The Data Protection Act 2018 is the UK's implementation of the EU General Data Protection Regulation (GDPR). It controls how organisations collect, store, and use personal data — any information that can identify a living individual.
| # | Principle | What it means |
|---|---|---|
| 1 | Lawful, fair & transparent | Data must be used legally, honestly, and people must know how it's used |
| 2 | Purpose limitation | Only use data for the specific reason it was collected — not other purposes |
| 3 | Data minimisation | Collect only what's necessary — no more |
| 4 | Accuracy | Data must be kept accurate and up to date |
| 5 | Storage limitation | Don't keep data longer than necessary |
| 6 | Security (integrity & confidentiality) | Store data securely — protect against unauthorised access, loss or damage |
The Information Commissioner's Office (ICO) enforces the DPA in the UK. Organisations can be fined up to £17.5 million or 4% of global annual turnover for serious breaches.
The Computer Misuse Act 1990 was the UK's first law specifically addressing computer crime. It created three main criminal offences:
| Offence | Description | Max Penalty |
|---|---|---|
| Section 1: Unauthorised access | Accessing a computer system without permission (hacking) | 2 years + fine |
| Section 2: Unauthorised access with intent | Hacking with the intention of committing a further crime (e.g. fraud, blackmail) | 5 years + fine |
| Section 3: Unauthorised modification | Altering, deleting, or damaging data without permission (includes deploying malware) | 10 years + fine |
Before 1990, there was no specific law against hacking — hackers could only be prosecuted under fraud or theft laws, which were poorly suited to computer crimes. The CMA specifically targets cyber offences and has been updated to cover DoS/DDoS attacks (Section 3A, added 2006) and offences targeting national infrastructure.
8 Edexcel-style questions · instantly marked
| Term | Definition |
|---|
Timed exam-style test.