Skip to main content
← All study guides
🛡️

Safety, Wellbeing & Responsible Use

DigComp 3.0 · Area 4 · 18 min read

Safety covers protecting your devices, your personal data, your wellbeing, and the environment in a digital world. It's the domain with the most immediate real-world consequences — one phishing click or one reused password can cause serious, lasting harm — so the assessment tests practical judgement, not just definitions.

What the assessment checks

  • Protecting devices (updates, antivirus, safe habits)
  • Protecting personal data and privacy (passwords, 2FA, phishing)
  • Protecting health and wellbeing online (screen habits, balance)
  • Protecting the environment (sustainable, responsible use of technology)

Key concepts

Phishing is the number-one threat — learn the signatures

The large majority of breaches start with a deceptive message engineering urgency or fear. Tell-tale signs: urgency ('act within 24 hours'), a request for credentials or payment, a slightly-wrong sender address or link domain, and unexpected attachments. The safe habit: never act via links in unexpected messages — go to the organisation directly through its official app or by typing the address yourself.

Example. An email 'from your bank' warns of suspicious activity and links to a login page. The domain is 'secure-bankname-verify.ru'. The competent response is to ignore the link and log in through the bank's real app — legitimate banks never email you a login link demanding urgency.

💡 Tip: Legitimate organisations never ask for your password. Urgency + a link + a credential request = phishing until proven otherwise.

Passwords: long, unique, plus 2FA

Two practices defeat most account attacks: a unique password for every important account (so one breach doesn't unlock the rest), and two-factor authentication (so a stolen password alone isn't enough). A password manager makes 'unique everywhere' effortless. Modern guidance favours long passphrases over forced frequent resets of complex-but-reused passwords.

Example. You reuse one password across ten sites. One of them is breached. Attackers now try that email/password pair everywhere ('credential stuffing') and walk into the other nine. Unique passwords + 2FA stops this cold.

💡 Tip: Turn on 2FA for email first — your email can reset every other account.

Keep software updated

Updates frequently patch security holes that attackers are actively exploiting. Indefinitely postponing them leaves known doors open. Enabling automatic updates on devices and apps is one of the highest-value, lowest-effort protections.

Example. The 2017 WannaCry ransomware spread through a Windows flaw that had been patched two months earlier — the victims simply hadn't updated. The update would have prevented it.

💡 Tip: 'Remind me later' for weeks is a real risk, not a neutral choice.

Practical safety habits

A few situational rules: avoid sensitive actions (banking) on untrusted public Wi-Fi; don't plug in unknown USB devices (a known attack vector); deny apps permissions they don't need (a flashlight app needs neither your contacts nor your location); and be cautious with unexpected 'you've won'/'parcel undeliverable' messages.

Example. A USB stick labelled 'Salaries' appears in the car park. Plugging it in 'to find the owner' is exactly the attack — the competent move is to hand it to IT, not connect it to anything.

💡 Tip: Question permissions and unsolicited messages; default to caution.

Wellbeing and sustainability count too

Digital safety in DigComp explicitly includes protecting your health and the environment. That means managing screen time and notifications for focus and sleep, recognising doom-scrolling's effects, and making sustainable tech choices — keeping devices longer, and recycling old electronics properly rather than binning them.

Example. Constant evening news-scrolling wrecking your sleep is a digital-wellbeing problem; the competent fix is bounded news times and keeping the phone out of the bedroom — not 'just scroll less' willpower.

💡 Tip: Wellbeing and environmental responsibility are genuine, tested parts of this domain — not filler.

Worked example: a test-style scenario

This is the kind of situational-judgement question the assessment uses. Try to choose before reading the verdicts.

An email that looks like it's from your bank warns of 'suspicious activity' and links to a login page. The sender address looks slightly off and the message is very urgent. What's the best response?

BestDon't click the link; log in through the bank's official app or by typing the address yourself.

Sidesteps the phishing link entirely and reaches the bank through a trusted route.

OkayHover over the link to inspect where it really goes before deciding.

A useful check, but risky as a habit — better to never engage with the link and go direct.

PoorClick the link and log in to check whether your account is really affected.

This is exactly what the attacker wants — you'd hand your credentials straight to a fake login page.

Common mistakes to avoid

Quick self-check

4 practice questions. Pick an answer to see whether you got it and why. Not scored or saved — just for your own preparation.

1. An 'urgent' email from your bank links to a login page; the sender address looks slightly off. Best response?

2. Best defence if one of your reused passwords is leaked in a breach?

3. You find a USB stick labelled 'Salaries' in the car park. What do you do?

4. Why install security updates promptly?

Free resources to go deeper

External, authoritative, free. Opens in a new tab.

Ready to prove it?

Take the free assessment and earn a verifiable credential.

Start the assessment →