What is personal data?
Personal data is any information about a living person who can be identified. Your name, phone number, email, photo, home address and live location are all personal data.
Some data is sensitive. If it leaks, it can hurt you more. Examples: health records, fingerprints and face scans (called biometric data), religion, money details.
Small facts can join together. Your school name + birthday + town may be enough to find you. So even "small" data matters.
Privacy and the data trail
Privacy means you decide who can see your information and how it is used. It is a human right in many constitutions and in the Universal Declaration of Human Rights.
Online, you leave a data trail (also called a digital footprint):
- Cookies: small files a website saves to remember you and track what you click.
- Permissions: location, camera, microphone and contacts that apps ask for.
- Accounts and forms: what you type in yourself.
Consent means a clear, free yes. You can also take it back later.
Principles of data protection law
Countries make data-protection laws, such as the EU's GDPR (2018) and India's Digital Personal Data Protection Act (2023). They share common principles:
- Lawful and clear purpose: say why data is collected and use it only for that.
- Data minimisation: collect only what is needed.
- Accuracy: keep it correct.
- Security: protect it with passwords, encryption and limited access.
- Storage limit: delete it when the job is done.
- Accountability: the organisation must prove it follows the rules.
In a database, good practice means giving each staff member access only to the data they need, encrypting it, and keeping a log of who opened it.
Your rights, threats and safe habits
The person the data is about is called the data subject. Data subjects usually have the right to:
- access their data (see what is held),
- correct wrong data,
- erase data ("right to be forgotten"),
- object or withdraw consent,
- complain to a data-protection authority.
Threats: identity theft (someone uses your details to pretend to be you), data breach (data leaks from a company), phishing (fake messages that trick you into giving data), and selling data without consent.
Try it at home
Open one app's settings. Count how many permissions it has. Switch off any it does not need. Then use a strong, different password and turn on two-step login.
Key formulas and definitions
- [object Object]
- [object Object]
- [object Object]
- [object Object]
- [object Object]
Worked examples
1. A calculator app asks for location, contacts and microphone. Which should you allow?
None. A calculator does only maths, so it needs none of these. Allowing them breaks data minimisation and adds risk.
2. A school keeps every student's medical file in a shared folder that all staff can open. What principle is broken and how to fix it?
Security (and access limits). Health data is sensitive. Only the nurse and class teacher need it, so the folder should be locked and access limited and logged.
3. Riya gets an SMS: 'Your bank account is blocked. Click the link and type your password.' What is this and what should she do?
It is phishing, a trick to steal data. She should not click. She should call the bank on its official number and report the message.
Common mistakes
- Thinking only secret data is personal. Your name and photo are personal data too.
- Thinking 'I have nothing to hide' means privacy does not matter. Leaked data can be used for fraud.
- Clicking 'Allow all' on every app. Give only the permissions the app truly needs.
- Thinking deleting a post removes it everywhere. Copies and screenshots may stay.