Community resourceWorksheet

OCR H446 1.5.1 Data protection: exam model and current-law bridge

Part 1 of 5 · H446 1.5.1 · Computing related legislation

OCR H446 1.5.1 asks students to apply data-protection principles, but the specification still names the Data Protection Act 1998 while current UK practice runs on the 2018 Act and the UK GDPR. This worksheet teaches the examined model and makes that boundary explicit, so historical exam content is never presented as today's law.

Students will:

  • apply the examined data-protection principles to a described processing activity
  • identify the processing action a principle engages, rather than naming the law alone
  • separate the examined 1998 naming from the current DPA 2018 and UK GDPR framework
  • correct a claim that treats the two layers as interchangeable
  • evaluate data-protection risks in an extended scenario and justify the principles engaged

Inside: 6 explanation cells, 1 multiple-choice question, 2 fill-in-the-blanks cells and 3 written answers. 28 marks, about 45 to 60 minutes.

Series: H446 1.5.1 · Computing related legislation, part 1 of 5.

Shared by Coding PathwayVerified teacher

  • 12 cells
  • About 45 minutes
  • CC BY-SA 4.0
  • Shared 31 Aug 2026
  • Updated 3 Sept 2026

Preview

The whole resource, exactly as a class sees it. Answers and marking are held back.

Data protection: exam model and current-law bridge

OCR still names the Data Protection Act 1998. Current UK practice uses the Data Protection Act 2018 with the UK GDPR. This worksheet makes that boundary explicit so historical exam content is not presented as current law, while current detail does not become surprise recall content.

Two accurate layers

Exam-facing and current data-protection layersknow which layer the question is testingOCR ASSESSMENT MODELData Protection Act 1998• fair and lawful use• specified purpose• adequate, relevant, not excessive• accurate, secure, time-limited• rights and protected transfersCURRENT-LAW NOTEDPA 2018 + UK GDPR• lawfulness, fairness, transparency• purpose limitation• data minimisation and accuracy• storage limitation and security• accountabilityShared exam habit: principle → organisation action→ effect on a person

For OCR questions, follow the Act or principles named or implied by the paper. The recurring duties are stable: use personal data lawfully and for stated purposes, collect only what is relevant, keep it accurate and secure, retain it only as needed and respect people's rights.

Current-law note checked 28 August 2026: the modern labels come from the DPA 2018/UK GDPR regime. The Data (Use and Access) Act 2025 has made targeted changes, but it is not additional H446 recall content.

Worked principle chain: community health study

A research group collects each participant's postcode, diagnosis, shoe size and email to study local asthma patterns. It keeps identifiable records indefinitely and lets every volunteer download the complete file.

  • Relevance/minimisation: shoe size is not needed for the stated study → excessive collection increases exposure without helping the purpose.
  • Storage limitation: identifiable data is retained without a defined need → risk continues after useful analysis ends.
  • Security: every volunteer can download the whole file → access is not limited to the work each person performs.

A principle is not a slogan. It changes what the organisation should collect, retain or permit.

Multiple choice1 mark

Which action most directly demonstrates purpose limitation?

  • AUsing clinic emails only to send the study updates described when they were collected
  • BKeeping every record forever in case it becomes useful
  • CGiving all volunteers administrator access
  • DCollecting unrelated details because storage is cheap
Fill in the blanks4 marks
Personal data should be used for a specified gap 1, limited to what is gap 2, kept gap 3 and protected with appropriate gap 4.
  • purpose
  • necessary
  • accurate
  • security
  • profit
Written answer6 marks

A tutoring service collects a learner's date of birth to place them in an age group. It later sells the dates to an unrelated advertiser without telling learners. Explain two data-protection principles that are engaged.

For each: name/describe the principle → identify the service action → explain what should change or why the person is affected.

Students type their answer here.

What must not be merged

Exam-facing factCurrent accuracy note
OCR lists DPA 1998Today's general regime is DPA 2018 + UK GDPR
OCR 2024 accepted the familiar 1998-style principlesCurrent guidance organises seven principles, including accountability
The paper controls what is being assessedDo not claim the repealed 1998 Act is today's complete law

Both routes reward the same disciplined application: principle → concrete processing action → effect or required change.

Written answer4 marks

A student writes: ‘The specification says DPA 1998, so DPA 2018 must be irrelevant and organisations still register every purpose exactly as in 1998.’ Correct the claim for an H446 learner.

State what to learn for the examination and what is currently accurate without expanding into an extra law course.

Students type their answer here.

Apply the model independently

The next tasks change the data, representation or context and reduce the support. Complete them using the method you have just learned, then check the required state or consequence.

Written answer9 marks

A sports app records location every minute to calculate a weekly route map. It also keeps raw location indefinitely, shares it with an unrelated recruiter and lets support staff see every user's history. Evaluate the data-protection risks and propose proportionate changes.

Develop at least three principle chains and recognise any legitimate purpose before judging the design.

Students type their answer here.

Fill in the blanks4 marks
For OCR, recognise the named DPA checkpoint gap 1 model. For current accuracy, the main regime is DPA checkpoint gap 2 with the UK GDPR. In either layer, apply a principle to an organisation's checkpoint gap 3 and explain the consequence for a checkpoint gap 4.

Return here whenever a legal answer names data protection but cannot identify the processing action or principle.