- What personal data is, and why organisations collect it.
- The difference between ethical and legal issues.
- How privacy, ownership, consent, misuse and data protection affect personal data.
- How to explain sensible decisions in a GCSE scenario.
Organisations often collect data about people: for example, when you create an account, use a fitness app, buy something online, or allow a website to use cookies.
Personal data
Personal data is any data that can identify a living person, either directly or indirectly. Examples include a name, email address, home address, phone number, date of birth, location data, photos, usernames, IP addresses and medical information.
Some data identifies you directly, such as your full name with your address. Other data may identify you indirectly when combined with other data. For example, “a Year 11 student at a small school who lives on Green Road” might identify one person even without giving their name.
Direct or indirect identification
If data can be linked back to a real person, treat it as personal data. If it has been truly anonymised so nobody can identify the person, it is no longer personal data.
Deciding whether data is personal
A supermarket stores: customer ID, postcode, purchase history and loyalty card number. Is this personal data?
- Check whether any item can identify a person directly. A loyalty card number may not look like a name, but the supermarket can link it to a named customer account.
- Check whether the items can identify a person indirectly. A postcode plus purchase history plus customer ID could narrow the data down to one household or person.
- Decide based on whether a person can be identified. This should be treated as personal data because the supermarket can link the records to an individual customer.
Collection and use
Collection means gathering personal data, such as through forms, apps, sensors, cookies or account registration. Use means doing something with that data, such as storing it, analysing it, sharing it, selling it, using it to make decisions, or deleting it.
Personal data should not be collected “just in case”. A good organisation thinks about what it needs, why it needs it, how long it will keep it, and how it will protect it.

Ethical issue
An ethical issue is about what is morally right or wrong. In computing, this often means thinking about fairness, harm, privacy, trust and how technology affects people.
Legal issue
A legal issue is about what the law says an organisation or person must or must not do. For personal data in the UK, this includes data protection law such as the UK GDPR and the Data Protection Act 2018.
Ethical and legal issues often overlap, but they are not identical. Something may be technically legal but still feel unfair or intrusive. For example, a company might legally collect location data with consent, but it may still be ethically questionable if users do not properly understand how often they are being tracked.
Legal does not always mean ethical
Do not write as if “legal” and “ethical” mean the same thing. Legal = rules and laws. Ethical = what is fair, responsible and unlikely to cause harm.
Separating ethical and legal concerns
A free game app asks for access to a player’s location and contacts, then uses the data for targeted advertising.
- Identify the legal concern. The app must have a lawful reason to collect and use the data, explain what it is doing, and follow data protection law.
- Identify the ethical concern. Even if the user clicks “agree”, collecting contacts and location may be excessive for a simple game.
- Link the concern to harm. The player may lose privacy, receive manipulative adverts, or have data shared in ways they did not expect.
Privacy
Privacy means a person’s right to control information about themselves and to keep personal details from being unnecessarily accessed, shared or exposed.
Privacy is important because personal data can reveal sensitive details about someone’s life, habits, health, beliefs, relationships or location. Poor privacy can lead to embarrassment, discrimination, identity theft, scams, or physical danger.
A key idea is data minimisation: only collect the personal data that is needed for a clear purpose.
Privacy by design
A system should be designed to protect privacy from the start, not have privacy added later as an afterthought.
For example, a revision app may need your username and password. It probably does not need your exact home address or live GPS location.
Reducing privacy risk
A school wants an app for students to check homework. The first design collects full name, date of birth, home address, GPS location and homework marks.
- Decide what the app’s purpose is. The purpose is to let students view homework and marks securely.
- Compare each item of data with the purpose. Name or student ID may be needed; homework marks are needed; live GPS location and home address are probably not needed.
- Reduce the risk. Remove unnecessary data collection and protect the remaining data with secure login and access controls.
Data subject and data controller
The data subject is the person the personal data is about. The data controller is the organisation or person that decides why and how the personal data will be processed.
“Ownership” of personal data can be tricky. A company may store and process data in its systems, but the data subject still has rights over data about them. So in an exam, it is usually better to talk about control, rights and responsibilities, not just “the company owns it”.
