A data-protection risk is a way that personal data could be seen, changed, shared or lost by someone who should not have that power. Case-study questions ask you to find the risk in a described situation and name a sensible control.
This skill belongs to safety, security and effects and also supports your written answers on user accounts and records.
How do you find the risk in a case?
Work through four questions in order. Each one narrows the answer.
- What data is there? List it, and mark which items identify a person.
- Where is it kept? A shared computer, a USB stick, an email, a paper file.
- Who can reach it? Staff, visitors, anyone on the network.
- What could go wrong? Seen by the wrong person, copied, altered, lost or kept too long.
The control then answers the risk directly: a password for unwanted viewing, encryption for a lost device, a lock for a paper file, deletion for data kept too long.
Worked example
Invented case: Kampung Hijau Library (fictional) keeps a spreadsheet with member names, home addresses and the books borrowed. The file sits on a USB stick that the librarian carries in a bag between the library and home.
Step 1, data: names and home addresses identify people. The borrowing history shows personal interests.
Step 2, location: a portable USB stick with no protection.
Step 3, access: whoever finds or takes the stick can open the file.
Step 4, risk: the stick could be lost or stolen, so strangers could read members’ addresses and reading habits.
Control: encrypt the file so it cannot be understood without a key, and keep the master copy on the library computer with a password. State the reason: encryption protects the data even when the device is lost.
The mistake to watch for
A common slip is writing a risk that has nothing to do with the data in the case.
Mistaken answer: “The library could get a virus.”
This names a general danger but never connects to members’ addresses or the USB stick.
The fix is to tie the risk to the data and the weak point: “The USB stick could be lost, so members’ addresses could be read by a stranger.” Always include who or what is affected.
Check yourself
1. A clinic (fictional) emails appointment lists with patient names to every member of staff, including cleaners. Name the risk and one control.
Show answer
Risk: people who do not need the patient details can see them, which breaks the idea of using data only for its purpose. Control: give each role access only to the information it needs, for example a list without names for the cleaners.
2. A school keeps exam results for former pupils from ten years ago “just in case”. Which data-protection idea does this go against?
Show answer
Keeping personal data longer than needed. The control is a retention rule that deletes records after a set period.
3. Why is encrypting a file better than renaming it to hide it?
Show answer
A renamed file can still be opened by anyone who finds it. Encryption scrambles the contents so they cannot be read without the key.
Where this leads next
Once you can state a risk and control cleanly, move to backup and recovery and then test yourself on the practice set. The practical task and evidence checker is useful when a brief asks you to protect a file you have produced.
If your written answers are close but keep missing the exact wording, online one-to-one ICT tuition lets a teacher mark up your phrasing with you.