Welcome to Legislation in Digital Technology!
Welcome to this study guide on Legislation for CCEA A Level Digital Technology (Unit A2 1: Information Systems). As digital technologies evolve, huge amounts of personal information are collected, processed, and stored every second. Laws are essential to protect individuals, hold organisations accountable, prevent cybercrime, and ensure fair access to information.
Don't worry if memorising legal acts feels overwhelming at first! We will break each law down into simple everyday concepts, explore real-world examples, and use handy memory tricks so you can master this topic for your exam.
1. Data Protection Act 2018 (DPA 2018) and UK GDPR
The General Data Protection Regulation (GDPR), incorporated into UK law via the Data Protection Act 2018, exists to protect the privacy and personal data of living individuals. If an organisation stores or processes information about you, they must obey these rules.
Key Roles in Data Protection
To understand the law, you must know who is involved:
• Data Subject: The living individual whose personal data is being held or processed (for example: you, a patient in a hospital, or a student in a school).
• Data Controller: The organisation or person that decides how and why personal data is collected and processed (for example: your school or a retail company).
• Data Processor: Any third party that processes data on behalf of the Data Controller (for example: a cloud storage provider or a payroll company).
• Information Commissioner's Office (ICO): The independent UK authority set up to uphold information rights and enforce data privacy laws. They have the power to issue substantial fines for data breaches.
The 6 Key Principles (Plus Accountability)
Whenever an organisation handles personal data, they must follow these principles:
1. Lawfulness, Fairness, and Transparency: Data must be processed legally and fairly. The organisation must be open and honest about how the data will be used.
2. Purpose Limitation: Data can only be collected for specified, explicit, and legitimate purposes. It cannot be used for something else later without consent.
3. Data Minimisation: Organisations must only collect the data they strictly need to achieve their purpose—nothing extra.
4. Accuracy: Personal data must be kept accurate and up to date. Inaccurate data must be erased or corrected immediately.
5. Storage Limitation: Data must not be kept for longer than is necessary for its stated purpose.
6. Integrity and Confidentiality (Security): Data must be processed securely, protected against unauthorised access, accidental loss, destruction, or damage using appropriate technical measures (like encryption and backups).
7. Accountability: The Data Controller is responsible for demonstrating compliance with all these principles.
Memory Aid: Remember the acronym L-P-M-A-S-I: Lawful, Purpose, Minimal, Accurate, Storage, Integrity.
Individual Rights of Data Subjects
Under the DPA 2018 / GDPR, you as a data subject have strong rights:
• Right to be informed: Knowing how your data is collected and used (e.g., privacy notices).
• Right of access (Subject Access Request): You can request a copy of the data an organisation holds about you.
• Right to rectification: You can ask for incorrect or incomplete data to be fixed.
• Right to erasure ("Right to be Forgotten"): You can request that your data be deleted if it is no longer needed.
• Right to restrict processing: You can limit the way an organisation uses your data.
• Right to data portability: You can obtain and reuse your personal data across different services (e.g., transferring banking details).
• Right to object: You can object to data processing, such as direct marketing.
• Rights related to automated decision making and profiling: Protection from decisions made solely by algorithms without human intervention.
Quick Review & Key Takeaway: The DPA 2018 / GDPR puts the user in control of their private data. Remember: Data Controllers must have a valid legal reason to collect data, keep only what they need, keep it safe, and delete it when finished.
2. Computer Misuse Act 1990 (CMA 1990)
The Computer Misuse Act 1990 was created to prevent unauthorised access and cyber attacks on computer systems. Before this law existed, hackers who gained access to systems without stealing physical items were difficult to prosecute.
The Three Main Offences
Section 1: Unauthorised access to computer material
• Simply logging into someone else's account without permission, guessing a password, or snooping on someone's files without authorisation—even if you change or steal nothing.
• Everyday Analogy: Walking into an unlocked house without permission just to look around.
Section 2: Unauthorised access with intent to commit or facilitate commission of further offences
• Gaining access to a system with the specific intention of committing another crime (like stealing money, blackmail, fraud, or industrial espionage).
• Everyday Analogy: Breaking into an office building specifically planning to steal cash from the safe.
Section 3: Unauthorised acts with intent to impair, or with recklessness as to impairing, operation of a computer
• Modifying or damaging data or programs without permission. This includes spreading viruses, launching Denial of Service (DoS/DDoS) attacks, deleting critical files, or encrypting files with ransomware.
• Everyday Analogy: Slashing someone's car tyres or vandalising their property so it no longer works.
Amendments (Section 3A)
Making, supplying, or obtaining articles for use in computer misuse offences: Writing, distributing, or downloading malware, hacking kits, keyloggers, or DoS tools knowing they will be used for malicious purposes.
Common Mistake to Avoid: Students often think that if you don't break or delete anything, it is not illegal. Under Section 1, simply accessing a system without permission is a criminal offence!
Quick Review & Key Takeaway: CMA 1990 covers unauthorised access (Section 1), unauthorised access with criminal intent (Section 2), unauthorised modification/impairment like malware or DoS (Section 3), and supplying hacking tools (Section 3A).
