UK GDPR (SQA National 5 Computing Science): Revision Note

Exam code: X816 75

Robert Hampton

Written by: Robert Hampton

Reviewed by: James Woodhouse

Updated on

UK GDPR

What is UK GDPR?

  • UK GDPR is a law that protects personal data and sets rules for how organisations collect, store, and use it

  • Personal data includes information that can identify a person, such as:

    • Name

    • Address

    • Date of birth

    • Email address

    • Contact number

Rules for handling data under UK GDPR

Rule

Description

Example

Processed lawfully, fairly and transparently

Data must be collected and used legally, and individuals must know how it is used

A company tells users why their personal data is being collected

Used only for the stated purpose

Data can only be used for the reason it was collected

A shop that collects an email for delivery updates cannot use it to send adverts without permission

Limited to what is necessary

Only the data required for the task should be collected

A cinema collects a customer’s email to send tickets, not their home address

Accurate

Personal data must be correct and kept up to date

A school updates contact details when a student moves house

Not kept longer than necessary

Data must be deleted when it is no longer needed

A company deletes a user’s data when they close their account

Held securely

Data must be stored safely to prevent unauthorised access or loss

A business encrypts customer data to stop hackers accessing it

Application of UK GDPR

  • If customer details are stolen, the company has failed to hold data securely

  • If a user cancels an account, the company should delete their data

  • UK GDPR only applies to personal data, not to non-personal information like measurements or prices

Worked Example

A local café, "Bean Scene," runs a digital loyalty scheme where customers provide their full name, mobile phone number, and favourite coffee order to register. This personal information is stored in a database.

(i) State one implication of the UK General Data Protection Regulation (UK GDPR) that the café must follow regarding this customer's data

[1]

(ii) The café manager decides to keep the customer’s record indefinitely in the database, just in case the customer decides to re-join the scheme years later.

State which specific UK GDPR requirement is violated by this action

[1]

(iii) Due to an accidental leak, the customer's mobile phone number is stolen by unauthorised personnel. The customer is informed of the leak.

State the requirement of the UK GDPR that the café has failed to meet

[1]

Answers

(i)

  • Data must be processed lawfully, fairly, and in a transparent manner [1 mark]

(ii)

  • Data must not be kept for longer than necessary [1 mark]

(iii)

  • Data must be held securely to prevent unauthorised access [1 mark]

Unlock more, it's free!

Join the 100,000+ Students that ❤️ Save My Exams

the (exam) results speak for themselves:

Robert Hampton

Author: Robert Hampton

Expertise: Computer Science Content Creator

Rob has over 16 years' experience teaching Computer Science and ICT at KS3 & GCSE levels. Rob has demonstrated strong leadership as Head of Department since 2012 and previously supported teacher development as a Specialist Leader of Education, empowering departments to excel in Computer Science. Beyond his tech expertise, Robert embraces the virtual world as an avid gamer, conquering digital battlefields when he's not coding.

James Woodhouse

Reviewer: James Woodhouse

Expertise: Computer Science & English Subject Lead

James graduated from the University of Sunderland with a degree in ICT and Computing education. He has over 14 years of experience both teaching and leading in Computer Science, specialising in teaching GCSE and A-level. James has held various leadership roles, including Head of Computer Science and coordinator positions for Key Stage 3 and Key Stage 4. James has a keen interest in networking security and technologies aimed at preventing security breaches.