📘 CodingMarble Learn

Data Privacy: Who Gets Your Data and How to Protect It

Personal data is any information that can point to you. Apps and websites collect it all the time. Privacy means you control who sees it and how it is used. Fair rules say data must be used for a clear purpose, kept small, kept safe and deleted when done. You have rights over your data, and simple habits keep you safe.

🎬 Step-by-step story

  1. Personal data is any fact that can point to you: name, phone, photo, location. Some data is sensitive, like health or fingerprints.
  2. Every app, website and card payment leaves a data trail. Small pieces of your data travel to company servers.
  3. Consent means your clear yes. The fewer permissions you give, the less data flows out.
  4. Anyone who holds data must follow four fair rules: clear purpose, collect little, keep it safe, delete when done.
  5. If data leaks, a thief can pretend to be you. Your rights let you see, correct, delete and complain.
  6. Free play: move the sharing slider and watch the risk meter rise or fall.

Tip: drag the 3D scene to turn it. Use two fingers to zoom.

🤔 Common doubts, cleared

Is my name really personal data? Everyone knows it.

Yes. It identifies you, and joined with other facts it can locate you.

Where does my data go when I use an app?

Small pieces travel to the company's servers through accounts, cookies and permissions.

Do I have to click Allow all?

No. Allow only what the app really needs. You can change it later in settings.

Can a company keep my data forever?

No. Under fair rules it must delete data when the purpose is over.

What can I do if my data is leaked?

Change passwords, tell your bank, ask the company what leaked, and complain to the authority.

What is personal data?

Personal data is any information about a living person who can be identified. Your name, phone number, email, photo, home address and live location are all personal data.

Some data is sensitive. If it leaks, it can hurt you more. Examples: health records, fingerprints and face scans (called biometric data), religion, money details.

Small facts can join together. Your school name + birthday + town may be enough to find you. So even "small" data matters.

Privacy and the data trail

Privacy means you decide who can see your information and how it is used. It is a human right in many constitutions and in the Universal Declaration of Human Rights.

Online, you leave a data trail (also called a digital footprint):

Consent means a clear, free yes. You can also take it back later.

Principles of data protection law

Countries make data-protection laws, such as the EU's GDPR (2018) and India's Digital Personal Data Protection Act (2023). They share common principles:

  1. Lawful and clear purpose: say why data is collected and use it only for that.
  2. Data minimisation: collect only what is needed.
  3. Accuracy: keep it correct.
  4. Security: protect it with passwords, encryption and limited access.
  5. Storage limit: delete it when the job is done.
  6. Accountability: the organisation must prove it follows the rules.

In a database, good practice means giving each staff member access only to the data they need, encrypting it, and keeping a log of who opened it.

Your rights, threats and safe habits

The person the data is about is called the data subject. Data subjects usually have the right to:

Threats: identity theft (someone uses your details to pretend to be you), data breach (data leaks from a company), phishing (fake messages that trick you into giving data), and selling data without consent.

Try it at home

Open one app's settings. Count how many permissions it has. Switch off any it does not need. Then use a strong, different password and turn on two-step login.

Key formulas and definitions

Worked examples

1. A calculator app asks for location, contacts and microphone. Which should you allow?

None. A calculator does only maths, so it needs none of these. Allowing them breaks data minimisation and adds risk.

2. A school keeps every student's medical file in a shared folder that all staff can open. What principle is broken and how to fix it?

Security (and access limits). Health data is sensitive. Only the nurse and class teacher need it, so the folder should be locked and access limited and logged.

3. Riya gets an SMS: 'Your bank account is blocked. Click the link and type your password.' What is this and what should she do?

It is phishing, a trick to steal data. She should not click. She should call the bank on its official number and report the message.

Common mistakes

Practice quiz

1. Which of these is sensitive personal data?
2. Data minimisation means:
3. Pretending to be someone using their stolen details is:
4. Valid consent must be:
5. The person whom the data is about is called the:

Practice: answer these yourself

Type or choose your answer, then press Check. Use a hint if you are stuck; the full solution appears after you answer.

Frequently asked questions

What is the difference between data privacy and data security?

Privacy is about who is allowed to use your data and why. Security is about the locks (passwords, encryption) that stop others from getting it.

What is GDPR?

The General Data Protection Regulation is the European Union's data-protection law from 2018. Many countries copied its ideas.

Does India have a data-protection law?

Yes. The Digital Personal Data Protection Act was passed in 2023. It gives people rights over their personal data and duties to companies.

Where this is taught

NetherlandsHAVO 5 (eindexamenjaar)Interaction
NetherlandsHAVO 5 (eindexamenjaar)Elective theme: Social and individual impact of computing
NetherlandsVWO 6 (eindexamenjaar)Interaction
NetherlandsVWO 6 (eindexamenjaar)Elective theme: Social and individual impact of computing
Spain4º ESODigital security and wellbeing
Germany (Bavaria)Jahrgangsstufe 9Data protection
FranceTerminaleManagement and digital — organisations and society

Learn first

Learn next

Related lessons

All Computer Science lessons