As organisations increasingly rely on digital systems to collect, process and store information, data protection has become both a governance and technical issue. Legal requirements, ethical responsibilities and information security controls often involve different teams, yet decisions in one area can create consequences in the others. This creates a challenge for organisations seeking to understand not only whether their information practices comply with applicable requirements, but also how those practices expose them to broader operational and ethical risks.
Ijeoma Mbonu examined this intersection through her work as a Junior Ethics Researcher and Project Manager, where she conducted legal- and ethics-focused research involving data protection, governance and regulatory compliance. Her work included developing ethical risk assessment matrices, carrying out comparative legal analysis and structuring research processes to help teams assess governance issues more systematically.
Mbonu developed ethical risk assessment matrices as a particularly practical part of her work. This gave ethical concerns a structured place in decision-making by providing a method for identifying and evaluating risks within research and governance processes, rather than treating them only as broad principles after a problem emerged.
The approach gave ethical considerations a more defined place within decision-making. A structured assessment can help researchers and organisational teams identify potential concerns, examine their implications and determine where they need additional safeguards or further review. This creates a clearer link between ethical principles and practical decisions in handling information and conducting projects.
Her work also involved in-depth statutory and comparative legal analysis across multiple case studies. This clarified how legal requirements applied across different situations rather than treating regulatory obligations as isolated rules. It showed where requirements overlap, where interpretations differ and what implications those differences may have for organisations handling sensitive information.
This combination of legal analysis and ethical risk assessment gave her work a distinct practical dimension. Instead of examining compliance solely as a question of whether an organisation had met a particular rule, the approach considered how legal obligations, ethical risks and organisational processes could interact.
This matters because data protection decisions rarely exist in isolation. The collection of personal information can raise questions about lawful use, consent and accountability. Storage and access can create security and privacy concerns. Sharing information with other parties can introduce additional obligations and risks. An organisation may therefore satisfy one requirement while leaving another aspect of its information governance inadequately addressed.
Mbonu’s work considered these relationships as part of a broader governance problem. By examining legal requirements alongside ethical considerations, her work contributed to a more structured way of thinking about risks that can otherwise become divided between legal, technical and operational functions.
The same principle applies to information security. Technical controls can restrict access, protect information and monitor systems. Still, they do not by themselves determine whether an organisation should collect particular information, how long it should retain it, who should be accountable for its use or whether a particular practice creates an ethical concern.
These questions require governance processes that extend beyond technology.
Mbonu’s work therefore placed data protection within a wider organisational context. It considered how regulatory and ethical questions could inform decision-making before problems became incidents or compliance failures. This preventive orientation is particularly important for organisations managing information across multiple functions, where researchers, technology teams, administrators and senior decision-makers must coordinate their responsibilities for data governance.
Her role as a project manager also shaped how she approached these issues. She managed research timelines, tracked milestones and coordinated communication between faculty supervisors and research teams. These responsibilities connected the substance of the research with the processes required to produce and review it.
That combination matters to governance work because effective risk management depends not only on identifying the right questions, but also on ensuring that teams address those questions consistently. Structured project management can establish clearer responsibilities, create points for review and help teams maintain visibility over work that involves multiple contributors.
The practical value of this approach becomes clearer when organisations respond to regulatory and ethical risks. Policies may establish broad expectations, but implementation requires people to interpret those expectations, assess risks and translate them into operational decisions. Without a structured process, important considerations can remain dispersed across departments or become dependent on individual judgment.
Mbonu’s research addressed this gap by examining ways to bring legal analysis, ethical evaluation and governance processes into closer alignment.
Her work also recognised that information governance involves a lifecycle rather than a single point of control. Information can move through collection, processing, storage, access, sharing, retention and disposal, with different risks emerging at each stage. A governance framework that considers only security at the point of storage, for example, may overlook questions arising during collection or sharing.
The ethical risk assessment work provided a basis for considering these questions more systematically. For example, her framework has been adopted by research committees at Adeleke University to guide the review of digital governance projects, and cited in internal policy updates at two regional consulting firms, demonstrating external recognition and practical use. By identifying potential risks and examining them through a structured framework, organisations can create clearer opportunities for review before decisions become embedded in operational processes.
This perspective has implications beyond academic research. Enterprises increasingly manage personal, financial and operational information across interconnected systems. They also work with external service providers, third-party platforms and distributed teams. Each additional relationship can create questions around responsibility, access, compliance and appropriate data use.
An integrated approach to governance can help organisations examine these risks together rather than treating each issue as a separate administrative obligation.
Mbonu’s comparative legal research further strengthened this perspective. It showed how legal obligations can vary according to circumstances and jurisdiction, helping decision makers recognise that compliance requires interpretation and contextual assessment, not simply the application of a universal checklist. For organisations operating across multiple regulatory environments, this analysis is especially useful.
The work also points toward a broader role for ethics within information security. Ethical analysis introduces additional questions about the consequences of organisational decisions, including how information is used and who may be affected by those decisions. Security professionals focus on protecting systems and information from unauthorised access, while legal and compliance professionals concentrate on obligations and regulatory exposure.
Bringing these perspectives together can give organisations a fuller understanding of risk.
This connection between law, ethics and technology would become increasingly relevant as digital systems expanded and organisations adopted more sophisticated forms of information processing. Questions around privacy, automated decision-making, accountability and responsible technology use require professionals who can understand both the technical environment and the rules and principles governing it.
Mbonu’s early work established a foundation for that interdisciplinary perspective. Her experience in legal and ethics research provided an understanding of regulatory interpretation, ethical assessment and accountability. At the same time, her work in information security and technology would build on those foundations by addressing how such principles can be incorporated into technical environments.
The significance of the work therefore lies not simply in its focus on compliance. It lies in the effort to make legal and ethical considerations more actionable within governance and risk processes.
By developing structured ethical risk assessment tools, conducting comparative legal analysis and coordinating research processes, Mbonu approached governance as a practical discipline involving assessment, documentation, review and accountability. Her work demonstrated how ethical and legal questions can move from abstract principles into structured considerations that inform organisational decisions.
This approach also provides an early link between her legal and ethics background and the cybersecurity, cloud security and enterprise risk work that would become part of her professional trajectory. Cybersecurity increasingly requires professionals to understand more than technical controls. They must also consider identity, governance, regulatory obligations, risk ownership and the consequences of how organisations manage information.
Mbonu’s work at Adeleke University placed these considerations within a structured research environment, giving her experience at the intersection of law, ethics, governance and information management.
As organisations continue to depend on digital infrastructure, that intersection has become increasingly important. Effective information governance requires technical safeguards, but it also requires clear rules, ethical evaluation, defined responsibilities and processes for identifying risk.
Mbonu’s contribution to this field began by examining how these elements could work together. Through ethical risk assessment, comparative legal analysis and structured governance research, she developed a practical perspective on a problem that continues to shape information security: how organisations can protect information while remaining accountable for the decisions they make about it.
That foundation connects her early work in law and ethics with the broader discipline of cybersecurity and enterprise risk, where responsible technology management increasingly depends on bringing technical protection, regulatory responsibility and organisational accountability into the same conversation.
Follow Us on Google News
Follow Us on Google Discover
