Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 19 pages
Summary

Summary - Core 2 Component 4: Data Analysis

Document preview thumbnail
Preview 3 out of 19 pages

This is notes needed for core 2 component 4 of t - level digital.

Content preview

Core 2 — Component 4: Legislation and
Regulatory Requirements
Notes compiled directly from your teacher's slide decks


This document is built to follow your teacher's actual PowerPoint slides, in the order she taught them, so it
maps straight back to your lessons. As you send more of the numbered decks, I'll keep adding them here in
order so this becomes one running set of notes for the whole component.

Slides compiled so far:
• 38 — Data Protection & CMA
• 39 — Health & Safety and Equality
• 40 — Intellectual Property, Monitoring & International Law
• 41 — Codes of Conduct
• 42 — Guidelines & Agreed Standards
• 43 — Acceptable Use Policies
• Plus: “Revision guide - content area 4.docx” (added two topics the slides didn't cover, plus practice Q&As)
This completes all slides for Component 4 (38-43), plus the additional revision guide, PLUS a few gaps found
by checking against the official Pearson spec directly (see the highlighted “Note” boxes below for what those
were).
Note: Her slides teach the Data Protection Act 1998. Your actual exam board (Pearson) now examines UK GDPR
(General Data Protection Regulation) / Data Protection Act 2018, which updated this law. I've kept her structure
and level of detail below, but flagged where the naming has moved on — worth a quick check with her on which
name she wants written in an answer.

, Slide Deck 38 — Data Protection & CMA

What is legislation?
• Laws can be national or international — e.g. the UK Data Protection Act 1998 was the national version of
the 1995 EU Data Protection Directive; EU countries had similar laws
• Laws can be criminal or civil:

– Civil case — one side may be awarded damages for loss
– Criminal case — guilty person may face a fine or prison sentence

The two main computing laws covered in this deck:
• Data Protection Act — controls how data about living people is stored and processed
• Computer Misuse Act 1990 — makes it an offence to access or modify computer material without
permission


Data Protection Act
Note: Current exam terminology: UK GDPR / Data Protection Act 2018. The concepts and roles below are the
same ones examined; only the exact Act name has been updated since 1998.

What is personal data?
• Personal data = data about an individual — information specific/personal to them
• The Act exists to protect these personal details
• Prompted by questions like: who stores information about you, how secure is it, and what are the
benefits/drawbacks of an organisation (e.g. your college) holding your data

Purpose of the Act
• A law designed to protect personal data stored on computers or in an organised paper filing system
• Created to protect individuals from misuse of this data
Key roles and rights
• Information Commissioner / Information Commissioner's Office (ICO) — anyone needing to store
personal information must register with the ICO, so it's recorded who is holding what
• Data controller — the legal person who controls and is responsible for keeping and using personal info;
must declare in advance what will be stored and how it will be used (recorded in the register)
• Data user — people who need to access/use personal data for their day-to-day job
Rights individuals have under the Act:
• To be given the data held about us
• To have incorrect data changed
• To prevent data being used about us if it will cause distress
• To stop data being used in attempts to sell us something
• To use the law to gain compensation
Exam tip: Keep the three roles straight: Information Commissioner (regulates/oversees registration), Data
Controller (decides how/why data is used, legally responsible), Data User (day-to-day access for their job). Mixing
these up is a common way to lose an easy mark.

Exemptions
Your slides flag that there ARE exemptions to the Data Protection Act, alongside a case study — the specific
exemptions and case study text weren't captured when I extracted this slide (likely an image or diagram).
Screenshot that slide and I'll add the detail in here.


Computer Misuse Act 1990

, Why it was created
• Developed to cope with the problems of computer hackers and viruses
• Virus — a program written to cause mischief or damage to a computer system (corrupts/erases files)
• Hacker — an unauthorised user who attempts to, or gains, access to an information system
What counts as a criminal offence
It is a criminal offence to make unauthorised access to computer material:
• With intent to commit/facilitate further offences (e.g. blackmailing)
• With intent to affect the operation of a computer (e.g. distributing viruses)
• Deliberate destruction of data / theft of data
• Copying software illegally (this includes watching illegal streams)
• Hacking
• Fraud — piracy/phishing
This law is specifically aimed at unauthorised access — what we generally call "hackers."

Worked scenario — classifying CMA offences
Your slides give two case-study scenarios to classify against the three CMA offence categories: unauthorised
access, unauthorised access with intent, and unauthorised modification of data.
Scenario A — the student:
• "A student hacks into a college database to impress his friends" → unauthorised access (no intent to cause
harm yet, just curiosity/showing off)
• "A week later he succeeds and alters his grades" → unauthorised modification of data (he has now
actually changed data)
• "Later he decides to change his grades again, but can't find the correct file" → unauthorised access with
intent (he intended to modify data again, even though he failed — intent alone is enough to commit this
offence)
Scenario B — the employee:
• "An employee about to be made redundant finds the MD's (Managing Director's) password; logs in using this
and looks at confidential files" → unauthorised access
• "After asking a friend he finds out how to delete things and wipes the main database" → unauthorised
modification of data
• "Having received his notice of redundancy he goes back into the file to try and cause damage but fails" →
unauthorised access with intent (attempted harm, even though it failed)
Exam tip: Notice the pattern in both scenarios: simple access = Level 1; access + intent to cause harm (even if it
fails) = a more serious level; actually modifying/deleting data = the modification offence. Exam scenario questions
often follow exactly this structure — read for whether harm was INTENDED, ATTEMPTED, or ACTUALLY DONE.

CMA — real-world issues
Examples of offences under the Act:
• Spreading a virus
• Attempting to log in without authorisation
• Using someone else's login
• Reading, changing or deleting data
• Obtaining or creating a "packet sniffer"
Why prosecutions are rare:
• Offences are difficult to prove
• Firms are embarrassed by being hacked — particularly banks — so may not report it
• Police lack expertise, time, and money to pursue cases
Your slides also note ongoing parliamentary debate about whether the CMA is still fit for purpose (it's from 1990
— long before modern cybercrime), with real-world sources referenced from The Register and ITPro on 2021

Document information

Study Level
Subject
Uploaded on
September 22, 2026
Number of pages
19
Written in
2026/2027
Type
Summary
$11.67

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
1
Last sold
-



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions