Skip to main content
← All study guides
🔒

Data & Privacy (GDPR)

GDPR · Data Protection · 18 min read

Data and privacy is about understanding your rights and responsibilities around personal data under the GDPR — and protecting privacy in practice. Whether you handle others' data at work or just your own online, these are essential, legally-grounded skills, and the assessment tests both the concepts and the practical judgement.

What the assessment checks

  • Understanding what personal data is and how the GDPR defines it
  • Consent and the individual rights the GDPR grants
  • Privacy settings and managing your digital footprint
  • Data protection in practice — minimisation, security, and breach response

Key concepts

What counts as personal data

Personal data is any information relating to an identified or identifiable living person — name, email, phone, location, an online identifier, a photo of someone's face, even an IP address in many cases. A separate, stricter category ('special category' data) covers health, religion, ethnicity, political views, and biometrics. Genuinely anonymous data isn't personal data — but beware: combining several 'anonymous' fields (age + postcode + job title) can re-identify someone.

Example. 'The weather today' or a public maths formula is not personal data. Your name, your email, your phone's location history, and a photo of your face all are. A dataset of 'anonymous' records that includes rare combinations can still identify individuals.

💡 Tip: If information can single out a living person, directly or combined with other data, treat it as personal data.

Consent must be real

Under the GDPR, valid consent is freely given, specific, informed, and unambiguous — a clear affirmative action. Pre-ticked boxes, buried fine print, or 'by using this site you agree' bundles are not valid consent. And consent is only one of several lawful bases for processing data; it isn't always required, but when relied on, it must meet that bar.

Example. A cookie banner with a giant 'Accept all' and a hidden 'reject' isn't genuine free consent. A clear choice with equally easy accept/reject options is.

💡 Tip: Know the four words: freely given, specific, informed, unambiguous.

Individual rights under the GDPR

The GDPR gives people concrete rights over their data: to be informed, to access a copy of their data, to rectify errors, to erasure ('right to be forgotten'), to restrict or object to processing, and to data portability. At work, a request from a customer to see their data ('subject access request') is a legal obligation with a deadline, not an optional courtesy.

Example. A customer emails asking what data you hold on them. That's a subject access request — you must locate their data across your systems and respond within the legal time limit (generally one month), not ignore it.

💡 Tip: Recognise a subject access request when you see one — and that it has a deadline.

Data minimisation: collect the minimum

A core GDPR principle: only collect data you actually need, use it only for the stated purpose, and don't keep it longer than necessary. 'Collect everything just in case' is both poor practice and a legal risk — every extra field is extra liability if you're breached.

Example. A newsletter signup that demands your date of birth, address, and phone number is over-collecting — it needs only an email. Each unnecessary field is data you must now protect and could leak.

💡 Tip: When designing any form, ask of each field: do we genuinely need this?

Protecting data in practice, and breach response

Practical protection means restricting access to those who need it, using secure methods to share (not unencrypted email or public links for sensitive data), and securely wiping devices before disposal. If a breach happens, the response sequence matters: contain it, assess the scope, then notify the regulator and affected people as required (in the EU, often within 72 hours) — never quietly cover it up.

Example. A spreadsheet of customer details is emailed unencrypted to the wrong person. The competent response: contain (recall/limit), assess who's affected, and notify as required — not delete the logs and hope no one notices.

💡 Tip: Breach response order: contain → assess → notify. Concealment is the worst option and often illegal.

Your own digital footprint

Privacy isn't only about others' data — it's managing what you expose. Reviewing app permissions, tightening social-media privacy settings, thinking before posting real-time location, and deleting accounts you no longer use all shrink your attack surface and your footprint.

Example. Posting 'at the airport, off for two weeks!' with your location advertises an empty home. Posting holiday photos after you're back is the privacy-aware version.

💡 Tip: Periodically review app permissions and privacy settings — defaults are rarely the most private.

Worked example: a test-style scenario

This is the kind of situational-judgement question the assessment uses. Try to choose before reading the verdicts.

A customer emails asking what personal data your organisation holds about them. What's the correct response?

BestTreat it as a data-subject access request: locate all their data across your systems and respond within the legal time limit.

This is a GDPR right with a deadline; handling it properly is both legally required and competent.

PoorAsk them to first prove why they want it.

People generally don't need to justify an access request; demanding a reason is not compliant.

PoorIgnore it — it's too much effort to compile.

Ignoring a subject access request breaches the GDPR and can lead to complaints and penalties.

Common mistakes to avoid

Quick self-check

4 practice questions. Pick an answer to see whether you got it and why. Not scored or saved — just for your own preparation.

1. Which of these is personal data under the GDPR?

2. A customer emails asking what data you hold on them. This is…

3. What does 'data minimisation' mean?

4. A breach exposes customer data. Correct response order?

Free resources to go deeper

External, authoritative, free. Opens in a new tab.

Ready to prove it?

Take the free assessment and earn a verifiable credential.

Start the assessment →