Data protection act — principles and why it exists
A data protection act sets the principles for holding personal data — obtained fairly and lawfully, used only for the stated purpose, kept accurate, not excessive, not kept longer than necessary, and secure. It is law because electronic data can be copied, searched and shared far faster and wider than paper — one breach can expose thousands — and it binds any organisation (schools, banks, employers), not just computer firms.
Personal data vs sensitive data
Personal data identifies a living individual — name, address, date of birth, or a photo in school uniform (the uniform reveals which school the child attends). Sensitive data is a subset that is especially private — e.g. medical history — needing an even higher level of protection. Both must be kept confidential to avoid inappropriate disclosure. All sensitive data is personal data, but not all personal data is sensitive.
eSafety — one action set per context
eSafety is minimising the dangers of internet-connected technology. The syllabus names four contexts — internet, email, social media and online gaming — each with its own danger-minimising actions. A mark-scoring answer names the specific context and its specific action; generic "be careful online" is not credited. eSafety also covers respecting others — not inappropriate images or language — not only self-protection.
Drawn from real examiner reports.
Splitting the data protection principles
"Describe the principles of a data protection act" gives a mark for each distinct principle, but candidates name only one or two — usually "keep it secure" or "keep it confidential" — and stop, losing the rest. List several distinct principles (fair and lawful, stated purpose, accurate, not excessive, not kept too long, secure), not one at length.
Flagged s22 P12 Q7 — candidates split the data protection principles and lost the mark; "apart from confidentiality and security" was ignored
Vague consequence, not a specific one
Asked what misusing personal data could cause, "something bad could happen" scores nothing — name a specific consequence: identity theft, fraud or blackmail. Asked for an example of identifying data, name a specific item: "bank account number" scores, "bank account details" does not; "medical history" scores, "personal information" does not.
Flagged w22 P11 Q11; s22 P12 Q7b — misuse => identity theft, fraud, blackmail; give a specific example ("bank account number", not "bank account details")
eSafety is not a list of security software
eSafety "discuss" questions are about behaviour, but candidates answer with security software — passwords, firewalls, anti-virus — which is topic 8.3 (security of data), and give a one-sided list. Name a behaviour strategy for the context (e.g. teacher-recommended sites, not meeting an online contact) and discuss it with a positive and a negative.
Flagged w22 P11 Q7 — discuss eSafety strategies with positives and negatives, not just "passwords/firewalls/anti-virus"
Personal data ≠ sensitive data
Candidates blur the two. Personal data is anything identifying a living individual (name, address, date of birth, photo in school uniform). Sensitive data is the special subset that is especially private — e.g. medical history — needing extra protection. Giving the same example for both, or a vague "personal information", loses the mark.
Right action, wrong context
Each context has its own named actions, and one is not credited in another context. Candidates give an internet action ("use teacher-recommended sites") for an online gaming question, or a social-media action ("block and report") for an email one. Read the context first, then give its action — online gaming = no real names, no personal or financial data.
eSafety also means respecting others
Candidates treat eSafety as only protecting themselves, but the syllabus also requires respecting others on social media — not distributing inappropriate images, not using inappropriate language, and respecting other people's confidentiality (netiquette). An answer that lists only self-protection actions misses these named social-media behaviours.
Flagged s22 P11 Q13c — netiquette/security
List principles, don't dwell
For "describe the principles of a data protection act", list several distinct principles briefly — each distinct principle is usually worth one mark — rather than writing at length about just one or two. Breadth scores here, not depth.
Name the context first
eSafety questions almost always specify a context — internet, email, social media or online gaming. Match your answer to it: an action for one context ("block and report" on social media) is not automatically right for another (online gaming wants "do not use a real name").
Be specific, not generic
Name a specific data item ("date of birth", "medical history", "bank account number") not a vague category ("personal information", "details"), and a specific consequence (identity theft, fraud, blackmail) not "something bad". The precise version scores; the vague one does not.
Discuss = both sides
For a "discuss" or "evaluate" eSafety question, give a positive and a negative/limitation for each strategy — a one-sided list, or a list of security software with no evaluation, does not meet the command word "discuss".
Data protection act — legislation that sets out principles organisations must follow when they collect, store, process or share personal data: obtained and processed fairly and lawfully; used only for the stated purpose; adequate, relevant and not excessive; accurate and kept up to date; not kept longer than necessary; kept secure; not transferred without adequate protection.
Personal data — data that can identify a living individual, e.g. name, address, date of birth, a photograph in school uniform.
Full notes, flashcards, Q&A and the topic quiz for every premium subject.
Premium plans are US$8.99/month or US$49.99/year — first month free.
Studying with a parent's blessing? Show them this.