⚖️ Paper 1 · Topic 5: Impacts of Technology
5.2a UK Legislation: DPA & Computer Misuse Act
Edexcel 1CP2 · GCSE Computer Science · ~14 min read · ✅ Free
Notes
──
Video
──
Slides
──
Worksheet
──
Quiz

The Data Protection Act 2018 (DPA)

The Data Protection Act 2018 is the UK's implementation of the EU General Data Protection Regulation (GDPR). It controls how organisations collect, store, and use personal data — any information that can identify a living individual.

Six Key Principles (must know these!)

#PrincipleWhat it means
1Lawful, fair & transparentData must be used legally, honestly, and people must know how it's used
2Purpose limitationOnly use data for the specific reason it was collected — not other purposes
3Data minimisationCollect only what's necessary — no more
4AccuracyData must be kept accurate and up to date
5Storage limitationDon't keep data longer than necessary
6Security (integrity & confidentiality)Store data securely — protect against unauthorised access, loss or damage

Rights of Individuals under the DPA

  • Right of access: individuals can request a copy of their personal data (a 'Subject Access Request')
  • Right to rectification: get inaccurate data corrected
  • Right to erasure ('right to be forgotten'): request deletion of data in certain circumstances
  • Right to restrict processing: limit how your data is used
  • Right to object: object to data being used for direct marketing

Who enforces the DPA?

The Information Commissioner's Office (ICO) enforces the DPA in the UK. Organisations can be fined up to £17.5 million or 4% of global annual turnover for serious breaches.

The Computer Misuse Act 1990 (CMA)

The Computer Misuse Act 1990 was the UK's first law specifically addressing computer crime. It created three main criminal offences:

OffenceDescriptionMax Penalty
Section 1: Unauthorised accessAccessing a computer system without permission (hacking)2 years + fine
Section 2: Unauthorised access with intentHacking with the intention of committing a further crime (e.g. fraud, blackmail)5 years + fine
Section 3: Unauthorised modificationAltering, deleting, or damaging data without permission (includes deploying malware)10 years + fine

Why is the CMA Important?

Before 1990, there was no specific law against hacking — hackers could only be prosecuted under fraud or theft laws, which were poorly suited to computer crimes. The CMA specifically targets cyber offences and has been updated to cover DoS/DDoS attacks (Section 3A, added 2006) and offences targeting national infrastructure.

Real-world Examples

  • A student guessing a classmate's password and reading their emails → Section 1
  • A hacker accessing a bank's systems intending to transfer money → Section 2
  • Releasing a virus that deletes files → Section 3
Exam tip: You MUST know the year of each Act and the specific offences. Edexcel exam questions often give you a scenario and ask you to identify which section of the Computer Misuse Act applies.
⚠️ Common Mistakes
  • Confusing the dates: DPA is 2018, Computer Misuse Act is 1990
  • Thinking the CMA only applies to hacking — Section 3 (unauthorised modification) covers malware
  • Not naming the ICO when asked about DPA enforcement
  • Saying 'GDPR' instead of 'DPA' in a UK context — the correct UK law is the DPA 2018
  • Confusing data minimisation (collect less) with data accuracy (keep it correct)
Video coming soon
Click slide or press arrow keys to navigate
✍️

Worksheet — 5.2a UK Legislation

8 Edexcel-style questions · instantly marked

Q1State the full name of the UK law that controls how organisations collect and use personal data, and give the year it was passed.[2]
✅ Mark scheme
Data Protection Act [1]; 2018 [1].
Q2State four of the six principles of the Data Protection Act 2018.[4]
✅ Mark scheme
Any four from: lawful, fair and transparent [1]; purpose limitation [1]; data minimisation [1]; accuracy [1]; storage limitation [1]; security/integrity and confidentiality [1].
Q3What is a 'Subject Access Request'?[2]
✅ Mark scheme
A formal request made by an individual [1]; to receive a copy of the personal data an organisation holds about them [1].
Q4State the three criminal offences created by the Computer Misuse Act 1990.[3]
✅ Mark scheme
Section 1: Unauthorised access to computer material [1]; Section 2: Unauthorised access with intent to commit a further offence [1]; Section 3: Unauthorised modification of computer material [1].
Q5A hacker accesses a hospital's computer system and deletes patient records. Which section of the Computer Misuse Act applies and what is the maximum penalty?[2]
✅ Mark scheme
Section 3 (Unauthorised modification of computer material) [1]; maximum penalty is 10 years in prison [1].
Q6Which UK organisation enforces the Data Protection Act? What power do they have?[2]
✅ Mark scheme
The Information Commissioner's Office (ICO) [1]; can fine organisations up to £17.5 million or 4% of global annual turnover for serious breaches [1].
Q7An employee at a company guesses their colleague's password and reads their private emails. Which section of the CMA applies?[2]
✅ Mark scheme
Section 1 [1]; because they accessed computer material (the email system) without authorisation/permission [1].
Q8Explain why the Computer Misuse Act 1990 was needed. What was the problem before this law existed?[3]
✅ Mark scheme
Before the CMA, there was no specific law targeting computer crime [1]; hackers could only be prosecuted under general fraud or theft laws [1]; these laws did not clearly apply to digital offences, making it difficult to prosecute cybercriminals effectively [1].
Topic Quiz
Q 1 of 15
You scored
out of 15
Click to reveal definition
🎉
Session complete!
TermDefinition
🎯

Mini Test — UK Legislation

Timed exam-style test.

← 5.1 Ethical Issues5.2a of 6Next: 5.2b Copyright →