3. Copyright, Designs and Patents Act 1988 (CDPA 1988)
The Copyright, Designs and Patents Act 1988 protects intellectual property (IP). It ensures that creators of original work retain control over how their creations are copied, distributed, and monetised.
What Does CDPA Protect in Digital Technology?
• Computer software and source code
• Website text, digital images, and graphics
• Video, audio, sound recordings, and animations
• Technical documentation, architecture diagrams, and system manuals
What Constitutes an Infringement?
• Making unauthorized copies of software (software piracy)
• Distributing copyrighted material over file-sharing networks without a licence
• Copying proprietary source code into your own commercial application without permission
• Using digital images or music on a commercial website without purchasing the appropriate licence
Software Licensing Models
1. Proprietary Software: Software where the source code is kept secret and users buy a licence allowing them to run the software under strict conditions (e.g., Microsoft Windows, Adobe Photoshop).
2. Open Source / Creative Commons: Software or media where the creator grants permissions for others to view, modify, and redistribute the work under specified licence terms (e.g., Linux, Apache).
Quick Review & Key Takeaway: CDPA protects the original creators of software and digital assets from unauthorized duplication and theft of their intellectual property.
4. Regulation of Investigatory Powers Act 2000 (RIPA 2000)
The Regulation of Investigatory Powers Act 2000 (and its updated counterpart, the Investigatory Powers Act) governs how public bodies (such as the police, security services, and intelligence agencies like GCHQ) can legally carry out digital surveillance and investigate criminal activities.
Key Powers Granted Under RIPA
• Interception of Communications: Law enforcement can monitor and intercept phone calls, emails, and internet browsing activity (with a valid warrant).
• Access to Communications Data: Authorities can demand "metadata" from Internet Service Providers (ISPs)—such as who called whom, timestamps, and IP addresses, without seeing the actual content of the message.
• Surveillance and Undercover Operations: Regulates covert human intelligence sources and electronic bugging.
• Compulsory Decryption: Authorities can legally demand that suspects hand over encryption keys or passwords. Refusing to supply an encryption key is an offence punishable by imprisonment.
The Balance: Privacy vs. National Security
RIPA is frequently discussed in exam questions regarding ethics:
• Arguments in favour: Essential for preventing terrorism, organised crime, cyberattacks, and child exploitation.
• Arguments against / Concerns: Can infringe on personal privacy and civil liberties if surveillance powers are misused or lack strict oversight.
Quick Review & Key Takeaway: RIPA gives legal permission to authorized law enforcement and security services to intercept digital communications and demand decryption keys to combat serious crime.
5. Freedom of Information Act 2000 (FOIA 2000)
The Freedom of Information Act 2000 provides public access to information held by public authorities in England, Wales, and Northern Ireland (such as government departments, local councils, schools, universities, police forces, and the NHS).
How the FOIA Operates
• Publication Schemes: Public authorities must proactively publish certain routine information about their policies, spending, and operations.
• Freedom of Information Requests: Any member of the public can submit a written request asking for recorded information held by a public body. The authority normally has \(20\) working days to respond.
Exemptions to FOIA
Not all information has to be released. Key exemptions include:
• National Security: Information that could compromise national defense.
• Personal Data: Information protected by the Data Protection Act (you cannot use FOIA to spy on another individual's private records).
• Commercial Sensitivity / Trade Secrets: Details that would unfairly damage a business or government contract negotiation.
Crucial Distinction:
• DPA / GDPR: Used to request your own personal data from any organisation.
• FOIA: Used to request non-personal public information from public bodies.
Quick Review & Key Takeaway: FOIA promotes transparency and public trust by allowing citizens to see how public authorities make decisions and spend public money.
Legislation Summary Matrix
Use this quick comparison table to help you identify which legislation applies in exam scenarios:
Data Protection Act 2018 / GDPR:
• Main Focus: Protecting personal data and privacy rights of individuals.
• Typical Scenario: A company loses an unencrypted laptop with customer records; a patient requests their medical records.
Computer Misuse Act 1990:
• Main Focus: Preventing hacking, malware, and unauthorised system interference.
• Typical Scenario: An employee guesses a manager's password; an attacker sends a virus or launches a DDoS attack.
Copyright, Designs and Patents Act 1988:
• Main Focus: Protecting intellectual property from illegal copying and distribution.
• Typical Scenario: Downloading cracked software; copying code or images without paying for a licence.
Regulation of Investigatory Powers Act 2000:
• Main Focus: Giving legal powers to security services to monitor communications.
• Typical Scenario: Police intercepting suspect emails or demanding a suspect reveal their hard drive encryption password.
Freedom of Information Act 2000:
• Main Focus: Giving the public access to recorded data from public authorities.
• Typical Scenario: A journalist asks a local council for records showing how much money was spent on road repairs.
Final Exam Tips
• Be specific with Act names and years: Always write out the full act name and year at least once in your answer (e.g., Computer Misuse Act 1990).
• Identify the correct role: When discussing GDPR, state clearly who is the Data Subject and who is the Data Controller.
• Link legislation to Information Systems: Always explain why the law matters to organisations (e.g., need for encryption, access controls, backups, privacy policies, staff training).