Data subjects may have rights such as:
- being told what data is collected and why
- asking to see the data held about them
- asking for inaccurate data to be corrected
- asking for data to be deleted in some situations
- objecting to certain uses of their data
Assuming the organisation can do anything with the data
If a user types data into a website, that does not mean the organisation can use it for any purpose. The organisation must still follow data protection rules and respect the user’s rights.
Consent
Consent means a person gives permission for their personal data to be collected or used for a specific purpose, after being properly informed about what will happen.
Good consent should be:
- freely given: the person has a real choice
- specific: consent is for a clear purpose
- informed: the person understands what they are agreeing to
- unambiguous: the person clearly agrees, such as by ticking a box
- withdrawable: the person can change their mind later
Consent is especially important when data is being used in a way the user may not expect, such as sharing it with another company or using it for marketing.
Consent is not a magic permission slip
Even if someone gives consent, the organisation should still collect only necessary data, keep it secure, and avoid unfair or harmful uses.
Checking valid consent
A website has a pre-ticked box saying: “I agree to receive marketing emails and allow my data to be shared with selected partners.”
- Check whether the consent is active. A pre-ticked box is not a clear active choice because the user may not notice it.
- Check whether the purpose is specific. “Selected partners” is vague, so the user may not know who will receive the data.
- Decide what should change. The website should use an unticked box and explain clearly what data will be shared, with whom, and why.
Misuse
Misuse of personal data means using, accessing, sharing, selling, changing or keeping personal data in a way that is unauthorised, unfair, unsafe or against the stated purpose.
Misuse can happen deliberately or accidentally. Examples include:
- an employee looking up a celebrity’s records without permission
- a company selling email addresses to advertisers without proper consent
- hackers stealing personal data after weak security
- data being used to discriminate against someone
- keeping old personal data for years after it is needed
- sending private information to the wrong email address
The consequences can be serious. Individuals may suffer identity theft, scams, embarrassment, stress, financial loss or discrimination. Organisations may face fines, legal action, loss of trust and reputational damage.
Harm is the link
When explaining misuse, link the action to a possible harm. For example: “Sharing medical data without permission could embarrass the person or lead to discrimination.”
Data protection
Data protection means the laws, policies and security measures used to make sure personal data is collected, stored, used, shared and deleted responsibly.
In the UK, organisations handling personal data must follow data protection law. At GCSE, you do not need to quote every legal article, but you should understand the main responsibilities.
Personal data should be:
- collected and used lawfully, fairly and transparently
- used only for a specific purpose
- adequate, relevant and limited to what is needed
- kept accurate and up to date
- kept only for as long as necessary
- protected using suitable security, such as passwords, access levels, encryption and backups
- handled by an organisation that is accountable for what it does
Applying data protection principles
An online shop wants to collect a customer’s name, delivery address, email, payment details, favourite colour, passport number and contacts list.
- Match the data to the purpose. Name, delivery address, email and payment details are needed to process and deliver the order.
- Identify excessive data. Favourite colour, passport number and contacts list are not needed for a normal online purchase.
- Apply data protection. The shop should not collect unnecessary data, should explain how required data will be used, and should secure it properly.
In a scenario, the same situation can involve several issues at once.
For example, a health app collecting heart rate and location data raises:
- privacy issues because the data can reveal personal habits and health
- ownership/control issues because users should know and control what happens to data about them
- consent issues because users must understand what they are agreeing to
- misuse issues if the data is sold, leaked or used for unfair profiling
- data protection issues because the organisation must keep the data secure and follow the law
Use the named issue in your explanation
If the question mentions privacy, ownership, consent, misuse or data protection, use that exact term and connect it to the scenario. This makes your answer precise.
In the exam
- Identify what personal data is being collected and who it is about.
- Link your answer to at least one named issue: privacy, ownership, consent, misuse or data protection.
- Explain the consequence, not just the label: say how a person or organisation could be harmed or protected.
Check yourself
- Why might collecting “extra” personal data be an ethical and legal problem?
- What makes consent valid when an app collects personal data?
- How could misuse of personal data harm both the individual and the organisation?