SLIDE 1
CSZone.co.uk
Click to advance · Arrow keys also work
Edexcel 1CP2 · Topic 5 · 5.2a

UK
Legislation

Computer Misuse Act 1990 · Data Protection Act 2018 · GDPR

CSZoneEdexcel GCSE Computer Science 1CP2
Computer Misuse Act 1990

Criminalising Hacking

Introduced to combat the rise of computer crime. Makes three key offences illegal in the UK:
Unauthorised access to computer systems — e.g. logging into someone else's account without permission
Unauthorised access with intent to commit further offences — e.g. hacking to commit fraud
Unauthorised modification of computer material — e.g. creating and distributing malware, deleting files
Penalties: up to 10 years imprisonment for the most serious offences
Data Protection Act 2018 & GDPR

Protecting Personal Data

The Data Protection Act 2018 implements the EU's GDPR into UK law. It regulates how organisations collect, store, and use personal data. The ICO (Information Commissioner's Office) enforces these rules.
Data must be collected for a specific, legitimate purpose and not used beyond that purpose
Data must be accurate, kept secure, and not held for longer than necessary
Individuals have the right to access their data and request deletion ("right to be forgotten")
GDPR Principles

The Eight Key Principles

Lawfully and fairly processed — with the consent of the data subject
Collected for specified, explicit, and legitimate purposes
Adequate, relevant, and limited to what is necessary
Accurate and kept up to date where necessary
Not kept longer than necessary; processed securely
Fines up to €20 million or 4% of global turnover for breaches
Exam Practice

Have a go at this question

Edexcel-style question
A student logs into a school's network using a teacher's password without permission. State which law this breaks and describe the offence committed.
3 marks
Computer Misuse Act 1990 [1]. The student has committed unauthorised access to a computer system [1] — they accessed the network using credentials they are not permitted to use [1].
Key Takeaways

What to Remember

CMA 1990: 3 offences — unauthorised access, access with intent, modification. Up to 10 years.
DPA 2018/GDPR: personal data must be lawfully, fairly, and securely processed
ICO enforces data protection law in the UK; massive fines for breaches
Individuals have rights: access their data, correct it, request deletion