Data & Privacy (GDPR)
GDPR · Data Protection · 18 min read
Data and privacy is about understanding your rights and responsibilities around personal data under the GDPR — and protecting privacy in practice. Whether you handle others' data at work or just your own online, these are essential, legally-grounded skills, and the assessment tests both the concepts and the practical judgement.
What the assessment checks
- ✓Understanding what personal data is and how the GDPR defines it
- ✓Consent and the individual rights the GDPR grants
- ✓Privacy settings and managing your digital footprint
- ✓Data protection in practice — minimisation, security, and breach response
Key concepts
What counts as personal data
Personal data is any information relating to an identified or identifiable living person — name, email, phone, location, an online identifier, a photo of someone's face, even an IP address in many cases. A separate, stricter category ('special category' data) covers health, religion, ethnicity, political views, and biometrics. Genuinely anonymous data isn't personal data — but beware: combining several 'anonymous' fields (age + postcode + job title) can re-identify someone.
💡 Tip: If information can single out a living person, directly or combined with other data, treat it as personal data.
Consent must be real
Under the GDPR, valid consent is freely given, specific, informed, and unambiguous — a clear affirmative action. Pre-ticked boxes, buried fine print, or 'by using this site you agree' bundles are not valid consent. And consent is only one of several lawful bases for processing data; it isn't always required, but when relied on, it must meet that bar.
💡 Tip: Know the four words: freely given, specific, informed, unambiguous.
Individual rights under the GDPR
The GDPR gives people concrete rights over their data: to be informed, to access a copy of their data, to rectify errors, to erasure ('right to be forgotten'), to restrict or object to processing, and to data portability. At work, a request from a customer to see their data ('subject access request') is a legal obligation with a deadline, not an optional courtesy.
💡 Tip: Recognise a subject access request when you see one — and that it has a deadline.
Data minimisation: collect the minimum
A core GDPR principle: only collect data you actually need, use it only for the stated purpose, and don't keep it longer than necessary. 'Collect everything just in case' is both poor practice and a legal risk — every extra field is extra liability if you're breached.
💡 Tip: When designing any form, ask of each field: do we genuinely need this?
Protecting data in practice, and breach response
Practical protection means restricting access to those who need it, using secure methods to share (not unencrypted email or public links for sensitive data), and securely wiping devices before disposal. If a breach happens, the response sequence matters: contain it, assess the scope, then notify the regulator and affected people as required (in the EU, often within 72 hours) — never quietly cover it up.
💡 Tip: Breach response order: contain → assess → notify. Concealment is the worst option and often illegal.
Your own digital footprint
Privacy isn't only about others' data — it's managing what you expose. Reviewing app permissions, tightening social-media privacy settings, thinking before posting real-time location, and deleting accounts you no longer use all shrink your attack surface and your footprint.
💡 Tip: Periodically review app permissions and privacy settings — defaults are rarely the most private.
Worked example: a test-style scenario
This is the kind of situational-judgement question the assessment uses. Try to choose before reading the verdicts.
A customer emails asking what personal data your organisation holds about them. What's the correct response?
This is a GDPR right with a deadline; handling it properly is both legally required and competent.
People generally don't need to justify an access request; demanding a reason is not compliant.
Ignoring a subject access request breaches the GDPR and can lead to complaints and penalties.
Common mistakes to avoid
- ✗Thinking only obviously-sensitive data is 'personal data'.
- ✗Treating pre-ticked boxes or buried terms as valid consent.
- ✗Not recognising a subject access request (or its deadline).
- ✗Over-collecting data 'just in case' instead of minimising.
- ✗Concealing a breach instead of contain → assess → notify.
Quick self-check
4 practice questions. Pick an answer to see whether you got it and why. Not scored or saved — just for your own preparation.
1. Which of these is personal data under the GDPR?
2. A customer emails asking what data you hold on them. This is…
3. What does 'data minimisation' mean?
4. A breach exposes customer data. Correct response order?
Free resources to go deeper
External, authoritative, free. Opens in a new tab.