5.2.1Personal data: privacy, ownership, consent and data protection
Edexcel GCSE Computer Science (1CP2) · Issues and impact › Ethical and legal issues
Practise Personal data: privacy, ownership, consent and data protection. 12 exam-style questions on this subtopic, at up to four difficulty levels, with full mark schemes and a progress tracker. Free, no account needed.
Cover the answers and test yourself. The app has these as flashcards that come back just before you'd forget them.
Define the term 'personal data'.
Information about a living person who can be identified from it.
A student guesses a teacher's password and looks at the class's test results. Identify the offence (A, B or C).
A
Sample questions
Written for this site in the style of Edexcel exam questions. They are not taken from real past papers.
Question 1Easy3 marks
(a) Define the term 'personal data'.[1]
(b) Give two examples of personal data.[2]
Show the answer and mark scheme
(a)Answer: Information about a living person who can be identified from it.
information that relates to an identified or identifiable living person
(b)Answer: Any two from: name, address, date of birth, email address, photo, bank details, health data, location.
name
home address
date of birth
email address / phone number
a photograph of the person
bank or card details
medical information
location data / IP address
Question 2Medium4 marks
A gym collects personal data from its members, including their names, addresses, dates of birth, bank details and information about their health.
Explain two ways in which the gym must handle this data to meet the requirements of data protection law.[4]
Show the answer and mark scheme
Answer: Keep the data secure (encryption, access levels); only collect what is needed (e.g. no salary details).
data must be kept secure
e.g. the gym should encrypt the data and use passwords and access levels so only authorised staff can see health and bank details
data must be adequate, relevant and limited to what is needed
e.g. the gym should not collect information it does not need, such as members' salaries
data must be accurate and kept up to date
e.g. addresses and bank details should be updated when they change
data must not be kept for longer than necessary
e.g. the gym should delete a member's data a reasonable time after their membership ends
data must only be used for the purpose it was collected for
e.g. the gym should not sell members' details to marketing companies
data must be processed lawfully, fairly and transparently
e.g. members must be told how their data will be used
Question 3Hard4 marks
A school plans to use fingerprint scanners so that students can pay for their lunch without cash.
Explain the legal and privacy issues the school must consider.[4]
Show the answer and mark scheme
Answer: Fingerprints are sensitive personal data: consent and an alternative are needed, and the data must be secured, used only for lunches and deleted when no longer needed.
fingerprints are biometric data, which is especially sensitive personal data and needs extra protection by law
the school needs consent and must tell students and parents clearly how the data will be used
students (or parents) who do not agree must be offered another way to pay
the data must be stored securely, e.g. encrypted, with access restricted
it must only be used for paying for lunch, not for other purposes
it must be deleted when a student leaves or it is no longer needed
a leak would be serious because, unlike a password, a fingerprint cannot be changed