Community resourceWorksheet

J277 1.6 Data Protection Act and Privacy

Part 2 of 5 · J277 1.6 Essentials

This worksheet introduces pupils to the Data Protection Act 2018 and its role in regulating the processing and protection of personal data. Activities include identifying personal data, evaluating data handling practices in scenarios, and applying principles such as purpose limitation, minimisation, accuracy, retention, and security. The material is straightforward and suitable for developing understanding of data privacy and the responsibilities of organisations handling personal information.

Shared by Chris H.Verified teacher

  • 13 cells
  • About 50 minutes
  • CC BY-SA 4.0
  • Shared 31 Jul 2026

Preview

The whole resource, exactly as a class sees it. Answers and marking are held back.

Digital impacts Essentials 2: personal data and the Data Protection Act

Organisations use personal data to provide services, make decisions and communicate with people. The Data Protection Act 2018 controls how personal data is processed and protects the rights of the people the data is about.

OCR expects the purpose and impact of the Act, not every detailed rule. You should be able to recognise responsible and irresponsible data handling and apply the law to a computing scenario.

What responsible data handling looks like

Personal data is information relating to an identifiable person. Names, account identifiers, photographs, location histories and health records can all be personal data.

At GCSE level, useful Data Protection Act principles are that personal data should be:

  • processed lawfully, fairly and transparently
  • collected for specified purposes and not later used in a way that conflicts with those purposes
  • adequate, relevant and limited to what is needed
  • accurate and kept up to date
  • kept no longer than necessary
  • protected using appropriate security

People also have rights concerning their data. These include being told how it is used, accessing it and having inaccurate information corrected in appropriate circumstances.

Do not write that consent is always required. An organisation needs a valid lawful basis, meaning a recognised legal reason for processing. Consent is one possible basis. Whatever basis is used, the other responsibilities still matter.

Fill in the blanks5 marks
An organisation should collect data for a ______, keep it ______, retain it only for as long as ______, collect only data that is ______, and protect it with appropriate ______.
  • accurate
  • unlimited period
  • specified purpose
  • relevant
  • public
  • security
  • necessary
Multiple choice, several answers3 marks

Which three items are personal data in the stated context? Select all that apply.

  • AThe total number of anonymous visitors to a national website
  • BA pupil's name linked to their attendance record
  • CA blank copy of a timetable template
  • DA photograph in which an employee can be identified
  • EA phone identifier linked to a user's location history

Scenario: a school wellbeing application

A school asks pupils to use an application that records:

  • their name and school account
  • a daily wellbeing score
  • every location visited during the whole day
  • notes entered for a school counsellor

The supplier plans to retain every record indefinitely and use the information to develop unrelated advertising services. Teachers need current wellbeing information, but they do not need a continuous location history.

Written answer6 marks

Identify three Data Protection Act concerns in the school application scenario. Explain each concern using information from the scenario.

Consider necessity, purpose, retention, transparency and security. Name the data or proposed action involved.

Students type their answer here.

Security is important, but it is not the whole answer

Encryption, access controls and strong authentication can reduce the risk of unauthorised access. However, securing data does not automatically make every collection or use appropriate.

For example, encrypting an unnecessary location history makes the stored data harder to steal, but the organisation must still ask:

  • Is there a clear purpose?
  • Is this amount of data needed?
  • Are people told how it is used?
  • Is it retained for an appropriate time?

This distinction helps you evaluate proposed improvements rather than naming “encryption” as a solution to every privacy issue.

Written answer6 marks

Recommend three changes that would make the school application's data handling more appropriate. Explain how each change addresses a different concern.

Choose specific changes such as reducing collection, limiting use, setting retention periods, correcting records or applying security. Do not repeat the same idea three times.

Students type their answer here.

Multiple choice1 mark

Which statement is the most accurate?

  • APersonal data can never be processed by an organisation
  • BEncrypting data means it may be kept forever for any purpose
  • CConsent is the only possible lawful basis for processing personal data
  • DAn organisation needs a lawful basis and must also handle personal data fairly, securely and for appropriate purposes
Written answer4 marks

A supermarket loyalty application has an incorrect date of birth for a customer. It also keeps precise location data from the application for years, although the data is not used to provide the loyalty service. Explain two relevant Data Protection Act responsibilities.

Use one responsibility for the incorrect information and a different responsibility for the unnecessary long-term location history.

Students type their answer here.

Written answer4 marks

A clinic stores patient appointment records in an account that every employee can open, including employees who do not need the information. Explain why this is a concern and recommend one suitable control.

Connect the access arrangement to confidentiality and appropriate security. Explain how the control changes who can reach the records.

Students type their answer here.

Written answer8 marks

Challenge: The school removes location tracking and encrypts all remaining wellbeing records. Evaluate the claim that these two changes completely resolve every data-protection and privacy concern.

Acknowledge what the changes improve, then test purpose, transparency, retention, accuracy, access and necessity. Reach a supported judgement.

Students type their answer here.

Essentials review

Check that you can:

  • recognise personal data from context
  • state the purpose of the Data Protection Act 2018
  • apply purpose, minimisation, accuracy, retention and security
  • explain that people have rights concerning their data
  • avoid claiming that consent is always required
  • distinguish securing data from deciding whether it should be collected

In an exam answer, name the relevant responsibility and apply it to the actual data and organisation in the question.