddeo, M., Wachter, S., & Floridi, L. (2016). The ethics of algorithms: Mapping the debate. Big Data & Society, 3(2), 1–21. https://doi.org/10.1177/2053951716679679
Nissenbaum, H. (2004). Privacy as contextual integrity. Washington Law Review, 79(1), 119–157.
Solove, D. J. (2006). A taxonomy of privacy. University of Pennsylvania Law Review, 154(3), 477–564. https://doi.org/10.2307/40041279
